QuixiCloud Data Processing Addendum (DPA)
Last Updated: July 10, 2026
Effective Date: May 1, 2026
1. Purpose
This Data Processing Addendum ("DPA") forms an integral part of the main Terms and Conditions between QuixiCloud Data Storage Private Limited ("QuixiCloud") and the customer ("Customer") using QuixiCloud services.
It specifically governs the processing of personal data in scenarios where the Customer acts as the Data Controller (or equivalent under applicable privacy laws) and QuixiCloud acts as the Data Processor.
2. Scope
This DPA applies to the processing of personal data across the following QuixiCloud services:
- QuixiCloud Web Platform and Storage Infrastructure
- Android and Windows Applications
- WebDAV endpoints
- QuixiCloud APIs
- Public File Sharing mechanisms
- Business and Enterprise Subscriptions
- Any future QuixiCloud services, unless otherwise explicitly stated.
3. Definitions
Capitalized terms used in this DPA have the following meanings:
- Personal Data: Any information relating to an identified or identifiable natural person processed by QuixiCloud on behalf of the Customer.
- Processing: Any operation performed on Personal Data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation, or retrieval.
- Controller: The entity (the Customer) that determines the purposes and means of the processing of Personal Data.
- Processor: The entity (QuixiCloud) that processes Personal Data on behalf of the Controller.
- Data Subject: The identified or identifiable natural person to whom the Personal Data relates.
- Subprocessor: Any third-party data processor engaged by QuixiCloud to assist in fulfilling its obligations with respect to providing the Services.
- Security Incident: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by QuixiCloud.
- Applicable Data Protection Law: Relevant privacy frameworks, including but not limited to the EU General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act (DPDPA).
4. Roles
The Customer (Controller)
The Customer bears the primary responsibility for the data they upload. The Customer determines:
- What personal data is uploaded to QuixiCloud.
- Why the data is uploaded.
- Who is granted access to the data (via account sharing or public links).
- How long the data is retained.
QuixiCloud (Processor)
QuixiCloud processes that data strictly upon the Customer's instructions, specifically to:
- Provide cloud storage capacity.
- Synchronize files across devices.
- Perform redundancy and disaster recovery backups.
- Maintain the security of the infrastructure.
- Comply with binding legal obligations.
5. Categories of Personal Data
Because QuixiCloud provides general-purpose cloud storage, the Customer controls exactly what data is uploaded. Examples of Personal Data processed may include:
- Names and contact details of the Customer's employees or clients.
- Uploaded business records, documents, or spreadsheets.
- Photographic images and videos.
- Network metadata required to operate the service.
Note: Due to our encryption architecture, QuixiCloud does not determine, scan, or analyze the semantic content of the Customer's files.
6. Processing Activities
In its capacity as a Data Processor, QuixiCloud may undertake the following processing activities:
- Securely storing and encrypting files.
- Replicating encrypted ciphertext data across regional arrays for resilience.
- Synchronizing data between the Customer's authenticated devices.
- Transferring data between infrastructure regions as strictly required for service availability.
- Permanently deleting data upon the Customer's instruction or automatically according to the agreed storage lifecycle.
7. Security Measures
QuixiCloud implements and maintains comprehensive administrative, technical, and physical safeguards. As detailed in our Security Policy, these include:
- Client-side encryption where applicable, and secure server-side streaming encryption for Upload Replay.
- Mandatory TLS for data in transit.
- AES-256 encryption at rest.
- Strict hierarchical cryptographic key management.
- Stringent administrative access controls and MFA.
- Infrastructure monitoring, replication, and disaster recovery.
8. Confidentiality
QuixiCloud ensures that all personnel authorized to process Customer Personal Data have committed themselves to strict confidentiality agreements or are under an appropriate statutory obligation of confidentiality. Furthermore, relevant personnel receive appropriate security and privacy training.
9. Subprocessors
To provide a globally available service, QuixiCloud may engage trusted Subprocessors, such as cloud infrastructure providers, payment gateways, and email delivery services. QuixiCloud guarantees that:
- Subprocessors are selected following rigorous security evaluations.
- They are bound by written agreements requiring them to protect Personal Data to a standard no less protective than this DPA.
- QuixiCloud remains fully liable to the Customer for the performance of the Subprocessor's obligations.
10. International Transfers
Customer data may be processed or stored in highly secure data centers located in regions including India, Singapore, Europe, and the United States, as necessary to provide optimal service and redundancy. QuixiCloud ensures that appropriate legal safeguards are implemented for all international transfers in accordance with Applicable Data Protection Law.
11. Data Subject Requests
If QuixiCloud receives a direct request from a Data Subject relating to Personal Data controlled by the Customer, QuixiCloud will not respond directly (unless legally compelled). Instead, we will promptly redirect the Data Subject to the Customer, and we will provide the Customer with reasonable technical assistance to respond to the request, where appropriate and permitted by law.
12. Security Incidents
If QuixiCloud becomes aware of a confirmed Security Incident affecting Customer-controlled Personal Data, we will notify the Customer without undue delay. QuixiCloud will provide the Customer with reasonably necessary information to support the Customer's legal reporting obligations, including the nature of the breach, the potential impact, and the remediation steps taken.
13. Audits
To protect the security of our multi-tenant infrastructure, QuixiCloud does not generally permit physical on-site audits by individual Customers. However, QuixiCloud will, upon written request, provide reasonable documentary evidence of its security controls and compliance posture. Any further audit requests may be subject to mutual agreement, reasonable advance notice, strict confidentiality requirements, and operational limitations.
14. Return or Deletion of Data
Upon termination of the Services:
- The Customer is responsible for exporting their data prior to account expiration, where technically feasible.
- Following expiration, QuixiCloud will systematically delete the Customer’s Personal Data according to the storage lifecycle specified in the Terms and Conditions.
- Certain minimal administrative records may be retained strictly where required by applicable law.
15. Liability
Any liability arising out of or relating to this DPA, whether in contract, tort, or other theory of liability, is subject in all respects to the limitations and exclusions of liability set forth in the main Terms and Conditions, unless mandatory Applicable Data Protection Law strictly requires otherwise.
16. Governing Law
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction established in the main Terms and Conditions.