DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) forms part of the Master Service Agreement (“MSA”) between XploroTech Solutions Private Limited (“XploroTech”, “Company”, “we”, “us”, or “our”) and the Customer identified in the applicable Order Form, subscription record, invoice, account registration, or electronic acceptance record (“Customer”, “you”, or “your”).
This DPA applies where XploroTech processes Customer Personal Data on behalf of the Customer in connection with VENTA Xploro POS, VENTA Admin, VENTA Insights, VENTA Captain, Xploro AI, related mobile applications, APIs, integrations, dashboards, support services, and future VENTA-branded services (“Services”).
In case of conflict between this DPA and the MSA regarding the processing of Customer Personal Data, this DPA shall prevail.
1. Definitions
Unless otherwise defined in this DPA, capitalised terms have the meanings assigned to them in the MSA.
“Applicable Data Protection Law” means all laws, rules, regulations, directions, and binding requirements applicable to the processing of Personal Data under this DPA, including, where applicable, the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000, related rules, and other applicable privacy or data-protection laws.
“Customer Personal Data” means Personal Data included within Customer Data that XploroTech processes on behalf of the Customer while providing the Services.
“Data Fiduciary” means the person who alone or in conjunction with other persons determines the purpose and means of processing Personal Data.
“Data Principal” means the individual to whom Personal Data relates.
“Data Processor” means a person who processes Personal Data on behalf of a Data Fiduciary.
“Personal Data” means any data about an individual who is identifiable by or in relation to such data.
“Personal Data Breach” means unauthorised processing, accidental disclosure, acquisition, sharing, use, alteration, destruction, loss, or loss of access to Customer Personal Data that compromises its confidentiality, integrity, or availability.
“Process”, “Processing”, or “Processed” means any wholly or partly automated operation performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, use, sharing, disclosure, transmission, restriction, erasure, or destruction.
“Subprocessor” means a third party engaged by XploroTech to process Customer Personal Data on behalf of the Customer in connection with the Services.
“Subprocessor List” means the current list of infrastructure, hosting, monitoring, communication, support, analytics, AI, and other approved service providers published at https://venta-pos.com/ai-subprocessors-and-data-use/
2. Roles of the Parties
2.1 For Customer Personal Data processed through the Services:
a. the Customer is generally the Data Fiduciary; and
b. XploroTech is generally the Data Processor acting on behalf of the Customer.
2.2 The Customer determines the purposes and means of its use of the Services, including the collection and use of Personal Data relating to its guests, customers, members, employees, delivery recipients, vendors, suppliers, business contacts, and other individuals.
2.3 XploroTech acts as an independent Data Fiduciary, and not as the Customer’s Data Processor, when processing Personal Data for its own legitimate business purposes, including:
a. account registration and account administration;
b. subscription management, invoicing, payment collection, and tax compliance;
c. contract management and legal compliance;
d. fraud prevention, misuse detection, platform security, and service integrity;
e. support-ticket management and customer communications;
f. marketing communications where permitted by applicable law;
g. website and product analytics;
h. internal audit, risk management, and dispute resolution; and
i. responding to lawful authority, regulatory, legal, or court requests.
2.4 The Privacy Notice governs XploroTech’s processing as an independent Data Fiduciary.
2.5 The Customer remains responsible for determining whether it is itself a Data Fiduciary, joint Data Fiduciary, Data Processor, employer, service provider, or another legally recognised role in relation to any Personal Data it processes through the Services.
3. Scope and Instructions for Processing
3.1 XploroTech shall process Customer Personal Data only:
a. to provide, maintain, secure, support, and improve the Services;
b. in accordance with the Customer’s documented instructions, including the Customer’s authorised use of the Services;
c. as necessary to perform the MSA, Order Form, support obligations, and this DPA;
d. as necessary to prevent fraud, abuse, security incidents, or unauthorised use;
e. as required by Applicable Data Protection Law, lawful authority request, court order, or regulatory requirement; and
f. as otherwise expressly authorised by the Customer in writing.
3.2 The Customer’s use of the Services, configuration of the Services, instructions to XploroTech, and actions of its Authorised Users shall constitute documented instructions for the purpose of this DPA.
