Simplify, Automate, and Scale Your Cloud Deployments in minutes!
Why Choose Kuberns for Your Cloud Deployment?
Boundless Features Built to Save You Time & Money
Find the Perfect Pricing Plan for You
Data Processing Addendum
The terms on which we process personal data on your behalf, what we commit to, and what stays your responsibility.
1. When this applies
This Addendum forms part of the Terms of Servicebetween Kuberns Tech Private Limited (“Kuberns”, “we”) and the customer who accepted them (“you”). You do not need to sign it separately — it applies automatically for as long as you use the platform.
It governs one specific thing: personal data inside the applications you deploy on Kuberns. For that data you are the Data Fiduciary (controller) and we are the Data Processor, and this Addendum sets out what we may do with it.
It does notgovern data about you as our account holder — your name, email, billing records and dashboard usage. For that data we are the Data Fiduciary in our own right, and the Privacy Policy applies instead. The distinction is set out in §2 of that policy.
Terms used here carry the meanings given in the Digital Personal Data Protection Act, 2023. Where you are subject to the GDPR, read “Data Fiduciary” as “controller”, “Data Processor” as “processor” and “Data Principal” as “data subject”.
2. What we process for you
Subject matter and nature. Hosting, building, deploying and operating the applications and managed resources you configure, and providing you logs, metrics and support in relation to them.
Purpose. To provide the platform to you. We do not process this data for any purpose of our own.
Duration. For as long as your account is active, plus the periods set out in §9 and on our Data Retention page.
Categories of personal data. Whatever your application holds. We do not control or inspect it. In practice this typically includes the contents of your managed databases, files your application writes, values you place in environment variables, and personal data that appears in your application logs.
Categories of data principals.Whoever uses your application — your customers, your employees, or your own end users.
Special categories. The platform is not designed for, and we do not knowingly accept, health, biometric, financial-account or government-identifier data placed into a deployed application without a prior written agreement with us. If your application handles such data, tell us before you deploy it.
3. Your instructions
We process personal data in your applications only on your documented instructions. Your use of the platform — the resources you create, the configuration you set, the actions you take in the dashboard and API — constitutes those instructions.
We will also process it where Indian law requires us to, in which case we will tell you before we do so unless the law prohibits us from telling you.
What we never do with it. We do not sell it, share it with data brokers, use it to build profiles, use it for advertising or analytics, or use it to train our own models. This is stated publicly in §4 of our Privacy Policy and it binds us here too.
If we believe an instruction you give us would breach the Act, we will tell you. We are not obliged to carry it out.
4. Confidentiality and staff access
Staff who can reach production systems are limited, bound by confidentiality obligations that survive the end of their engagement, and granted access only where their role requires it.
Actions taken against production systems are attributable to an individual. Access is removed when someone leaves or changes role.
5. Security measures
We maintain the following technical and organisational measures. They are the same measures described in §10 of our Privacy Policy, restated here as a contractual commitment rather than a description.
- Encryption in transit. TLS on all connections to the platform.
- Encryption at rest for the most sensitive categories, including the environment variables and secrets you configure, managed-database credentials, connected-account access tokens, payment mandate tokens and SSL private keys.
- Access control. Role-based permissions on the platform, restricted staff access to production, and authenticated, attributable administrative action.
- Isolation. Your workloads run in resources provisioned for your environment, in the region you select.
- Integrity of the deployment path. Signature verification on inbound repository webhooks, and least-privilege cloud credentials for the infrastructure we provision.
- Monitoring and logging, retained only as long as we need them and as long as Indian law requires.
- Resilience. Health checks and automated recovery of failed containers, and backups of managed databases where you have enabled them.
What remains yours. The security of your own application code and dependencies, the credentials you supply, who you grant access to your projects, your data classification decisions, and taking and testing your own backups. Automated recovery of a container is not a substitute for a recoverable backup.
We may update these measures, but not in a way that materially reduces the level of protection.
6. Sub-processors
You give us general authorisation to engage sub-processors. The current list, what each one receives, and where it processes, is published at kuberns.com/subprocessors and kept up to date.
Each sub-processor is engaged under a written contract imposing data protection obligations substantially the same as those in this Addendum. We remain responsible to you for their performance.
Changes. We will update that page before a new sub-processor begins processing personal data on your behalf. If you object to an addition on reasonable data protection grounds, tell us within 30 days and we will work with you to find an alternative; if we cannot, you may terminate the affected service without penalty.
7. Helping you answer data-principal requests
Requests from your end users are yours to answer, not ours. You have direct access to the data in your applications through the platform, which is normally all that is required.
If a data principal contacts us directly about data inside your application, we will not respond substantively. We will tell them to contact you, and tell you that they contacted us.
Where you cannot fulfil a request through the platform itself, we will give you reasonable assistance, taking into account the nature of the processing and the information available to us.
8. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf.
Our notice will describe, so far as we know it at the time:
- what happened and when we became aware of it;
- the categories and approximate volume of personal data and data principals affected;
- the likely consequences;
- what we have done and are doing about it;
- a contact point for further information.
Where we cannot provide all of that at once, we will provide it in stages as it becomes available rather than delaying the first notice.
Notifying the Data Protection Board and affected data principals in respect of data inside your application is your obligation as Data Fiduciary. We will give you the information you reasonably need to do it.
9. Deletion and return of your data
You can export or delete data in your applications yourself at any time, through the platform.
On termination of your account, personal data we hold on your behalf is deleted within 30 days, except where Indian law requires us to retain something for longer — principally tax and accounting records, and the logs we are required to keep. Those are retained for the periods set out on our Data Retention page and for no other purpose.
Take any export you need before you terminate. We cannot restore an account or its data after deletion has run.
Backups are cycled out on their own schedule; data in a backup is not returned to active use and is overwritten in the ordinary course.
10. Information and audit
On reasonable written request, and no more than once a year unless required by a regulator or following a breach affecting you, we will provide the information reasonably necessary to demonstrate our compliance with this Addendum.
What we can offer today. Written answers to security and privacy questionnaires, and the documentation published here and on the pages this Addendum links to. We do not currently hold a third-party certification such as SOC 2 or ISO 27001, and we would rather say so than imply otherwise.
On-site audits are available only where a regulator requires one, on reasonable notice, during business hours, subject to confidentiality, and without disrupting the platform or exposing another customer’s data.
11. Where processing happens
Your applications run in the AWS region you select: Mumbai, N. Virginia, London, Frankfurt or Sydney.
Our control plane — the dashboard, account records, project metadata and build logs — is in Mumbai, India.
AI processing takes place outside India, at the providers listed on our Subprocessors page. Which provider handles a given request depends on availability, so the country can vary.
Under s.16 of the Act, transfers outside India are permitted except to countries the Central Government has restricted by notification. Where a transfer is also subject to the GDPR, it is made under the European Commission’s Standard Contractual Clauses, which are incorporated into this Addendum by reference, with Kuberns as data importer.
12. Precedence and changes
Where this Addendum conflicts with the Terms of Service on the processing of personal data, this Addendum prevails. In all other respects the Terms continue to apply.
Our liability under this Addendum is subject to the limitations and exclusions in the Terms.
If we change this Addendum, we publish the new version here with a new version number and a dated entry below. Where a change materially reduces your rights, we will give notice before it takes effect.
Questions about this Addendum, or a request for a countersigned copy, go to our Grievance Officer at the address in §13 of the Privacy Policy.
13. Version history
Each revision of this Addendum is numbered, so you can tell which version applied and when it changed. We keep the previous entries here rather than replacing them.
- Version 1.0— 3 September 2026. First published.

