Tutorials/NDA / Confidentiality Agreement Structure

NDA / Confidentiality Agreement Structure

Purpose

This document sets out the confidentiality agreements Hybrowlabs uses, who signs which one, and what each contains. It is published so that a customer assessing us can see the obligations already in place around their information before the first discovery call.

This describes our standard structure. The executed agreement governs in every case, and where a customer's own agreement is signed, that document prevails over anything written here.

Which agreement applies

Counter-party Agreement Signed before
Employees, interns and trainees Confidentiality clause within the employment contract First day of employment
Contractors and consultants Standalone confidentiality agreement Start of the engagement
Prospective customers Mutual NDA Discovery, demonstration or sharing of requirements
Contracted customers Confidentiality clause within the MSA, or the customer's own NDA Any access to customer systems or data
Vendors and subprocessors Confidentiality and data protection terms within the vendor agreement Any exposure to customer data
Subcontracting organisations Back-to-back confidentiality terms mirroring the customer agreement Assignment of any personnel

Where a customer requires an additional project-specific NDA on top of the MSA, we execute it and restrict the account team to the named individuals listed in it.

Confidential information

Confidential information covers customer data held in ERP instances, business and financial information, requirements and process documentation, source code and configuration, architecture and infrastructure detail, credentials and access tokens, security assessments and findings, commercial terms, personal data of employees and customers, and any information marked confidential or that a reasonable person would treat as confidential given the circumstances of disclosure.

Information disclosed orally, in a demonstration, or during a workshop is covered on the same basis as written material. We do not require a confidentiality legend as a precondition of protection.

Exclusions

The obligations do not apply to information that is already public without breach, was lawfully known before disclosure, is independently developed without reference to the disclosed material, or is lawfully received from a third party without restriction.

Where disclosure is compelled by law or a court, the recipient gives notice to the disclosing party where it is lawful to do so and discloses only what is required.

Permitted use and need to know

Confidential information is used only for the purpose it was disclosed for, and only by personnel assigned to that account. Access to a customer environment is not granted on the basis of role alone. It follows assignment and is withdrawn on reassignment.

Approved recipients

Confidential information is disclosed within Hybrowlabs only to personnel bound by the agreements above. Disclosure outside Hybrowlabs requires a written agreement with the recipient and a business purpose, and where the recipient will process customer data, assessment under the Vendor / Subprocessor Management Policy and entry in the Subprocessor Register.

Security obligations

Recipients apply the controls set out in the Acceptable Use Policy, including named accounts, multi-factor authentication, encrypted devices, approved channels for transfer, and prohibition on personal storage and unapproved external services.

Suspected loss or unauthorised disclosure is reported internally without delay and to the customer within the timelines set out in the applicable agreement.

Intellectual property boundary

Confidentiality and ownership are separate questions, and the agreements treat them separately.

Customer data, customer business information and code written specifically for a customer under a paid engagement belong to the customer, subject to the payment terms in the applicable agreement.

Hybrowlabs pre-existing frameworks, internal libraries, tooling and products remain ours and are licensed to the customer for use within the delivered solution rather than assigned.

ERPNext and the Frappe Framework are third-party open-source software under their own licence terms. A confidentiality agreement does not alter those terms, and neither party can use an NDA to restrict rights that the open-source licence grants. Where a custom application is derived from Frappe, the licence position is confirmed with the customer before development rather than left to the NDA to resolve.

General skills, methods and know-how that our people carry in their heads from experience are not restricted, provided no confidential material, customer data or customer-specific code is used or reproduced.

Return and destruction

On request, or at the end of an engagement, confidential material is returned or deleted, including working copies, local downloads, ticket attachments and backups within our control. Deletion is confirmed in writing where the customer asks for it.

Material that must be retained to meet a legal or audit obligation is identified and remains subject to the confidentiality terms for as long as it is held.

Survival and duration

Confidentiality obligations survive the end of employment, contract or engagement. The default survival period in our standard agreements is three years from the end of the engagement and indefinite for trade secrets and personal data.

Where a customer requires a longer or perpetual period, we accept it.

Customer paper

We routinely sign customer NDAs rather than insisting on our own.

Our standard positions are:

  • Accepted without negotiation: longer or perpetual survival, broader definitions of confidential information, stricter return and destruction terms, named-personnel restrictions, and audit rights
  • Raised for discussion: obligations that conflict with open-source licence terms, unlimited liability for indirect loss, non-solicitation clauses covering our whole workforce rather than the account team, and clauses that would prevent us from serving other customers in the same sector
  • Declined: any term requiring assignment of our pre-existing frameworks or products as a condition of confidentiality

Raising a point does not delay the engagement. We can begin discovery under a mutual NDA while a specific clause is settled.

Signature authority

Chinmay Kulkarni, Director, is the sole signatory for Hybrowlabs. No other person is authorised to execute a confidentiality agreement, accept amended terms, or waive an obligation on behalf of the company.

Evidence maintained

Hybrowlabs can produce the following for customer due diligence or audit, subject to redaction:

  • Signed confidentiality agreements for all personnel
  • Executed customer NDAs and MSA confidentiality clauses
  • Vendor and subprocessor confidentiality terms
  • Back-to-back agreements with subcontracting organisations
  • Policy acknowledgements
  • Named-personnel lists where a customer requires them
  • Return and destruction confirmations
  • Exception approvals
  • HR Security Policy
  • Acceptable Use Policy
  • Background Verification Process
  • Vendor / Subprocessor Management Policy
  • Subprocessor Register

Need help with your workflow setup?

If you're stuck or want help applying these guides to your setup, our team can assist with configuration, customization, and workflow implementation.