Last updated: 1 July 2025
Data Processing Agreement
This Data Processing Agreement ("DPA") governs the processing of personal data by QuickCommerceOS ("Processor") on behalf of customers ("Controller") in connection with the QuickCommerceOS platform. This DPA forms part of and is subject to the QuickCommerceOS Terms of Service.
Enterprise and government customers: If you require a signed DPA, a custom DPA, or specific data localization commitments, please contact [email protected]. We can accommodate specific data handling requirements through a negotiated agreement.
1. Definitions
"Controller" means the QuickCommerceOS customer who determines the purposes and means of processing personal data on the platform.
"Processor" means QuickCommerceOS, which processes personal data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person processed through the QuickCommerceOS platform, including end-user data (marketplace customers, vendors, delivery partners).
"Processing" means any operation performed on personal data, including collection, recording, storage, retrieval, use, disclosure, or erasure.
"Sub-processor" means any third party engaged by QuickCommerceOS to process personal data on the Controller's behalf.
2. Scope and Nature of Processing
QuickCommerceOS processes personal data as a Processor acting on the Controller's behalf. The nature, purpose, and categories of data processed are:
- Marketplace customers: Name, contact details, order history, delivery addresses, payment method tokens
- Vendors: Business name, contact information, bank account details for settlement, catalog data
- Delivery partners: Name, contact details, location data during active deliveries, earnings records
Processing activities include storage, retrieval, order processing, payment orchestration, analytics, and communications as necessary to provide the platform.
3. Controller Obligations
The Controller agrees to:
- Have a lawful basis for collecting and processing personal data before using the platform to process it
- Provide appropriate privacy notices to data subjects (end users, vendors, delivery partners) as required by applicable law
- Handle data subject requests (access, deletion, correction) in coordination with QuickCommerceOS where the data is held on our infrastructure
- Ensure that any personal data submitted to the platform is submitted in compliance with applicable data protection laws
4. Processor Obligations
QuickCommerceOS as Processor agrees to:
- Process personal data only on documented instructions from the Controller, except where required by law
- Ensure that personnel authorized to process personal data are subject to appropriate confidentiality obligations
- Implement appropriate technical and organizational security measures to protect personal data
- Assist the Controller in fulfilling data subject rights requests, data breach notifications, and data protection impact assessments
- Delete or return all personal data to the Controller upon termination of services, at the Controller's choice, unless legal retention obligations apply
- Make available information necessary to demonstrate compliance with this DPA and to support audits
5. Sub-processors
QuickCommerceOS uses sub-processors to deliver its services. Current sub-processors include cloud infrastructure providers, payment processors, email delivery services, and analytics tools. A current list of sub-processors is available upon request.
We will provide at least 30 days' notice before engaging a new sub-processor that will have access to Controller personal data, giving you the opportunity to object. All sub-processors are bound by data processing agreements with equivalent protections to those in this DPA.
6. Security Measures
QuickCommerceOS implements the following categories of technical and organizational security measures:
- Encryption of data at rest and in transit (TLS 1.2+)
- Access controls and role-based permissions for internal staff
- Regular security assessments and vulnerability testing
- Incident response procedures and breach notification protocols
- Data minimization and purpose limitation practices
7. Data Breach Notification
In the event of a personal data breach affecting Controller data, QuickCommerceOS will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach, providing sufficient information to meet the Controller's notification obligations under applicable law.
8. Data Transfers
QuickCommerceOS is based in India. Data processing primarily occurs on infrastructure located in India. If you require data to remain within a specific jurisdiction, contact [email protected] to discuss whether this can be accommodated.
9. Duration and Termination
This DPA is effective for the duration of the QuickCommerceOS subscription and terminates upon expiry or termination of the Terms of Service. Upon termination, we will delete or return all Controller personal data within 90 days, unless legally required to retain it.
10. Contact
Data protection queries: [email protected]
To request a signed DPA or negotiate custom data processing terms, contact us at the same address.