Scope & System Architecture
This Privacy & Data Protection Policy specifically governs all software products, micro-applications, billing engines, Point-of-Sale (POS) interfaces, and cloud ERP systems operating under the Solanacy Websoft Suite, developed and distributed by Solanacy Technologies (Howrah, West Bengal, India).
The provisions herein apply to all standard and customized installations of the following six Websoft industry editions:
- Grocery & Supermarket POS: Barcode scanning, weighing scale synchronizers, inventory registers, and WhatsApp digital billing.
- Restaurant & Cafe KOT: Live Kitchen Order Ticket (KOT) routing, table QR ordering, cashier registers, and steward apps.
- Pharmacy & Healthcare ERP: Batch-expiry tracking, Schedule H/H1 registers, doctor prescription archives, and D-DEY PMS integrations.
- E-Commerce & Retail Engine: Multi-channel inventory, customer order portals, cart persistence, and automated shipping webhooks.
- Services & Agencies Portal: Appointment bookings, client retainer management, digital contract signing, and milestone invoicing.
- Custom Enterprise ERP: Multi-branch consolidated ledgers, factory floor supply chain tracking, and custom role workflows.
Data Controller vs. Data Processor Roles
Under the Digital Personal Data Protection (DPDP) Act 2023 and international privacy frameworks (GDPR), the legal relationships governing data handled within Solanacy Websoft are clearly demarcated as follows:
| Entity | Legal Classification | Responsibilities & Authority |
|---|---|---|
| The Merchant / Business Client (Shop Owner, Clinic, Restaurant, Enterprise) |
Data Fiduciary (Controller) | Determines the purpose and means of collecting customer data (e.g. phone numbers for billing, prescription records for pharmacy sales). Responsible for obtaining necessary customer consent. |
| Solanacy Technologies (Websoft Suite Platform) |
Data Processor | Processes transaction records, generates bills, routes kitchen tickets, and stores records solely on the direct instruction of the Merchant. Solanacy possesses zero independent ownership or rights to monetize merchant customer data. |
Merchant Information We Collect
To configure, license, and maintain a business client's Websoft deployment, Solanacy collects the following categories of direct merchant business information:
- Business Identity: Legal business trade name, registered GSTIN, shop/clinic establishment license number, owner/proprietor full name, and official registered address.
- Administrative Credentials: Super-admin email address, phone number, and cryptographically hashed passwords (salted with Argon2/bcrypt; cleartext passwords are never stored).
- Fiscal & Billing Details: Bank account details for UPI settlement mapping, billing address for annual software support invoices, and payment gateway API credentials (stored in secure client environment variables).
- System Telemetry & Performance Logs: Server CPU/RAM health metrics, database connection pool statistics, API response latencies, and error stack traces for proactive bug fixing.
End-Customer Data Handling & Rights
When a merchant uses Solanacy Websoft to serve their retail shoppers, restaurant patrons, or clinic patients, certain end-customer data is entered into the system. Solanacy Websoft handles this data under rigorous protective parameters:
- Customer Phone Numbers: Collected solely for generating and dispatching GST-compliant digital invoices, WhatsApp order confirmations, and tracking links. Never utilized by Solanacy for marketing.
- Delivery Addresses: In E-Commerce, Grocery, and Restaurant modules, customer shipping addresses and GPS coordinates are used strictly for fulfillment and delivery boy dispatch.
- Purchase History & Loyalty Balances: Itemized invoice histories are stored to calculate customer loyalty points, return/exchange authorizations, and warranty validation as determined by the merchant.
POS Architecture & Offline-First Storage
Solanacy Websoft billing terminals employ a resilient Offline-First Architecture utilizing browser IndexedDB, WebAssembly (WASM) SQLite, and local hardware caching to guarantee that checkout operations continue seamlessly even during severe broadband outages:
- Local Cache Isolation: Invoices generated while offline are encrypted and temporarily persisted within the local browser sandbox or device SQLite database until connectivity is re-established.
- Bi-directional Sync Verification: Upon network restoration, offline transactions are synchronized with the merchant's dedicated cloud instance using cryptographic conflict-resolution algorithms.
- Zero Terminal Leakage: Cashier session data, till balances, and offline cache keys are automatically cleared upon terminal logout or shift end.
