โ† Back to home
Legal

Data Processing Addendum

How Pronttera processes End-Customer personal data on a Shop's behalf. This addendum forms part of our Terms and Conditions and prevails over them on data-protection matters.

Last updated 21 September 2026

1. Roles and definitions

This Data Processing Addendum ("DPA") forms part of the Terms and Conditions between Pronttera ("Processor", "we") and the Shop ("Fiduciary", "you"), and applies whenever we process End-Customer personal data on your behalf through the Frostique platform.

For End-Customer personal data processed via your storefront, you are the Data Fiduciary โ€” you determine the purposes and means โ€” and Pronttera is your Data Processor, processing only on your behalf. "Personal Data", "Data Principal" (the End Customer), "Data Fiduciary" and related terms have the meanings given under the Digital Personal Data Protection Act, 2023 and applicable rules ("Data Protection Law").

Personal data of your own account and team members is processed by Pronttera as an independent Data Fiduciary under our Privacy Policy, and is outside this DPA.

2. Scope of processing

  • Subject matter โ€” hosting and operating your white-label storefront and order management on Frostique.
  • Duration โ€” the subscription term, plus the 90-day post-cancellation retention window described in section 10.3 of the Terms and Conditions.
  • Nature and purpose โ€” collection, storage, display and transmission of End-Customer data to receive, process and fulfil Orders; order-status notifications; and the features included in your plan, such as wishlist and custom-cake requests.
  • Data Principals โ€” your End Customers: storefront visitors and buyers.
  • Categories of data โ€” name; phone and email; delivery address; order details and history; custom-cake request contents; wishlist and preferences; storefront usage data.
  • Special categories โ€” not intended to be processed. You must not direct the submission of sensitive data through free-text fields.

3. Our obligations as Processor

We will:

  • Process End-Customer personal data only on your documented instructions โ€” your configuration and use of the platform constitute those instructions โ€” and not for our own purposes. We do not use End-Customer data for our marketing, and we never sell it.
  • Ensure that persons authorised to process the data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures, including encryption in transit, access controls and role-based permissions, logical tenant separation, audit logging of billing and subscription events, and payment handling delegated to an RBI-regulated gateway so that full card and UPI credentials are never stored on the platform.
  • Assist you with reasonable measures to respond to Data Principals’ requests for access, correction and erasure โ€” self-serve tools in the dashboard where available, and cooperation for the rest.
  • Notify you without undue delay, targeting within 72 hours, after becoming aware of a personal-data breach affecting End-Customer data, with the information reasonably needed for your own notifications to the Data Protection Board of India and to affected Data Principals.
  • On termination or expiry of your subscription, retain the data in archived form for 90 days for reactivation or export at your request, and then permanently delete it โ€” or delete it earlier on your verified written instruction โ€” except where retention is required by law.
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

4. Sub-processors

You provide general authorisation for the sub-processors below. We impose data-protection obligations on them consistent with this DPA, and remain responsible for their performance:

  • Razorpay Software Pvt. Ltd. (India) โ€” payment processing and autopay mandates.
  • Cloud hosting provider โ€” infrastructure, storage and backups.
  • Transactional email provider โ€” delivery of service and order emails.
  • WhatsApp and SMS providers (planned) โ€” order and renewal notifications.

We will give notice, by email or in the dashboard, of intended additions or replacements; if you reasonably object on data-protection grounds and no resolution is found, you may cancel per the Terms and Conditions. Current provider names and processing regions are available from info@pronttera.com on request.

5. Your obligations as Fiduciary

You are responsible for:

  • Having a lawful basis, including consent where required, for collecting and processing End-Customer data.
  • Publishing your own privacy notice to End Customers and honouring it.
  • The accuracy and lawfulness of your instructions to us.
  • Responding to Data Principals’ requests and grievances directed to you.
  • Using End-Customer data outside the platform โ€” exports, for example โ€” in compliance with Data Protection Law.

6. Audits and information

No more than once in any 12-month period, and on at least 30 days’ written notice, you may request written information โ€” including summaries of security practices โ€” reasonably necessary to verify our compliance with this DPA.

Any further audit rights, if agreed for Enterprise plans, will be set out in the applicable order form, conducted at your cost, during business hours, and subject to confidentiality.

7. Liability and precedence

Each party’s liability under this DPA is subject to the limitations and caps in section 18 of the Terms and Conditions. The order of precedence for data-protection matters is: this DPA, then the Privacy Policy, then the Terms and Conditions.

8. Governing law

This DPA is governed by the laws of India, with exclusive jurisdiction of the courts at Pune, Maharashtra, India.

9. Contact

Data-protection matters and breach notices go to our Grievance Officer โ€” info@pronttera.com ยท +91 77678 25344 โ€” Pronttera, KPCT Mall, Fatima Nagar, Pune, Maharashtra, India.

Still have a question?

Email us at info@pronttera.com and a human will get back to you.

Other policies
Privacy PolicyCookie PolicyTerms and ConditionsAcceptable Use PolicyEnd User Licence AgreementRefund Policy

This page is provided for information. It does not constitute legal advice.