Data Processing Agreement (DPA)
Last Updated: August 29, 2026
1. Parties & Relationship
This Data Processing Agreement ("DPA") applies to wholesale distributors ("Customer", "Data Fiduciary" or "Data Controller") who enter retail store customer data into SlipDesk ("Data Processor"), operating from Pune, Maharashtra, India. This agreement supplements our Terms of Service in compliance with applicable Indian data protection laws, including the Digital Personal Data Protection (DPDP) Act.
2. Scope & Nature of Processing
The Data Processor processes retail customer data solely on behalf of and under the documented instructions of the Customer for the following purposes:
- Transcribing incoming WhatsApp orders into itemized wholesale invoices.
- Formatting delivery challans and dispatch loading manifests.
- Maintaining customer balance ledgers and generating WhatsApp payment reminders.
3. Categories of Data Processed
- Data Subjects: Retail kirana store owners, commercial buyers, and distributor employees.
- Data Types: Business name, contact person name, mobile telephone number, delivery route area, physical store address, order line items, and financial debit/credit balance records.
4. Technical & Organizational Security Measures
The Data Processor implements rigorous safeguards:
- Tenant Isolation: Multi-tenant cloud databases employ Row Level Security (RLS) in PostgreSQL ensuring that data belonging to Organization A cannot be viewed or accessed by Organization B.
- Encryption: Data in transit is protected by TLS 1.3 encryption.
- Local Isolation: Client-side LocalStorage records reside exclusively within the distributor's local browser instance.
5. Authorized Sub-processors
The Customer provides general authorization for the following essential infrastructure sub-processors:
- Supabase Inc.: Managed PostgreSQL cloud database hosting with data encryption at rest.
- Vercel Inc.: Application hosting and secure edge network delivery.
6. Data Portability & Termination Erasure
The Customer has self-serve access to export or delete all processed data at any time via Settings. Upon termination of service, all cloud-hosted database records will be permanently deleted upon verified request.