LAPTOPFIRST DATA PROCESSING ADDENDUM (DPA)
Standard Contractual Addendum for Laptop Rental Vendors (Enterprise & B2B)
Effective Date: 1st April 2026
Last Updated: 24th September 2026
Reference Agreement: LaptopFirst Vendor Terms of Service (“Principal Agreement”)
Operated By: Lapswap Tech Private Limited (CIN: U62099DL2024PTC426597), a company incorporated under the Companies Act, 2013, with its registered office at 161-L, Plot No. 9, Sector-7, Evergreen Apartment, Dwarka Sec-6, South West Delhi, Delhi – 110075, India.
APPLICABILITY & STATUS: This Data Processing Addendum (“DPA”) supplements the LaptopFirst Vendor Terms of Service entered into between LaptopFirst (“Data Processor”, “Company”, “we”, or “us”) and the Laptop Rental Vendor subscribing to the Platform (“Data Fiduciary”, “Vendor”, or “you”).
This DPA governs the processing of personal data relating to your rental customers, prospective renters, and hardware telemetry under the Digital Personal Data Protection Act, 2023 (India) (“DPDPA”) and international data protection regulations where applicable.
1. DEFINITIONS AND INTERPRETATION
- “Applicable Data Protection Law” means the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and any rules, regulations, or amendments enacted thereunder.
- “Data Fiduciary” (or “Data Controller”) means the Laptop Rental Vendor, who determines the purpose and means of processing personal data (including initiating device enrollment, conducting renter KYC, and issuing remote lock commands).
- “Data Processor” means LaptopFirst, which processes personal data strictly on behalf of and under the documented instructions of the Data Fiduciary.
- “Data Principal” (or “Data Subject”) means the individual to whom personal data relates, specifically the rental customer, guarantor, or end-user possessing a Managed Device.
- “Personal Data” means any data about an individual who is identifiable by or in relation to such data, processed by LaptopFirst in providing the Platform services.
- “Personal Data Breach” means any unauthorized or accidental processing, access, disclosure, acquisition, alteration, loss, or destruction of Personal Data affecting the Platform or Managed Devices.
- “Sub-processor” means any third-party infrastructure provider, API partner, or service vendor engaged by LaptopFirst who processes Personal Data in connection with the Platform.
2. ROLES, SCOPE & DOCUMENTED INSTRUCTIONS
2.1 Capacity of the Parties
The parties acknowledge and agree that:
- The Vendor is the Data Fiduciary with respect to Renter personal data, KYC documents, and device assignment records;
- LaptopFirst is the Data Processor appointed by the Vendor to provide inventory cataloging, software telemetry processing, asset protection enforcement, and verification routing services.
2.2 Processing on Documented Instructions
LaptopFirst shall process Personal Data only on documented instructions from the Vendor, which include:
- The provisions of the Principal Agreement and this DPA;
- Administrative configurations, command executions (lock, wipe, alert), and queries initiated by the Vendor through the Platform dashboard (
app.laptopfirst.in); - Processing necessary to comply with applicable statutory laws or binding judicial orders (in which case LaptopFirst will notify the Vendor in advance, unless legally prohibited).
2.3 Warranty of Lawful Collection
The Vendor represents and warrants that:
- It has established a valid, documented legal ground (including explicit Data Principal consent where required by the DPDPA) to collect, process, and transfer Renter Personal Data to LaptopFirst;
- It has provided transparent privacy notices to Renters disclosing the use of asset tracking software on rented laptops prior to handing over possession.
3. PROCESSOR OBLIGATIONS & CONFIDENTIALITY
3.1 Personnel Commitments
LaptopFirst shall ensure that all employees, contractors, and technical personnel authorized to process Personal Data:
- Have executed binding written confidentiality agreements;
- Are granted access strictly on a role-based, least-privilege, need-to-know basis;
- Receive regular training on cybersecurity, data privacy hygiene, and statutory DPDPA compliance.
3.2 Non-Exploitation Covenant
LaptopFirst covenants that it shall never:
- Sell, rent, monetize, or trade Personal Data to any third party or marketing broker;
- Use Renter Personal Data or Managed Device telemetry for profiling, commercial behavioral advertising, or independent commercial gain;
- Intercept, read, or process personal user documents, web browsing histories, or private communications residing on Managed Devices.
4. SUB-PROCESSORS
4.1 Prior General Authorization
The Vendor grants LaptopFirst general written authorization to engage the Sub-processors listed in Annexure 3 to support platform infrastructure, authentication, database hosting, and verification relay.
4.2 Sub-processor Obligations
LaptopFirst shall impose contractual obligations on each Sub-processor that are no less protective than those set forth in this DPA, including:
- Implementation of appropriate technical and organizational security measures;
- Strict confidentiality restrictions;
- Mandates to delete or return Personal Data upon conclusion of service.
