Standard Contractual Clauses and data processing terms
Agreement Overview
Last updated: July 04, 2026
This Data Processing Agreement ("DPA") applies when the GANGA Offensive Ops platform processes personal data on behalf of customers who are controllers under applicable data protection law (GDPR, UK GDPR, LGPD, etc.).
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between GANGA Offensive Ops Pvt. Ltd. ("Processor") and its customers ("Controller") for the use of the GANGA Offensive Ops platform.
This DPA applies when the Controller processes personal data through the platform and the Processor accesses, stores, or processes that data on behalf of the Controller.
In case of conflict between this DPA and the main agreement, this DPA shall prevail with respect to data protection obligations.
Scope and Purpose
The Processor processes personal data only on documented instructions from the Controller. The subject matter, duration, nature, and purpose of processing are defined by the services subscribed to.
Processing activities include: account management, authentication, OSINT data collection and storage, threat intelligence aggregation, analytics (where consented), and platform security monitoring.
The Processor shall not process personal data for any purpose other than providing the agreed services unless required by applicable law.
Standard Contractual Clauses (SCCs)
Where personal data is transferred from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries without an adequacy decision, the parties agree to rely on the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor) as the transfer mechanism.
The SCCs are incorporated by reference into this DPA. In the event of conflict between the SCCs and this DPA, the SCCs shall prevail for international data transfers.
The parties shall conduct Transfer Impact Assessments (TIAs) as required and implement supplementary measures to ensure essentially equivalent protection.
Sub-Processors
The Processor engages the following sub-processors for specific processing activities:
Infrastructure: Cloud hosting providers (AWS, GCP) for compute, storage, and database services.
Payment processing: Stripe for payment handling and fraud detection.
Analytics: Anonymized analytics providers (opt-in only) for platform performance monitoring.
The Processor shall notify the Controller at least 30 days before engaging a new sub-processor. The Controller may object within 14 days of notification.
All sub-processors are bound by data processing obligations no less protective than those in this DPA.
Security Measures
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Encryption: Data encrypted at rest (AES-256) and in transit (TLS 1.3). Sensitive fields use field-level encryption.
Access controls: Role-based access control, multi-factor authentication, and principle of least privilege for all personnel.
Monitoring: Real-time security monitoring, intrusion detection, and automated threat response.
Incident response: Documented incident response procedures with notification to the Controller within 72 hours of a confirmed breach.
Regular penetration testing and security audits by independent third parties.
Data Subject Rights
The Processor shall assist the Controller in fulfilling data subject rights requests, including:
Right of access — Provide export of all personal data associated with the Controller's account.
Right to rectification — Update or correct personal data upon Controller instruction.
Right to erasure — Delete personal data within 30 days of a verified deletion request.
Right to data portability — Export data in machine-readable formats (JSON).
Right to object — Cease processing based on legitimate interest upon Controller instruction.
The Processor shall respond to all data subject rights requests within the timeframes required by applicable law.
Data Retention
The Processor retains personal data only as long as necessary to provide the services or as required by law.
OSINT search results: Retained for 30 days from creation, then permanently deleted.
Account data: Retained until the Controller requests deletion or the account is idle for 365 days.
Backup data: Purged within 90 days of source data deletion.
The Processor shall provide confirmation of data deletion upon request from the Controller.
Data Breach Notification
In the event of a personal data breach, the Processor shall:
Notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach.
Provide the Controller with: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
Cooperate with the Controller and take reasonable steps to assist in investigating and mitigating the effects of the breach.
Maintain a record of all data breaches, including facts relating to the breach, its effects, and remedial action taken.
Contact
For questions about this DPA or to exercise data protection rights:
Data Protection Officer: dpo@gangaoffensiveops.com.np
Address: GANGA Offensive Ops Pvt. Ltd., New Delhi, India
We respond to all data protection inquiries within 30 days.