Data Processing Addendum
Version 1.0 — Effective: June 17, 2026
1. Introduction
1.1This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between FactoryNerve Technologies Pvt. Ltd. (“FactoryNerve,” “Processor”) and the Customer (“Controller”).
1.2 This DPA governs the processing of Personal Data by FactoryNerve on behalf of the Customer in connection with the provision of the FactoryNerve platform and services.
1.3This DPA is effective upon the Customer’s acceptance of the Agreement and continues in effect until the Agreement is terminated.
1.4This DPA is governed by the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and, where applicable, other data protection laws, including the UK GDPR and India’s Digital Personal Data Protection Act, 2023.
2. Definitions
Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. In addition:
- “Customer” means the entity that has subscribed to the FactoryNerve platform and acts as the Data Controller.
- “FactoryNerve” means FactoryNerve Technologies Pvt. Ltd., acting as the Data Processor.
- “Personal Data” means any information relating to an identified or identifiable natural person as defined in Article 4(1) of the GDPR.
- “Processing” has the meaning given in Article 4(2) of the GDPR.
- “Data Subject” means an identified or identifiable natural person as defined in Article 4(1) of the GDPR.
- “Sub-processor” means a third-party engaged by FactoryNerve to process Personal Data on behalf of the Customer.
- “Supervisory Authority” means an independent public authority established pursuant to Article 51 of the GDPR.
3. Scope and Roles
3.1 The parties acknowledge and agree that:
- The Customer is the Data Controller of all Personal Data processed through the FactoryNerve platform.
- FactoryNerve is the Data Processor of that Personal Data, acting on the documented instructions of the Customer.
Categories of Data Subjects
The Personal Data processed concerns the following categories of Data Subjects:
- Customer’s employees and workers whose attendance, shift, and production data is recorded
- Customer’s contractors, temporary staff, and visitors
- Customer’s authorized users and account administrators
Categories of Personal Data
The Personal Data processed includes:
- Employee names, identification numbers, contact details, and role/designation
- Attendance records, check-in/out times, shift assignments, and leave records
- Production performance data associated with individual workers
- Any other Personal Data uploaded to the platform by the Customer
Purpose of Processing
FactoryNerve processes Personal Data solely for the purpose of providing the FactoryNerve platform and related services as described in the Agreement, including attendance tracking, production reporting, inventory management, OCR document processing, invoicing, and employee management, all on the documented instructions of the Customer.
4. Customer Obligations (as Data Controller)
The Customer is responsible for:
- Establishing a lawful basis for processing Personal Data and complying with applicable data protection laws.
- Obtaining all necessary consents from Data Subjects where required by law.
- Ensuring the accuracy, completeness, and legality of all Personal Data uploaded to the platform.
- Providing appropriate privacy notices to Data Subjects regarding the processing of their data.
- Responding to Data Subject requests (FactoryNerve will assist as described in Section 9).
- Configuring the platform’s access controls, retention settings, and security features appropriately.
5. FactoryNerve Obligations (as Data Processor)
FactoryNerve shall:
- Process Personal Data only on the documented instructions of the Customer, unless required to do otherwise by applicable law (in which case FactoryNerve will notify the Customer of that legal requirement before processing, unless prohibited).
- Ensure that all persons authorized to process Personal Data are bound by appropriate confidentiality obligations.
- Implement and maintain the technical and organizational security measures described in Section 6 and Annex 2.
- Assist the Customer in fulfilling its obligations to respond to Data Subject requests (Section 9).
- Assist the Customer with data protection impact assessments and consultations with Supervisory Authorities, where required.
- Delete or return all Personal Data upon termination of the Agreement (Section 11).
- Make available all information necessary to demonstrate compliance with this DPA.
6. Security Measures
FactoryNerve shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as described in our Security page. These measures include, at minimum:
- Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256).
- Access controls based on the principle of least privilege.
- Multi-factor authentication for administrative access.
- Regular vulnerability scanning and penetration testing.
