Data Processing Agreement

Last updated: 15 June 2026

This Data Processing Agreement ("DPA") forms part of the Retail Commerce OS Terms of Service and applies where we process personal data on your behalf as a data processor under applicable data protection laws (including the DPDP Act 2023 and GDPR where applicable).

1. Definitions

Controller: the Retail Commerce OS customer. Processor: Retail Commerce OS. Personal Data: any information relating to an identified or identifiable natural person.

2. Processing instructions

We process personal data only on your documented instructions, including for service delivery, support, and security purposes.

3. Security

We maintain appropriate technical and organisational measures including: encryption in transit and at rest, access controls, regular security assessments, and incident response procedures.

4. Sub-processors

We use the following categories of sub-processors to deliver our services:

We will notify you 30 days before adding new sub-processors that process personal data.

4a. Call recording & voice data

Where you enable the Calling module, call recordings constitute personal data under applicable law. You are the data controller for these recordings. We process them on your instructions to provide transcription, AI analysis, and quality scoring features. Recordings are stored in your workspace's configured S3 bucket and subject to the retention period you configure (default 365 days). You may reduce retention or disable recording at any time in workspace settings.

5. Data subject rights

We will assist you in responding to data subject requests (access, rectification, erasure) within 72 hours of notification.

6. Breach notification

We will notify you of any personal data breach without undue delay, and no later than 72 hours after becoming aware.

7. Return and deletion

By default, your data is retained for 90 days after termination so a subscription cancelled by mistake can be recovered. If you explicitly request return or deletion, we will return all personal data in machine-readable format or delete it within 30 days of that request, except where retention is required by law.

7a. Data residency

Our production infrastructure runs on a European hosting provider — customer data is not India-resident by default. Enterprise customers may request dedicated India-region deployment (VPS within India), available under a custom infrastructure addendum. All data in transit is encrypted (TLS 1.2+); credentials and API keys are encrypted at rest (AES-256-GCM). Personal data is processed by the sub-processors listed in section 4 above, each of which is bound by equivalent data protection obligations.

8. Audits & certifications

We do not currently hold SOC 2 or ISO 27001 certification. We satisfy audit requests through: (a) completion of your standard security questionnaire, (b) review of our documented security controls, and (c) on-site audit with 30 days advance notice as described in this section. We intend to pursue SOC 2 Type II as the company scales — this DPA will be updated once an engagement begins.

You may audit our compliance with this DPA once per year with 30 days notice.

9. Contact

Privacy contact: [email protected]