Data Processing Agreement
Last updated: 2026-07-01
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between GrowThozhil Solutions Partnership Firm(“POSEngine”, “we”, “us”) and the customer (“you”, “Data Fiduciary”) who has subscribed to POSEngine services. It governs POSEngine’s role as a Data Processor under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).
1. Roles
You are the Data Fiduciary for the personal data of your customers, staff, and vendors that you enter into or generate through POSEngine. We are the Data Processor — we process that data on your written instructions (this DPA, the Terms of Service, and our documented APIs) and for no other purpose. We are also the Data Fiduciary for personal data about you directly (your account, billing, support communications) — that data is governed by our Privacy Policy.
2. Categories of personal data we process on your behalf
- Customer identifiers: name, phone, email, GSTIN, postal address, loyalty membership
- Sales evidence: invoice line items, payment mode, refund/return records
- Vendor identifiers: business name, contact, GSTIN, address, bank details for purchase orders
- Staff identifiers: name, phone, email, role, login timestamps
- Cash session data: opening/closing balances, variance, cashier identity
3. Purpose of processing
Solely to provide the POSEngine service as described in the Terms of Service: billing, inventory, sales, GST returns, receipts & notifications, sync between terminals, backup, and features you explicitly enable. We do not sell, rent, share for advertising, or use your data to train models.
4. Security measures (DPDP §8(4))
- Encryption in transit (TLS 1.2+) and at rest (AWS RDS, S3 SSE-AES256)
- Per-tenant data isolation — every query is scoped by storeId; audited quarterly
- Access controls: least-privilege IAM roles, no direct human access to production DB except via short-lived audited session
- Immutable append-only consent records with server-side timestamp + IP evidence
- Automated backups daily (14-day retention) plus manual snapshots pre-deploy
- CloudWatch alarms on webhook + mail failures + 5xx bursts + RDS/Redis health
- Multi-AZ database replication + automatic failover
5. Sub-processors
We use the following sub-processors and require each to maintain security and confidentiality obligations no less protective than this DPA:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services India Pvt Ltd | Compute, storage, database, DNS | Mumbai (ap-south-1) |
| Razorpay Software Pvt Ltd | Payment processing | India |
| Sendinblue SAS (Brevo) | Transactional email delivery | EU (GDPR-adequate) |
| Meta Platforms (WhatsApp Cloud API) | Customer messaging (only if you enable) | USA / Ireland |
| Quicko (Quicko Infosoft Pvt Ltd) / NIC | GST e-invoice (IRN) / e-way bill (only if you enable) | India |
We will give you at least 30 days’ notice at your registered email before adding a new sub-processor or replacing an existing one, so you may object.
6. Data Principal rights (DPDP §11-14)
When a Data Principal exercises their rights (access, correction, erasure, grievance), you are the primary responder. We will help you comply within 5 business days of your written request. Requests may be sent to grievance@posengine.in.
7. Data breach notification (DPDP §8(6))
In the event of a personal data breach affecting your data, we will notify you without undue delay and no later than 24 hours after we become aware. We will include: nature of the breach, categories and approximate number of Data Principals affected, likely consequences, and measures taken. This assists you in your own 72-hour notification obligation to the Data Protection Board.
8. Data retention and deletion
We retain your data for the duration of your subscription plus a 30-day grace period after termination, during which you may export via the Admin dashboard. After that, we permanently delete customer PII within 60 days, except that consent evidence (ConsentRecord rows) is retained for 3 years post-account-closure per DPDP §8(7).
9. Cross-border transfers
Data at rest and in-country processing are performed in India (AWS Mumbai). If a sub-processor is located outside India (Brevo/EU, Meta/US), transfers happen only when you enable the corresponding feature and under contractual data protection terms.
10. Termination
Either party may terminate this DPA by giving 30 days’ written notice, or immediately for material breach. Upon termination we return or delete your data as instructed by you, subject to retention obligations above.
11. Grievance officer & contact
Grievance Officer: Mohanraj S, Managing Partner
Email: grievance@posengine.in
Address: GrowThozhil Solutions, Namakkal, Tamil Nadu 637408, India
Response SLA: 24 hours during Indian business days.
12. Consent to this DPA
By ticking the consent box at signup or by continuing to use the POSEngine service after the effective date shown at the top of this page, you agree to this DPA. Your acceptance is recorded in our append-only ConsentRecord log (version hash pinned to the exact text you saw).