The DPA governing how Lacspace processes personal data on behalf of business customers — for GDPR, DPDP, and other data-protection compliance.
Effective: 25 July 2026
A plain-language summary — the full text below is what legally applies.
This Data Processing Agreement (“DPA”) forms part of the agreement between the business customer (“Controller”) and Lacspace Corporation Pvt. Ltd. (“Processor”) for the provision of the Services. It applies where Lacspace processes personal data on the Controller's behalf. The Controller determines the purposes and means of processing; Lacspace processes only on the Controller's documented instructions.
Terms such as “personal data,” “processing,” “controller,” “processor,” “data subject,” and “supervisory authority” have the meanings given under applicable data-protection law (including the GDPR and India's DPDP Act, as relevant). Other capitalised terms have the meanings in the main agreement and our Privacy Policy.
Lacspace will process personal data only to provide the Services and per the Controller's documented instructions, including as set out in Annex A, unless required otherwise by law (in which case we will inform the Controller where legally permitted). We will notify the Controller if we believe an instruction infringes applicable law.
Lacspace ensures that personnel authorised to process personal data are bound by confidentiality obligations and process data only as needed to provide the Services.
Lacspace implements appropriate technical and organisational measures to protect personal data (see Annex B), including tenant isolation, encryption in transit, access controls, and audit logging, taking into account the state of the art, the risks, and the nature of the data.
The Controller authorises Lacspace to engage sub-processors listed on our sub-processors page, under contracts imposing data-protection obligations equivalent to this DPA. We remain responsible for our sub-processors' performance and will provide a mechanism to notify of and object to changes.
Taking into account the nature of the processing, Lacspace will assist the Controller with appropriate measures to respond to data-subject requests (access, rectification, erasure, portability, objection, and restriction). Where a data subject contacts us directly, we will refer them to the relevant Controller.
Lacspace will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, and will provide information reasonably available to help the Controller meet its notification obligations.
Where processing involves transfers of personal data across borders, Lacspace will implement appropriate safeguards required by applicable law, such as Standard Contractual Clauses or equivalent mechanisms, and honour data-residency commitments agreed with the Controller.
Lacspace will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an appointed auditor, subject to reasonable confidentiality, scope, and frequency limits.
On termination of the Services, and at the Controller's choice, Lacspace will return or delete the personal data it processes on the Controller's behalf, except where retention is required by law. Regulated data may be soft-deleted to preserve history where legally required.
Enterprise customers who require a countersigned DPA can request one at legal@lacspace.com or via privacy@lacspace.com.
This document is version v1.0, effective 25 July 2026. © 2026 Lacspace Corporation Pvt. Ltd. All rights reserved.
Privacy PolicySub-processorsSecurity & DisclosureTerms of Use