3.3 Where XploroTech is required by law to process Customer Personal Data other than on the Customer’s instructions, XploroTech shall notify the Customer before such processing where legally permitted. If notification is prohibited by law, XploroTech may process such Customer Personal Data to the extent legally required.
3.4 XploroTech shall not sell Customer Personal Data or use Customer Personal Data for targeted advertising unrelated to the provision, security, support, or improvement of the Services.
3.5 XploroTech shall not use Customer Personal Data, AI prompts, source code, schemas, support logs, or AI outputs to train a general-purpose AI model unless the Customer separately opts in through a written agreement or an expressly enabled product setting.
3.6 XploroTech may use aggregated and de-identified information that does not reasonably identify the Customer or an individual for service security, product improvement, analytics, capacity planning, benchmarking, and research.
4. Customer Responsibilities
4.1 The Customer represents and warrants that it has all necessary rights, authority, notices, permissions, consents, lawful bases, and approvals required to provide Customer Personal Data to XploroTech and permit its processing under this DPA.
4.2 The Customer is responsible for:
a. providing Data Principals with all legally required notices;
b. obtaining consent where consent is the appropriate legal basis;
c. responding to Data Principal requests, complaints, corrections, deletion requests, and consent withdrawals, except where XploroTech is legally required to respond directly;
d. ensuring that Personal Data entered into VENTA is accurate, relevant, and lawfully obtained;
e. configuring user roles, permissions, outlet access, data visibility, and integrations appropriately;
f. maintaining records and evidence of consent, where required;
g. ensuring that its Authorised Users use the Services lawfully; and
h. ensuring that the processing of Personal Data of children or persons requiring lawful guardian consent is carried out only where legally permitted and appropriately authorised.
4.3 The Customer shall not submit or permit submission of:
a. passwords, OTPs, PINs, private keys, API secrets, or other authentication credentials;
b. full payment-card numbers, CVV, magnetic-stripe data, or sensitive payment-authentication data;
c. malware, ransomware, malicious code, or harmful files;
d. Personal Data that the Customer is not authorised to process or disclose; or
e. information prohibited by Applicable Data Protection Law, payment-network rules, or other applicable law.
4.4 The Customer shall promptly notify XploroTech if it becomes aware of unauthorised access, misuse, loss, disclosure, or other security issue involving Customer Personal Data processed through the Services.
5. Confidentiality and Personnel
5.1 XploroTech shall ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
5.2 XploroTech shall limit access to Customer Personal Data to personnel, contractors, and Subprocessors who have a legitimate need to access such data for the purposes permitted under this DPA.
5.3 XploroTech shall maintain role-based access controls and reasonable procedures designed to ensure that access to Customer Personal Data is limited to authorised persons.
6. Security Measures
6.1 XploroTech shall maintain reasonable administrative, technical, organisational, and physical safeguards designed to protect Customer Personal Data against unauthorised access, disclosure, alteration, loss, destruction, or misuse.
6.2 The security measures maintained by XploroTech are described in Schedule 2 to this DPA.
6.3 XploroTech may update or modify its security measures from time to time, provided that such changes do not materially reduce the overall protection of Customer Personal Data during an active Subscription Term.
6.4 The Customer acknowledges that no software, internet service, cloud environment, communication network, or security control can guarantee absolute security. XploroTech does not guarantee that the Services will be immune from all cyber incidents, unauthorised access attempts, vulnerabilities, or failures.
7. Subprocessors
7.1 The Customer authorises XploroTech to engage Subprocessors for the provision, operation, security, support, improvement, and delivery of the Services.
7.2 XploroTech shall ensure that each Subprocessor is bound by written obligations that are materially consistent with XploroTech’s data-protection obligations under this DPA, taking into account the nature of the processing performed by that Subprocessor.
7.3 XploroTech remains responsible for the acts and omissions of its Subprocessors to the extent required by Applicable Data Protection Law and the MSA.
7.4 XploroTech shall maintain a current Subprocessor List, including relevant AI service providers where AI Services are enabled.
