Data Processing Terms
Last updated: October 5, 2026
Summary in plain English
These Data Processing Terms govern how Mikky processes diner and guest records on behalf of restaurant operators under the Digital Personal Data Protection Act, 2023.
The restaurant remains the sole Data Fiduciary and retains full ownership and control over all customer records and order histories.
We process guest data strictly upon documented customer instructions and never monetize, pool, or sell dining databases.
Mandates end-to-end encryption, strict sub-processor governance, 72-hour breach notification, and full data return or deletion upon contract termination.
1. Roles and scope under the DPDP Act, 2023
These Data Processing Terms (“DPA”) form part of the SaaS Agreement between Mikky Technologies Private Limited (“Data Processor”) and the contracting restaurant or cafe enterprise (“Data Fiduciary”).
The subject matter, nature, and purpose of processing consists of ingesting POS billing data, computing churn scores, identifying visit intervals, and transmitting authorized promotional and transactional updates to diners via WhatsApp.
2. Processing strictly on documented instructions
The Data Processor shall process diner personal data solely on the documented instructions of the Data Fiduciary, unless otherwise mandated by applicable Indian law. The Data Processor shall not:
- Use customer data for its own commercial, marketing, or advertising purposes.
- Pool or cross-reference diner contact lists across different restaurant clients.
- Train or fine-tune public foundation AI models using client dining data.
3. Confidentiality and personnel vetting
All employees, contractors, and engineers of Mikky who have access to customer data are bound by strict non-disclosure obligations, comprehensive background checks, and role-based least-privilege access rules.
4. Technical and organizational security measures
The Data Processor implements defense-in-depth security controls, including:
- Data Encryption: AES-256 encryption at rest for databases and backups; TLS 1.3 encryption for all data in transit across public networks.
- Network Isolation: Production databases operate in private VPCs with no direct internet ingress.
- Access Governance: Multi-factor authentication (MFA) required across all infrastructure administrative consoles.
5. Approved sub-processors
The Data Fiduciary grants general authorization to engage the following sub-processors:
| Sub-processor | Service Provided | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud compute and VPC hosting | Mumbai / Hyderabad, India |
| Supabase Inc. | Managed PostgreSQL database | AWS Mumbai region |
| Meta Platforms, Inc. | WhatsApp Business Platform API | Meta Global Cloud Infrastructure |
| Resend Inc. | System alert and notification emails | Enterprise Cloud |
6. Assisting with diner rights requests
The Data Processor provides built-in dashboard tools and deletion endpoints enabling the Data Fiduciary to respond swiftly to diner requests for access, correction, or erasure of personal data under Section 11 of the DPDP Act, 2023.
7. Personal data breach notification
In the event of a confirmed personal data breach affecting client data, the Data Processor shall notify the affected Data Fiduciary without undue delay and in any event within 72 hours of becoming aware of the incident, providing details regarding the scope, affected records, and remedial mitigation measures.
8. Deletion and return at contract end
Upon termination of subscription services, the Data Processor shall, at the choice of the Data Fiduciary, securely export all customer records and subsequently delete all production and replica database copies within 30 days, except where retention is strictly required by applicable Indian law.
9. Audits and compliance verification
The Data Processor shall make available to the Data Fiduciary all information reasonably necessary to demonstrate compliance with these processing obligations and allow for audits conducted by the Data Fiduciary or an agreed independent auditor. Contact: privacy@mikky.in.
Governing Law: Indian Law. Exclusive jurisdiction: Courts at Bengaluru, India.
Reference: Digital Personal Data Protection Act, 2023 (DPDP Act) & Information Technology Act, 2000.