B2B Data Protection & Merchant Privacy Standards

Privacy & Data Protection Policy
Solanacy Websoft Suite & POS Engines

This policy governs how Solanacy Websoft processes, secures, and maintains the data of business clients (merchants, healthcare providers, retailers, and enterprises) and their respective end-customers across all 6 Websoft editions.

Effective Date: September 20, 2026
Statutory Alignment: DPDP Act 2023, IT Act 2000 & BSA 2023
Data Sovereignty: AWS Asia Pacific (Mumbai)
Corporate Entity: Solanacy Technologies, Howrah, India
Section 01

Scope & System Architecture

This Privacy & Data Protection Policy specifically governs all software products, micro-applications, billing engines, Point-of-Sale (POS) interfaces, and cloud ERP systems operating under the Solanacy Websoft Suite, developed and distributed by Solanacy Technologies (Howrah, West Bengal, India).

The provisions herein apply to all standard and customized installations of the following six Websoft industry editions:

  • Grocery & Supermarket POS: Barcode scanning, weighing scale synchronizers, inventory registers, and WhatsApp digital billing.
  • Restaurant & Cafe KOT: Live Kitchen Order Ticket (KOT) routing, table QR ordering, cashier registers, and steward apps.
  • Pharmacy & Healthcare ERP: Batch-expiry tracking, Schedule H/H1 registers, doctor prescription archives, and D-DEY PMS integrations.
  • E-Commerce & Retail Engine: Multi-channel inventory, customer order portals, cart persistence, and automated shipping webhooks.
  • Services & Agencies Portal: Appointment bookings, client retainer management, digital contract signing, and milestone invoicing.
  • Custom Enterprise ERP: Multi-branch consolidated ledgers, factory floor supply chain tracking, and custom role workflows.
Corporate Policy Relationship: For general corporate website browsing, career inquiries, or non-software services, please consult the overarching Solanacy Corporate Privacy Policy. This Websoft policy prevails in all matters regarding software-processed business data.
Section 02

Data Controller vs. Data Processor Roles

Under the Digital Personal Data Protection (DPDP) Act 2023 and international privacy frameworks (GDPR), the legal relationships governing data handled within Solanacy Websoft are clearly demarcated as follows:

Entity Legal Classification Responsibilities & Authority
The Merchant / Business Client
(Shop Owner, Clinic, Restaurant, Enterprise)
Data Fiduciary (Controller) Determines the purpose and means of collecting customer data (e.g. phone numbers for billing, prescription records for pharmacy sales). Responsible for obtaining necessary customer consent.
Solanacy Technologies
(Websoft Suite Platform)
Data Processor Processes transaction records, generates bills, routes kitchen tickets, and stores records solely on the direct instruction of the Merchant. Solanacy possesses zero independent ownership or rights to monetize merchant customer data.
Zero Monetization Guarantee: Solanacy Websoft will never sell, lease, rent, trade, or share your business transaction data, customer phone numbers, or sales metrics with third-party advertisers, credit scoring agencies, or data brokers under any circumstances.
Section 03

Merchant Information We Collect

To configure, license, and maintain a business client's Websoft deployment, Solanacy collects the following categories of direct merchant business information:

  • Business Identity: Legal business trade name, registered GSTIN, shop/clinic establishment license number, owner/proprietor full name, and official registered address.
  • Administrative Credentials: Super-admin email address, phone number, and cryptographically hashed passwords (salted with Argon2/bcrypt; cleartext passwords are never stored).
  • Fiscal & Billing Details: Bank account details for UPI settlement mapping, billing address for annual software support invoices, and payment gateway API credentials (stored in secure client environment variables).
  • System Telemetry & Performance Logs: Server CPU/RAM health metrics, database connection pool statistics, API response latencies, and error stack traces for proactive bug fixing.
Section 04

End-Customer Data Handling & Rights

When a merchant uses Solanacy Websoft to serve their retail shoppers, restaurant patrons, or clinic patients, certain end-customer data is entered into the system. Solanacy Websoft handles this data under rigorous protective parameters:

  • Customer Phone Numbers: Collected solely for generating and dispatching GST-compliant digital invoices, WhatsApp order confirmations, and tracking links. Never utilized by Solanacy for marketing.
  • Delivery Addresses: In E-Commerce, Grocery, and Restaurant modules, customer shipping addresses and GPS coordinates are used strictly for fulfillment and delivery boy dispatch.
  • Purchase History & Loyalty Balances: Itemized invoice histories are stored to calculate customer loyalty points, return/exchange authorizations, and warranty validation as determined by the merchant.
End-Customer Right to Erasure: If an end-customer requests the deletion of their personal details, the merchant can execute this directly via the Websoft Admin Dashboard under Settings > Customer Privacy > Anonymize Customer, which cryptographically shreds the customer's identity while preserving statutory financial totals for GST audit compliance.
Section 05

POS Architecture & Offline-First Storage

Solanacy Websoft billing terminals employ a resilient Offline-First Architecture utilizing browser IndexedDB, WebAssembly (WASM) SQLite, and local hardware caching to guarantee that checkout operations continue seamlessly even during severe broadband outages:

  • Local Cache Isolation: Invoices generated while offline are encrypted and temporarily persisted within the local browser sandbox or device SQLite database until connectivity is re-established.
  • Bi-directional Sync Verification: Upon network restoration, offline transactions are synchronized with the merchant's dedicated cloud instance using cryptographic conflict-resolution algorithms.
  • Zero Terminal Leakage: Cashier session data, till balances, and offline cache keys are automatically cleared upon terminal logout or shift end.
Section 06

WhatsApp Business & Invoicing Engine

Solanacy Websoft features an integrated WhatsApp notification engine connected via the official Meta WhatsApp Cloud API:

  • Strict Transactional Intent: Messages dispatched through the Websoft bot are limited strictly to digital bills, KOT tickets, table reservation confirmations, prescription readiness, and delivery status updates.
  • One-Touch Opt-Out: Every automated message includes clear instructions allowing the recipient to reply with STOP to immediately revoke consent and halt automated WhatsApp notifications from that merchant.
  • End-to-End Transit Security: Communications between Websoft servers and the Meta WhatsApp Cloud API are secured via mutual TLS (mTLS) with payload encryption.
Section 07

Payment Gateways & UPI Dynamic QR

Solanacy Websoft enables frictionless digital payments via UPI Dynamic QR, POS soundboxes, and online payment aggregators (Razorpay, Cashfree, Stripe, Pine Labs):

PCI-DSS Compliant Tokenization: Solanacy Websoft does not capture, store, or process raw credit card numbers, debit card numbers, CVVs, or bank account PINs. All financial settlements are performed through RBI-licensed payment aggregators utilizing encrypted payment tokens.

When dynamic UPI QR codes are displayed on the POS customer display or printed on receipts, the QR code encodes only the merchant's Virtual Payment Address (VPA), invoice amount, and unique bill reference ID.

Section 08

Role-Based Access Control (RBAC) & Audit Logs

Internal security within a merchant's business is enforced through granular Role-Based Access Control:

Role Permitted Data Access Restricted Data
Cashier / Steward Create orders, add items, view active table, generate bill. Cannot view profit margins, supplier purchase costs, or full customer master database.
Store Manager Apply authorized discounts, void mistaken lines, view shift sales summary. Cannot export full customer database or alter system tax configurations.
Pharmacist Dispense medicines, verify Schedule H prescriptions, record doctor details. Cannot modify historical batch prices or audit logs.
Super Admin (Owner) Full access to sales reports, P&L statements, user management, and data export. All sensitive actions (e.g. database wipe, bulk price override) require 2FA authentication.

All high-impact actions—including invoice cancellations, cash drawer manual open events, price overrides, and staff permission alterations—are indelibly recorded in an append-only audit log with timestamp, staff ID, and IP address.

Section 09

Data Sovereignty & Cryptographic Security

Solanacy Websoft maintains strict adherence to Indian data localization mandates and enterprise security standards:

  • Data Sovereignty: All production databases, media attachments, and automated backups are physically housed within secure data centers located in Mumbai, India (AWS ap-south-1).
  • Encryption in Transit: All HTTP traffic is strictly routed over TLS 1.3 with automated HSTS preloading, neutralizing man-in-the-middle (MITM) risks.
  • Encryption at Rest: Cloud database volumes, automated snapshot backups, and uploaded documents are encrypted using AES-256 with hardware security module (HSM) managed keys.
Section 10

Subprocessors & Cloud Infrastructure

To provide high-availability hosting, automated messaging, and secure processing, Solanacy Websoft engages the following certified cloud subprocessors:

Subprocessor Service Purpose Data Jurisdiction
Amazon Web Services (AWS) Cloud compute, RDS database instances, S3 media storage Mumbai, India
Cloudflare, Inc. DDoS mitigation, web application firewall (WAF), edge routing Global Edge (India Points of Presence)
Meta Platforms (WhatsApp Cloud API) Automated bill dispatch, order alerts, customer support bot Enterprise Tier (Encrypted in transit)
Razorpay / Cashfree Payments Payment links, UPI dynamic QR verification, card tokenization India (RBI Regulated)
Section 11

Data Retention & Zero Lock-In Ownership

Solanacy stands firmly against vendor lock-in. We believe that your business data and software should belong unconditionally to you:

  • 100% Code & Data Ownership: For clients choosing full deployment, all source code, database schemas, and data instances are delivered into your own cloud accounts. You hold the master keys.
  • Instant Full Data Export: At any time, a merchant super-admin can generate a complete export of all inventory registers, customer ledgers, sales archives, and audit records in standard CSV, JSON, or SQL dump format.
  • Account Deletion & Data Purging: Upon contract completion or written termination, all merchant database records hosted on Solanacy-managed servers are permanently purged and cryptographically overwritten within 14 calendar days, unless statutory tax regulations (such as 6-year GST invoice retention) mandate archiving.
Section 12

Data Protection Officer & Grievance Redressal

In compliance with the Digital Personal Data Protection Act 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, Solanacy Technologies has designated a dedicated Data Protection Officer:

Designation
Data Protection Officer (DPO) — Websoft Division
Corporate Entity
Solanacy Technologies
Official Email
Engineering Desk / WhatsApp
Registered Office & Jurisdiction
Howrah, West Bengal 711101, India
Resolution Commitment
Acknowledged within 48 hours; resolved within 30 days
Formal Data Subject Access Request (DSAR)
Business clients or end-customers seeking formal data inspection, correction, or audit logs may submit a request with subject line [Websoft Privacy Request] to [email protected].