WhatsApp Business & Invoicing Engine
Solanacy Websoft features an integrated WhatsApp notification engine connected via the official Meta WhatsApp Cloud API:
- Strict Transactional Intent: Messages dispatched through the Websoft bot are limited strictly to digital bills, KOT tickets, table reservation confirmations, prescription readiness, and delivery status updates.
-
One-Touch Opt-Out: Every automated message includes clear instructions allowing the recipient to reply with
STOPto immediately revoke consent and halt automated WhatsApp notifications from that merchant. - End-to-End Transit Security: Communications between Websoft servers and the Meta WhatsApp Cloud API are secured via mutual TLS (mTLS) with payload encryption.
Payment Gateways & UPI Dynamic QR
Solanacy Websoft enables frictionless digital payments via UPI Dynamic QR, POS soundboxes, and online payment aggregators (Razorpay, Cashfree, Stripe, Pine Labs):
When dynamic UPI QR codes are displayed on the POS customer display or printed on receipts, the QR code encodes only the merchant's Virtual Payment Address (VPA), invoice amount, and unique bill reference ID.
Role-Based Access Control (RBAC) & Audit Logs
Internal security within a merchant's business is enforced through granular Role-Based Access Control:
| Role | Permitted Data Access | Restricted Data |
|---|---|---|
| Cashier / Steward | Create orders, add items, view active table, generate bill. | Cannot view profit margins, supplier purchase costs, or full customer master database. |
| Store Manager | Apply authorized discounts, void mistaken lines, view shift sales summary. | Cannot export full customer database or alter system tax configurations. |
| Pharmacist | Dispense medicines, verify Schedule H prescriptions, record doctor details. | Cannot modify historical batch prices or audit logs. |
| Super Admin (Owner) | Full access to sales reports, P&L statements, user management, and data export. | All sensitive actions (e.g. database wipe, bulk price override) require 2FA authentication. |
All high-impact actions—including invoice cancellations, cash drawer manual open events, price overrides, and staff permission alterations—are indelibly recorded in an append-only audit log with timestamp, staff ID, and IP address.
Data Sovereignty & Cryptographic Security
Solanacy Websoft maintains strict adherence to Indian data localization mandates and enterprise security standards:
- Data Sovereignty: All production databases, media attachments, and automated backups are physically housed within secure data centers located in Mumbai, India (AWS ap-south-1).
- Encryption in Transit: All HTTP traffic is strictly routed over TLS 1.3 with automated HSTS preloading, neutralizing man-in-the-middle (MITM) risks.
- Encryption at Rest: Cloud database volumes, automated snapshot backups, and uploaded documents are encrypted using AES-256 with hardware security module (HSM) managed keys.
Subprocessors & Cloud Infrastructure
To provide high-availability hosting, automated messaging, and secure processing, Solanacy Websoft engages the following certified cloud subprocessors:
| Subprocessor | Service Purpose | Data Jurisdiction |
|---|---|---|
| Amazon Web Services (AWS) | Cloud compute, RDS database instances, S3 media storage | Mumbai, India |
| Cloudflare, Inc. | DDoS mitigation, web application firewall (WAF), edge routing | Global Edge (India Points of Presence) |
| Meta Platforms (WhatsApp Cloud API) | Automated bill dispatch, order alerts, customer support bot | Enterprise Tier (Encrypted in transit) |
| Razorpay / Cashfree Payments | Payment links, UPI dynamic QR verification, card tokenization | India (RBI Regulated) |
Data Retention & Zero Lock-In Ownership
Solanacy stands firmly against vendor lock-in. We believe that your business data and software should belong unconditionally to you:
- 100% Code & Data Ownership: For clients choosing full deployment, all source code, database schemas, and data instances are delivered into your own cloud accounts. You hold the master keys.
- Instant Full Data Export: At any time, a merchant super-admin can generate a complete export of all inventory registers, customer ledgers, sales archives, and audit records in standard CSV, JSON, or SQL dump format.
- Account Deletion & Data Purging: Upon contract completion or written termination, all merchant database records hosted on Solanacy-managed servers are permanently purged and cryptographically overwritten within 14 calendar days, unless statutory tax regulations (such as 6-year GST invoice retention) mandate archiving.
Data Protection Officer & Grievance Redressal
In compliance with the Digital Personal Data Protection Act 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, Solanacy Technologies has designated a dedicated Data Protection Officer:
[Websoft Privacy Request] to [email protected].