Data Processing Agreement
Last updated: 22 September 2026
This Data Processing Agreement ("DPA") forms part of our Terms of Service. It applies whenever Stivan Technologies ("we", "us") processes personal data on your behalf as a result of hosting an application you've built on ProjectHelm - it does not cover data we process as controller for our own purposes, such as your own account and billing details, which our Privacy Policy covers instead. By using the Platform to build an application that collects personal data from its own users, you accept this DPA.
1. Roles
Where your application collects or stores personal data about its own users - your customers, members or however you refer to them - you are the controller of that data: you decide why it's collected and how it's used. We act as your processor: we host the application and its database, and we process that data only to provide the Platform, not for our own purposes.
2. What we do with it
We process personal data in your application's database only as needed to run the Platform - storing it, backing it up, and making it available to your application and to you through the Platform's own features. We don't use it for our own analytics, marketing, or to train AI models, and we don't access it beyond what's needed to operate, secure or support the Platform, or where you ask us to (for example, if you contact support about a specific record).
3. Sub-processors
We use a small number of sub-processors to run the Platform: our cloud hosting and database providers, our container registry, and - only if you connect them to your application yourself - the third-party services listed in our Terms (payment gateways, Zoho/email delivery services, SMS providers). Connecting a third-party service to your application is your own choice; from that point, it processes your application's data under its own terms, as your processor, not ours. We'll give you reasonable notice before adding a new infrastructure sub-processor that would materially change how your data is handled.
4. Technical and Organizational Security Measures
We maintain appropriate technical and organizational safeguards to protect your application's data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access:
- Encryption: All web traffic is encrypted in transit using industry-standard TLS (HTTPS). Sensitive credentials and two-factor secrets are securely encrypted or hashed at rest.
- Access control & RBAC: Strong role-based access controls separate public anonymous static pages from authenticated administrative and member data. Superuser and role boundaries are enforced server-side.
- File upload validation: Uploaded images and documents are subjected to server-side size limits, extension whitelisting, and image stream decoding (via SkiaSharp) to prevent malicious executable injection.
- Tenant & data isolation: Multi-tenant boundary isolation ensures that databases, schemas, uploads, and runtime memory are segregated across application instances.
- Operational security: Infrastructure access is restricted to authorized personnel with multi-factor authentication, and automated database backups are performed regularly.
5. Confidentiality
Anyone on our side with access to your application's data is bound by confidentiality obligations that cover it.
6. Helping you respond to your users
If one of your application's own users asks you to access, correct or delete their data, the Platform gives you the tools to do that directly where possible. Where it doesn't, contact support@stivan.in and we'll help. We don't respond to your users' requests directly ourselves - that's your responsibility as controller, and we'll forward any request we receive that's clearly meant for you.
7. Data breaches
If we become aware of a security incident that compromises personal data in your application, we'll notify you without undue delay so you can meet any notification obligations you have to your own users or regulators.
8. International transfers
Some of our infrastructure and sub-processors may be located outside your own country. Where that's the case, we rely on their own contractual and security commitments to keep the data appropriately protected wherever it's processed.
9. When you leave
If you delete your application or close your account, we delete or anonymise the personal data it held within a reasonable period, in line with our Privacy Policy, except where we're required to keep something longer by law.
10. Demonstrating compliance
If you reasonably need information from us to meet your own compliance obligations as controller (for example, a description of the security measures in section 4), write to support@stivan.in and we'll provide what we reasonably can.
11. Changes to this DPA
We may update this DPA from time to time. If we make a material change, we'll update the date at the top of this page.
12. Contact us
Questions about this DPA? Email support@stivan.in.
Stivan Technologies, GSTIN 36AJPPV8123R1Z2, registered at Level 6, N Heights, Plot No. 38, Sy No. 64, Hitech City Phase 2, Madhapur, Hyderabad, Telangana 500081, India.