Data Processing Addendum
Version 1.0 — Effective Date: 25 August 2026
This Data Processing Addendum ("DPA") forms part of the Osto Terms of Service and applicable Order Form between Customer and the Osto contracting entity identified in that Order Form.
| Controller / Data Fiduciary | Customer, where Customer determines the purposes and means of processing. |
|---|---|
| Processor / Data Processor | Osto, where Osto processes Personal Data on Customer's behalf. |
| Processing locations | India, the United States, and other locations used by approved Sub-processors, subject to applicable transfer requirements. |
| Contact | privacy@osto.one | legal@osto.one |
Drafting note: This DPA is drafted to operate with Osto's current Terms of Service and Privacy Notice, including the GDPR and India's Digital Personal Data Protection Act, 2023 ("DPDP Act") where applicable. Final legal review is recommended before publication or execution.
1. Scope and Applicability
1.1 Purpose. This DPA governs Osto's processing of Personal Data contained in Customer Data on Customer's behalf in connection with the Platform and applicable Platform Support Activities.
1.2 Relationship to Terms. The Terms of Service and applicable Order Form govern the purchase and use of the Platform. This DPA governs the processing of Personal Data. If this DPA conflicts with the Terms of Service concerning Personal Data processing, this DPA controls to the extent of the conflict.
1.3 Separate Controller Processing. Osto may process certain personal information for its own purposes, including account administration, billing, marketing, website operation, security, fraud prevention, legal compliance, and business relationship management. Such processing is governed by Osto's Privacy Notice and is outside this processor relationship.
1.4 Applicable Law. For GDPR processing, this DPA is intended to satisfy the applicable Article 28 controller-processor requirements. For processing subject to India's DPDP Act, this DPA applies to the extent the relevant provisions are applicable and in force. The parties will comply with mandatory processor requirements of other applicable Data Protection Laws.
2. Definitions
2.1 Defined Terms. Capitalized terms not defined here have the meanings given in the Terms of Service.
2.2 Data Protection Law. Means laws governing the privacy, protection, or security of Personal Data, including the GDPR, UK GDPR where applicable, the DPDP Act and applicable rules when in force, and other applicable data-protection laws.
2.3 Personal Data. Means personal data, personal information, or equivalent information contained in Customer Data that is subject to Data Protection Law.
2.4 Processing. Includes access, collection, storage, use, disclosure, transmission, analysis, retrieval, alteration, and deletion of Personal Data.
2.5 Sub-processor. Means a third party engaged by Osto to process Personal Data on Customer's behalf in connection with the Platform.
2.6 Security Incident. Means unauthorized acquisition of or access to Customer Data in Osto's possession or control that compromises its confidentiality, integrity, or availability, excluding failed attempts and events caused solely by Customer systems, credentials, Users, or third-party services.
3. Roles and Responsibilities
3.1 Customer. Customer determines the purposes and means of processing Personal Data through the Platform and is responsible for the lawful basis, required notices and consents, Data Subject or Data Principal rights, and the lawfulness of its instructions.
3.2 Osto. Osto processes Personal Data on Customer's behalf and in accordance with Customer's documented instructions, this DPA, the Terms of Service, the applicable Order Form, and applicable Data Protection Law.
3.3 Instructions. Customer's instructions include processing necessary to provide and operate the Platform and Platform Support Activities, the Order Form, this DPA, Customer's Platform configuration and use, and other lawful written instructions consistent with the Agreement. If Osto reasonably believes an instruction violates Data Protection Law, Osto will inform Customer unless prohibited by law.
3.4 Customer Data. Customer remains responsible for the accuracy, legality, quality, and completeness of Customer Data and for all rights, permissions, notices, consents, and lawful bases required to provide it to Osto or connect third-party systems.
4. Processing Details
4.1 Subject Matter. The subject matter is provision, operation, security, maintenance, support, configuration, and improvement of the Platform and Platform Support Activities.
4.2 Duration. Processing continues for the applicable Subscription Period and any additional period during which Osto is required or permitted to retain Personal Data under the Agreement or applicable law.
4.3 Nature and Purpose. Processing may include hosting, storage, transmission, security monitoring, vulnerability and compliance assessment, logging, support, troubleshooting, integration with connected systems, generation of Platform outputs, fraud and misuse prevention, and compliance with lawful instructions and applicable law.
4.4 Data Categories. Depending on the Platform capabilities used, Customer Data may include identity and contact information, account information, credentials and authentication data, device and endpoint information, network and system telemetry, logs, application and source-code data, security findings, compliance evidence, configuration data, prompts, and other information Customer elects to process.
4.5 Restricted Data. Customer must not intentionally submit Restricted Data except as permitted under the Terms of Service and applicable safeguards. If Restricted Data appears incidentally, it remains subject to this DPA and applicable security commitments.
