GDPR, DPDP, CCPA-ready data processing terms — including SCCs, HIPAA BAA, and AI Training annexes for enterprise compliance.
Last Updated
March 2026
Document Type
DPA + Annexes
Coverage
GDPR · DPDP · CCPA · HIPAA
This Data Processing Addendum forms part of the Terms and Conditions and any applicable Marketplace Agreement between Kuinbee Information Services Private Limited ("Processor") and the entity accessing or using Kuinbee's platform services ("Controller").
⚠️ Scope: This DPA applies where Kuinbee processes Personal Data on behalf of the Customer. Enterprise customers may request execution of this DPA at legal@kuinbee.com.
"Applicable Data Protection Laws"
All laws applicable to the processing of Personal Data, including but not limited to:
Where Kuinbee processes Customer Personal Data in connection with platform services, Kuinbee acts as a Data Processor. Customer acts as the Data Controller, determining the purpose and means of processing.
Subject Matter: Processing necessary to provide marketplace and data infrastructure services.
Duration: For the term of the Agreement and until deletion or return of Personal Data.
Nature of Processing:
Categories of Data Subjects
Customer users · Business representatives · End-users (if applicable)
Categories of Personal Data
Account information · Business contact data · Uploaded structured datasets (if containing personal data)
Kuinbee shall:
Kuinbee implements commercially reasonable safeguards including:
Security measures are periodically reviewed and updated.
Where Personal Data is transferred outside the originating jurisdiction, Kuinbee shall ensure lawful transfer mechanisms:
Customer acknowledges that cross-border hosting may occur where infrastructure is globally distributed.
Kuinbee shall assist Customer, where technically feasible, in responding to:
If Kuinbee receives a data subject request directly, it shall forward the request to Customer unless legally prohibited.
Kuinbee shall notify Customer without undue delay after becoming aware of a breach affecting Customer-controlled data.
Notification shall include, where available:
Kuinbee shall cooperate in investigation and mitigation.
Upon reasonable notice, Customer may request information demonstrating compliance. Kuinbee may satisfy audit requirements through:
Physical audits shall be subject to confidentiality safeguards and reasonable scheduling.
Upon termination of services, Kuinbee shall:
unless retention is required by law. Backup deletion may occur in accordance with retention cycles.
Each Party's liability under this DPA shall be subject to the liability limitations set out in the main Agreement. Nothing in this DPA limits liability where such limitation is prohibited by Applicable Data Protection Laws.
Where Datasets are uploaded by independent Suppliers:
This DPA applies only to data processed by Kuinbee as Processor.
This DPA shall be governed by the laws specified in the main Agreement.
In the event of conflict:
Supporting documents incorporated by reference into this DPA.
Data Exporter (Controller)
Enterprise Customer using Kuinbee services
Data Importer (Processor)
Kuinbee Information Services Pvt. Ltd., Pune, Maharashtra, India
Purpose of Processing:
Categories of Data Subjects:
Customer representatives · Business users · Dataset data subjects (if personal data included) · API users
Sensitive Data Handling:
Where special categories are processed: enhanced safeguards apply, encryption enforced, access strictly role-based, processing only under lawful basis.
Access Control
Data Transmission
Data Storage
Infrastructure
Incident Response
Personnel & Sub-Processors
Where GDPR applies and transfers occur outside the EEA, Kuinbee supports:
Upon request, Kuinbee may:
SCCs may be incorporated by reference into the DPA.
⚠️ This section applies only where Customer uploads or processes Protected Health Information (PHI).
Kuinbee acts as a Business Associate solely for hosting or transmission functions, where applicable.
Kuinbee shall:
Subcontractors handling PHI must agree to equivalent safeguards. If Kuinbee materially breaches HIPAA obligations and fails to cure, Customer may terminate.
This annex applies where Datasets are used for machine learning or AI training.
Lawful Basis Requirements:
Bias & Fairness Controls:
Prohibited AI Uses:
Regulatory Alignment:
Enterprise customers may request a signed copy of this DPA, SCC execution, or HIPAA BAA by contacting:
Legal
legal@kuinbee.com