Data Processing Addendum

The terms under which LetBuyy processes your shoppers' data for you.

Applies to
Merchants
Clauses
10
Reading time
3 min
Revised
3 August 2026

These policies are published for review and are not yet in force. LetBuyy has not opened to merchants, so no agreement has been formed with anyone. They take effect on the day the platform launches, and the effective date will be stated here. Last revised 3 August 2026.

In short

  • When your store holds customer data, you are the Data Fiduciary and LetBuyy is your Processor.
  • We act on your instruction, do not use your customer data for our own purposes, and hold our sub-processors to the same terms.
  • This addendum forms part of your agreement with us and applies automatically — there is nothing to sign.

This summary is written to be understood. The clauses below are what actually applies — where the two differ, the clauses govern.

  1. Roles

    You determine what personal data your store collects from shoppers and why. That makes you the Data Fiduciary under the DPDP Act, and the equivalent of a controller under other regimes.

    We process that data solely to provide the platform to you. That makes us your Processor. We do not decide the purposes and we do not process for our own.

  2. Our instructions

    We process shopper data only as needed to deliver the service, to keep it secure, and where a law compels us. Your configuration of the platform is your instruction.

    If a legal requirement forces us to process beyond your instruction, we will tell you before doing so unless the law forbids notice.

  3. Confidentiality and access

    Access to production data is limited to personnel who need it, is authenticated individually, and is logged.

    Everyone with such access is bound by confidentiality obligations that survive the end of their engagement.

  4. Sub-processors

    We use the sub-processors listed in the Sub-processor Register, each bound to obligations no weaker than these.

    We will give notice before adding a sub-processor that handles shopper personal data, so you have a chance to object. Objecting may mean you cannot continue using the affected feature.

    We remain responsible to you for our sub-processors' performance.

  5. Security measures

    Encryption in transit and at rest; per-tenant isolation enforced at the database layer; least-privilege access; step-up authentication on money-moving operations; signed webhooks and queue messages; and monitoring of access to production systems.

    The Security Practices page describes these in more detail. We may improve a measure but will not materially weaken the overall level of protection.

  6. Personal data breach

    If we become aware of a breach affecting your shoppers' data, we will notify you without undue delay with what we know: what happened, what data and how many people are affected, what we are doing, and what you should do.

    The DPDP Rules require the Data Fiduciary to notify affected individuals and the Board. Since that is you, we will give you what you need to meet that duty on time.

  7. Helping you answer your shoppers

    When a shopper exercises a right against you, we make the underlying data available to you through the dashboard and the APIs so you can answer without needing us in the loop.

    For anything the tooling does not cover, ask and we will help within the time your legal deadline allows.

  8. Return and deletion

    Export your data at any time while your account is open. Do it before you close the account — that is the point at which it becomes hard.

    After closure, data is deleted at the end of the wind-down period, except records we are legally required to retain — principally invoices, orders, and ledger entries under tax and company law.

    Backups age out on their own cycle rather than being individually edited, so deletion from backups completes when the backup expires.

  9. Where data is processed

    We prefer Indian regions for primary data storage. Some sub-processors operate globally distributed infrastructure, and the register states where each one runs.

    The DPDP Act permits transfer outside India except to countries the government restricts. We will comply with any such restriction if one is notified.

  10. Demonstrating compliance

    We will provide the information reasonably needed to show we meet this addendum. Where an audit right applies, it is exercised on reasonable notice, no more than once a year absent a breach, and without compromising other merchants' data.

Questions about this document

Write to support@letbuyy.com and quote the clause number. For a complaint rather than a question, use the grievance process.