Skip to content

Data Processing Agreement

Varcio Data Processing Agreement

The standard terms under which we process personal data on a customer's behalf: our role, security safeguards, sub-processors, where data is hosted, breach notice, audit and deletion.

Last updated

About this agreement

This Data Processing Agreement (the “DPA”) forms part of the agreement between Varcio (“Varcio”, “we”) and the customer that has subscribed to the Varcio service (the “Customer”) (together, the “Agreement”). It applies to the extent Varcio processes Personal Data on the Customer’s behalf.

This is our standard agreement, version 1.0. It applies to every customer that uses the service. If you need changes, or a signed copy for your records, write to support@varcio.com.

1. Definitions

“Personal Data”, “Data Fiduciary”, “Data Processor”, “Data Principal”, “Personal Data Breach” and “processing” have the meanings given in the Digital Personal Data Protection Act 2023 and its Rules (together, the “DPDP Law”). “Data Protection Law” means the DPDP Law and any other law on the protection of personal data that applies to the processing under this DPA, including the Information Technology Act 2000 and the rules under it while they remain in force.

“Customer Personal Data” means Personal Data contained in content the Customer or its users submit to, connect to, or generate in the service: for example cloud inventory and billing metadata, resource tags, support tickets, assistant conversations, and uploaded documents. “Sub-processor” means a third party Varcio engages to process Customer Personal Data.

2. Roles and scope

  1. For Customer Personal Data, the Customer is the Data Fiduciary and Varcio is its Data Processor. Varcio processes it only to provide, secure, support and bill for the service, and as the Customer instructs.
  2. For personal data Varcio collects for its own purposes (for example account sign-in details, billing contacts, and website and status-page visitors), Varcio is a Data Fiduciary and handles it under its Privacy Policy. This DPA does not govern that data.
  3. The Customer is responsible for having a lawful basis to give Varcio Customer Personal Data, for the accuracy of the instructions it gives, and for the notices and consents its own Data Principals are owed.

3. Instructions

Varcio processes Customer Personal Data on the Customer’s documented instructions. The Agreement, this DPA, and the Customer’s use and configuration of the service are its complete instructions. Varcio will tell the Customer if it believes an instruction infringes Data Protection Law. Varcio will not use Customer Personal Data to train machine-learning models, and will not sell it or use it for advertising.

4. Confidentiality and personnel

Varcio limits access to Customer Personal Data to personnel who need it to provide the service, and binds them to written confidentiality obligations that continue after their engagement ends.

5. Security safeguards

Varcio maintains reasonable security safeguards to protect Customer Personal Data, including those in Annex 2, and will not materially reduce them during the term. These are intended to meet the security safeguards in DPDP Rule 6, including encryption, access control, logging and monitoring, and backups for continued processing, and the retention of logs and processing records for at least one year.

6. Sub-processors

  1. The Customer gives Varcio general authorisation to engage the Sub-processors listed on the Varcio Trust Center at the date of the Agreement and in Annex 3.
  2. Varcio will give at least 30 days’ notice of a new Sub-processor, or of a change to the country in which a Sub-processor processes Customer Personal Data, by updating the Trust Center and emailing the Customer’s registered administrators.
  3. The Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve it; if they cannot, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the remainder of the term.
  4. Varcio imposes on each Sub-processor written obligations no less protective than this DPA and remains responsible for their performance.

7. Data location and transfers

  1. Customer Personal Data is hosted in the AWS region stated on the Trust Center on the effective date of the Agreement (Annex 4). Varcio will give at least 30 days’ notice before moving it to a different country, except where a move is needed to comply with law or to respond to an emergency, in which case Varcio will notify the Customer as soon as it can.
  2. Where processing involves a transfer outside India, Varcio will comply with the DPDP Law, including any restriction the Central Government notifies on transfer to a country or territory, and will tell the Customer if a restriction affects the service.
  3. Where the Customer is subject to a sector rule that requires data to be held in India, the parties will record that requirement in a signed order, and Varcio will host the Customer’s data accordingly.

8. Personal Data Breach

  1. Varcio will notify the Customer’s security contact without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Where the Customer has told Varcio in writing that it is a regulated entity with a shorter regulatory reporting period, Varcio will use reasonable efforts to notify it in time for the Customer to meet that period.
  2. The notice will describe, as far as then known: the nature of the breach and when it occurred; the categories and approximate number of Data Principals and records; the likely consequences; the measures taken or proposed; and a contact. Varcio will add detail as it learns it.
  3. Varcio will cooperate with the Customer’s investigation and with the Customer’s notices to the Data Protection Board of India, to affected Data Principals, and to any other authority.
  4. Varcio reports cyber incidents to the Indian Computer Emergency Response Team (CERT-In) as the law requires. Varcio’s process is documented in its Personal Data Breach Response Procedure, which it will make available to the Customer on request.

