Data Processing Agreement
For institutions and organisations using ElevateU under an Institution licence.
Effective 24 June 2026 · Last updated 5 July 2026
1. Definitions and roles
Terms such as Data Fiduciary, Data Processor, Data Principal and personal datahave the meaning given in the Digital Personal Data Protection Act, 2023 ("DPDP Act").
- For personal data the Customer submits or directs us to process on its behalf (e.g. a college uploading its students' data), the Customer is the Data Fiduciary and MarshallRidge Consulting Private Limited acts as a Data Processor processing such data only on the Customer's documented instructions.
- For personal data we determine the purpose and means of (e.g. our own account, security and billing data), MarshallRidge Consulting Private Limited is the Data Fiduciary, governed by our Privacy Notice.
2. Scope and instructions
We process Customer personal data only (a) to provide the ElevateUService, (b) per the Customer's documented lawful instructions, and (c) as required by applicable law (in which case we will inform the Customer unless legally prohibited). The Customer is responsible for the lawfulness of its instructions and for having a valid basis (including consent) for the processing it directs.
3. Confidentiality
We keep Customer personal data confidential, limit access to personnel who need it to provide the Service, and bind such personnel to confidentiality obligations.
4. Security
We maintain reasonable technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls and least-privilege, optional multi-factor authentication, rate-limiting, logging and monitoring, consistent with the DPDP Act and the reasonable-security-practices standard under the Information Technology Act, 2000.
5. Sub-processors
The Customer authorises us to engage sub-processors to provide the Service. Current sub-processors include:
- Amazon Web Services (AWS) — database hosting, Mumbai region (ap-south-1), India.
- Cloudflare — application delivery and compute.
- Google (Gemini API) — optional AI-generated guidance and insights.
- Razorpay — payment processing.
- Our transactional email provider — service and security emails.
We impose data-protection obligations on sub-processors that are no less protective than this DPA, and remain responsible for their performance. We will give the Customer reasonable notice of any intended addition or replacement of a sub-processor and an opportunity to object on reasonable data-protection grounds.
6. Assistance with Data Principal rights
Taking into account the nature of processing, we will provide reasonable assistance to the Customer to respond to Data Principals exercising their rights (access, correction, erasure, nomination, withdrawal of consent) under the DPDP Act. If we receive such a request directly relating to Customer data, we will, unless legally required to act, refer the Data Principal to the Customer.
7. Deletion / return and retention
On expiry or termination of the Customer's licence, we will, at the Customer's choice, delete or return Customer personal data within a reasonable period, except where retention is required by law. Routine retention periods are described in our Privacy Notice.
8. Personal data breach notification
We will notify the Customer without undue delayafter becoming aware of a personal data breach affecting Customer data, with information reasonably available to assist the Customer's own obligations to the Data Protection Board and affected Data Principals. For reportable cyber security incidents we also notify CERT-In within six (6) hours per the CERT-In Directions dated 28 April 2022.
9. Audit
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, allow the Customer (or its mandated auditor) to verify compliance no more than once per year, in a manner that does not disrupt our operations or compromise other customers' data.
10. Cross-border transfer
The Customer authorises transfer/processing of personal data outside India by the sub-processors listed above, in accordance with Section 16 of the DPDP Act (which permits transfer except to countries restricted by the Central Government). Core student/account data is hosted in the AWS Mumbai (ap-south-1) region; AI processing via Google Gemini may occur outside India.
11. Liability and precedence
EACH PARTY'S LIABILITY UNDER OR IN CONNECTION WITH THIS DPA IS SUBJECT TO THE LIMITATIONS AND AGGREGATE CAP IN THE TERMS OF USE / THE MASTER AGREEMENT BETWEEN THE PARTIES, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW. Nothing in this DPA excludes or limits liability that cannot be excluded by law, including non-excludable liability and penalties under the DPDP Act, 2023, or any non-waivable consumer remedy. If there is a conflict between this DPA and the Terms of Use on the subject of personal-data processing, this DPA prevails.
12. Governing law and jurisdiction
This DPA is governed by the laws of India, and the courts at Mumbai, Maharashtra, India have exclusive jurisdiction, without prejudice to any non-waivable statutory forum.
13. Contact
Data Protection Officer, MarshallRidge Consulting Private Limited
- Email: contact@marshallridgeconsulting.in
- Address: Unit No. 52, 2nd Floor, C-39A, Gami Industrial Park, MIDC, Thane, Navi Mumbai, Maharashtra 400705, India
- CIN: U62099MR2026PTC476835 · GSTIN: 27AAUCM9705F1ZY