7.5 Where reasonably practicable, XploroTech shall provide notice of a material new Subprocessor through the Subprocessor List, dashboard, email, or another reasonable electronic method before the Subprocessor processes Customer Personal Data.
7.6 If the Customer has a reasonable data-protection objection to a new Subprocessor, the Customer must notify XploroTech in writing within fifteen (15) days of the notice. The parties shall work in good faith to address the objection.
7.7 If XploroTech cannot reasonably address the objection, XploroTech may suspend or discontinue the affected Service or feature for that Customer. The Customer may terminate the affected Service in accordance with the MSA and applicable commercial terms.
8. International Data Transfers
8.1 Customer Personal Data may be processed in India and, where necessary for the Services, in other countries or territories where XploroTech, its affiliates, cloud providers, or approved Subprocessors operate.
8.2 XploroTech shall ensure that any cross-border transfer is carried out in accordance with Applicable Data Protection Law, including any applicable restrictions, notifications, contractual requirements, or government directions.
8.3 The Customer authorises such transfers solely for the purposes permitted under this DPA and subject to the safeguards described in this DPA and the applicable Subprocessor arrangements.
8.4 Where a law requires Customer Personal Data to be stored, retained, accessed, or processed within a particular jurisdiction, the Customer shall notify XploroTech before enabling the relevant Service or providing such Customer Personal Data.
9. Data Principal Requests
9.1 The Customer is responsible for responding to requests from Data Principals relating to their Personal Data, including requests for access, correction, completion, updating, deletion, consent withdrawal, grievance redressal, or information about processing.
9.2 If XploroTech receives a request directly from a Data Principal relating to Customer Personal Data, XploroTech shall, where legally permitted and reasonably practicable:
a. forward the request to the Customer;
b. direct the Data Principal to contact the Customer; or
c. respond only to confirm that the request has been forwarded, without independently acting on the request.
9.3 XploroTech shall provide reasonable assistance to the Customer, taking into account the nature of processing and functionality of the Services, to enable the Customer to respond to Data Principal requests.
9.4 XploroTech may charge reasonable professional-service fees for extensive, custom, repetitive, or technically complex assistance that exceeds standard support, unless such assistance is required due to XploroTech’s breach of this DPA.
10. Personal Data Breach Management
10.1 XploroTech shall maintain an incident-response process designed to identify, assess, contain, investigate, and address Personal Data Breaches.
10.2 If XploroTech becomes aware of a confirmed Personal Data Breach affecting Customer Personal Data, XploroTech shall notify the Customer without undue delay and, where reasonably practicable, within twenty-four (24) hours after confirmation.
10.3 The initial notification may be limited where complete information is not yet available. XploroTech shall provide additional information as it becomes reasonably available, including where appropriate:
a. the nature of the Personal Data Breach;
b. the categories of affected Customer Personal Data;
c. the approximate number or category of affected Data Principals, where known;
d. the likely consequences or risks;
e. measures taken or proposed to contain, investigate, mitigate, or remediate the incident; and
f. a contact point for further information.
10.4 The Customer is responsible for determining whether notification to affected Data Principals, the Data Protection Board of India, law-enforcement bodies, regulators, insurers, payment networks, or other authorities is required.
10.5 XploroTech shall provide reasonable assistance to the Customer in connection with the Customer’s breach-notification and remediation obligations, taking into account the nature of the incident and the information available to XploroTech.
10.6 XploroTech’s notification of a Personal Data Breach does not constitute an admission of fault, liability, or legal responsibility.
11. Assistance with Compliance
11.1 Taking into account the nature of processing and the information available to XploroTech, XploroTech shall provide reasonable assistance to the Customer with:
a. security measures relating to Customer Personal Data;
b. investigation and mitigation of a Personal Data Breach;
c. responding to Data Principal requests;
d. deletion or return of Customer Personal Data;
e. responding to lawful privacy or data-protection inquiries; and
f. other obligations under Applicable Data Protection Law that apply to the Customer in connection with Customer Personal Data processed through the Services.
11.2 XploroTech does not provide legal, tax, regulatory, or compliance advice. The Customer remains responsible for obtaining independent professional advice regarding its obligations under Applicable Data Protection Law.
