Data Processing

Data Processing Policy

This document describes how SR Innovations processes personal data on behalf of merchants as a GDPR data processor — what we process, how, and the safeguards we apply.

Effective date: January 1, 2026  ·  SR Innovations, India

01

Introduction & Purpose

This Data Processing Policy ("Policy") sets out the terms on which SR Innovations Private Limited ("SR Innovations", "we", "us") processes personal data on behalf of merchants ("Merchant", "you") who use the SR Innovations subscription management platform.

This Policy is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (GDPR), applicable Indian data protection law, and the data processing agreement requirements of the Shopify Partner Programme.

By installing and using any SR Innovations application, the Merchant agrees to the terms of this Policy. This Policy forms part of and is incorporated into the SR Innovations Merchant Partner Agreement.

02

Definitions

ControllerThe natural or legal person who determines the purposes and means of processing personal data. In the context of this Policy, the Merchant is the Controller.
ProcessorA natural or legal person who processes personal data on behalf of the Controller. SR Innovations is the Processor.
Personal DataAny information relating to an identified or identifiable natural person ('data subject'), including names, email addresses, postal addresses, payment identifiers, and IP addresses.
ProcessingAny operation performed on personal data, including collection, storage, use, disclosure, erasure, or destruction — whether or not by automated means.
Sub-processorAny third party appointed by SR Innovations to carry out processing activities on behalf of the Merchant. See Section 7.
Data SubjectThe identified or identifiable natural person to whom personal data relates — in this context, typically the Merchant's end-customers.
03

Data Processing Relationship

Merchant = Data Controller

The Merchant determines which customers are enrolled in subscriptions, what data is collected at checkout, and for what purposes subscription data is used. The Merchant is responsible for establishing a lawful basis for processing and for responding to data subject rights requests from their customers.

SR Innovations = Data Processor

SR Innovations processes personal data only on the documented instructions of the Merchant, only to the extent necessary to deliver the subscription management service, and in accordance with this Policy. We do not process personal data for our own purposes.

04

Subject Matter and Nature of Processing

SR Innovations processes personal data to provide a subscription management platform for Shopify merchants. The processing activities include: creating and managing subscriber records, processing recurring billing events, sending subscription lifecycle communications (confirmation, renewal, failed payment, cancellation), and generating subscription analytics for the Merchant's dashboard.

Processing is carried out electronically and is automated for routine operations (billing runs, renewal notifications). Manual processing occurs only in the context of support interactions and is limited to the minimum necessary to resolve the support request.

05

Categories of Personal Data Processed

Identity dataFirst name, last name, username or similar identifier
Contact dataEmail address, postal address, phone number
Financial dataPayment method identifiers (tokenized), billing address, transaction history
Subscription dataSubscription plan, subscription status, renewal dates, cancellation reasons
Technical dataIP address, browser type, session identifiers (for security purposes only)
Usage dataInteraction data with the merchant's subscriber portal, aggregated and anonymized

We do not process special categories of personal data (health data, biometric data, racial or ethnic origin, political opinions, or similar sensitive categories) unless the Merchant explicitly provides such data, in which case a separate data processing addendum is required.

06

Purposes of Processing

Creating, updating, and managing subscriber profiles on behalf of the Merchant
Executing recurring billing events and communicating with payment processors
Sending transactional emails: subscription confirmation, renewal reminders, payment failure notifications, and cancellation confirmations
Providing the Merchant with subscription analytics via the SR Innovations dashboard
Responding to data subject rights requests made to the Merchant and forwarded to SR Innovations
Maintaining audit logs for fraud detection and security incident response
Providing customer support to the Merchant in relation to their subscribers
07

Sub-Processors

SR Innovations uses the following sub-processors to deliver its services. Each sub-processor is bound by a data processing agreement that provides at least the same level of protection as this Policy. We will notify Merchants of any changes to the sub-processor list at least 30 days before the change takes effect.

