Legal

Data Processing Addendum.

Last updated: July 29, 2026 · Nxcart as your Data Processor.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Nxcart and the merchant (“you”). It governs how Nxcart processes the personal data of your shoppers on your behalf. It is designed around India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and supports merchants who also serve customers under the EU/UK GDPR.


1. Roles of the parties

For personal data of your shoppers and customers processed through the Service, you are the Data Fiduciary (controller) and Nxcart is the Data Processor (processor). You decide the purposes and means of processing; we process only to provide the Service to you. For your own merchant account data, Nxcart is the Data Fiduciary, governed by our Privacy Policy.

2. Scope of processing

  • Subject matter — operating your online store on the Service.
  • Duration — for as long as your account is active, plus the deletion period in § 9.
  • Nature & purpose — storing and processing orders, rendering checkout, sending transactional messages, calculating tax and shipping, and the features you enable.
  • Types of data — shopper name, contact and address details, order and payment status, and store interaction data.
  • Categories of Data Principals — your shoppers, customers, and recipients.

3. Our obligations as Data Processor

Nxcart will:

  • Process shopper personal data only on your documented instructions (which include your configuration and use of the Service), unless required otherwise by law.
  • Not sell shopper personal data and not use it for our own purposes or to train third-party foundation models.
  • Ensure personnel with access are bound by confidentiality.
  • Apply reasonable security safeguards (§ 5).
  • Assist you, taking into account the nature of processing, to respond to Data Principal requests and to meet your security, breach-notification, and similar obligations.
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

4. Sub-processors

You authorise Nxcart to engage sub-processors to deliver the Service. Each is bound by data-protection terms no less protective than this DPA. Current sub-processors include:

  • Amazon Web Services — cloud hosting and storage (primarily AWS Mumbai).
  • Razorpay — payment processing.
  • Delhivery and similar carriers — shipping and tracking.
  • AWS SES — transactional email delivery.

We will give notice of any new sub-processor that materially affects shopper data so you can object on reasonable grounds.

5. Security measures

We maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest (AES-256), masking of sensitive fields, application-layer encryption of secrets, least-privilege access control, access logging and monitoring, and tenant isolation. We review these measures periodically.

6. Personal-data breaches

If Nxcart becomes aware of a personal-data breach affecting shopper data we process for you, we will notify you without undue delay and provide information reasonably available to help you meet your notification obligations to the Data Protection Board of India and affected Data Principals.

7. Data Principal requests

If a shopper contacts Nxcart to exercise their rights (access, correction, erasure, etc.) in respect of data we process for you, we will, where lawful, direct them to you as the Data Fiduciary and assist you in responding, using the tools available in the Service.

8. Cross-border transfers

Shopper data is hosted primarily in India. Where a sub-processor operates outside India, transfers are limited to jurisdictions permitted under the DPDP Act and are subject to appropriate contractual safeguards. For GDPR-covered data, the parties will rely on a recognised transfer mechanism such as Standard Contractual Clauses.

9. Return & deletion

On termination of your account, you may request an export of your store data for 30 days. After that, Nxcart will delete or anonymise shopper personal data processed for you, except where retention is required by law (e.g. tax and invoice records).

10. Your responsibilities

As the Data Fiduciary, you are responsible for having a lawful basis (such as consent) to collect shopper data, for publishing your own privacy notice, for the accuracy of your instructions, and for responding to your Data Principals. Nxcart provides the tools; the fiduciary obligations remain yours.

11. General

This DPA is incorporated into and governed by the Terms of Service. If any conflict arises on the subject of data processing, this DPA prevails. Questions: contact@nxcart.io.