Version 2.0 — July 1, 2026

Notice: This DPA applies to Drive.'s business and enterprise customers who are subject to the GDPR, UK GDPR, or equivalent data protection laws. If you are an individual user, our Privacy Policy governs how we process your data.

1. Definitions

Capitalized terms used in this DPA have the meanings given in the General Data Protection Regulation (Regulation (EU) 2016/679) where applicable.

2. Scope and Purpose

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Drive. ("Processor") and the Customer ("Controller") when the Customer uses Drive.'s services in a business or enterprise capacity. It sets out the terms governing the Processing of Personal Data by the Processor on behalf of the Controller.

3. Roles of the Parties

The Customer is the Controller of Personal Data processed under this DPA. Drive. is the Processor. Drive. processes Personal Data only on documented instructions from the Controller, unless required to do otherwise by applicable law.

4. Description of Processing

Categories of data subjects: End users of the Customer who use Drive. storage services.

Categories of personal data: Email addresses, display names, device identifiers, and encrypted file metadata.

Special categories of data: None. Drive.'s architecture prevents processing of special category data as all file content is end-to-end encrypted and inaccessible.

Processing operations: Collection, storage, transmission, and deletion of the above data for the purpose of providing encrypted storage services.

5. Processor Obligations

Drive. shall:

6. Data Subject Rights

Drive. shall assist the Controller in fulfilling its obligations to respond to data subject requests under Chapter III of the GDPR. Because of Drive.'s zero-knowledge architecture:

7. Subprocessing

The Controller provides general authorization for Drive. to engage Subprocessors. A current list of Subprocessors is maintained at drivedot.cloud/subprocessors. Drive. shall notify the Controller at least 30 days before adding or replacing any Subprocessor.

8. Technical and Organizational Measures

Drive. maintains the following security measures:

9. Security Breach Notification

Drive. shall notify the Controller within 48 hours of becoming aware of a Personal Data breach. The notification shall include:

10. Data Retention and Deletion

Upon termination of the Service, Drive. shall delete all Personal Data within 30 days, unless retention is required by applicable law. Encrypted files that have been deleted by the user may be removed from servers within 30 days.

11. Governing Law

This DPA shall be governed by and construed in accordance with the laws of India. Any disputes arising under this DPA shall be resolved in the courts of Kota, Rajasthan.

12. Contact

For DPA requests or questions:

Email: dpo@drivedot.cloud