Amazon Web Services (AWS)

Cloud infrastructure & data hosting

India (ap-south-1), EU (eu-west-1)

Shopify Billing

Plan charges & discount issuance

Global (Shopify infrastructure)

SendGrid (Twilio)

Transactional email delivery

United States

Cloudflare

CDN, DDoS protection & DNS

United States

08

Technical & Organizational Security Measures

SR Innovations implements the following technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction:

Encryption in Transit

All data transmitted between clients, servers, and sub-processors uses TLS 1.3. Legacy TLS versions (1.0, 1.1) and SSLv3 are explicitly disabled.

Encryption at Rest

Personal data stored in our databases is encrypted at rest using AES-256. Encryption keys are managed in a dedicated secrets vault with rotation policies.

Access Controls

Access to personal data follows the principle of least privilege. Staff access is role-based, logged, and reviewed quarterly. Production database access requires two-factor authentication.

Security Audits

We conduct annual penetration testing by a third-party security firm and quarterly internal vulnerability scans. Findings are tracked to remediation.

Incident Response

We maintain a documented incident response plan. In the event of a data breach, we follow the notification procedures in Section 11. Staff are trained annually on this plan.

Employee Training

All staff with access to personal data complete mandatory privacy and security training at onboarding and annually thereafter.

09

International Data Transfers

Personal data processed by SR Innovations is primarily stored on AWS infrastructure located in India (ap-south-1 region). Where data is transferred to sub-processors located outside India or outside the European Economic Area (EEA), SR Innovations ensures that an adequate level of protection is in place through one or more of the following mechanisms:

Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA
Sub-processor Privacy Shield or equivalent adequacy decision where applicable
Binding contractual commitments providing equivalent protections to those required under applicable Indian and EU data protection law

Merchants who require data residency within the EEA or a specific jurisdiction should contact us at legal@srinnov.com to discuss available data residency options.

10

Assistance with Data Subject Rights Requests

SR Innovations will assist the Merchant in responding to data subject rights requests, including requests to access, correct, restrict, or delete personal data. This assistance is provided through the automated mechanisms described in our Data Deletion Policy, and through manual support where required.

Where a data subject contacts SR Innovations directly with a rights request that should be directed to the Merchant as Controller, we will forward the request to the Merchant within 5 business days and notify the data subject accordingly.

11

Data Breach Notification

In the event of a personal data breach, SR Innovations will notify affected Merchants within 72 hours of becoming aware of the breach, satisfying the GDPR Article 33 processor obligation.

Notification will include: a description of the nature of the breach; the categories and approximate number of data subjects affected; the categories and approximate number of personal data records affected; the likely consequences of the breach; and the measures taken or proposed to address the breach.

Where not all information is available within 72 hours, SR Innovations will provide information in phases as it becomes available. Merchants are responsible for notifying their end-customers and relevant supervisory authorities as required by applicable law.

12

Audit Rights

The Merchant may, upon reasonable written notice of at least 30 business days, request an audit of SR Innovations' data processing activities to verify compliance with this Policy. Audits may be conducted by the Merchant or an independent third-party auditor appointed by the Merchant, subject to reasonable confidentiality obligations.

SR Innovations may, at its discretion, satisfy an audit request by providing up-to-date third-party audit reports (SOC 2 Type II or equivalent) in lieu of a direct audit. The cost of any audit not covered by such reports is borne by the Merchant.

13

Return or Deletion of Data

Upon termination of the Merchant's subscription or upon written request from the Merchant, SR Innovations will, at the Merchant's choice, return all personal data to the Merchant in a machine-readable format (CSV or JSON) or delete all personal data from our systems.

Return or deletion will be completed within 30 days of the termination date or request, subject to the legal retention obligations described in the Data Deletion Policy. SR Innovations will provide written confirmation when deletion is complete.

14

Data Protection Contact

For all data processing enquiries, including requests to review this Policy, to discuss specific processing activities, or to raise a complaint about how we handle personal data:

SR Innovations — Data Protection

legal@srinnov.com

Mortimer Wheeler House, 46 Eagle Wharf Road, London N1 7ED

We respond to all data protection enquiries within 5 business days. Where a response requires legal review, we will acknowledge receipt within 24 hours and provide a substantive response within 14 days.

This Policy is incorporated by reference into the SR Innovations Merchant Partner Agreement. In the event of conflict, the Merchant Partner Agreement prevails for commercial terms; this Policy prevails for data protection obligations.