Nabha

Nabha Data Processing Addendum (DPA)

Version 1.0 · Last updated 9 September 2026 · Varalix Digitech Solutions

This Addendum forms part of the Terms of Service whenever Customer Data includes personal data. It is written for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, and is compatible with the SPDI Rules 2011. Capitalised terms have the meaning given in the Terms. It applies automatically; enterprise customers who need a signed copy can write to founder@nabha.cloud.

1. Roles and scope

1.1 For personal data contained in Customer Data ("Customer Personal Data"), Customer is the Data Fiduciary (or acts for one) and Varalix is the Data Processor. Varalix processes Customer Personal Data only on Customer's documented instructions — the Terms, Customer's configuration of the Service, and written instructions — and for no other purpose, unless required by law, in which case Varalix will inform Customer unless the law prohibits it.

1.2 Nature and purpose: hosting, storage, parsing, visualisation, alarming, ML analysis and AI-assisted interpretation of device telemetry and related metadata; support. Duration: the term of the Terms plus the retention periods in Section 7. Categories of data principals: Customer's employees, contractors and operators; site contacts. Categories of data: names, work emails, roles, operator or shift identifiers, and any personal data Customer chooses to include in device payloads, tag names or dashboards. Customer should not send sensitive personal data (health, biometric or financial data) through the Service and represents that it will not do so without written agreement.

1.3 Customer is responsible for the lawfulness of the personal data it submits (notice, consent, purpose) and for its own obligations as Data Fiduciary, including notices to Data Principals, their rights, and any breach notification to the Data Protection Board of India.

2. Security measures

Varalix maintains, and will keep maintaining, at minimum: (a) encryption of personal data in transit and at rest, and hashing of credentials; (b) access control and least privilege on all systems holding Customer Personal Data, with isolation between organisations; (c) logging and monitoring of access, reviewed periodically, to detect, investigate and remediate unauthorised access; (d) measures to continue processing after a compromise of confidentiality, integrity or availability; (e) retention of the logs and personal data described in Section 7 for the periods stated there; (f) flow-down of equivalent security obligations to every sub-processor; and (g) other appropriate technical and organisational measures, which Varalix may update provided the overall level of protection is not reduced.

3. Personnel and confidentiality

Varalix ensures that every person authorised to process Customer Personal Data is bound by confidentiality and has received appropriate instruction.

4. Sub-processors

4.1 Customer authorises the sub-processors listed at nabha.cloud/legal/sub-processors as at the date Customer accepts the Terms: Google Cloud (hosting, India), Paddle and Razorpay (billing), Resend (transactional email), and the AI providers named in the AI Features Addendum, the latter only for data Customer submits to an AI-assisted feature.

4.2 Varalix will give at least 30 days' notice of any new or replacement sub-processor, by updating that page and emailing account administrators. Customer may object in writing on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of any prepaid fees for the unused part of the current billing month.

4.3 Varalix binds each sub-processor by written terms no less protective than this Addendum and remains responsible for its performance.

4.4 AI providers. Data reaches an AI provider only when a user in Customer's organisation uses an AI-assisted feature, and only the provider Customer has selected receives it. What is sent, and Customer's controls, are described in the AI Features Addendum.

5. Cross-border transfers

Primary processing takes place in India (Google Cloud, asia-south1, Mumbai). Customer authorises transfers to the countries listed on the sub-processor page for the stated purposes, subject to any conditions the Central Government notifies under section 16 of the DPDP Act. If a transfer becomes restricted, Varalix will stop it and, where feasible, offer an alternative.

6. Personal-data breach

6.1 Varalix will notify Customer of a personal-data breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it, with the information then reasonably available (nature, extent, timing, likely consequences, measures taken and proposed, and a contact person), and will supplement the notice as the investigation proceeds, so that Customer can meet its own duties to the Data Protection Board and to affected Data Principals.

6.2 Varalix separately complies with its own reporting duties, including CERT-In incident reporting, and will inform Customer where such a report concerns Customer Personal Data, unless the law prohibits it.

7. Retention, return and deletion

7.1 On termination or expiry, Customer may export Customer Data for 30 days (Terms, Section 11.3). After that window Varalix deletes Customer Personal Data from the live Service within 30 days and from backups in the ordinary backup cycle, and will confirm deletion in writing on request.

7.2 Statutory retention prevails. Varalix retains, in a restricted store, only what Indian law requires: personal data, traffic data and processing logs for 1 year from processing (DPDP Rule 8(3)); registration information for 180 days after cancellation (IT Rules 2021, Rule 3(1)(h)); subscriber records for 5 years after closure (CERT-In Directions 2022); and system logs for a rolling 180 days. These records are used for no other purpose and are deleted when the period ends.

8. Assistance and Data Principal rights

Varalix will, at Customer's reasonable request and at Customer's cost where the effort is material, assist Customer in responding to Data Principals' requests (access, correction, erasure, nomination, grievance) that Customer cannot fulfil itself through the Service. Any such request Varalix receives directly is forwarded to Customer without response other than an acknowledgement and redirection.

9. Audit

Once in any twelve months, and after a confirmed breach, Customer may request written evidence of Varalix's compliance with this Addendum: this Addendum, Varalix's published policies, and summaries of any third-party assessment or certification Varalix holds. An on-site audit is available only where a regulator or a law binding on Customer requires it, on 30 days' notice, during business hours, at Customer's cost, and under confidentiality.

10. Liability and precedence

Liability under this Addendum is subject to the limitations and exclusions in Section 10 of the Terms. If this Addendum conflicts with the Terms on the processing of Customer Personal Data, this Addendum prevails.

11. Contact

Varalix's contact for this Addendum and for Data Principals is founder@nabha.cloud. The Grievance Officer is named in Section 11 of the Privacy Policy.