sales@mtechzilla.com+1 302 208 5468

MTechZilla Data Processing Addendum

GDPR / UK GDPR – Controller–Processor Data Processing Terms

Version 1.0 | 24 August 2026

International transfers: This DPA contains transfer provisions but does not reproduce the official EU SCCs or UK IDTA/Addendum. Where a restricted transfer occurs, the applicable official transfer mechanism must be completed and incorporated/executed as required.

Table of Contents

1. Purpose and Application

MTechZilla Technologies Private Limited (“MTechZilla”, “Processor”, “we”, “us” or “our”) provides information technology, software development, consulting, staffing and related services. This Data Processing Addendum (“DPA”) governs the processing of Personal Data by MTechZilla on behalf of a customer (“Customer” or “Controller”) where the Customer acts as controller and MTechZilla acts as processor under the EU GDPR, UK GDPR, or another applicable data protection law requiring materially equivalent processor terms.

This DPA forms part of the applicable Master Services Agreement, Statement of Work, Service Agreement, Order Form or other written agreement between the Customer and MTechZilla (the “Agreement”). Where this DPA conflicts with the Agreement on data protection matters, this DPA prevails to the extent necessary to satisfy applicable data protection law, unless expressly agreed otherwise in writing.

This DPA does not apply to Personal Data for which MTechZilla determines the purposes and means of processing in its own capacity as a controller. MTechZilla’s public Privacy Policy describes such controller processing.

2. Definitions

“Data Subject”, “Personal Data”, “Processing”, “Controller”, “Processor”, “Sub-processor” and related terms have the meanings given under applicable data protection law. “Customer Data” means Personal Data processed by MTechZilla on behalf of the Customer under the Agreement.

“Applicable Data Protection Law” means the EU GDPR, UK GDPR, applicable national implementing legislation, and other data protection laws expressly applicable to the Processing under the Agreement. “Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data.

3. Roles and Instructions

The Customer is the Controller and MTechZilla is the Processor for Customer Data, except where applicable law or the Agreement expressly provides otherwise.

MTechZilla shall process Customer Data only on the Customer’s documented instructions, including instructions concerning the subject matter, duration, nature and purpose of Processing, categories of Data Subjects, categories of Personal Data, retention and deletion. The Agreement and applicable SOW constitute the Customer’s initial documented instructions.

MTechZilla shall promptly inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. MTechZilla shall not process Customer Data for its own independent purposes, except where required by law or expressly authorised in writing by the Customer.

4. Confidentiality

MTechZilla shall ensure that persons authorised to process Customer Data are bound by appropriate confidentiality obligations or an appropriate statutory duty of confidentiality. Access to Customer Data shall be limited to personnel and contractors who require access for the performance of the services and related support functions.

MTechZilla shall provide appropriate privacy and security awareness training to personnel with material access to Customer Data and shall maintain internal policies governing the handling of Personal Data.

5. Security of Processing

MTechZilla shall implement and maintain appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data, taking into account the nature of the Processing, the state of the art, implementation costs and the risk to Data Subjects.

Baseline measures are described in Annex 2. They may be supplemented by security commitments in the Agreement, SOW, security schedule, SOC report, ISO certification or other written security documentation provided to the Customer. MTechZilla may update security measures where the overall level of security is not materially reduced.

6. Assistance with Data Subject Rights

Taking into account the nature of the Processing, MTechZilla shall provide reasonable assistance to the Customer to enable the Customer to respond to requests by Data Subjects exercising rights under Applicable Data Protection Law, including access, rectification, erasure, restriction, portability and objection, to the extent applicable.

If MTechZilla receives a Data Subject request relating to Customer Data, MTechZilla shall, unless prohibited by law, promptly refer the request to the Customer and shall not independently respond except as instructed by the Customer or required by law.

7. Security Incidents and Breach Assistance

MTechZilla shall notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Data. The notification shall, to the extent reasonably available, describe the nature of the incident, categories of data and Data Subjects affected, likely consequences, mitigation measures taken or proposed, and a point of contact.

MTechZilla shall reasonably cooperate with the Customer in investigating, mitigating and documenting a Security Incident and in preparing notifications required by Applicable Data Protection Law. MTechZilla shall not notify a supervisory authority or Data Subject concerning Customer Data unless required by law or instructed by the Customer.

