Last updated July 13, 2026
This Data Processing Agreement (DPA) defines the relationship between you (the Controller) and Nexline Global Pvt. Ltd. (the Processor) when processing personal data.
Effective as of: July 13, 2026
Parties:
This DPA applies when you use Uprity to process personal data of customers, employees, or other data subjects. It is mandatory for customers subject to:
By using Uprity to process personal data, you agree to this DPA.
The Processor processes personal data only on documented instructions from the Controller, including:
Instructions are defined in the Privacy Policy and Terms of Service.
The Processor implements appropriate technical and organizational measures to protect personal data:
See our Security page for full details.
The Processor engages sub-processors (third-party service providers) to process personal data. The Controller is informed of all sub-processors via the Sub-processors list.
The Processor:
The Processor assists the Controller in responding to data subject requests for:
Requests must be submitted through your account or via privacy@uprity.com. The Processor acknowledges requests promptly and responds within 30 days (consistent with our Privacy Policy), or any shorter period required by applicable law.
Upon discovering a personal data breach affecting the Controller's personal data, the Processor notifies the Controller without undue delay, and in any case within 72 hours of discovery, so that the Controller can meet its own notification obligations (e.g., to supervisory authorities under GDPR, or to the Data Protection Board of India and affected data principals under the DPDPA 2023 and its Rules). Where Nexline Global Pvt. Ltd. is itself the Data Fiduciary for the affected data, it will make those notifications directly.
Notification includes:
Personal data may be transferred to countries outside the data subject's jurisdiction. For transfers between India and the EU, the Processor relies on:
An SCCs annex is appended to this DPA and available upon request.
This DPA remains in effect for the duration of the Service. Upon termination:
The Controller may audit the Processor's compliance with this DPA through:
If and when we obtain third-party security certifications (e.g., SOC 2), reports will be made available under NDA on request.
The Processor's aggregate liability under this DPA is subject to the same limitations and cap as the Terms of Service (fees paid in the 3 calendar months preceding the claim), except where applicable data protection law does not permit such limitation.
The Processor may modify this DPA if required by law. Material changes are communicated 30 days in advance. The Controller may terminate the Service if changes are unacceptable.
This DPA is executed by and between the Parties as of the Effective Date. It supplements the Terms of Service and Privacy Policy.
For Enterprise customers: A signed DPA PDF is available upon request. Email legal@uprity.com for execution.
Questions about this DPA?