12. Audits and Compliance Information
12.1 Upon reasonable written request, no more than once in a twelve (12) month period, XploroTech shall provide the Customer with reasonable information available to XploroTech to demonstrate compliance with this DPA.
12.2 Such information may include security policies, compliance summaries, audit summaries, penetration-test summaries, certifications, questionnaire responses, or other relevant materials, where available and subject to confidentiality, security, and legal restrictions.
12.3 If the information provided is insufficient to demonstrate compliance and Applicable Data Protection Law requires an audit, the Customer may request a remote or on-site audit subject to:
a. at least thirty (30) days’ prior written notice;
b. reasonable scope, timing, and duration;
c. no disruption to XploroTech’s operations, systems, other customers, or security controls;
d. confidentiality obligations acceptable to XploroTech;
e. use of an independent auditor that is not a competitor of XploroTech; and
f. the Customer bearing its own audit costs and any reasonable costs incurred by XploroTech, unless the audit identifies a material breach by XploroTech.
12.4 XploroTech may satisfy audit requests through a mutually agreed third-party audit report, security assessment, certification, or equivalent evidence where appropriate.
13. Return, Retention, and Deletion of Customer Personal Data
13.1 During the Subscription Term, the Customer may access, export, or retrieve Customer Data using available Service functionality, subject to the Customer’s subscription plan, permissions, technical limitations, and the Data Retention and Customer Exit Policy.
13.2 Upon termination or expiry of the applicable Services, XploroTech shall return, delete, anonymise, archive, or otherwise handle Customer Personal Data in accordance with the Data Retention and Customer Exit Policy.
13.3 XploroTech may retain Customer Personal Data where necessary for:
a. compliance with applicable law, tax requirements, statutory-record obligations, or lawful authority requests;
b. security, fraud prevention, audit, backup, disaster recovery, or business-continuity purposes;
c. dispute resolution, claim management, or enforcement of agreements;
d. internal accounting, subscription, and payment records; or
e. de-identification or anonymisation.
13.4 Customer Personal Data retained in backups shall be isolated from ordinary production use and shall be deleted or overwritten in accordance with XploroTech’s standard backup-retention cycle, unless longer retention is required by law or reasonably necessary for the purposes described in Clause 13.3.
13.5 Once Customer Personal Data is deleted or anonymised, it may not be recoverable.
14. AI Services
14.1 Where Xploro AI or other AI Services are enabled, the Xploro AI Addendum and AI Subprocessors & Data Use Notice shall apply in addition to this DPA.
14.2 XploroTech may process Customer Personal Data through XploroTech-hosted models and approved third-party AI Subprocessors only for authorised AI functionality, including data analytics, report querying, troubleshooting, bug analysis, code or schema analysis, help articles, support, and related authorised uses.
14.3 XploroTech shall apply reasonable role-based and tenant-isolation controls designed to ensure that AI Services access only Customer Data that the requesting Authorised User is permitted to access.
14.4 AI-generated outputs may be inaccurate, incomplete, biased, outdated, or unsuitable for a particular business, legal, tax, operational, or technical purpose. The Customer remains responsible for validating AI outputs before relying on them.
14.5 AI Services must not independently make changes to statutory records, GST records, payment records, financial ledgers, inventory balances, membership balances, invoices, or transaction history without explicit authorised user action and auditable controls.
15. Liability
15.1 The liability provisions, exclusions, and limitations in the MSA apply to this DPA.
15.2 Nothing in this DPA expands XploroTech’s liability beyond the limits stated in the MSA, except to the extent such limitation is prohibited by Applicable Data Protection Law.
16. Term and Termination
16.1 This DPA takes effect when the Customer accepts the MSA or first uses the Services and remains in effect for as long as XploroTech processes Customer Personal Data on behalf of the Customer.
16.2 Termination or expiry of the MSA shall automatically terminate this DPA, except for provisions that by their nature are intended to survive, including confidentiality, audit, liability, deletion, retention, dispute resolution, and legal-compliance obligations.