8. Sub-processors

The Customer provides MTechZilla with general authorisation to engage Sub-processors for the Processing of Customer Data, subject to this section. MTechZilla shall maintain a current list of material Sub-processors used to process Customer Data and make it available to the Customer on request or through an online notice where practicable.

MTechZilla shall enter into a written agreement with each Sub-processor imposing data protection obligations materially equivalent to those applicable to MTechZilla under this DPA, to the extent relevant to the services.

MTechZilla remains responsible to the Customer for the performance of the Sub-processor’s obligations to the extent required by Applicable Data Protection Law. MTechZilla shall provide notice of material Sub-processor changes where required by the Agreement or Applicable Data Protection Law. The Customer may object on reasonable data protection grounds within the agreed notice period.

9. International Transfers

Where Customer Data is transferred from the EEA to MTechZilla in India, or otherwise to a country not recognised as providing adequate protection, the parties shall use an applicable lawful transfer mechanism.

For transfers subject to the EU GDPR, the parties may incorporate the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, using Module 2 (Controller to Processor), where applicable, with the Customer as Data Exporter and MTechZilla as Data Importer. The SCCs shall be completed with the processing details in Annex 1 and security measures in Annex 2 and prevail in the event of conflict concerning the international transfer.

For transfers subject to the UK GDPR, the parties shall use the UK International Data Transfer Agreement or UK International Data Transfer Addendum to the EU SCCs, as applicable. The applicable transfer mechanism shall be completed and executed or incorporated as required.

MTechZilla shall notify the Customer if it becomes aware of a legal requirement that materially prevents compliance with an applicable transfer mechanism, unless prohibited by law.

10. Government and Law-Enforcement Requests

If MTechZilla receives a legally binding request from a public authority for Customer Data, MTechZilla shall, unless legally prohibited, notify the Customer before disclosure and provide reasonable assistance so the Customer may assess or challenge the request. MTechZilla shall disclose only the minimum amount legally required.

11. DPIAs and Regulatory Assistance

Taking into account the nature of the Processing and information available to MTechZilla, MTechZilla shall reasonably assist the Customer with data protection impact assessments, prior consultations with supervisory authorities, security assessments and other compliance activities required by Applicable Data Protection Law.

MTechZilla shall make available information reasonably necessary to demonstrate compliance with its processor obligations under this DPA and Applicable Data Protection Law.

12. Audit and Compliance Information

Upon reasonable written request, MTechZilla shall provide information reasonably necessary to demonstrate compliance with this DPA, including relevant security documentation, certifications, independent audit reports or summaries, and responses to reasonable security questionnaires, subject to confidentiality and security restrictions.

Where the information provided is insufficient and Applicable Data Protection Law requires an audit, the Customer may conduct, or appoint an independent auditor to conduct, an audit on reasonable notice during normal business hours, subject to reasonable confidentiality, access-control, safety and business-continuity requirements.

Where the Customer has access to a relevant independent SOC 1/SOC 2 or equivalent report covering the applicable services and period, the parties shall first use that report and related documentation to satisfy reasonable assurance requirements before requesting an on-site audit.

13. Records and Accountability

MTechZilla shall maintain records of Processing carried out on behalf of Customers to the extent required by Applicable Data Protection Law and shall make relevant information available to the Customer or supervisory authority as legally required.

MTechZilla shall maintain appropriate internal procedures for privacy governance, information security, incident response, access management and third-party risk management.

14. Return and Deletion of Customer Data

At the Customer’s choice, upon termination or expiry of the relevant services MTechZilla shall return or securely delete Customer Data, unless retention is required by Applicable Data Protection Law. Where deletion is required, MTechZilla shall use reasonable measures to securely delete or render Customer Data inaccessible, subject to technical backup cycles and legal retention requirements.

Customer Data remaining in backups as part of ordinary disaster-recovery processes shall remain protected and shall not be restored or otherwise processed except for disaster recovery or legal compliance, after which it shall be deleted in accordance with normal retention cycles.

15. Customer Responsibilities

The Customer is responsible for determining the purposes and means of Processing, establishing a lawful basis for Processing, providing required privacy notices, obtaining required consents, ensuring its instructions to MTechZilla are lawful, responding to Data Subject requests, and ensuring Customer Data supplied to MTechZilla is adequate, relevant and limited to what is necessary for the agreed services.

The Customer shall not instruct MTechZilla to process special-category data, criminal-offence data, children’s data or other highly sensitive information unless the parties have agreed the relevant Processing and safeguards in writing.

