Enterprise B2B Data Processing Addendum

Data Processing Agreement (DPA)
Solanacy Websoft Suite & Cloud Architectures

This Data Processing Agreement establishes the rigorous technical, legal, and operational commitments undertaken by Solanacy Technologies as Data Processor on behalf of Merchants and Enterprise Clients as Data Fiduciaries under the Digital Personal Data Protection (DPDP) Act, 2023.

Effective Date: September 21, 2026
Statutory Alignment: DPDP Act 2023 & CERT-In Mandates
Data Sovereignty: AWS Asia Pacific (Mumbai)
Evidence Standard: BSA 2023 (Sec 61 & 63)
Section 01

Scope, Purpose & Statutory Precedence

This Data Processing Agreement ("DPA") supplements the Solanacy Websoft Terms of Service and governs the processing of personal data by Solanacy Technologies on behalf of the commercial client ("Merchant" or "Enterprise Client") in connection with the deployment and ongoing operation of the Solanacy Websoft Suite (covering Grocery POS, Restaurant KOT, Pharmacy ERP, E-Commerce, Services, and Enterprise ERP).

This Agreement is formulated strictly in accordance with:

  • Digital Personal Data Protection (DPDP) Act, 2023: Specifically Sections 6, 8, 9, and 10 governing the duties of Data Fiduciaries and Data Processors.
  • Information Technology Act, 2000: Sections 43, 66, 72, and 79 regarding cybersecurity safeguards and safe harbor principles.
  • CERT-In Directions (April 28, 2022): Mandating 6-hour cybersecurity incident reporting to the Indian Computer Emergency Response Team.
  • Bharatiya Sakshya Adhiniyam, 2023 (BSA): Sections 61 & 63 regarding electronic audit log integrity.
Section 02

Data Fiduciary vs. Data Processor Roles

The legal standing of the contracting parties under the DPDP Act 2023 is explicitly established as follows:

Entity Statutory Status Authority & Legal Bounds
The Merchant / Client
(Shop, Clinic, Restaurant, Enterprise)
Data Fiduciary Determines the purpose and legal grounds for processing personal data (e.g. capturing customer phone numbers for GST invoices or doctor prescription archives). Retains exclusive proprietary ownership of all uploaded data.
Solanacy Technologies
(Websoft Platform Provider)
Data Processor Processes personal data strictly on behalf of and pursuant to the documented instructions of the Data Fiduciary. Does not determine the purpose of processing and has zero right to monetize or independently retain data.
Strict Independence Guarantee: Solanacy Technologies will never aggregate, profile, sell, or disclose the Merchant's customer data, transaction records, patient files, or sales reports to any advertiser, commercial broker, or competitor under any pretext.
Section 03

Nature & Scope of Processing

Personal data processed by Solanacy Websoft is restricted strictly to what is technologically necessary to fulfill the core operational functions of the software suite:

  • Billing & Invoicing Data: Customer mobile phone numbers, billing names, GST numbers, itemized purchase records, and digital payment transaction references.
  • Healthcare & Prescription Records (Pharmacy ERP): Patient names, age, prescribing physician name, medical registration number, Schedule H/H1 prescription scans, and dosage instructions (handled under doctor-patient confidentiality).
  • Order Fulfillment & Delivery Data: Delivery street addresses, landmark details, customer contact numbers, and delivery confirmation timestamps.
  • Staff Administrative Data: Employee usernames, role permissions (Cashier, Steward, Pharmacist, Manager), terminal login sessions, and shift reconciliation audit logs.
Section 04

Categories of Data Principals

The processing activities governed by this DPA involve the following categories of Data Principals:

Data Principal Category Data Processed Primary Processing Purpose
Retail & Supermarket Shoppers Phone number, name, loyalty points, purchase ledger GST invoice generation, WhatsApp receipt delivery, loyalty calculation
Restaurant & Cafe Patrons Table number, order selections, payment mode, phone (optional) Kitchen Order Ticket (KOT) routing, table billing, digital receipts
Clinic Patients & Pharmacy Clients Name, age, prescription image, doctor details, dispensed batch Statutory Schedule H register maintenance, drug expiry safety
E-Commerce Customers Shipping address, email, phone number, order history Parcel dispatch, courier webhook sync, order tracking
Merchant Staff & Operators Name, mobile number, role, shift logs, IP address Role-based access control (RBAC), internal security audit trails
Section 05

Processor Commitments & Documented Instructions

Solanacy Technologies as Data Processor makes the following irrevocable statutory covenants to the Data Fiduciary:

  • Processing Exclusively on Instructions: Solanacy shall process personal data solely in accordance with the documented instructions of the Merchant (as articulated in the Terms of Service and this DPA), unless otherwise required by Indian statutory law.
  • Confidentiality Obligations: All software engineers, DevOps personnel, and support agents with access to merchant database instances are bound by comprehensive, written Non-Disclosure Agreements (NDAs).
  • No Cross-Tenant Data Mingling: In hosted multi-tenant or single-tenant cloud environments, merchant databases are logically separated via dedicated database schemas, separate encryption keys, and strict Row-Level Security (RLS) policies.
Section 06

Technical & Organizational Security (TOMs)

