Data Processing Addendum
v1.0 · Effective 25 September 2026
Forms part of the Terms of Service · Accepted with them at /activate/terms
- Roles. The Merchant is the Data Fiduciary for personal data of its Customers ("Customer Data"); SchemeBook is a Data Processor engaged under a valid contract as DPDP Act §8(2) requires.
- Scope of processing. SchemeBook processes Customer Data only to provide the Platform as described in the Terms: enrollment, dues, reminders, receipts, passbook, online payment via Setu, reports and export. No other purpose.
- Instructions. The Merchant's configuration of the Platform (schemes, reminder schedule, opt-outs, staff access) constitutes its documented instructions. SchemeBook will not process Customer Data outside those instructions unless required by law, in which case it will inform the Merchant if permitted.
- Merchant obligations. The Merchant warrants that it has given Customers the portal notice, obtained any consent required for reminders and receipts on WhatsApp/SMS, has the right to enter Customer Data, and will honour Customer rights requests through the console.
- Sub-processors. The Merchant authorises the sub-processors listed in Privacy Policy §2.5. SchemeBook gives 30 days' notice before adding one; the Merchant may object in writing, and if the objection cannot be resolved may terminate under the Terms.
- Security. SchemeBook maintains the measures in Privacy Policy §2.7 and grants staff access on a least-privilege basis.
- Confidentiality. SchemeBook staff and contractors with access to Customer Data are bound by confidentiality obligations.
- Breach. SchemeBook notifies the Merchant of a personal-data breach affecting Customer Data without undue delay after becoming aware, with enough detail for the Merchant to meet its notification duties.
- Assistance. SchemeBook provides the tools (console edit, opt-out, export, audit trail) for the Merchant to respond to Customer rights requests, and reasonable further assistance on request.
- Deletion and return. On termination, Customer Data is available for export for 30 days, then deleted per Privacy Policy §2.8, except where law requires retention.
- Audit. Once a year, or after a breach, the Merchant may request a written summary of SchemeBook's security controls. On-site audits are by agreement and at the Merchant's cost.
- Liability. Governed by the Terms §1.10.