4.6 Data Subjects. Depending on Customer's use of the Platform, the categories of Data Subjects or Data Principals whose Personal Data may be processed include Customer's employees, contractors, users, customers, prospective customers, suppliers, business contacts, and other individuals whose Personal Data is contained in Customer Data or in systems and environments connected to the Platform.
5. Osto Processing Obligations
5.1 Lawful Processing. Osto will process Personal Data only for the purposes described in this DPA and the Agreement, on Customer's documented instructions, or where required by applicable law.
5.2 Confidentiality. Osto will ensure that persons authorized to process Personal Data are subject to confidentiality obligations or an appropriate statutory duty and access Personal Data only as necessary for their role.
5.3 Assistance. Taking into account the nature of processing and information available to Osto, Osto will provide reasonable assistance with Data Subject or Data Principal requests, security obligations, breach response, and data-protection impact assessments where required by law.
5.4 Compliance Information. Osto will maintain information reasonably necessary to demonstrate compliance with this DPA and provide reasonable compliance information subject to confidentiality, security, and protection of proprietary information.
6. Security of Processing
6.1 Safeguards. Osto will maintain administrative, technical, physical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of Personal Data appropriate to the Platform and processing risks.
6.2 Measures. Measures include, as appropriate: access control and least privilege; authentication; confidentiality commitments; encryption in transit and at rest; logging and monitoring; vulnerability management; secure development; backup and recovery; incident response; and periodic security assessment.
6.3 Changes. Osto may update security measures to reflect changes in technology, threats, law, and the Platform, provided it will not materially weaken the overall level of protection applicable to Customer Data during the Subscription Period.
6.4 Customer Security. Customer remains responsible for credentials, account configuration, endpoints, integrations, access permissions, Customer systems, User activity, and other controls within its responsibility.
7. Security Incidents
7.1 Notification. Osto will notify Customer without undue delay, and in any event within seventy-two (72) hours after confirming a Security Incident affecting Customer Data.
7.2 Information. To the extent reasonably available and subject to legal and security restrictions, the notice will describe the nature of the incident, affected systems or data, known or reasonably suspected consequences, and containment and remediation measures.
7.3 Response. Osto will investigate, contain, mitigate, and remediate a confirmed Security Incident in accordance with its incident-response procedures and will provide reasonable cooperation required by applicable Data Protection Law.
7.4 Updates. Osto will provide material updates as reasonably appropriate while the incident remains under investigation or remediation.
7.5 No Admission. Notification does not constitute an admission of fault or liability. Failed attempts and events that do not compromise Customer Data are not Security Incidents.
8. Sub-processors
8.1 Authorization. Customer provides Osto general authorization to engage Sub-processors to process Personal Data for the purposes of providing the Platform.
8.2 List. Osto will maintain a current Sub-processor list and make it available through Osto's designated legal, privacy, or subprocessor disclosure channel.
8.3 Changes. Where required by applicable law, Osto will provide at least ten (10) days' notice before adding or replacing a Sub-processor that will process Customer Data, unless a shorter period is reasonably required by an urgent security, legal, or operational circumstance.
8.4 Objections. Where applicable law provides a right to object, Customer may object on reasonable data-protection grounds. The parties will work in good faith to address the objection and discuss commercially reasonable alternatives if Osto cannot reasonably resolve it.
8.5 Flow-down. Osto will require Sub-processors to be bound by written obligations concerning Personal Data appropriate to their processing role and will remain responsible for them to the extent required by applicable law and this DPA.
8.6 Affiliates and Providers. Osto may use Affiliates, authorized personnel, contractors, and service providers to operate and support the Platform, including providers that process Personal Data, subject to appropriate confidentiality and data-protection obligations.
9. Data Subject and Data Principal Rights
9.1 Requests. Osto will not independently respond to requests concerning Customer Data except where required by law. Where Osto receives such a request, it will, where legally permitted, direct the individual to Customer and provide reasonable assistance.
9.2 Assistance. Osto will provide reasonable technical and organizational assistance to enable Customer to respond to applicable rights requests, taking into account the nature of processing and information available to Osto.
9.3 Customer Instructions. Customer may instruct Osto to correct, return, restrict, or delete Customer Data where technically supported and subject to this DPA, the Terms of Service, and applicable law.
10. Impact Assessments and Regulatory Assistance
10.1 DPIA Assistance. Where required by applicable law, Osto will provide reasonable assistance with data-protection impact assessments, taking into account the nature of processing and information reasonably available to Osto.
10.2 Regulator Requests. Where legally permitted, Osto will promptly inform Customer of a legally binding request from a regulator or public authority for Customer Data and reasonably cooperate with Customer in responding where required by law.
10.3 Compelled Disclosure. If Osto is legally required to disclose Personal Data to a government authority, Osto will disclose only the data legally required and, where legally permitted, provide Customer reasonable notice and cooperation.
