cartly.Back to Cartly

DATA PROCESSING ADDENDUM

Your customers, your rules.

You are the controller of your customers’ data. Cartly is your processor. This addendum sets out what that means: we act only on your instructions, keep the data confidential and secure, tell you within 72 hours if something goes wrong, and delete everything when you leave.

Effective 15 September 2026 · Cartly, operated from India · pratikr557@gmail.com

Contents

  1. 1Scope and parties
  2. 2Roles
  3. 3Processing on your instructions
  4. 4Details of the processing
  5. 5Confidentiality
  6. 6Sub-processors
  7. 7Security measures
  8. 8Personal data breach
  9. 9Assistance with requests and obligations
  10. 10Deletion and return
  11. 11Information and audit
  12. 12Contact

Other documents

Privacy PolicyTerms of Service

1. Scope and parties

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the merchant (“you”, the controller) and Cartly (the processor). It applies whenever Cartly processes personal data about your customers or other individuals on your behalf: names, email addresses, phone numbers, addresses, order details and message content that you upload or connect.

It is written to meet the processor requirements of the Indian Digital Personal Data Protection Act, 2023 and Article 28 of the GDPR and UK GDPR. If there is a conflict between this DPA and the Terms, this DPA wins for anything concerning personal data.

2. Roles

You decide why and how your customers’ data is processed; you are the controller (in Indian law, the Data Fiduciary). Cartly processes that data only to provide the service to you; Cartly is the processor. Cartly is separately the controller of your own merchant account data, which is covered by the Privacy Policy rather than this DPA.

3. Processing on your instructions

Cartly will process personal data only on your documented instructions. Your instructions are: the Terms, this DPA, the settings you choose in your workspace, and the actions you take in it (for example uploading a CSV, sending a campaign or booking a shipment). We will not process the data for any other purpose. If we believe an instruction breaks the law, we will tell you before acting on it.

You are responsible for making sure the data you bring to Cartly was collected lawfully and that you have the consents needed for what you ask Cartly to do with it, including sending WhatsApp messages.

4. Details of the processing

Subject matterRunning your commerce workspace: catalogue, customers, orders, WhatsApp follow-ups, shipping.
DurationFor as long as you have a Cartly account, plus the deletion period in section 10.
Nature and purposeStoring, organising, displaying and transmitting the data so that Cartly can act on your instructions.
Data subjectsYour customers and prospective customers; recipients of orders; your staff who use the workspace.
Categories of dataNames, email addresses, phone numbers, postal addresses, order history and amounts, message content, tags and notes you add.
Special categoriesNone expected. Do not upload health, religious, political, biometric or similar data.

5. Confidentiality

Everyone who works on Cartly and has access to personal data is bound by a duty of confidentiality. Access is limited to what is needed to operate and support the service, and is not used to look at your customers’ data out of curiosity or for any purpose of our own.

6. Sub-processors

You authorise Cartly to use the following sub-processors. Each is bound by written terms that protect personal data to a standard no lower than this DPA.

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageMumbai, India
CloudflareHosting, edge network, scheduled jobsGlobal edge network
GoogleMerchant sign-inGlobal
WaplifyWhatsApp Business messagingAs per Waplify’s terms
ShiprocketShipping and courier bookingIndia
OpenAIText and image generation in StudioUnited States

Waplify and Shiprocket act through accounts you hold directly with them, under your own agreements. We will give you at least 14 days’ notice by email before adding or replacing a sub-processor that handles your customers’ data. If you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the service and export your data.

7. Security measures

Cartly applies technical and organisational measures appropriate to the risk, including:

  • Encryption of all data in transit (TLS) and of stored integration credentials at rest.
  • Workspace isolation, so that one merchant cannot read another’s data, enforced at the database level.
  • Authentication for every request to the application; no anonymous access to personal data.
  • Access to production systems limited to the people who operate Cartly.
  • Logging of processing activity so that actions can be traced.
  • Regular updates to dependencies and review of changes before they ship.
  • Backups maintained by our database provider, on a short rotation.

Cartly has not yet undergone an independent security audit or certification and does not claim one. We will update this section as our measures develop.

8. Personal data breach

If Cartly becomes aware of a personal data breach affecting your data, we will notify you by email without undue delay and within 72 hours of becoming aware of it. The notice will describe what happened, the categories and approximate number of people and records affected, the likely consequences, and what we are doing about it. We will give further information as it becomes available and will cooperate with you in meeting your own notification obligations.

9. Assistance with requests and obligations

If one of your customers exercises a right (access, correction, deletion, objection) directly with Cartly, we will forward the request to you within five working days and will not respond on your behalf unless you ask us to. Your workspace lets you find, edit, export and delete individual customer records so you can respond yourself.

Taking into account the nature of the processing and the information available to us, we will assist you reasonably with data protection impact assessments and consultations with a supervisory authority.

10. Deletion and return

You can export your customer, product and order data at any time from Settings. When you delete your account, or when the service ends, Cartly will delete all personal data processed on your behalf within 30 days, except where the law requires us to keep it, in which case we will keep only what is required and continue to protect it under this DPA. Raw uploaded CSV files are in any case deleted 90 days after import.

11. Information and audit

On request, no more than once a year unless there has been a breach, Cartly will provide the information reasonably needed to show that we meet this DPA. Where that is not enough, you may carry out an audit, at your cost, on reasonable notice, during business hours and without disrupting the service. We may ask you to sign a confidentiality agreement first.

12. Contact

Data protection matters: pratikr557@gmail.com. This DPA takes effect on the same date as the Terms and remains in force for as long as Cartly processes personal data on your behalf.

Questions about this document? Write to pratikr557@gmail.com.

Privacy PolicyTerms of ServiceData Processing Addendum