Data Processing Addendum (DPA)
Last updated: August 11, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service and reflects the parties' agreement with respect to the processing of personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable Indian data protection laws.
1. Definitions
- "Data Principal" means the individual to whom the personal data relates.
- "Data Fiduciary" means the organization that determines the purposes and means of processing personal data (i.e., you, the customer).
- "Data Processor" means the entity that processes personal data on behalf of the Data Fiduciary (i.e., AirBuild / Increatech Business Solution Pvt Ltd).
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act.
- "Processing" means any operation performed on personal data, including collection, storage, use, sharing, and deletion.
- "Security Incident" means any unauthorized access, acquisition, use, or disclosure of personal data.
2. Roles and Scope
You (the customer) are the Data Fiduciary. AirBuild (Increatech Business Solution Pvt Ltd) is the Data Processor. We process personal data on your behalf solely for the purpose of providing the Service as described in the Terms of Service.
3. Processing Details
3.1 Categories of Personal Data Processed
- Names and email addresses of organization members and invitees.
- IP addresses and device information from download/install logs.
- Profile information (e.g., Google OAuth profile data).
3.2 Purposes of Processing
- User authentication and session management.
- Organization and team management.
- Build distribution and install link tracking.
- Security monitoring and fraud prevention.
3.3 Duration of Processing
We process personal data for the duration of your subscription and for the retention periods specified in our Privacy Policy.
4. Our Obligations
As Data Processor, we agree to:
- Process personal data only on your documented instructions, including transfers to third countries, unless required by Indian law.
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures as described in our Privacy Policy.
- Notify you without undue delay (and within 72 hours) upon becoming aware of a Security Incident.
- Assist you in responding to requests from Data Principals exercising their rights under the DPDP Act.
- Assist you in meeting your obligations under the DPDP Act, including security, breach notification, and data impact assessments.
- Delete or return all personal data after the end of the Service, unless retention is required by Indian law.
5. Sub-Processors
We engage the following categories of sub-processors to provide the Service:
- Cloud hosting: For server infrastructure and data storage.
- Payment processing: Razorpay for subscription billing.
- Email delivery: For transactional and notification emails.
- Error monitoring: Sentry for application error tracking.
We remain liable for the acts and omissions of our sub-processors as if they were our own. We will notify you of any intended changes to sub-processors, giving you the opportunity to object.
6. Cross-Border Data Transfers
Personal data may be processed and stored in cloud infrastructure located outside India. We ensure that such transfers comply with the DPDP Act, 2023 and that sub-processors provide appropriate safeguards, including standard contractual clauses where applicable.
7. Security Incident Notification
In the event of a Security Incident, we will:
- Notify you within 72 hours of becoming aware of the incident.
- Provide relevant details, including the nature of the incident, categories of data affected, and remedial actions taken.
- Cooperate with you in notifying the Data Protection Board of India and affected Data Principals, as required by law.
- Take reasonable steps to mitigate and remediate the incident.
8. Audits and Certifications
We maintain appropriate security certifications and may provide you with relevant audit reports upon reasonable request. You may audit our compliance with this DPA, subject to confidentiality obligations and reasonable notice.
9. Deletion of Data
Upon termination of the Service, we will delete all personal data processed on your behalf within 30 days, unless retention is required by Indian law (e.g., GST invoice retention for 7 years). You may also request earlier deletion by contacting privacy@airbuild.dev.
10. Grievance Officer
Our Grievance Officer can be contacted at dpo@airbuild.dev for any grievances related to the processing of personal data under this DPA.
11. Changes to This DPA
We may update this DPA from time to time to reflect changes in law or practice. We will notify you of material changes at least 30 days before they take effect.
12. Contact
For questions about this DPA, contact dpo@airbuild.dev or write to:
Increatech Business Solution Pvt Ltd
Coimbatore, Tamil Nadu
India