This Data Processing Addendum (“DPA”) forms part of the agreement (“Agreement”) between SOLDOFI SOLUTIONS PRIVATE LIMITED (“Soldofi”) and the customer identified in the applicable Order Form, subscription agreement or other agreement (“Customer”). This DPA applies where Soldofi processes Personal Data on behalf of Customer in providing the Services.
1. Definitions
1.1 “Applicable Data Protection Law”
means privacy and data-protection laws applicable to the processing covered by this DPA, which may include, as applicable:
- the UK GDPR
- the UK Data Protection Act 2018
- India’s Digital Personal Data Protection Act 2023 and rules made under it, as and when applicable
- the Australian Privacy Act 1988 and Australian Privacy Principles
- the California Consumer Privacy Act, as amended
- applicable US state privacy laws; and
- other applicable privacy or data-protection legislation.
1.2 “Customer Personal Data”
means Personal Data contained in Customer Data that Soldofi processes on behalf of Customer.
1.3 “Data Subject”
includes an individual, Data Principal, consumer or other equivalent person protected by Applicable Data Protection Law.
1.4 “Personal Data”
means personal data, personal information or equivalent information protected by Applicable Data Protection Law.
1.5 “Personal Data Breach”
means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.
1.6 “Subprocessor”
means another processor engaged by Soldofi to process Customer Personal Data on behalf of Customer.
2. Roles of the Parties
Customer determines the purposes and means of processing Customer Personal Data except where otherwise required by applicable law.
Accordingly, where applicable:
- Customer acts as controller, Data Fiduciary, business or equivalent responsible entity; and
- Soldofi acts as processor, Data Processor, service provider, contractor or equivalent service provider.
Each party is responsible for complying with obligations applicable to its respective role.
3. Customer Instructions
Soldofi will process Customer Personal Data only:
- to provide the Services
- according to Customer’s documented instructions
- as configured or initiated by Customer through the Services
- as necessary to comply with the Agreement; or
- where required by applicable law.
The Agreement, this DPA, Customer’s use and configuration of the Services and other documented instructions accepted by Soldofi constitute Customer’s instructions.
If applicable law requires Soldofi to process Customer Personal Data other than according to Customer’s instructions, Soldofi will inform Customer before such processing unless legally prohibited.
Soldofi will inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law.
4. Customer Responsibilities
Customer is responsible for:
- determining the lawfulness of its processing
- providing required privacy notices
- obtaining required permissions or consents
- ensuring instructions are lawful
- ensuring it has authority to provide Customer Personal Data to Soldofi
- responding to Data Subjects except where Soldofi is independently responsible
- configuring access and permissions appropriately; and
- determining appropriate retention requirements for Customer Data.
5. Confidentiality
Soldofi will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access will be limited to personnel who require it for legitimate purposes relating to the Services.
6. Security
Soldofi will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures may include, as appropriate:
- encryption in transit
- protection of stored data
- identity and access management
- least-privilege controls
- role and permission controls
- segregation of duties
- secrets management
- audit logging
- environment separation
- vulnerability management
- security monitoring
- backups
- incident-response procedures
- change management; and
- supplier security controls.
Soldofi may update security measures as technologies and risks evolve, provided the overall level of protection is not materially reduced.
7. Subprocessors
Customer generally authorises Soldofi to engage Subprocessors to provide the Services.
Soldofi will:
- impose data-protection obligations on Subprocessors appropriate to the processing they perform
- remain responsible for its obligations under this DPA notwithstanding its engagement of Subprocessors to the extent required by Applicable Data Protection Law; and
- maintain information identifying material Subprocessors used to process Customer Personal Data.
Where required by Applicable Data Protection Law or the Agreement, Soldofi will provide notice of new material Subprocessors and a reasonable mechanism for Customer to raise legitimate data-protection objections.
An objection must relate to reasonable data-protection concerns.