11. International Data Transfers
11.1 Locations. Customer acknowledges that Osto may process Customer Data in India, the United States, and other countries in which Osto or approved Sub-processors operate, subject to applicable law.
11.2 Transfer Mechanisms. Where EU GDPR or UK GDPR requires a transfer mechanism, the parties will use an applicable lawful mechanism, including adequacy decisions where available or the European Commission Standard Contractual Clauses ("EU SCCs") and, for UK transfers, the UK International Data Transfer Addendum or another lawful mechanism.
11.3 EU SCCs. Where EU SCCs are required, the legally appropriate controller-to-processor module will apply and be completed with the required transfer information. The EU SCCs control over this DPA to the extent of a direct conflict concerning the specific transfer.
11.4 Transfer Safeguards. Where required, Osto will apply reasonable safeguards and transfer-assessment measures appropriate to the destination, processing, and risks involved.
11.5 India. For processing subject to the DPDP Act, Osto and Customer will comply with applicable transfer restrictions and requirements that are in force. Osto may process Personal Data outside India where permitted by applicable law and Customer's documented instructions.
12. AI Features and Personal Data
12.1 No Model Training. Osto will not use Customer Data to train, fine-tune, or develop AI or machine-learning models, whether Osto's own or those of a third party, unless Customer expressly opts in.
12.2 AI Processing. Where Customer uses AI Features, Osto may route Customer Data through approved model providers solely to generate AI Output, subject to contractual restrictions appropriate to the service.
12.3 Customer Responsibility. Customer is responsible for determining whether and how AI Features may be used for its data, use case, workforce, customers, and regulatory environment, including required notices, consents, human oversight, and restrictions.
12.4 Feedback and Aggregated Data. Osto may use Feedback and Aggregated Data as permitted by the Terms of Service. Aggregated Data will not be used in a form that reasonably identifies Customer, its Users, or an individual.
13. Audits and Compliance Evidence
13.1 Evidence. Upon reasonable written request, Osto will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, policies, summaries of independent assessments, or other appropriate evidence.
13.2 Audit. Osto may satisfy an audit request by providing available third-party audit reports, certifications, penetration-test summaries, security questionnaires, or equivalent evidence where reasonably sufficient.
13.4 Costs. Customer bears its own audit costs.
14. Return, Deletion and Retention
14.1 During the Agreement. Customer may export Customer Data using functionality Osto provides and may request deletion during the Subscription Period where technically supported and permitted by the Agreement.
14.2 After Termination. After termination or expiry, Osto will keep export functionality available for thirty (30) days and may thereafter delete Customer Data from production systems within a further sixty (60) days, except data required by law, routine encrypted backups until normal rotation, and Aggregated Data.
14.3 Legal Retention. Where law requires retention, Osto will retain only what is required and protect it under this DPA for as long as retained.
14.4 Backups. Personal Data may remain in routine encrypted backups until normal rotation and will not be used for ordinary processing while retained solely for backup or recovery.
14.5 Deletion Confirmation. Upon reasonable written request, Osto will confirm deletion or return where the applicable retention circumstances permit such confirmation.
15. Communications and Confidentiality
15.1 Confidentiality. Each party will protect Personal Data and other Confidential Information in accordance with the confidentiality obligations in the Terms of Service.
15.2 Regulatory Communications. Each party is responsible for its own legally required notifications to regulators, Data Subjects, Data Principals, customers, employees, or other persons. Osto will reasonably cooperate with Customer where required by applicable law.
15.3 Public Statements. Neither party will make a public statement identifying the other party as responsible for a Security Incident or data-protection event without prior written coordination, except where disclosure is required by law, regulation, court order, or a competent authority.
15.4 Use of Platform. Customer will not represent to a regulator, auditor, customer, insurer, media outlet, or other third party that Osto's Platform constitutes an independent audit, certification, or guarantee of security or that an incident could not occur. Nothing prevents truthful disclosure where required by law or contract.
16. Liability
16.1 Terms of Service. The liability exclusions, allocations, and caps in the Terms of Service apply to this DPA and the processing of Personal Data, except to the extent a different allocation is required by applicable law.
16.2 No Double Recovery. A claim arising from the same event may not result in duplicative recovery under the Terms of Service and this DPA.
16.3 Mandatory Liability. Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited.
17. Term and Termination
17.1 Term. This DPA begins when it becomes applicable to the parties' processing of Personal Data and continues while Osto processes Personal Data on Customer's behalf.
17.2 End of Processing. This DPA terminates when Osto no longer processes Personal Data on Customer's behalf, subject to retention required or permitted under the Agreement or applicable law.
17.3 Survival. Confidentiality, security of retained Personal Data, deletion and retention, liability, and provisions that by their nature survive will survive termination for the required period.
