Data Processing Addendum
Version and effective date: 9 July 2026
This Addendum forms part of the Store Owner Agreement between the registered store owner (“Store”) and the operator of RushTech POS (“RushTech”).
1. Roles and scope
For personal data that the Store enters, collects, receives or manages for its business—including customer, employee, supplier, order, booking, invoice and support data—the Store determines the business purpose and is generally the Data Fiduciary. RushTech acts as a Data Processor when it hosts or otherwise processes that data to provide the contracted service.
RushTech separately acts as a Data Fiduciary for limited information it processes for its own legitimate service purposes, such as store registration, licensing, subscription billing, platform security, fraud prevention, support administration, legal compliance and service improvement. Where applicable and authorised, Haka Hospitality may support selected business verification, GST billing, and WhatsApp Business verification activities for RushTech POS, but this does not transfer ownership of the RushTech POS brand, software, or store/customer data to Haka Hospitality.
Each party remains responsible for the obligations that apply to its role under the Digital Personal Data Protection Act, 2023, its notified rules and other applicable law as those provisions commence.
2. Processing instructions
RushTech will process Store Personal Data only to provide, secure, maintain and support the enabled RushTech services; fulfil documented Store instructions; comply with applicable law; prevent fraud or misuse; and protect the rights and security of users and systems.
The Store’s use and configuration of the service, support requests and this Addendum constitute documented instructions. RushTech will notify the Store where an instruction appears unlawful unless prohibited by law.
3. Processing schedule
| Subject matter | Hosted POS, online ordering, Store Owner access, support, reporting, optional cloud backup and related operational services. |
|---|---|
| Duration | For the active service relationship and the applicable deletion, backup, dispute and legal-retention periods. |
| People | Customers, prospective customers, employees/users, suppliers, delivery personnel, booking guests, store representatives and support participants. |
| Data | Identity and contact data; addresses and delivery location; account identifiers; orders, bookings, payments and invoices; loyalty/credit records; staff permissions; supplier and inventory records; support messages; device, security and audit data; and data contained in optional backups. |
| Operations | Collection, recording, organisation, hosting, encryption, retrieval, transmission, reporting, support, backup, restoration, restriction, anonymisation and deletion. |
| Sensitive/high-risk context | The Store must not enter Aadhaar, passwords, payment PINs, CVV, unnecessary medical information or other data not required by an enabled lawful workflow. |
4. Store responsibilities
- Have a lawful purpose and provide required notices or obtain valid consent where applicable.
- Collect only data reasonably required for the Store’s operations and keep it accurate.
- Configure products, policies, retention, staff roles and permissions appropriately.
- Protect credentials and devices, remove access promptly when staff leave, and notify RushTech of suspected compromise.
- Respond to customer rights, refund, employment, tax and consumer-law obligations for Store-controlled records.
- Do not instruct RushTech to process data unlawfully or use the service for prohibited discrimination, surveillance, spam or fraud.
5. RushTech responsibilities
- Limit access to authorised personnel and service components with a business need.
- Use reasonable technical and organisational safeguards, including access controls, tenant separation, encrypted transport, password hashing, logging and appropriate encryption at rest where implemented.
- Maintain confidentiality obligations for persons authorised to process Store Personal Data.
- Assist the Store, within reasonable technical capability, with verified access, correction, deletion, grievance and breach obligations.
- Not sell Store Personal Data or use it for unrelated advertising.
6. Service providers and subprocessors
The service may use hosting/infrastructure providers (currently including Hostinger), Google services such as Firebase, Google Sign-In and mapping/geocoding, Razorpay or another store-configured payment provider, email/notification providers, and technical support providers. RushTech's current production hosting server is located in India, and hosting-provider backup copies may be stored in Singapore.
Some providers act as subprocessors and others as independent Data Fiduciaries under their own terms, depending on the service. RushTech will require appropriate data-protection and security commitments where it appoints a processor and will provide updated provider information through its Privacy Policy or service notices.
The Store authorises these providers where needed for enabled features. If a material new provider creates a materially different processing risk, RushTech will give reasonable notice where practicable.
7. Security incidents
RushTech will investigate confirmed incidents affecting Store Personal Data, take reasonable containment and remediation measures, and provide the Store with available information reasonably needed for its legal assessment. The Store must promptly report suspected incidents and cooperate by preserving evidence, securing its accounts and following reasonable containment instructions.
Regulatory or individual notifications will be handled according to each party’s legal role. Neither party should make a misleading statement or name the other publicly without a lawful basis.
8. Rights requests and cooperation
If RushTech receives a request relating primarily to Store-controlled records, it may direct the requester to the Store and provide reasonable technical assistance. RushTech may respond directly for data it controls independently. Identity must be verified before personal data is disclosed, corrected or deleted.
Assistance that requires substantial custom engineering, restoration of archived data or legal work may be charged at an agreed reasonable rate unless applicable law requires otherwise.
9. Retention, return and deletion
During an active subscription, the Store may use available reports, exports and backup functions. The Store is responsible for retaining legally required business records and maintaining appropriate independent copies.
Following termination or a verified lawful request, RushTech will delete or anonymise Store Personal Data within a reasonable period, subject to financial/tax records, disputes, fraud/security evidence, legal holds, technical dependencies and protected backup cycles. Store-controlled records may be returned or exported using available product functions before closure.
Residual backup copies remain protected and expire through the applicable backup cycle, including any provider backup copies stored outside India such as Singapore. RushTech is not required to delete data that it must retain as an independent Data Fiduciary under law.
10. Audit information and responsibility
On reasonable written request, RushTech may provide available security, policy or compliance information relevant to the service. Requests must protect other tenants, confidential system information and security. On-site or third-party audits require prior written agreement regarding scope, timing, confidentiality and cost.
Each party is responsible for its own acts, omissions and legal obligations. Liability remains subject to the Store Owner Agreement to the fullest extent permitted by law; nothing limits liability that cannot lawfully be limited.
11. Priority and contact
If this Addendum conflicts with the Store Owner Agreement solely on personal-data processing, this Addendum controls. The remaining Store Owner Agreement continues to apply.
Operator and data-protection contact: Indrapal Singh Kohli, trading as RushTech POS, Surat, Gujarat, India. Email info@rushtechpos.com / phone +91 94287 69913. Where applicable and authorised, Haka Hospitality may support selected business verification, GST billing, and WhatsApp Business verification activities for RushTech POS.
Related documents: Store Owner Agreement, Privacy Policy, and Terms of Service.