4.3 Notification of Sub-processor Changes
- LaptopFirst shall maintain an updated list of Sub-processors at
https://laptopfirst.in/privacy/sub-processors(or notify the Vendor via email/dashboard alert). - LaptopFirst will notify the Vendor at least fourteen (14) days prior to engaging any new Sub-processor, giving the Vendor an opportunity to raise reasonable data protection objections.
- If the Vendor reasonably objects on legitimate data protection grounds and the parties cannot reach an amicable resolution, the Vendor may terminate the affected Platform subscription without penalty.
5. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES (TOMS)
- LaptopFirst shall implement and maintain the comprehensive technical, operational, and physical security measures set forth in Annexure 2.
- These measures are designed to ensure a level of security appropriate to the risk, including:
- End-to-end TLS 1.3 encryption for all data in transit;
- AES-256 encryption for databases, backups, and BitLocker keys at rest;
- Logical multi-tenant isolation enforced via PostgreSQL Row-Level Security (RLS);
- Anti-tamper watchdog controls, code signing, and OTP-gated uninstallation.
- LaptopFirst reserves the right to update or enhance its technical measures provided that such modifications do not degrade the overall security posture of the Platform.
6. PERSONAL DATA BREACH MANAGEMENT & NOTIFICATION
6.1 Breach Notification to Vendor
In the event LaptopFirst confirms a Personal Data Breach affecting Personal Data processed on behalf of the Vendor, LaptopFirst shall:
- Notify the Vendor via email to the registered administrator address without undue delay (and in any event within forty-eight (48) hours of formal confirmation);
- Take immediate, commercially reasonable remedial steps to contain, mitigate, and resolve the security incident.
6.2 Contents of Breach Notice
The notification shall, to the extent information is available, provide:
- A description of the nature of the breach, including affected data categories and approximate numbers of Data Principals;
- The identity of LaptopFirst’s technical point of contact;
- The likely consequences and potential risks of the breach;
- The immediate remedial actions taken or planned to mitigate potential adverse impacts.
6.3 Assistance with Regulatory Filings
LaptopFirst shall provide reasonable technical cooperation to assist the Vendor in fulfilling statutory breach notification obligations to the Data Protection Board of India (DPBI), the Indian Computer Emergency Response Team (CERT-In), or affected Renters.
7. DATA PRINCIPAL RIGHTS ASSISTANCE
- Taking into account the nature of the processing, LaptopFirst shall provide reasonable technical assistance to the Vendor (via dashboard tools, export features, or direct administrative queries) to enable the Vendor to fulfill requests by Data Principals exercising statutory rights under the DPDPA, including:
- The right to access a summary of Personal Data;
- The right to correction or erasure of outdated/inaccurate records;
- The right to grievance redressal.
- If LaptopFirst receives a request directly from a Renter, LaptopFirst shall promptly notify the Renter to submit their request directly to the Rental Vendor (the Data Fiduciary), and shall not respond independently except upon the Vendor’s written instruction.
8. AUDIT RIGHTS & COMPLIANCE DEMONSTRATION
- Upon the Vendor’s reasonable written request (not more than once per twelve-month calendar period), LaptopFirst shall provide documentation, summaries of third-party security audits, or architectural attestations to verify compliance with this DPA.
- If an enterprise Vendor reasonably requires an onsite or remote technical inspection, the parties shall agree in advance on reasonable scope, timing, non-disclosure protocols, and safety conditions. The Vendor shall bear all costs of such inspection unless a material data breach has occurred as a direct result of LaptopFirst’s gross negligence.
9. DATA DELETION, RETURN & PRUNING SCHEDULES
9.1 Programmatic Lifecycle Pruning
The Vendor acknowledges and authorizes the automated programmatic pruning routines operating on LaptopFirst databases:
- Diagnostic agent logs: Permanently destroyed after 7 days;
- Device heartbeats & battery vitals: Permanently destroyed after 30 days;
- Geographic coordinates: Permanently destroyed after 90 days;
- Administrative audit trails: Retained for 400 days to satisfy statutory security logging mandates under Indian law, then purged.
9.2 Post-Termination Deletion
Upon expiration or termination of the Principal Agreement, LaptopFirst shall:
- Provide the Vendor a thirty (30) day window to export active inventory and customer records via standard JSON/CSV export;
- Following the export window, permanently de-identify, purge, or overwrite all Vendor Data and associated Renter records from active production databases;
- Backups residing in cold storage (AWS S3) shall be overwritten or rotated out within statutory backup retention windows (maximum 90 days following active database deletion).
