Data processing agreement
NeevCloud Technologies Private Limited (“ai.ml”, “we”), Indore, Madhya Pradesh, India. Last updated 10 September 2026.
This agreement is incorporated into the terms of service for every organisation. A copy filled in with your organisation's details and the current sub-processor list can be downloaded from the console (Settings → Data policy → Documents) and printed to PDF.
1. Roles and subject matter
The customer organisation is the data fiduciary / controller of the personal data in its API traffic; ai.ml is the processor. Processing consists of forwarding requests to the model providers selected by the customer’s routing and data policy, metering, and storing payloads only as the customer’s data policy instructs.
2. Instructions
The customer’s instructions are the API requests and the data policy set in the console (logging, retention, zero-data-retention, no-train, regions, redaction). We process personal data only on those instructions and tell the customer if an instruction appears to breach the law.
3. Security
TLS in transit; encryption at rest with per-organisation keys; access limited to staff who need it, under audit; annual penetration test; vulnerability disclosure at security@ai.ml.
4. Sub-processors
The customer authorises the providers reachable through its data policy and the infrastructure vendors on the sub-processor page. Changes are announced 14 days ahead by email and the policy.activated webhook; the customer may object by restricting its policy.
5. Breach notification
Without undue delay and within 72 hours of confirming a personal-data breach, with what we know and what we are doing.
6. Assistance and audits
We help with data-subject requests, impact assessments and regulator enquiries at reasonable cost, and make our audit reports available under NDA; on-site audits once a year with 30 days’ notice.
7. Transfers
Transfers outside India follow the DPDP Act’s rules; for EU data the Standard Contractual Clauses (module 2) are incorporated by reference.
8. Erasure
On instruction (console erasure request, 30-day wait) and at the end of the retention period, payloads are crypto-shredded and personal data deleted, with a completion receipt. The ledger and invoices are kept as tax law requires.
9. Term
For as long as the organisation exists. Erasure follows closure.