16. Liability and Priority

Nothing in this DPA limits a party’s liability where such limitation is prohibited by Applicable Data Protection Law. Commercial liability, indemnity and limitation provisions remain governed by the Agreement unless the parties expressly agree otherwise.

Where this DPA is incorporated into an Agreement, references to applicable law include the applicable EU GDPR and/or UK GDPR to the extent they apply to the Processing.

17. Term and Changes

This DPA remains in effect for so long as MTechZilla processes Customer Data on behalf of the Customer under the Agreement. The parties may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Law, regulatory guidance, transfer mechanisms or security practices, provided that a material change does not materially reduce the protections afforded to Customer Data.

18. Contact

For privacy and data protection matters, contact: privacy@mtechzilla.com. MTechZilla’s public Privacy Policy identifies its privacy contact and grievance officer details.

Annex 1 – Details of Processing

  • Subject matter: Processing of Personal Data necessary to provide contracted IT services, including software development, application support, cloud/hosting-related support, consulting, project delivery, staffing or other services specified in the Agreement/SOW.
  • Duration: For the term of the Agreement and thereafter for the limited period required to return, delete or retain Personal Data as permitted or required.
  • Nature and purpose: Collection, access, consultation, use, hosting, storage, organisation, modification, transmission, support, troubleshooting, security monitoring and deletion solely to provide and support the contracted services.
  • Categories of Data Subjects: Customer employees and contractors; Customer customers, users, prospects and business contacts; suppliers and business partners; website/application users; and other individuals whose Personal Data the Customer instructs MTechZilla to process.
  • Categories of Personal Data: Identification and contact details; professional information; account and authentication information; technical/device and usage information; communications; transaction and service information; project/application data; and other categories specified in the Agreement/SOW. Special-category data should be processed only where expressly agreed and legally permitted.
  • Processing locations: India and other countries in which MTechZilla or approved Sub-processors operate, subject to applicable transfer mechanisms and Customer instructions.

Annex 2 – Technical and Organisational Measures

  • Access control: Role-based and least-privilege access; access limited to personnel with a business need; authentication controls and, where implemented for the relevant system, multi-factor authentication; periodic review and removal of unnecessary access.
  • Confidentiality: Personnel and relevant contractors are subject to confidentiality obligations; privacy/security responsibilities are communicated through policies and training.
  • Transmission security: TLS or equivalent encryption is used where appropriate to protect Personal Data in transit.
  • Storage security: Encryption at rest is used for applicable systems and data stores. MTechZilla’s current public Privacy Policy states that stored credentials are protected using encryption and that AES-256 encryption is used for stored data where applicable.
  • Network and endpoint security: Firewalls, malware protection, secure configuration, patching and other reasonable controls appropriate to the environment.
  • Secure development: Security considerations are incorporated into development and change processes appropriate to the services, including access control, testing and vulnerability remediation where applicable.
  • Logging and monitoring: Security-relevant events are logged and monitored to the extent appropriate to the systems and risk.
  • Backup and recovery: Backup, recovery and business-continuity measures are maintained where necessary for the contracted service and applicable risk profile.
  • Incident response: Documented procedures for identifying, assessing, escalating, containing, investigating, remediating and documenting Security Incidents.
  • Data minimisation and retention: Customer Data is processed only as necessary for the contracted services and is returned/deleted in accordance with the DPA and Agreement.
  • Physical security: Reasonable physical and environmental safeguards are maintained at offices and data-centre/hosting locations used for Customer Data, including where controls are provided by an approved hosting provider.
  • Third-party risk: Material Sub-processors are subject to contractual data protection and security requirements and appropriate vendor due diligence.
  • Governance: MTechZilla maintains privacy and information-security policies and supports compliance through internal accountability, documented procedures and appropriate assurance activities.

Annex 3 – Sub-processor and Transfer Information

MTechZilla may use hosting, analytics, communications, CRM, scheduling, hiring, development or other service providers that process Personal Data in connection with the services. Customer Data Sub-processors should be confirmed against the applicable service/SOW before execution.

  • EU transfer mechanism: Where required, EU SCCs (Module 2, Controller to Processor) under Commission Implementing Decision (EU) 2021/914.
  • UK transfer mechanism: UK IDTA or UK International Data Transfer Addendum to the EU SCCs, as applicable.
  • Sub-processor changes: MTechZilla will provide notice where required by the Agreement or Applicable Data Protection Law and will maintain a process for addressing reasonable data-protection objections