17. Contact Details
For privacy, data-protection, or Personal Data Breach matters, contact:
Privacy / Grievance Contact: xploro@xplorotech.com
Security Incident Contact:xploro@xplorotech.com
Legal Notices: xploro@xplorotech.com
VENTA Legal Centre: https://www.venta-pos.com/legal
SCHEDULE 1
DETAILS OF PROCESSING
A. Subject Matter
Processing of Customer Personal Data through VENTA software, applications, APIs, integrations, support systems, hosting environments, analytics systems, security systems, backup environments, and AI Services where enabled.
B. Duration
For the duration of the applicable Subscription Term and thereafter for the period specified in the Data Retention and Customer Exit Policy, subject to legal, tax, security, backup, audit, fraud-prevention, and dispute-resolution obligations.
C. Nature of Processing
Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, disclosure to authorised recipients, analysis, support, security monitoring, backup, restoration, correction, restriction, deletion, anonymisation, and destruction.
D. Purposes of Processing
- Providing VENTA POS, Admin, Insights, Captain, and related Services.
- Managing orders, invoices, payments, inventory, reservations, memberships, loyalty, customer interactions, reporting, and business operations.
- Providing support, training, implementation, maintenance, upgrades, troubleshooting, and bug analysis.
- Maintaining platform security, access control, audit logs, fraud prevention, and incident response.
- Enabling authorised integrations with delivery aggregators, payment systems, accounting systems, hardware, messaging services, and other approved services.
- Providing AI functionality where enabled, including authorised data analytics, report queries, help content, support, code analysis, bug-fix suggestions, and troubleshooting.
- Meeting legal, regulatory, accounting, tax, security, audit, and contractual obligations.
E. Categories of Data Principals
- Customer owners, directors, partners, administrators, managers, employees, cashiers, captains, warehouse users, and other Authorised Users.
- Guests, diners, customers, delivery recipients, reservation contacts, members, loyalty-program users, and invoice recipients.
- Vendors, suppliers, distributors, service providers, franchise contacts, and business contacts.
- Individuals contacting XploroTech support on behalf of the Customer.
- Any other individual whose Personal Data is entered into the Services by or on behalf of the Customer.
F. Categories of Customer Personal Data
- Names, mobile numbers, email addresses, addresses, and business contact details.
- Customer, guest, reservation, membership, loyalty, order, invoice, payment-reference, delivery, and communication records.
- Employee names, roles, attendance-related information where enabled, device assignments, user permissions, access logs, and activity logs.
- Vendor, supplier, purchase, inventory, dispatch, and operational-contact details.
- Technical information such as device identifiers, IP addresses, login history, browser/app version, access logs, error logs, and diagnostic records.
- Support-ticket content, screenshots, attachments, logs, error traces, and authorised troubleshooting information.
- AI prompts, AI outputs, report queries, schema details, code fragments, and diagnostic information where AI Services are enabled.
- Any other Personal Data uploaded, entered, generated, or made available by the Customer or its Authorised Users.
SCHEDULE 2
SECURITY MEASURES
XploroTech shall maintain security measures appropriate to the nature of the Services and the risks involved in processing Customer Personal Data. These measures include, where applicable:
Periodic review and improvement of security controls based on risk, technology changes, service changes, and operational requirements.
Role-based access controls and least-privilege access principles.
Authentication controls for customer accounts and administrative systems.
Multi-factor authentication for privileged access where supported by the relevant environment.
Encryption of Customer Personal Data in transit using industry-standard secure communication protocols.
Encryption or equivalent safeguards for stored Customer Personal Data where appropriate to the relevant environment.
Logging and monitoring of security-relevant events, access events, system activity, and operational errors.
Secure development, code-review, deployment, and change-management practices.
Vulnerability management, security patching, and risk-based remediation processes.
Segregation measures designed to prevent unauthorised cross-customer access.
Backup, restoration, business-continuity, and disaster-recovery procedures appropriate to the Services.
Security awareness and confidentiality obligations for relevant personnel.
Third-party risk management and written contractual controls for Subprocessors.
Incident-response procedures for security events and Personal Data Breaches.