10. GOVERNING LAW AND JURISDICTION
This DPA shall be governed by, construed, and enforced in accordance with the laws of India. Any disputes arising under or in connection with this DPA shall be subject to the exclusive jurisdiction of the competent courts in New Delhi, Delhi, India.
ANNEXURE 1: DETAILS OF DATA PROCESSING
| Parameter | Specification |
|---|---|
| Subject Matter | Provision of cloud-based laptop rental inventory management, remote asset protection (MDM), and identity/credit verification relay. |
| Duration of Processing | For the duration of the Vendor's active subscription to the Platform plus applicable statutory retention and post-termination archival windows. |
| Nature and Purpose | 1. Fleet asset protection, theft mitigation, and remote configuration of rental hardware. 2. Verifying Renter identity and soft creditworthiness to evaluate lease eligibility. 3. Maintaining audit logs for statutory compliance under Indian IT and DPDP regulations. |
| Categories of Data Principals | 1. Vendor administrative personnel and staff. 2. Prospective and active Renters (customers leasing laptops from the Vendor). |
| Categories of Personal Data | • Hardware Telemetry: Serial number, MAC address, hostname, CPU/RAM/Disk specs, battery status, uptime, IP address. • Location Data: Approximate and GPS geographic coordinates. • Identification Records (Relayed): Renter name, email, phone, government ID (PAN, Aadhaar/ID, address proof). • Credit Scoring Data (Relayed): Risk scoring outputs and liability indicators from soft credit checks. |
| Special Categories / Sensitive Data | Financial/KYC identifiers (PAN) processed strictly via encrypted relay to accredited identity verification service providers and registered credit assessment partners. No biometric data or sensitive personal files are collected. |
ANNEXURE 2: TECHNICAL & ORGANIZATIONAL MEASURES (TOMS)
- Cryptographic Standards:
- Transport layer encryption: TLS 1.3 enforced for all WebSockets, agent heartbeats, and web dashboard connections.
- Storage layer encryption: AES-256 encryption applied to all PostgreSQL database volumes, automated S3 backups, and recovery keys.
- BitLocker Recovery Keys: Encrypted server-side using a dedicated master secret (
RECOVERY_KEY_SECRET).
- Multi-Tenant Logical Isolation:
- Multi-tenancy enforced using PostgreSQL Row-Level Security (RLS) bound to authenticated
tenant_idclaims extracted from verified JWT tokens.
- Multi-tenancy enforced using PostgreSQL Row-Level Security (RLS) bound to authenticated
- Agent Hardening & Anti-Tamper:
- System service architecture with automated KeepAlive.
- Background watchdog daemons running every 2 minutes (
MiteWatchdog/com.mite.watchdog) verifying Authenticode/CodeSign signatures before execution. - Time-based One-Time Password (TOTP) enforcement blocking local uninstallation without vendor-generated authorization.
- Physical & Cloud Infrastructure:
- Servers hosted in tier-3/tier-4 certified data centers (Railway, Cloudflare Edge, AWS) maintaining SOC 2 Type II and ISO 27001 certifications.
ANNEXURE 3: AUTHORIZED SUB-PROCESSORS
| Sub-Processor Entity | Service Function | Personal Data Processed | Processing Location |
|---|---|---|---|
| Supabase (Firebase, Inc.) | Admin Authentication & JWT Generation | Vendor admin email, session tokens | India |
| Railway Corp. | MDM Server Infrastructure & API Control Plane | Hardware telemetry, device commands, IP addresses | Singapore |
| Cloudflare, Inc. | Dashboard Hosting (Workers), CDN, R2 Storage | Web requests, cached assets, encrypted installers | Global Edge |
| Amazon Web Services (AWS S3) | Cold Storage Database Backups | Encrypted database archives | India |
| Apple Inc. | Push Notification Service (APNs) & ABM/DEP | Device UDID, APNs tokens, serials | United States |
| Accredited Identity Verification Service Provider | Renter KYC & Government ID Verification | Renter ID, PAN, proof of address | India |
| Registered Credit Assessment Partner | Renter Soft Credit Assessment & Risk Scoring | Renter PAN, full name, score output | India |
| Hotjar Ltd. | Dashboard UI/UX Heatmaps & Diagnostics | Vendor admin interaction flows, clicks | EU (Malta) |
EXECUTION (FOR CUSTOM OR ENTERPRISE AGREEMENTS)
For the Data Fiduciary (Rental Vendor):
Authorized Signature: ____________________________________
Full Legal Name: ____________________________________
Business / Entity Name: ____________________________________
Designation: ____________________________________
Date: ____ / ____ / 202____
For the Data Processor (LaptopFirst):
Authorized Signature: ____________________________________
Full Legal Name: ____________________________________
Entity Name: Lapswap Tech Private Limited (operating as “LaptopFirst”)
Designation: Authorized Signatory
Date: ____ / ____ / 202____