Data Processing Addendum

Last updated: 31 August 2026

This Data Processing Addendum ("DPA") forms part of the agreement between 11TechSquare Private Limited ("Growspace", "we", "us") and the customer ("Customer", "you") for the provision of Growspace M2M and IoT connectivity services. It records how we handle personal data on your behalf, and applies to the extent we process personal data governed by the Digital Personal Data Protection Act, 2023 ("DPDP Act") or comparable data protection law.

1. Data Protection Officer

You can reach our Data Protection Officer directly on any matter covered by this DPA, including a data principal request, a security concern, or a suspected breach:

Data Protection Officer: Ankit Rawat
Email: admin@growspace.in
Postal address: 11TechSquare Private Limited, B-101, Surya Marg, Tilak Nagar, Jaipur 302004, Rajasthan, India

We acknowledge requests within 72 hours and respond substantively within the period required by applicable law.

The same office acts as our Grievance Officer for the purposes of section 13 of the DPDP Act. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

2. Roles of the parties

3. Subject matter, nature and purpose

Item Detail
Subject matter Provision of M2M/IoT SIM and eSIM connectivity, lifecycle management, and the associated connectivity management platform.
Duration For the term of the agreement, plus the retention period in section 8.
Nature of processing Collection, storage, structuring, retrieval, transmission, and deletion as required to deliver and support the service.
Purpose Provisioning and managing SIM/eSIM connectivity, billing and usage reporting, platform access control, and technical support.
Categories of data principals Your authorised platform users, and where applicable your own end customers whose devices use Growspace connectivity.
Categories of personal data Account identity and contact details (name, business email, phone), authentication data, platform activity and audit logs, and device/connectivity identifiers (such as ICCID, IMSI and IMEI) to the extent these relate to an identifiable individual.
Special category data None. The service is not designed to process sensitive personal data or children's data, and you must not upload such data without a prior written agreement.

4. Our obligations as processor

5. Security measures

6. Sub-processors

You give general authorisation for Growspace to engage the sub-processors listed below. Each is bound by data protection obligations no less protective than this DPA, and we remain liable for their performance. We will give you at least 30 days' notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds.

Sub-processor Location of processing Purpose
Amazon Web Services, Inc. Mumbai, India (ap-south-1) Cloud infrastructure hosting the Growspace platform, website, databases and backups.
Zoho Corporation Pvt. Ltd. India Business email, and capture of enquiries submitted through the website contact form.
Google LLC (Google Fonts) United States and global edge network Delivery of web fonts to website visitors. Receives the visitor's IP address; no account or platform data is shared.
Bharti Airtel Limited (Airtel) India Mobile network connectivity, SIM/eSIM provisioning, and roaming for devices on the Growspace network.
Vodafone Idea Limited (Vi) India Mobile network connectivity, SIM/eSIM provisioning, and roaming for devices on the Growspace network.
Bharat Sanchar Nigam Limited (BSNL) India Mobile network connectivity, SIM/eSIM provisioning, and roaming for devices on the Growspace network.
Reliance Jio Infocomm Limited (Jio) India Mobile network connectivity, SIM/eSIM provisioning, and roaming for devices on the Growspace network.

7. Cross-border transfers

Platform and customer data is stored and processed in India. Where a sub-processor listed above processes data outside India, that transfer is made only to countries not restricted by the Central Government under section 16 of the DPDP Act, and under contractual terms requiring an equivalent standard of protection.

8. Retention and deletion

We retain personal data processed on your behalf for as long as the agreement is in force. On termination, we will delete or return that data within 30 days of your written request, except where retention is required by law — in which case the data remains protected by this DPA until deletion is permitted.

9. Assisting with data principal rights

If a data principal contacts us directly about data we process on your behalf, we will not respond substantively. We will forward the request to you without undue delay and help you answer it. The rights themselves, and how individuals exercise them against Growspace as a Data Fiduciary, are set out in our Privacy Policy.

10. Personal data breach

If we become aware of a personal data breach affecting data processed on your behalf, we will notify you without undue delay and in any event within 72 hours of becoming aware, with the information known at that time — nature of the breach, categories and approximate number of data principals affected, likely consequences, and the measures taken or proposed. We will co-operate with your own notifications to the Data Protection Board of India and to affected individuals.

11. Audit

On reasonable written notice, and no more than once in any twelve-month period unless required by a regulator or following a breach, we will make available the information necessary to demonstrate compliance with this DPA and allow for an audit conducted by you or an independent auditor bound by confidentiality.

12. Contact

Questions about this DPA, or a request for a signed copy, can be sent to admin@growspace.in or contact@growspace.in.