Sellly

Data Processing Addendum

Effective: 28 September 2026 · Version: 2026-09-28

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the company that runs Sellly ("Sellly", "Processor") and the Merchant ("Merchant", "Data Fiduciary"). A Merchant accepts it when an owner agrees to the Terms.

1. Definitions

Terms not defined here have the meaning in the Digital Personal Data Protection Act, 2023 ("DPDP Act") and its Rules. "Customer Data" means personal data of the Merchant's customers that Sellly processes to provide the Service: WhatsApp numbers, profile names, messages, order details, addresses, location pins, payment references and screenshots, and receipts. "Personal Data Breach" has the meaning in section 2(u) of the DPDP Act.

2. Roles and instructions

2.1 The Merchant is the Data Fiduciary for Customer Data. Sellly is its Data Processor.

2.2 Sellly processes Customer Data only on the Merchant's documented instructions. The Terms, this DPA and the Merchant's use and configuration of the Service are the instructions. Sellly will tell the Merchant if it believes an instruction breaks the law.

2.3 Nature and purpose: receiving and sending WhatsApp messages, taking and managing orders, storing and displaying payment evidence, generating receipts, forwarding customer questions to the Merchant, exports and erasure on request, backups, security and support.

2.4 Sellly doesn't sell Customer Data, use it to advertise, combine it across merchants, or use it to train machine-learning models.

2.5 Sellly may create aggregated, de-identified statistics (for example platform order counts) that can't identify the Merchant, a customer or any person.

3. Merchant's responsibilities

The Merchant will: give customers any notice and obtain any consent the law requires (each store's privacy page, linked from the store and from the first WhatsApp message to a new customer, helps with this); have a lawful basis for the processing it instructs; handle customers' rights requests with the tools in section 7; not instruct Sellly to collect data beyond what the order needs (for example no ID documents or card numbers); and meet obligations for children's data if it sells to people under 18.

4. Confidentiality and personnel

People at Sellly with access to Customer Data are bound by written confidentiality obligations and get access only to the extent needed. Sellly support staff open a Merchant's account only to resolve a request from the Merchant or to investigate a security or abuse issue. Each time, they record a reason; access lasts at most 60 minutes; it is read-only unless an owner allows changes (for up to 24 hours); the Merchant's owners are emailed; and it is recorded in the Merchant's activity log. Support can never change payment details, the WhatsApp number, the team or billing, export data or delete the store.

5. Security

Sellly maintains the measures in Annex 2, which it may update if the overall level of protection is not reduced.

6. Subprocessors

6.1 The Merchant authorises the subprocessors listed at /subprocessors (Annex 1).

6.2 Sellly gives at least 30 days' notice by email before adding or replacing a subprocessor. The Merchant may object on reasonable data-protection grounds; if the parties can't resolve it, the Merchant may terminate the affected Service and receive a pro-rata refund of prepaid fees.

6.3 Sellly imposes data-protection terms on each subprocessor no less protective than this DPA, to the extent the subprocessor's standard terms allow, and remains responsible for its subprocessors. Meta processes WhatsApp messages also under its direct terms with the Merchant.

7. Assistance with rights requests

The Service lets the Merchant: find a customer's records; download one customer's data as a file (for an access request); erase a customer's details (for an erasure request; orders stay for the Merchant's accounts without anything identifying the customer); correct addresses; and download everything the business holds. If a customer writes to Sellly directly, Sellly forwards the request to the Merchant within 3 working days and doesn't respond on the Merchant's behalf unless asked.

8. Personal Data Breach

8.1 Sellly will notify the Merchant without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Customer Data.

8.2 The notice will describe, as far as known: what happened, when, the data and number of people affected, likely consequences, measures taken and proposed, and a contact. Sellly will update the Merchant as it learns more.

8.3 Sellly will give the Merchant the information it needs to inform affected customers and the Data Protection Board as the DPDP Rules require, including within the 72-hour detailed-report window.

8.4 Sellly handles its own reporting to CERT-In under the CERT-In Directions (within 6 hours).

9. Deletion and return

9.1 During the term, the Merchant can download all its data and files at any time.

9.2 When the Merchant deletes its business, Sellly keeps Customer Data for 30 days so the Merchant can reverse the deletion, then deletes it from live systems. Encrypted backups containing it are deleted within 35 days after that. Sellly may keep data it must keep by law, isolated and used for nothing else, and keeps a store under investigation or a legal order until that ends.

9.3 On request after deletion, Sellly will confirm in writing that deletion is complete.

10. Audits and information

Sellly will make available information reasonably needed to show compliance with this DPA: this document, its security overview, the subprocessor list and, on request once a year, written answers to a reasonable security questionnaire. On-site audits are available only where required by law or after a Personal Data Breach, with 30 days' notice, at the Merchant's cost, under confidentiality.

11. Transfers

Customer Data is processed in the locations listed at /subprocessors, which may be outside India. Sellly will stop transfers to any country the Government of India restricts under section 16 of the DPDP Act.

12. Liability

Each party's liability under this DPA is subject to the limitations in the Terms, with the higher limit stated there for data-protection breaches.

13. Duration

This DPA lasts as long as Sellly processes Customer Data for the Merchant.

Annex 1: Subprocessors

The current list, with what each receives and where, is at /subprocessors.

Annex 2: Security measures