Logo
Riven

Data Processing Agreement

Last updated 13 September 2026

This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions (the “Agreement”) between Riven Deploy, a sole proprietorship owned by Aakash Mistry (“Riven Deploy”, “we”, “us”, “our”), and the person or organisation that uses our Services (“Customer”, “you”, “your”).

This DPA applies to the extent that we process personal data on your behalf in the course of providing the Services. It supplements, and does not replace, our Privacy Policy, which describes how we handle personal data for which we ourselves are responsible.

By using the Services, you accept this DPA. If you require a countersigned copy for your records, see Section 16.

1. Definitions

1.1

Terms including "Data Fiduciary", "Data Processor", "Data Principal", "personal data" and "personal data breach" have the meanings given to them in the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it.

1.2

"Customer Data" means personal data that you, or the end users of your applications, upload to, store on, transmit through, or otherwise process using the Services, and which we process on your behalf.

1.3

"Services" means the deployment, hosting, storage, database and related services made available by Riven Deploy.

1.4

"Sub-processor" means a third party engaged by us that processes Customer Data in connection with the Services.

2. Roles of the parties

2.1

You are the Data Fiduciary in respect of Customer Data. You determine the purposes and means of its processing.

2.2

We act as a Data Processor in respect of Customer Data, and process it solely on your behalf.

2.3

We are an independent Data Fiduciary in respect of the account data we collect from you directly, for example your name, email address, authentication identity and billing information. That processing is governed by our Privacy Policy and not by this DPA.

2.4

Nothing in this DPA makes us a joint fiduciary with you, or gives us any right to determine the purposes for which Customer Data is processed.

3. Details of the processing

3.1

Subject matter. Provision of application deployment, hosting, compute, storage, database and related services as described in the Agreement.

3.2

Duration. For the term of the Agreement, together with the retention period described in Section 12.

3.3

Nature and purpose. Hosting, storing, transmitting, processing and making available Customer Data as technically necessary to run the applications and services you deploy, and to provide support you request.

3.4

Types of personal data. Determined entirely by you through the applications you deploy. We do not prescribe or inspect the categories of data you choose to process.

3.5

Categories of Data Principals. Determined entirely by you. These typically include your own end users, customers, employees, contractors and business contacts.

3.6

Your instructions. Your documented instructions to us consist of the Agreement, this DPA, the configuration choices you make within the platform, and any further written instructions you give us in relation to the Services. We will inform you if, in our reasonable opinion, an instruction appears to conflict with the DPDP Act.

4. Our obligations

4.1

We will process Customer Data only for the purpose of providing the Services and only on your instructions as described in Section 3.6.

4.2

We will not sell, rent, license or otherwise make Customer Data available to any third party except as permitted under Section 9 (Sub-processors) or as required by law.

4.3

We will not use Customer Data for our own purposes, including product development, benchmarking, analytics, advertising or the training of machine learning models.

4.4

We will implement and maintain the security measures described in Section 7.

4.5

We will ensure that any person we authorise to access Customer Data is subject to a duty of confidentiality and processes Customer Data only as necessary to perform their role.

4.6

We will provide you with reasonable assistance, at your cost where the effort is material, in:

  1. (a)responding to requests from Data Principals exercising their rights;
  2. (b)meeting your own obligations in relation to security safeguards and breach reporting;
  3. (c)responding to enquiries from the Data Protection Board of India or any other competent authority.
4.7

If we receive a legally binding demand from a public authority for Customer Data, we will, unless prohibited by law, notify you before disclosing anything, and will limit any disclosure to what is legally required.

5. Your obligations

5.1

You are responsible for establishing and maintaining a lawful basis for the collection and processing of Customer Data, including providing any notice to and obtaining any consent from your Data Principals that the DPDP Act requires.

5.2

You are responsible for the accuracy, quality and legality of Customer Data and for the means by which you acquired it.

5.3

You are responsible for security within your own application, including your source code, dependencies, application-level access controls, user authentication, API keys, database credentials and the configuration of your deployments.

5.4

You will not upload to or process through the Services any category of personal data that is subject to additional legal or regulatory requirements beyond those addressed in this DPA, including payment card data subject to PCI DSS, or health records subject to specific regulatory regimes, unless we have agreed to this with you in writing in advance.

5.5

You will respond to requests from your own Data Principals. Where such a request relates to Customer Data held on our systems and you cannot fulfil it through the platform's own features, you may ask us for assistance under Section 4.6.