In accordance with Section 8(5) of the DPDP Act 2023, Solanacy implements industry-standard Technical and Organizational Measures (TOMs) to safeguard personal data against unauthorized access, destruction, alteration, or disclosure:

  • Encryption in Transit: 100% of network traffic between user browsers, POS terminals, and cloud APIs is encrypted using TLS 1.3 with strict HSTS preloading.
  • Encryption at Rest: All production database volumes, automated snapshot backups, and stored prescription documents are encrypted using AES-256 with AWS Key Management Service (KMS) hardware security modules.
  • Cryptographic Password Salting: All user credentials are protected using salted Argon2id or bcrypt hashes. Cleartext passwords are never logged, transmitted, or stored.
  • Automated Backup & Disaster Recovery: Daily automated snapshots with point-in-time recovery (PITR) across multi-availability zones within the AWS Mumbai region.
Section 07

Subprocessor Management & Authorization

The Data Fiduciary grants general authorization to Solanacy Technologies to engage the following certified third-party subprocessors for critical infrastructure services:

Subprocessor Processing Activity Data Center Location Certifications
Amazon Web Services (AWS) Cloud compute (EC2), managed database (RDS), asset storage (S3) Mumbai, India (ap-south-1) ISO 27001, SOC 1/2/3, PCI-DSS Level 1
Cloudflare, Inc. Edge DDoS mitigation, Web Application Firewall (WAF), TLS termination Global Edge (India PoPs) ISO 27001, SOC 2 Type II
Meta Platforms (WhatsApp Cloud API) Automated digital receipt and order notification delivery Enterprise Cloud (mTLS encrypted) SOC 2, SOC 3
Razorpay / Cashfree Payments UPI Dynamic QR generation, card tokenization, payment webhooks India (RBI Regulated) PCI-DSS Level 1, RBI PA License

Solanacy shall provide at least thirty (30) days advance notice to the Merchant prior to onboarding any new subprocessor. The Merchant retains the right to object on reasonable data protection grounds.

Section 08

CERT-In Compliance & Data Breach Notification

In compliance with the CERT-In Cybersecurity Directions (April 2022) and Section 8(6) of the DPDP Act, 2023:

Immediate 6-Hour Breach Notification: In the event of a confirmed or reasonably suspected personal data breach, unauthorized database access, or ransomware event affecting the Merchant's data, Solanacy shall notify the Merchant's designated super-admin in writing without undue delay, and in any event within six (6) hours of becoming aware of the incident.

The breach notification shall include: (i) the nature and scope of the incident; (ii) categories and approximate number of Data Principals affected; (iii) technical measures implemented or recommended to mitigate the breach; (iv) contact details of our Data Protection Officer leading the incident response.

Section 09

Assistance with Data Principal Rights (DSAR)

Under Chapter III of the DPDP Act 2023, Data Principals enjoy statutory rights to access, correct, update, and erase their personal data:

  • In-App Self-Service Tools: Solanacy Websoft provides built-in administrative capabilities enabling the Merchant to directly view, export, update, or cryptographically anonymize customer records without needing manual engineering intervention.
  • Technical Assistance: If the Merchant is unable to execute a Data Subject Access Request (DSAR) through the dashboard, Solanacy shall provide technical assistance within forty-eight (48) hours of receipt of a written request from the Merchant.
  • Direct End-User Requests: If an end-customer contacts Solanacy directly regarding their data, Solanacy shall promptly redirect the request to the relevant Merchant Data Fiduciary without modifying the record independently.
Section 10

Audits & Compliance Verification

To provide enterprise clients with complete verification assurance:

  • Compliance Documentation: Upon written request, Solanacy will provide the Merchant with copies of relevant security certifications, third-party penetration test executive summaries, and architectural security whitepapers.
  • On-Site / Remote Audits: Once per calendar year, an enterprise Merchant (or its independent, certified security auditor) may conduct a structured security audit of Solanacy's processing systems, provided: (i) thirty (30) days advance written notice is given; (ii) the audit occurs during regular business hours without disrupting other clients; (iii) the auditor is bound by a strict NDA.
Section 11

Termination, Data Return & Cryptographic Shredding

Upon termination or expiration of the master software licensing agreement:

  • 14-Day Full Export Window: Solanacy shall provide the Merchant with uninterrupted access for fourteen (14) calendar days to export all databases, customer registers, prescription logs, and invoice histories in standard CSV, JSON, or SQL dump format.
  • Cryptographic Data Shredding: Following the 14-day export window, Solanacy shall permanently delete, destroy, and cryptographically overwrite all copies of the Merchant's personal data residing on Solanacy-managed servers and backup volumes, unless Indian statutory tax law (e.g. 6-year GST invoice retention mandates) requires archival storage.
Section 12

Execution, Jurisdiction & DPO Contact Desk

This DPA forms an integral part of the commercial contract between Solanacy Technologies and the Merchant. In the event of any conflict between this DPA and the general Terms of Service regarding data processing, the provisions of this DPA shall prevail.

Data Protection Officer (DPO)
Data Protection & Compliance Office
Corporate Entity
Solanacy Technologies
DPA / DSAR Dedicated Email
Engineering Desk / WhatsApp
Registered Office & Jurisdiction
Howrah, West Bengal 711101, India
Breach Hotline & Incident Desk
Available 24/7/365 for confirmed security incidents