18. General
18.1 Order of Precedence. If this DPA conflicts with the Terms of Service, this DPA controls only with respect to Personal Data processing. Customer-specific data-protection terms in an Order Form control only to the extent expressly stated and legally permitted.
18.2 Changes. Osto may update this DPA where reasonably required to reflect changes in law, the Platform, security practices, Sub-processors, or data-protection requirements, provided Osto will not materially reduce the protections applicable to Customer Data during a committed Subscription Period.
18.3 Severability. If any provision is unenforceable, it will be limited to the minimum extent necessary and the remaining provisions remain effective.
18.4 Electronic Acceptance. Electronic acceptance of the Terms of Service or an Order Form incorporating this DPA constitutes acceptance of this DPA.
18.5 No Third-Party Beneficiaries. This DPA does not create rights for third parties except where mandatory Data Protection Law expressly provides otherwise.
18.6 Contact. Privacy matters may be directed to privacy@osto.one. Legal notices may be directed to legal@osto.one.
Annex 1. Processing Details
A. Subject Matter and Purpose
Processing is carried out to provide, operate, secure, maintain, support, configure, and improve the Platform and Platform Support Activities, including cybersecurity, compliance automation, security assessments, VAPT, logging, integrations, security guidance, and related functionality.
B. Categories of Personal Data
- Names, work email addresses, phone numbers, job titles, organization and account information.
- User identifiers, authentication information, access records, and account activity.
- Device, endpoint, browser, IP address, network, operating system, application, and telemetry information.
- Security logs, vulnerability findings, scan results, compliance evidence, configuration information, and incident-related information.
- Source code, application data, prompts, files, documents, and other content Customer chooses to submit or connect.
- Other Personal Data contained in Customer Data or connected environments.
C. Categories of Data Subjects / Data Principals
Customer employees, contractors, Users, administrators, customers, prospects, suppliers, business contacts, and other individuals whose Personal Data is contained in Customer Data or connected environments.
D. Processing Operations
Collection, transmission, storage, organization, retrieval, access, analysis, security monitoring, vulnerability assessment, compliance assessment, logging, support, troubleshooting, integration, generation of Platform outputs, deletion, and other operations necessary to provide the Platform.
Annex 2. Technical and Organizational Measures
Access Control. Role-based and least-privilege practices, authentication controls, access reviews, and controlled administrative access.
Encryption. Encryption of Personal Data in transit using industry-standard transport security and encryption at rest where supported by the applicable Platform environment.
Personnel Security. Confidentiality obligations, role-based access, security and data-protection awareness, and access limited to personnel with a business need.
Logging and Monitoring. Logging and monitoring of relevant systems and security events to support detection, investigation, and response.
Vulnerability Management. Processes for identifying, assessing, prioritizing, and addressing vulnerabilities affecting systems used to provide the Platform.
Secure Development. Security practices integrated into software development, change management, testing, and release processes.
Incident Response. Procedures for identifying, investigating, containing, mitigating, remediating, and communicating Security Incidents.
Backup and Recovery. Backup and recovery controls appropriate to critical Platform infrastructure and operational dependencies.
Business Continuity. Reasonable continuity and recovery measures for critical Platform infrastructure and dependencies.
Sub-processor Management. Security and data-protection review of relevant providers and contractual obligations appropriate to their processing role.
Data Retention and Deletion. Deletion and retention practices consistent with the Agreement, including production deletion and routine backup rotation.
Physical Security. Physical access controls and safeguards appropriate to facilities used to process Customer Data.
Annex 3. International Transfer Framework
Where Personal Data is transferred from the European Economic Area or United Kingdom to a jurisdiction without an applicable adequacy mechanism, the parties will use a lawful transfer mechanism required by applicable law. Osto's current Privacy Notice states that it may process data in India and the United States and relies on European Commission Standard Contractual Clauses for applicable transfers, together with the UK International Data Transfer Addendum or UK International Data Transfer Agreement for applicable UK transfers.
Where EU SCCs are required for a controller-to-processor transfer, the parties will use the legally appropriate module and complete the required annex information. Where Osto acts as a processor and engages a Sub-processor in a third country, the applicable transfer mechanism will be implemented as required by applicable law.
Annex 4. Sub-processor Information
Osto maintains the current list of Sub-processors used to process Customer Data through its designated subprocessor disclosure channel. The list may identify the provider, service, processing purpose, and processing location. Customer may request the current list by contacting privacy@osto.one or legal@osto.one. Sub-processor changes are handled under Section 8 of this DPA and applicable law.
Publication checklist: Complete the Effective Date; publish the current Sub-processor List; confirm the applicable EU SCC/UK transfer documents and annex information; confirm the live Privacy Notice and Terms of Service; and have counsel review customer-specific, sector-specific, and jurisdiction-specific requirements.