6. Confidentiality and access to Customer Data

6.1

We treat Customer Data as confidential and do not access the contents of your applications, databases or storage volumes except where strictly necessary:

  1. (a)to provide technical support that you have requested;
  2. (b)to investigate or remedy a fault, outage or security issue affecting the platform;
  3. (c)to protect the security, integrity or availability of the Services or of other customers;
  4. (d)where required by law or by a competent authority.
6.2

Access under Section 6.1 is limited to authorised personnel, restricted to what is necessary in the circumstances, and recorded. We will make a record of such access available to you on reasonable written request.

6.3

Our confidentiality obligations survive the termination of the Agreement.

7. Security measures

7.1

We maintain reasonable technical and organisational security safeguards designed to protect Customer Data against unauthorised access, disclosure, alteration, loss and destruction. Our current measures are described on our security page and include:

  1. (a)encryption of data in transit using TLS across the platform and for applications hosted on it;
  2. (b)isolation of each customer's workloads, with separate namespaces and separate credentials;
  3. (c)restricted and authenticated access to production infrastructure, limited to authorised personnel;
  4. (d)role-based access control and audit logging within customer workspaces;
  5. (e)continuous monitoring of platform availability, with alerting;
  6. (f)handling of payment information entirely by our payment gateway, such that card and UPI details are never stored on our systems.
7.2

Our security page also sets out, transparently, the measures we do not currently have in place, including the absence of multi-server failover and the absence of formal certifications such as SOC 2 or ISO 27001. You acknowledge that you have had the opportunity to review that page and have assessed whether the Services are appropriate for your intended use.

7.3

We may update our security measures from time to time. We will not make changes that materially reduce the overall level of protection afforded to Customer Data.

7.4

You are responsible for assessing whether the measures described in Section 7.1 are appropriate having regard to the nature and sensitivity of the Customer Data you choose to process using the Services.

8. Personal data breach

8.1

If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay, and in any event within seventy-two (72) hours of becoming aware of it.

8.2

Our notification will include, to the extent the information is available to us at the time:

  1. (a)a description of the nature of the breach;
  2. (b)the categories and approximate volume of Customer Data affected;
  3. (c)the likely consequences of the breach;
  4. (d)the measures we have taken or propose to take to address it and to mitigate its effects.
8.3

Where we do not have all of this information at the time of first notification, we will provide it in stages as it becomes available, without further undue delay.

8.4

We will notify you using the email address registered on your account. You are responsible for keeping a monitored email address on file for this purpose.

8.5

We will take reasonable steps to contain and remediate the breach, and will cooperate with you so that you can meet your own notification obligations to Data Principals and to the Data Protection Board of India.

8.6

Our notification to you under this Section is not, and should not be treated as, an acknowledgement of fault or liability on our part.

8.7

Breaches occurring within your own application, including those arising from your source code, dependencies, credentials or configuration, are not personal data breaches of ours. We will assist you in investigating such incidents under Section 4.6, but responsibility for them rests with you.

9. Sub-processors

9.1

You give us general authorisation to engage Sub-processors to process Customer Data in connection with the Services.

9.2

Our current Sub-processors are:

Sub-processorPurposeProcessing location
Amazon Web Services India Private LimitedCloud infrastructure, compute and storageIndia (Mumbai, ap-south-1)
Razorpay Software Private LimitedPayment processing and invoicingIndia
[Transactional email provider]Platform and notification emails[location]
9.3

Before we engage a new Sub-processor that will process Customer Data, or replace an existing one, we will give you at least thirty (30) days' notice by email or through the platform.

9.4

If you have a reasonable objection to a new Sub-processor on data protection grounds, you may notify us within that notice period. We will work with you in good faith to address the objection. If we cannot, you may terminate the affected Services without penalty, and we will refund any prepaid fees covering the unused remainder of the then-current billing period.

9.5

We impose data protection obligations on our Sub-processors that are no less protective than those in this DPA, and we remain responsible to you for their performance.

10. Data Principal rights

10.1

The platform provides features that allow you to access, export and delete Customer Data held on our systems, so that you can respond to requests from your Data Principals directly.

10.2

Where you are unable to fulfil such a request using those features, we will provide reasonable assistance under Section 4.6.

10.3

If we receive a request directly from one of your Data Principals in relation to Customer Data, we will not respond to it substantively. We will instead direct the individual to you, and inform you of the request, unless we are legally required to act otherwise.