- 24/7 monitoring, intrusion detection, and incident response procedures.
- Automated daily backups with cross-region redundancy.
7. Sub-processors
7.1 The Customer authorizes FactoryNerve to engage Sub-processors to process Personal Data. A current list of Sub-processors is maintained at /subprocessors.
7.2 FactoryNerve shall notify the Customer of any intended changes concerning the addition or replacement of Sub-processors at least 30 days in advance via email.
7.3 The Customer may object to a new Sub-processor within 30 days of notification. If the objection is reasonable and cannot be resolved within 30 days, the Customer may terminate the Agreement without penalty.
7.4 FactoryNerve shall enter into written agreements with all Sub-processors that impose data protection obligations equivalent to those in this DPA. FactoryNerve remains fully liable for all acts and omissions of its Sub-processors.
8. International Data Transfers
8.1The Customer’s Personal Data is primarily stored in AWS Mumbai, India (ap-south-1). When Personal Data is transferred from the European Economic Area (EEA), the United Kingdom, or Switzerland to India or other countries, the following safeguards apply:
- Standard Contractual Clauses (SCCs): FactoryNerve has executed the EU Standard Contractual Clauses (Module 2: Controller-to-Processor) with all relevant Sub-processors.
- Data Processing Agreements: Written DPAs with all Sub-processors incorporating the required transfer safeguards.
- Supplementary measures: Technical controls (encryption, access controls) as described in Section 6.
8.2 FactoryNerve will ensure that all transfers of Personal Data comply with applicable data protection laws and will implement any additional measures required by regulatory guidance.
9. Data Subject Rights
9.1 FactoryNerve shall assist the Customer in responding to Data Subject requests under Chapter III of the GDPR, including rights of:
9.2 FactoryNerve shall respond to any assistance request from the Customer regarding Data Subject rights within 5 business days.
9.3If a Data Subject makes a request directly to FactoryNerve, FactoryNerve shall promptly forward the request to the Customer (within 48 hours) and shall not respond to the Data Subject without the Customer’s prior authorization.
10. Data Breach Notification
10.1 FactoryNerve shall notify the Customer without undue delay and, where feasible, within 24 hours of becoming aware of a confirmed Personal Data Breach involving Customer Data.
10.2 The notification shall include, to the extent available:
- The nature of the Personal Data Breach, including categories and approximate number of Data Subjects and records concerned.
- The likely consequences of the Personal Data Breach.
- The measures taken or proposed to address the breach and mitigate its effects.
- The name and contact details of the Data Protection Officer or other contact point for further information.
10.3 The Customer is responsible for notifying the relevant Supervisory Authority and affected Data Subjects as required by applicable law. FactoryNerve will provide reasonable cooperation in this process.
10.4 For reporting security incidents: security.factorynerve.online@redvortexorg.me.
11. Data Deletion and Return
11.1 Upon termination of the Agreement, the Customer may request export of Personal Data for up to 30 days following termination. FactoryNerve will make the data available in a commonly used, machine-readable format.
11.2 After the 30-day export window, FactoryNerve shall delete all Personal Data from its production systems and backups, subject to Section 11.3.
11.3 FactoryNerve may retain Personal Data to the extent required by applicable law (e.g., invoicing records required for tax purposes), provided that such data remains subject to the confidentiality and security obligations of this DPA.
11.4 A certification of deletion is available upon request from legal.factorynerve.online@redvortexorg.me.
12. Audit Rights
12.1Upon 30 days’ written notice, the Customer may audit FactoryNerve’s compliance with this DPA, no more than once per calendar year.
12.2The audit shall be conducted in a manner that minimizes disruption to FactoryNerve’s operations. The Customer shall bear its own audit costs, unless the audit reveals a material breach of this DPA, in which case FactoryNerve shall reimburse reasonable audit costs.
12.3 As an alternative to an on-site audit, FactoryNerve may provide:
- Copies of its SOC 2 Type II report (when available) or equivalent certification.
- Summary results of the most recent penetration test.