9. Data Principal requests

If Varcio receives a request from a Data Principal about Customer Personal Data, it will refer the person to the Customer and will not respond on the Customer’s behalf unless the Customer asks it to. Taking into account the nature of the processing, Varcio will give the Customer reasonable assistance, by product features (including export, correction and deletion) or on request, so the Customer can meet its obligations on access, correction, erasure and grievance redressal.

10. Assistance and records

Varcio will give the Customer the information reasonably needed to show compliance with this DPA and to carry out any data-protection impact assessment or audit the Customer or a regulator requires, and will keep records of the processing it carries out for the Customer.

11. Audit

  1. Varcio will make available its current security documentation, policies and any independent audit reports it holds, and will answer reasonable security questionnaires.
  2. If that is not enough, the Customer may audit Varcio’s compliance with this DPA once a year, or after a Personal Data Breach, on 30 days’ written notice, during business hours, under confidentiality, and without unreasonable disruption. Where the Customer is a regulated entity, Varcio will give the access to records and premises that its regulator requires of the Customer, and will require its Sub-processors to allow the same where the Customer’s regulator requires it.
  3. Each party bears its own costs, except that Varcio will bear the reasonable cost of an audit that finds a material breach of this DPA.

12. Return and deletion

  1. The Customer may export its data through the product during the term and during the 30-day window that follows a request to close the organisation.
  2. After that window, Varcio deletes Customer Personal Data from its production systems, including uploaded files. Copies in backups and prior file versions expire within 7 days after deletion.
  3. Varcio keeps what the law requires it to keep (for example accounting records, and processing logs for the period the DPDP Law prescribes) and a permanent record that the deletion occurred, and continues to protect it under this DPA.
  4. On request Varcio will confirm the deletion in writing.

13. Liability, term and precedence

Each party’s liability under this DPA is subject to the limitations in the Agreement. This DPA lasts as long as Varcio processes Customer Personal Data. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails. The governing law and courts are those stated in the Agreement.

Annex 1. Details of processing

Subject matter
Providing the Varcio cloud-cost management platform.
Duration
The term of the Agreement, plus the return and deletion period in clause 12.
Nature and purpose
Hosting, storing, analysing and displaying Customer Personal Data; generating recommendations and reports; sending notifications; providing support; securing and backing up the service.
Data Principals
The Customer’s employees, contractors and other users; people named in resource tags, tickets, chat and uploaded documents; and people whose data the Customer otherwise connects.
Categories of Personal Data
Names, work email addresses and other contact details; user and account identifiers; cloud resource owner and team tags; free text in tickets, conversations and documents; IP addresses and device data of users.
Sensitive data
The service is not designed to receive payment-card data, government identifiers or health data. The Customer should not submit them.

Annex 2. Security measures

  • Encryption in transit with TLS 1.2 or later on every public hostname; encryption at rest with AES-256 for the database, object storage and cache.
  • Credentials and integration secrets are additionally encrypted per record with envelope encryption under a customer-managed AWS KMS key.
  • Access control: authenticated sessions, role-based permissions, workspace-scoped queries, multi-factor authentication and passkey options, and single sign-on (SAML and OIDC) where the Customer enables it.
  • Logging and monitoring: an audit log, hash-chained per workspace so tampering is detectable, and infrastructure audit trails; logs are retained for at least one year.
  • Backups: automated database backups with point-in-time recovery for 7 days.
  • Change control, vulnerability disclosure, penetration testing programme and incident response as described in Varcio’s published policies.
  • The current, dated description of these measures is on the Varcio Trust Center, which prevails if it is more specific.

Annex 3. Sub-processors

The current list, with the purpose, the data involved and the region for each, is published on the Varcio Trust Center and is part of this DPA. Changes follow clause 6.

Annex 4. Hosting location

The AWS region that hosts Customer Personal Data on the effective date is stated on the Varcio Trust Center under “Data residency”. Clause 7 applies to any change.

General support
support@varcio.com
Billing and invoice questions
billing@varcio.com

Signed-in customers can also use the in-product Support page for account-specific issues.

Back to top

  • Varcio is a digital software service. No physical goods are shipped.
  • Cloud-provider usage and infrastructure charges remain billed by the relevant cloud provider.
  • If a signed order form, MSA, or enterprise agreement exists, that document controls over these public pages to the extent of any conflict.