11. Data location and transfers

11.1

Applications, services and databases you deploy on Riven Deploy are hosted on infrastructure located in India (AWS Mumbai, ap-south-1).

11.2

We do not transfer Customer Data outside India except where a Sub-processor listed in Section 9.2 processes limited operational data outside India as indicated in that table, or where you yourself configure your application to send data to a destination outside India.

11.3

Where you configure your application to transmit Customer Data to third-party services outside India, that transfer is made by you and under your control, and this DPA does not apply to it.

12. Retention, return and deletion

12.1

You may export Customer Data at any time during the term of the Agreement using the platform's export features, or by connecting directly to your own services and databases.

12.2

On termination or expiry of the Agreement, we will retain Customer Data for fifteen (15) days so that you can export it, after which it will be deleted from our active production systems.

12.3

Where your account is terminated by us for illegal use, abuse, security threat, or where immediate action is required by law, Customer Data may be deleted without the retention period in Section 12.2.

12.4

Residual copies of Customer Data may persist in system backups or logs for a limited further period, and will be removed in the ordinary course of our retention cycles and in any event within thirty (30) days of the deletion under Section 12.2. Such copies are not accessed during that period except where required by law.

12.5

We will confirm deletion in writing on your reasonable written request.

12.6

We may retain Customer Data beyond these periods only where and for so long as retention is required by applicable law, and in that case only for the purpose of that legal requirement.

13. Audits and information

13.1

On reasonable written notice, and no more than once in any twelve (12) month period unless a personal data breach has occurred, we will:

  1. (a)respond to a reasonable written security and data protection questionnaire; and
  2. (b)provide such information within our possession as is reasonably necessary to demonstrate our compliance with this DPA.
13.2

We are not currently certified under SOC 2, ISO 27001 or any equivalent framework, and do not hold audit reports of that kind. This is stated openly on our security page.

13.3

We do not offer on-site or physical audits of our infrastructure, which is operated by the Sub-processor named in Section 9.2 and is not under our physical control. Where you require assurance in respect of that infrastructure, the relevant certifications are published by that Sub-processor.

13.4

Any information disclosed to you under this Section is our confidential information and may be used only for the purpose of assessing our compliance with this DPA.

14. Liability

14.1

Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement, including the aggregate cap on liability contained in it.

14.2

The limitations in Section 14.1 do not apply to liability that cannot lawfully be limited or excluded, including liability arising from fraud, gross negligence or wilful misconduct.

14.3

You will indemnify us against claims, penalties and losses arising from your failure to comply with Section 5, including your failure to establish a lawful basis for processing Customer Data or to provide required notices to your Data Principals.

15. Term, changes and precedence

15.1

This DPA takes effect when you begin using the Services and continues for as long as we process Customer Data on your behalf.

15.2

We may update this DPA from time to time, including to reflect changes in law, in our Sub-processors, or in our security measures. Where a change is material, we will give you at least thirty (30) days' notice by email or through the platform before it takes effect.

15.3

We will not make changes to this DPA that materially reduce the protections afforded to Customer Data.

15.4

If there is any conflict between this DPA and the Agreement in relation to the processing of Customer Data, this DPA prevails. In all other respects the Agreement prevails.

15.5

If any provision of this DPA is found to be unenforceable, the remaining provisions continue in full force.

16. Acceptance and signed copies

16.1

This DPA applies automatically to your use of the Services. No signature is required for it to take effect.

16.2

If your organisation requires a countersigned copy for its records, email us at [email protected] with your legal entity name, registered address and the name and designation of your authorised signatory. We will send a copy of this DPA, signed on our behalf, for you to countersign.

16.3

The terms of a countersigned copy issued under Section 16.2 will be identical to this published DPA. We do not negotiate variations to this DPA on standard plans. If your requirements go beyond it, contact us to discuss a custom arrangement.

17. Contact and grievances

17.1

For any matter relating to this DPA, including data protection enquiries, breach notifications and requests under Sections 4.6, 12.5 or 13.1, contact:

Aakash Mistry

Proprietor and Grievance Officer, Riven Deploy

[email protected]

[email protected]

17.2

We will acknowledge communications sent to this address within forty-eight (48) hours and will respond substantively within thirty (30) days.

18. Governing law and jurisdiction

18.1

This DPA is governed by the laws of India.

18.2

The courts at Mumbai, Maharashtra have exclusive jurisdiction over any dispute arising out of this DPA, subject to any dispute resolution provisions in the Agreement.