Last updated: 1 July 2026 · Effective date: 1 July 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Zurlux Technologies Private Limited ("Zurlux", "Data Processor") and the Customer ("Data Fiduciary") for the provision of the PatchMortem service. This DPA is prepared in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.
1. Scope and purpose
This DPA applies to Zurlux's processing of personal data on behalf of the Customer in connection with the PatchMortem platform. Zurlux processes personal data only on documented instructions from the Customer and only as necessary to deliver the contracted service.
2. Definitions
- "Personal Data" has the meaning given in the DPDP Act 2023
- "Processing" means any operation performed on Personal Data including collection, storage, use, analysis, sharing, or deletion
- "Data Fiduciary" means the Customer, who determines the purpose and means of processing
- "Data Processor" means Zurlux, which processes data on behalf of the Data Fiduciary
3. Data Zurlux processes on your behalf
- Infrastructure telemetry: patch failure signals, Windows Event Log entries, error codes, and host identifiers collected by the PatchMortem agent
- End-user identifiers: names and email addresses of users who access the PatchMortem dashboard on behalf of the Customer
- Approval records: identifiers of personnel who approve or reject remediation actions within PatchMortem
4. Zurlux's obligations as Data Processor
- Process Personal Data only on documented instructions from the Customer
- Ensure that personnel authorised to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the Customer in responding to Data Principal rights requests within 30 days
- Notify the Customer without undue delay (and within 72 hours where feasible) upon becoming aware of a Personal Data breach
- On termination of the service, delete or return all Personal Data within 90 days unless retention is required by applicable law
- Make available to the Customer all information necessary to demonstrate compliance with this DPA
5. Sub-processors
Zurlux uses the following sub-processors to deliver the PatchMortem service. Customers will be notified of changes to this list with 30 days' notice:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure, compute, storage | ap-south-1 (Mumbai, India) |
| Pinecone | Vector database for patch pattern matching | India region |
| Anthropic | LLM fallback for classification (anonymised signals only) | API — no data retention |
6. Security measures
Zurlux implements the following technical and organisational measures:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for all data at rest
- Per-tenant encryption key isolation via AWS KMS
- Role-based access control with principle of least privilege
- Multi-factor authentication for all administrative access
- Append-only audit logging of all data access and processing activities
- Regular security assessments and penetration testing
7. Data localisation
All Customer Personal Data is stored and processed within India (AWS ap-south-1, Mumbai). Zurlux will not transfer Customer Personal Data outside India without prior written consent from the Customer and a valid legal basis under the DPDP Act 2023.
8. Audit rights
The Customer has the right to audit Zurlux's data processing activities related to Customer Data, upon 30 days' written notice, no more than once per calendar year. Zurlux will provide relevant documentation and reasonable access to support the audit.
9. Governing law
This DPA is governed by the laws of India, including the DPDP Act 2023 and associated rules. Any disputes will be resolved in accordance with the governing law clause of the main service agreement.
10. Contact
Data Protection contact:
Zurlux Technologies Private Limited
Flat No. 304, C-Wing, Aavishkar, Moshi, Pune, Maharashtra 412105
privacy@zurlux.com