If the parties cannot reasonably resolve a valid objection, the parties will work in good faith to identify an appropriate solution, which may include termination of the affected feature or Service where no reasonable alternative exists.
8. Data Subject Requests
Taking into account the nature of the processing, Soldofi will provide reasonable assistance to Customer in responding to valid requests from Data Subjects where required by Applicable Data Protection Law.
If Soldofi receives a request relating to Customer Personal Data for which Customer is responsible, Soldofi may direct the requester to Customer unless Soldofi is legally required to respond directly.
Customer remains responsible for determining how to respond to such requests.
9. Personal Data Breaches
Soldofi will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where notification is required under Applicable Data Protection Law.
To the extent reasonably available, Soldofi will provide information concerning:
- the nature of the breach
- affected data
- affected Data Subjects
- likely consequences
- measures taken or proposed; and
- information reasonably required for Customer’s regulatory assessment.
Information may be provided in phases as an investigation progresses.
Soldofi’s notification of an incident does not constitute an admission of fault or liability.
Customer is responsible for regulatory and Data Subject notifications for which Customer is legally responsible.
10. Assistance With Compliance
Taking into account the nature of processing and information available to Soldofi, Soldofi will provide reasonable assistance required by Applicable Data Protection Law concerning:
- security
- Personal Data Breach assessment
- regulatory notifications
- data-protection impact assessments; and
- prior consultation with regulators,
to the extent the relevant obligation relates to Soldofi’s processing of Customer Personal Data.
11. Return and Deletion
Following termination or expiration of the Services, Soldofi will delete or return Customer Personal Data in accordance with the Agreement and Customer’s valid instructions, unless applicable law requires retention.
Customer Personal Data may remain temporarily in backups until deleted or overwritten through Soldofi’s normal backup lifecycle.
During such period, remaining data will remain subject to applicable protections and will not be restored except where reasonably necessary for disaster recovery, security or legal purposes.
12. Audits and Information
Soldofi will make information reasonably necessary to demonstrate compliance with this DPA available to Customer.
Where required by Applicable Data Protection Law, Customer may request an audit concerning Soldofi’s compliance.
The parties will seek to satisfy audit requirements through current independent security reports, certifications, questionnaires or other documentation where reasonably sufficient.
Where an additional audit is legally required and existing documentation is insufficient:
- reasonable advance notice must be provided
- the audit must occur during normal business hours
- it must not unreasonably interfere with Soldofi’s operations
- auditors must be subject to confidentiality obligations
- the audit must not expose information concerning other customers; and
- Customer will bear reasonable costs unless the audit identifies a material breach by Soldofi.
13. International Transfers
Soldofi will implement a legally recognised transfer mechanism where Applicable Data Protection Law requires one for a transfer of Customer Personal Data.
13.1 United Kingdom
Where Customer Personal Data protected by UK data-protection law is transferred to a country that does not benefit from an applicable adequacy regulation and a transfer mechanism is required, the parties will use an applicable lawful transfer mechanism, which may include:
- the UK International Data Transfer Agreement; or
- the UK International Data Transfer Addendum to the EU Standard Contractual Clauses,
as appropriate.
13.2 Other Jurisdictions
Where another jurisdiction requires contractual or other safeguards for international transfers, the parties agree that the applicable legally recognised mechanism will apply to the extent required.
Soldofi will implement supplementary measures where reasonably necessary based on the nature of the transfer and applicable law.
14. California and Other US State Privacy Laws
To the extent Soldofi processes Customer Personal Data as a service provider, contractor or processor under applicable US state privacy law:
Soldofi will not:
- sell Customer Personal Data
- share Customer Personal Data for cross-context behavioural advertising
- retain, use or disclose Customer Personal Data outside the direct business relationship except as permitted by applicable law and the Agreement; or
- combine Customer Personal Data with personal information received from other persons except as permitted by applicable law.
Soldofi processes such information only for the business purposes described in the Agreement and Customer’s documented instructions.
