Skip to main content
Mikky
Compliance & Legal

Data Processing Terms

Last updated: October 5, 2026

Summary in plain English

These Data Processing Terms govern how Mikky processes diner and guest records on behalf of restaurant operators under the Digital Personal Data Protection Act, 2023.

The restaurant remains the sole Data Fiduciary and retains full ownership and control over all customer records and order histories.

We process guest data strictly upon documented customer instructions and never monetize, pool, or sell dining databases.

Mandates end-to-end encryption, strict sub-processor governance, 72-hour breach notification, and full data return or deletion upon contract termination.

1. Roles and scope under the DPDP Act, 2023

These Data Processing Terms (“DPA”) form part of the SaaS Agreement between Mikky Technologies Private Limited (“Data Processor”) and the contracting restaurant or cafe enterprise (“Data Fiduciary”).

The subject matter, nature, and purpose of processing consists of ingesting POS billing data, computing churn scores, identifying visit intervals, and transmitting authorized promotional and transactional updates to diners via WhatsApp.

2. Processing strictly on documented instructions

The Data Processor shall process diner personal data solely on the documented instructions of the Data Fiduciary, unless otherwise mandated by applicable Indian law. The Data Processor shall not:

  • Use customer data for its own commercial, marketing, or advertising purposes.
  • Pool or cross-reference diner contact lists across different restaurant clients.
  • Train or fine-tune public foundation AI models using client dining data.

3. Confidentiality and personnel vetting

All employees, contractors, and engineers of Mikky who have access to customer data are bound by strict non-disclosure obligations, comprehensive background checks, and role-based least-privilege access rules.

4. Technical and organizational security measures

The Data Processor implements defense-in-depth security controls, including:

  • Data Encryption: AES-256 encryption at rest for databases and backups; TLS 1.3 encryption for all data in transit across public networks.
  • Network Isolation: Production databases operate in private VPCs with no direct internet ingress.
  • Access Governance: Multi-factor authentication (MFA) required across all infrastructure administrative consoles.

5. Approved sub-processors

The Data Fiduciary grants general authorization to engage the following sub-processors:

Sub-processorService ProvidedData Location
Amazon Web Services (AWS)Cloud compute and VPC hostingMumbai / Hyderabad, India
Supabase Inc.Managed PostgreSQL databaseAWS Mumbai region
Meta Platforms, Inc.WhatsApp Business Platform APIMeta Global Cloud Infrastructure
Resend Inc.System alert and notification emailsEnterprise Cloud

6. Assisting with diner rights requests

The Data Processor provides built-in dashboard tools and deletion endpoints enabling the Data Fiduciary to respond swiftly to diner requests for access, correction, or erasure of personal data under Section 11 of the DPDP Act, 2023.

7. Personal data breach notification

In the event of a confirmed personal data breach affecting client data, the Data Processor shall notify the affected Data Fiduciary without undue delay and in any event within 72 hours of becoming aware of the incident, providing details regarding the scope, affected records, and remedial mitigation measures.

8. Deletion and return at contract end

Upon termination of subscription services, the Data Processor shall, at the choice of the Data Fiduciary, securely export all customer records and subsequently delete all production and replica database copies within 30 days, except where retention is strictly required by applicable Indian law.

9. Audits and compliance verification

The Data Processor shall make available to the Data Fiduciary all information reasonably necessary to demonstrate compliance with these processing obligations and allow for audits conducted by the Data Fiduciary or an agreed independent auditor. Contact: privacy@mikky.in.

Governing Law: Indian Law. Exclusive jurisdiction: Courts at Bengaluru, India.

Reference: Digital Personal Data Protection Act, 2023 (DPDP Act) & Information Technology Act, 2000.