Data Processing Agreement (DPA)

Privacy Compliance & Data Processing Agreement

To comply with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the emerging Digital Personal Data Protection (DPDP) Act, 2023, the following outlines the data relationship between you (the Restaurant Partner) and us (Techcardz Services Private Limited).

4.1 Data Fiduciary and Data Processor Roles

Data Fiduciary (Restaurant Partner): You are the Data Fiduciary. You independently determine the purpose and means of collecting personal data from your diners (e.g., collecting phone numbers for order tracking, marketing, or loyalty points). You are legally responsible for obtaining the necessary consent from your diners to collect this data.

Data Processor (Techcardz Services Private Limited): We are the Data Processor. We process the diners' personal data strictly on your behalf, according to your instructions, and solely for the purpose of operating the techrestoPOS software features you have activated.

4.2 Obligations of the Data Fiduciary (You)

You agree to:

  • Obtain clear, explicit, and verifiable consent from diners before using techrestoPOS to capture their data.
  • Ensure that your use of the platform's SMS, marketing, and loyalty features complies with all anti-spam laws (e.g., TRAI regulations in India).
  • Respond to and manage any "Right to be Forgotten" or data deletion requests made by your diners.

4.3 Obligations of the Data Processor (Us)

We agree to:

  • Process data only to deliver the Services outlined in these Terms.
  • Implement robust technical and organizational measures to ensure a level of security appropriate to the risk.
  • Provide you with the necessary software tools (via the Admin Dashboard) to delete, anonymize, or export customer data to fulfill your legal obligations to your diners.
  • Notify you without undue delay, and in no case later than 72 hours, after becoming aware of a personal data breach affecting your tenant environment.

4.4 Sub-Processors

You authorize Techcardz Services Private Limited to engage third-party sub-processors (such as cloud infrastructure providers) to process personal data. We ensure that our sub-processors are bound by data protection obligations at least as restrictive as those contained in this agreement.