- Completed security questionnaire responses.
13. Liability and Indemnification
13.1Each party’s liability arising out of or related to this DPA shall be subject to the limitations set forth in the Agreement.
13.2 FactoryNerve shall be liable for any breaches of this DPA caused by its Sub-processors to the same extent as if FactoryNerve itself had committed the breach.
13.3The Customer agrees to indemnify and hold FactoryNerve harmless from any claims, damages, or penalties arising from the Customer’s failure to comply with its obligations as Data Controller under applicable data protection laws.
14. Term and Termination
14.1 This DPA commences on the effective date of the Agreement and continues until the Agreement is terminated.
14.2 The obligations under Sections 11 (Data Deletion and Return), 13 (Liability), and 15 (Governing Law) shall survive termination of this DPA.
15. Governing Law
15.1 This DPA shall be governed by and construed in accordance with the laws of India, without regard to its conflict-of-laws principles. However, the data protection principles of the GDPR shall apply regardless of the governing law.
15.2 Any dispute arising out of this DPA shall be resolved in accordance with the dispute resolution provisions of the Agreement.
16. Contact Information
DPA Questions: legal.factorynerve.online@redvortexorg.me
Data Subject Requests: legal.factorynerve.online@redvortexorg.me
Security Incidents: security.factorynerve.online@redvortexorg.me
Data Protection Officer: dpo@factorynerve.online
Annex 1: Details of Processing
| Element | Details |
|---|---|
| Nature and purpose of processing | Provision of the FactoryNerve SaaS platform for operational data management, including attendance tracking, production reporting, inventory management, OCR document processing, invoicing, and employee records management. |
| Duration of processing | For the duration of the Agreement plus up to 60 days following termination for data retrieval, then deletion subject to legal retention requirements. |
| Categories of Data Subjects | Customer’s employees, contractors, temporary workers, visitors, and authorized users. |
| Types of Personal Data | Names, identification numbers, contact information, role/designation, attendance data, shift assignments, leave records, production performance data, and any other Personal Data uploaded by the Customer. |
| Processing location | Primary: AWS Mumbai, India (ap-south-1). Sub-processors may process in other regions as listed at /subprocessors. |
Annex 2: Security Measures
The technical and organizational security measures implemented by FactoryNerve are described in detail on our Security page. In summary:
- Encryption: TLS 1.3 in transit; AES-256 at rest.
- Access controls: RBAC, least privilege, MFA for admins.
- Infrastructure: AWS VPC with WAF, DDoS protection, security groups.
- Application security: Input validation, parameterized queries, CSP headers, CSRF tokens.
- Backups: Daily encrypted backups with 30-day rolling retention and cross-region replication.
- Incident response: 24/7 monitoring, automated alerts, documented IR plan.
- Personnel: Background checks, confidentiality agreements, annual security training.
- Vulnerability management: Weekly automated scans, annual penetration testing, dependency monitoring.
Annex 3: Sub-processors
A current list of Sub-processors engaged by FactoryNerve is maintained at /subprocessors.
Categories of Sub-processors include cloud infrastructure providers (AWS), email delivery services (Resend), analytics and monitoring tools (PostHog, Sentry), and payment processors (Stripe, Razorpay).
All Sub-processors are bound by written agreements that impose data protection obligations equivalent to those in this DPA, including the EU Standard Contractual Clauses where applicable.
Execution of DPA
This DPA is hereby incorporated into the Agreement. By accepting the Agreement, the Customer agrees to be bound by the terms of this DPA. If the Customer requires a separately executed copy of this DPA, please contact legal.factorynerve.online@redvortexorg.me.
FactoryNerve Technologies Pvt. Ltd.
Signed: ____________________________
Name: ____________________________
Title: ____________________________
Date: ____________________________
Customer
Signed: ____________________________
Name: ____________________________
Title: ____________________________
Date: ____________________________
© 2026 FactoryNerve Technologies Pvt. Ltd.
Privacy Policy|Terms of Service|Security|Return to FactoryNerve