BitsToBug Studios LLP
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the master services agreement, statement of work or other written agreement (the “Principal Agreement”) between the client (the “Controller” or “Data Fiduciary”) and BitsToBug Studios LLP (the “Processor” or “Data Processor”). It governs the processing of personal data by BitsToBug on the client's behalf. In the event of conflict between this DPA and the Principal Agreement in relation to data protection, this DPA prevails.
This document is published for transparency. An executable copy for signature is available on request from support@bitstobug.com.
1. Scope and roles
The client determines the purposes and means of processing and acts as Controller. BitsToBug processes personal data solely on the client's documented instructions and acts as Processor. Where BitsToBug engages sub-processors, it does so as permitted under Section 5.
2. Processing details
| Item | Description |
|---|---|
| Subject matter | Provision of engineering, cloud, artificial intelligence, design and support services under the Principal Agreement |
| Duration | The term of the Principal Agreement, plus any agreed transition and deletion period |
| Nature and purpose | Development, integration, testing, hosting support, maintenance and troubleshooting of client systems |
| Types of personal data | As determined by the client, which may include identity, contact, account, transactional, usage and, where the client so instructs, special category data |
| Categories of data subjects | As determined by the client, which may include the client's customers, patients, citizens, employees and contractors |
3. Processor obligations
- Process personal data only on the client's documented instructions, including as to international transfers, unless required otherwise by law, in which case we will inform the client unless legally prohibited.
- Ensure that persons authorised to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures as set out in Section 4.
- Assist the client, insofar as reasonably possible, in responding to data subject requests and in fulfilling obligations relating to security, breach notification, data protection impact assessments and prior consultation.
- Not process personal data for our own purposes, and not sell, rent or otherwise disclose personal data except as permitted under this DPA.
- At the client's election, delete or return all personal data at the end of the engagement, and delete existing copies unless retention is required by law.
4. Security measures
BitsToBug maintains measures appropriate to the risk, including encryption in transit using industry standard protocols and at rest where supported; role based access control on the principle of least privilege; multi-factor authentication for administrative access; network segregation between client environments; secure software development practices including peer review and dependency scanning; centralised logging and monitoring; documented backup and recovery procedures; a documented incident response process; and periodic review of these measures. Further detail is published at https://www.bitstobug.com/security.
5. Sub-processors
The client grants general authorisation for BitsToBug to engage sub-processors, subject to the following. BitsToBug shall impose data protection obligations on each sub-processor no less protective than those in this DPA, shall remain fully liable for the performance of each sub-processor, shall maintain a current list of sub-processors available on request, and shall give the client at least thirty days notice of any intended addition or replacement, during which the client may object on reasonable data protection grounds.
6. Personal data breach
BitsToBug shall notify the client without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the client's personal data. The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. BitsToBug shall cooperate with the client and take reasonable steps to mitigate the effects.
7. International transfers
BitsToBug operates from India and may process personal data there. Where personal data originating in the European Economic Area or the United Kingdom is transferred, the parties shall enter into the applicable Standard Contractual Clauses or International Data Transfer Agreement, which are incorporated by reference. Where the Digital Personal Data Protection Act, 2023 applies, transfers shall comply with the Act and any restrictions notified by the Central Government. Where the client requires data residency in a specific jurisdiction, this shall be agreed in the Principal Agreement.
8. Audit
BitsToBug shall make available to the client all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the client or an auditor mandated by the client, on reasonable prior written notice, no more than once in any twelve month period except where required by a supervisory authority or following a personal data breach, during normal business hours, and subject to confidentiality obligations.
9. Liability and governing law
Liability under this DPA is subject to the limitations and exclusions set out in the Principal Agreement. This DPA is governed by the laws of India, and disputes shall be resolved in accordance with the dispute resolution provisions of the Principal Agreement.