Data Processing Addendum

Version and effective date: 9 July 2026

This Addendum forms part of the Store Owner Agreement between the registered store owner (“Store”) and the operator of RushTech POS (“RushTech”).

1. Roles and scope

For personal data that the Store enters, collects, receives or manages for its business—including customer, employee, supplier, order, booking, invoice and support data—the Store determines the business purpose and is generally the Data Fiduciary. RushTech acts as a Data Processor when it hosts or otherwise processes that data to provide the contracted service.

RushTech separately acts as a Data Fiduciary for limited information it processes for its own legitimate service purposes, such as store registration, licensing, subscription billing, platform security, fraud prevention, support administration, legal compliance and service improvement. Where applicable and authorised, Haka Hospitality may support selected business verification, GST billing, and WhatsApp Business verification activities for RushTech POS, but this does not transfer ownership of the RushTech POS brand, software, or store/customer data to Haka Hospitality.

Each party remains responsible for the obligations that apply to its role under the Digital Personal Data Protection Act, 2023, its notified rules and other applicable law as those provisions commence.

2. Processing instructions

RushTech will process Store Personal Data only to provide, secure, maintain and support the enabled RushTech services; fulfil documented Store instructions; comply with applicable law; prevent fraud or misuse; and protect the rights and security of users and systems.

The Store’s use and configuration of the service, support requests and this Addendum constitute documented instructions. RushTech will notify the Store where an instruction appears unlawful unless prohibited by law.

3. Processing schedule

Subject matterHosted POS, online ordering, Store Owner access, support, reporting, optional cloud backup and related operational services.
DurationFor the active service relationship and the applicable deletion, backup, dispute and legal-retention periods.
PeopleCustomers, prospective customers, employees/users, suppliers, delivery personnel, booking guests, store representatives and support participants.
DataIdentity and contact data; addresses and delivery location; account identifiers; orders, bookings, payments and invoices; loyalty/credit records; staff permissions; supplier and inventory records; support messages; device, security and audit data; and data contained in optional backups.
OperationsCollection, recording, organisation, hosting, encryption, retrieval, transmission, reporting, support, backup, restoration, restriction, anonymisation and deletion.
Sensitive/high-risk contextThe Store must not enter Aadhaar, passwords, payment PINs, CVV, unnecessary medical information or other data not required by an enabled lawful workflow.

4. Store responsibilities

5. RushTech responsibilities

6. Service providers and subprocessors

The service may use hosting/infrastructure providers (currently including Hostinger), Google services such as Firebase, Google Sign-In and mapping/geocoding, Razorpay or another store-configured payment provider, email/notification providers, and technical support providers. RushTech's current production hosting server is located in India, and hosting-provider backup copies may be stored in Singapore.

Some providers act as subprocessors and others as independent Data Fiduciaries under their own terms, depending on the service. RushTech will require appropriate data-protection and security commitments where it appoints a processor and will provide updated provider information through its Privacy Policy or service notices.

The Store authorises these providers where needed for enabled features. If a material new provider creates a materially different processing risk, RushTech will give reasonable notice where practicable.

7. Security incidents

RushTech will investigate confirmed incidents affecting Store Personal Data, take reasonable containment and remediation measures, and provide the Store with available information reasonably needed for its legal assessment. The Store must promptly report suspected incidents and cooperate by preserving evidence, securing its accounts and following reasonable containment instructions.

Regulatory or individual notifications will be handled according to each party’s legal role. Neither party should make a misleading statement or name the other publicly without a lawful basis.

8. Rights requests and cooperation

If RushTech receives a request relating primarily to Store-controlled records, it may direct the requester to the Store and provide reasonable technical assistance. RushTech may respond directly for data it controls independently. Identity must be verified before personal data is disclosed, corrected or deleted.

Assistance that requires substantial custom engineering, restoration of archived data or legal work may be charged at an agreed reasonable rate unless applicable law requires otherwise.

9. Retention, return and deletion

During an active subscription, the Store may use available reports, exports and backup functions. The Store is responsible for retaining legally required business records and maintaining appropriate independent copies.

Following termination or a verified lawful request, RushTech will delete or anonymise Store Personal Data within a reasonable period, subject to financial/tax records, disputes, fraud/security evidence, legal holds, technical dependencies and protected backup cycles. Store-controlled records may be returned or exported using available product functions before closure.

Residual backup copies remain protected and expire through the applicable backup cycle, including any provider backup copies stored outside India such as Singapore. RushTech is not required to delete data that it must retain as an independent Data Fiduciary under law.

10. Audit information and responsibility

On reasonable written request, RushTech may provide available security, policy or compliance information relevant to the service. Requests must protect other tenants, confidential system information and security. On-site or third-party audits require prior written agreement regarding scope, timing, confidentiality and cost.

Each party is responsible for its own acts, omissions and legal obligations. Liability remains subject to the Store Owner Agreement to the fullest extent permitted by law; nothing limits liability that cannot lawfully be limited.

11. Priority and contact

If this Addendum conflicts with the Store Owner Agreement solely on personal-data processing, this Addendum controls. The remaining Store Owner Agreement continues to apply.

Operator and data-protection contact: Indrapal Singh Kohli, trading as RushTech POS, Surat, Gujarat, India. Email info@rushtechpos.com / phone +91 94287 69913. Where applicable and authorised, Haka Hospitality may support selected business verification, GST billing, and WhatsApp Business verification activities for RushTech POS.

Related documents: Store Owner Agreement, Privacy Policy, and Terms of Service.