Where applicable law grants Customer rights to take reasonable steps to verify Soldofi’s compliant use of Personal Data, Soldofi will provide reasonable cooperation consistent with this DPA.
15. India
Where India’s Digital Personal Data Protection Act 2023 and implementing rules apply to processing under this DPA:
- Customer will act as Data Fiduciary where it determines the purpose and means of processing
- Soldofi will act as Data Processor where it processes Customer Personal Data on Customer’s behalf
- Soldofi will process such information according to Customer’s instructions and applicable contractual requirements; and
- the parties will cooperate in satisfying applicable security, breach, rights and deletion requirements.
Nothing in this section applies an obligation before the relevant statutory provision has become legally effective unless the parties expressly agree otherwise.
16. Australia
Where the Australian Privacy Act applies, the parties will cooperate in meeting applicable Australian Privacy Principle requirements relevant to the Services.
Where Soldofi handles Personal Information on Customer’s behalf, Soldofi will:
- use the information for the purposes contemplated by the Agreement
- maintain reasonable security protections
- provide reasonable assistance concerning access, correction and privacy complaints where applicable; and
- implement appropriate arrangements for overseas disclosures where required.
17. Google Workspace API Data
Where Customer Personal Data originates from Google Workspace APIs, Soldofi will process that information in accordance with applicable Google API policies in addition to this DPA.
Soldofi’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Such information will not be sold or used for targeted advertising.
Google Workspace API data will not be used to create, train or improve general-purpose machine-learning or artificial-intelligence models where prohibited by Google’s applicable policies.
18. Processing Details
Subject Matter
Provision of Soldofi’s finance and accounting workflow Services.
Duration
For the duration of the Agreement and any limited retention period permitted or required under the Agreement or applicable law.
Nature and Purpose
Processing required to provide functionality such as:
- supplier management
- supplier onboarding
- invoice processing
- document processing
- accounts payable management
- approvals
- payment planning
- reconciliation
- reporting
- supplier communications
- accounting integrations
- email integrations
- audit trails
- support
- security; and
- related financial administration.
Categories of Data Subjects
May include:
- Customer employees
- authorised users
- directors and officers
- contractors
- supplier personnel
- vendor personnel
- Customer contacts
- Customer customers
- individuals appearing in accounting records
- individuals appearing in communications or documents; and
- other persons whose Personal Data Customer submits to the Services.
Categories of Personal Data
May include:
- identity information
- business contact information
- account information
- user identifiers
- employment or organisational information
- supplier information
- invoice information
- financial-account and remittance information
- accounting information
- transaction information
- tax and registration information
- email communications
- documents and attachments
- approval records
- audit information
- IP addresses
- authentication information; and
- technical and security information.
Special or Sensitive Data
The Services are not designed for Customer to intentionally submit special-category or highly sensitive Personal Data except where a feature expressly supports such processing.
Customer should not submit such information unless necessary, lawful and appropriate for the applicable Service.
Financial-account and remittance information may be treated as security-sensitive information and protected accordingly.
Frequency
Processing may occur continuously or as initiated by Customer, its authorised users, integrations or configured workflows.
19. Order of Precedence
If this DPA conflicts with the Agreement regarding processing of Personal Data, this DPA controls to the extent of that conflict.
Mandatory provisions of Applicable Data Protection Law and applicable transfer mechanisms prevail where required.
20. Liability
Liability arising under this DPA is subject to the liability provisions of the Agreement unless Applicable Data Protection Law prohibits such limitation.
21. Term
This DPA remains effective for as long as Soldofi processes Customer Personal Data on Customer’s behalf.
22. Contact
Data-protection communications concerning this DPA may be directed to:
SOLDOFI SOLUTIONS PRIVATE LIMITED
P-303, INDRAPRASTH-6, PRAHALADNAGAR
Ahmedabad – 380015, Gujarat, India
Email: support@soldofi.com