Version 2.0 — July 1, 2026
1. Definitions
Capitalized terms used in this DPA have the meanings given in the General Data Protection Regulation (Regulation (EU) 2016/679) where applicable.
- Controller: The entity that determines the purposes and means of processing personal data.
- Processor: The entity that processes personal data on behalf of the Controller.
- Personal Data: Any information relating to an identified or identifiable natural person.
- Subprocessor: A third-party processor engaged by the Processor.
2. Scope and Purpose
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Drive. ("Processor") and the Customer ("Controller") when the Customer uses Drive.'s services in a business or enterprise capacity. It sets out the terms governing the Processing of Personal Data by the Processor on behalf of the Controller.
3. Roles of the Parties
The Customer is the Controller of Personal Data processed under this DPA. Drive. is the Processor. Drive. processes Personal Data only on documented instructions from the Controller, unless required to do otherwise by applicable law.
4. Description of Processing
Categories of data subjects: End users of the Customer who use Drive. storage services.
Categories of personal data: Email addresses, display names, device identifiers, and encrypted file metadata.
Special categories of data: None. Drive.'s architecture prevents processing of special category data as all file content is end-to-end encrypted and inaccessible.
Processing operations: Collection, storage, transmission, and deletion of the above data for the purpose of providing encrypted storage services.
5. Processor Obligations
Drive. shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure that persons authorized to process Personal Data are bound by confidentiality
- Implement appropriate technical and organizational measures as described in Section 8
- Not engage Subprocessors without prior notice and the Controller's consent
- Assist the Controller in responding to data subject requests
- Notify the Controller of any Personal Data breach without undue delay
- Delete or return all Personal Data at the end of the Service
6. Data Subject Rights
Drive. shall assist the Controller in fulfilling its obligations to respond to data subject requests under Chapter III of the GDPR. Because of Drive.'s zero-knowledge architecture:
- Access requests: Drive. can provide account metadata and encrypted file blobs.
- Rectification requests: Controllers can modify display names and profile information directly.
- Erasure requests: Drive. will delete all associated Personal Data within 30 days of account deletion.
- Portability requests: Drive. can export account metadata in a structured format.
7. Subprocessing
The Controller provides general authorization for Drive. to engage Subprocessors. A current list of Subprocessors is maintained at drivedot.cloud/subprocessors. Drive. shall notify the Controller at least 30 days before adding or replacing any Subprocessor.
8. Technical and Organizational Measures
Drive. maintains the following security measures:
- End-to-end encryption for all files, documents, and media
- Encryption at rest for all stored data (AES-256)
- TLS 1.3 with certificate pinning for all data in transit
- Hardware-backed key storage in device secure enclaves
- Access controls with role-based permissions and audit logging
- Regular security training for all employees
- Annual third-party security audits and penetration testing
- 24/7 intrusion detection and security monitoring
- Incident response plan with defined SLAs
9. Security Breach Notification
Drive. shall notify the Controller within 48 hours of becoming aware of a Personal Data breach. The notification shall include:
- The nature of the breach, including categories and approximate number of data subjects affected
- Contact information for further information
- Likely consequences and measures taken or proposed
10. Data Retention and Deletion
Upon termination of the Service, Drive. shall delete all Personal Data within 30 days, unless retention is required by applicable law. Encrypted files that have been deleted by the user may be removed from servers within 30 days.
11. Governing Law
This DPA shall be governed by and construed in accordance with the laws of India. Any disputes arising under this DPA shall be resolved in the courts of Kota, Rajasthan.
12. Contact
For DPA requests or questions:
Email: dpo@drivedot.cloud