Legal

Data Processing Agreement

Controller / processor roles, GDPR-style clauses, confidentiality, and security measures for enterprise customers.

Last updated: July 2026

1. Roles

For marketplace end-customer personal data synced through integrations you enable, you (the seller / business customer) are typically the Data Controller (or equivalent under Indian law / DPDP). Khodi Mart acts as a Data Processor / service provider processing that data on your documented instructions to provide the Platform.

For account, billing, support tickets, and platform telemetry about your users of Khodi Mart, we act as an independent controller / business for that processing as described in the Privacy Policy.

2. Data Controller obligations

  • Ensure you have a lawful basis to sync marketplace and customer data into Khodi Mart.
  • Configure integrations with least-privilege scopes and disconnect when no longer needed.
  • Respond to end-customer rights requests that apply to your retail business.
  • Not instruct Khodi Mart to process data for unlawful purposes.
  • Keep your authorised users’ access lists accurate.

3. Data Processor obligations

  • Process personal data only to provide Platform features you enable and as documented in product Docs / this DPA.
  • Apply technical and organisational security measures described in our Security Policy.
  • Ensure personnel with access are bound by confidentiality.
  • Engage subprocessors under written terms no less protective than this DPA; maintain a list available to Enterprise customers under NDA.
  • Assist with reasonable deletion / export / access requests subject to verification and legal retention.
  • Notify you without undue delay of a personal-data breach affecting your Controller data, where legally required.

4. Categories of data & data subjects

  • Data subjects: your retail end-customers (via marketplace APIs), your staff users, and (where applicable) logistics contacts on labels.
  • Categories: identifiers, contact and address fields on orders, order/shipment metadata, inventory identifiers, settlement summaries, support content you submit.
  • Special category data: not intentionally collected; do not upload health or biometric data into MAYA or tickets.

5. GDPR / international clauses

Where GDPR or similar regimes apply to an enterprise customer’s processing, the parties will execute or incorporate standard contractual clauses / transfer tools as needed. Primary operations are India-centric; some subprocessors (cloud, email, LLM providers) may process data in other jurisdictions under appropriate safeguards.

6. Confidentiality

Each party will protect the other’s confidential business information and not disclose it except to personnel and subprocessors who need it to perform under this DPA, or as required by law (with notice where legally permitted).

7. Security measures

  • TLS in transit; AES-256-GCM (or equivalent) for marketplace tokens at rest.
  • Role-based access and seller-scoped queries.
  • Audit logs for sensitive integration actions.
  • Backups, rate limiting, and vulnerability management as described in Security Center.
  • Enterprise customers may negotiate additional audit rights in a signed MSA.

8. Retention & return

Upon termination of processing services for Controller data, we will delete or return personal data in our systems within a commercially reasonable period, except where law requires retention or data has been anonymised. Marketplace tokens are wiped on disconnect.

9. Contact

Enterprise DPA / MSA requests: support@khodimart.com with subject “DPA / Enterprise”. Security: security@khodi.in.

Also see Trust Center, Privacy, Terms, Security, Compliance, Cookies, DPA, Disclosure, and Help.