Data Processing Addendum

Last updated September 2026. This forms part of the Terms of Service and applies to every Parchi account.

1. Who is who

You are the Data Fiduciary for the personal data you enter about your customers and staff. We are your Data Processor for it: we store it, show it back to you, and act on your instructions.

Separately, we are the Data Fiduciary for your own account data — your name, email and phone. That part is covered by the Privacy Policy.

2. What we process, and on what instruction

Customer names, phone numbers, email addresses, addresses, GSTINs, dates of birth, visit history, bills, payments and any notes you write. We process it only to provide the service: storing it, computing totals, rendering messages you choose to send, and producing the reports and exports you ask for.

We do not use it for our own purposes. We do not sell it, share it with advertisers, profile anybody with it, or use it to train machine learning models.

3. Children's data

Tuition centres, coaching classes and some fitness businesses store records about students, who may be minors. Under the DPDP Act, processing a child's personal data requires verifiable parental consent and prohibits tracking or targeted advertising directed at children.

Obtaining that consent is your obligation as the fiduciary. Ours, as processor, is that we never profile, track or advertise to anybody in your records — child or adult — which we do not do for any user of this product.

4. Subprocessors

Everyone who processes your data on our behalf, and what for.

CompanyWhat forWhere
Hetzner Application hosting and database Germany
Cloudflare R2 Logo and export file storage European Union
Amazon SES Transactional email India (ap-south-1)
Razorpay Our own licence billing India
Expo Push notification delivery United States

We will tell you before adding one. Each is bound by terms no weaker than these.

5. Security

Encrypted in transit and at rest. Access to production data is limited to those who need it, and every time one of us acts inside your account it is recorded in a log you can read — More → Account → Activity. Backups are nightly, encrypted, off-site and restore-tested.

6. If something goes wrong

We will notify you without undue delay and in any case within 72 hours of becoming aware of a breach affecting your data, with what happened, what was affected, and what we are doing. You remain responsible for notifying the individuals concerned and the Data Protection Board, since you are their fiduciary — we will give you everything you need to do it.

7. Deletion and return

You can export everything at any time, in a format built to be imported elsewhere. When you delete your account we permanently remove the data after 30 days. Anything covered by a retention period in the Privacy Policy is deleted on that schedule, enforced nightly.

8. Contact

Grievance Officer
support@applightinfotech.com

Parchi