Data Processing Policy
This document describes how SR Innovations processes personal data on behalf of merchants as a GDPR data processor — what we process, how, and the safeguards we apply.
Effective date: January 1, 2026 · SR Innovations, India
Introduction & Purpose
This Data Processing Policy ("Policy") sets out the terms on which SR Innovations Private Limited ("SR Innovations", "we", "us") processes personal data on behalf of merchants ("Merchant", "you") who use the SR Innovations subscription management platform.
This Policy is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (GDPR), applicable Indian data protection law, and the data processing agreement requirements of the Shopify Partner Programme.
By installing and using any SR Innovations application, the Merchant agrees to the terms of this Policy. This Policy forms part of and is incorporated into the SR Innovations Merchant Partner Agreement.
Definitions
Data Processing Relationship
Merchant = Data Controller
The Merchant determines which customers are enrolled in subscriptions, what data is collected at checkout, and for what purposes subscription data is used. The Merchant is responsible for establishing a lawful basis for processing and for responding to data subject rights requests from their customers.
SR Innovations = Data Processor
SR Innovations processes personal data only on the documented instructions of the Merchant, only to the extent necessary to deliver the subscription management service, and in accordance with this Policy. We do not process personal data for our own purposes.
Subject Matter and Nature of Processing
SR Innovations processes personal data to provide a subscription management platform for Shopify merchants. The processing activities include: creating and managing subscriber records, processing recurring billing events, sending subscription lifecycle communications (confirmation, renewal, failed payment, cancellation), and generating subscription analytics for the Merchant's dashboard.
Processing is carried out electronically and is automated for routine operations (billing runs, renewal notifications). Manual processing occurs only in the context of support interactions and is limited to the minimum necessary to resolve the support request.
Categories of Personal Data Processed
We do not process special categories of personal data (health data, biometric data, racial or ethnic origin, political opinions, or similar sensitive categories) unless the Merchant explicitly provides such data, in which case a separate data processing addendum is required.
Purposes of Processing
Sub-Processors
SR Innovations uses the following sub-processors to deliver its services. Each sub-processor is bound by a data processing agreement that provides at least the same level of protection as this Policy. We will notify Merchants of any changes to the sub-processor list at least 30 days before the change takes effect.
Amazon Web Services (AWS)
Cloud infrastructure & data hosting
India (ap-south-1), EU (eu-west-1)
Shopify Billing
Plan charges & discount issuance
Global (Shopify infrastructure)
SendGrid (Twilio)
Transactional email delivery
United States
Cloudflare
CDN, DDoS protection & DNS
United States
Technical & Organizational Security Measures
SR Innovations implements the following technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction:
Encryption in Transit
All data transmitted between clients, servers, and sub-processors uses TLS 1.3. Legacy TLS versions (1.0, 1.1) and SSLv3 are explicitly disabled.
Encryption at Rest
Personal data stored in our databases is encrypted at rest using AES-256. Encryption keys are managed in a dedicated secrets vault with rotation policies.
Access Controls
Access to personal data follows the principle of least privilege. Staff access is role-based, logged, and reviewed quarterly. Production database access requires two-factor authentication.
Security Audits
We conduct annual penetration testing by a third-party security firm and quarterly internal vulnerability scans. Findings are tracked to remediation.
Incident Response
We maintain a documented incident response plan. In the event of a data breach, we follow the notification procedures in Section 11. Staff are trained annually on this plan.
Employee Training
All staff with access to personal data complete mandatory privacy and security training at onboarding and annually thereafter.
International Data Transfers
Personal data processed by SR Innovations is primarily stored on AWS infrastructure located in India (ap-south-1 region). Where data is transferred to sub-processors located outside India or outside the European Economic Area (EEA), SR Innovations ensures that an adequate level of protection is in place through one or more of the following mechanisms:
Merchants who require data residency within the EEA or a specific jurisdiction should contact us at legal@srinnov.com to discuss available data residency options.
Assistance with Data Subject Rights Requests
SR Innovations will assist the Merchant in responding to data subject rights requests, including requests to access, correct, restrict, or delete personal data. This assistance is provided through the automated mechanisms described in our Data Deletion Policy, and through manual support where required.
Where a data subject contacts SR Innovations directly with a rights request that should be directed to the Merchant as Controller, we will forward the request to the Merchant within 5 business days and notify the data subject accordingly.
Data Breach Notification
In the event of a personal data breach, SR Innovations will notify affected Merchants within 72 hours of becoming aware of the breach, satisfying the GDPR Article 33 processor obligation.
Notification will include: a description of the nature of the breach; the categories and approximate number of data subjects affected; the categories and approximate number of personal data records affected; the likely consequences of the breach; and the measures taken or proposed to address the breach.
Where not all information is available within 72 hours, SR Innovations will provide information in phases as it becomes available. Merchants are responsible for notifying their end-customers and relevant supervisory authorities as required by applicable law.
Audit Rights
The Merchant may, upon reasonable written notice of at least 30 business days, request an audit of SR Innovations' data processing activities to verify compliance with this Policy. Audits may be conducted by the Merchant or an independent third-party auditor appointed by the Merchant, subject to reasonable confidentiality obligations.
SR Innovations may, at its discretion, satisfy an audit request by providing up-to-date third-party audit reports (SOC 2 Type II or equivalent) in lieu of a direct audit. The cost of any audit not covered by such reports is borne by the Merchant.
Return or Deletion of Data
Upon termination of the Merchant's subscription or upon written request from the Merchant, SR Innovations will, at the Merchant's choice, return all personal data to the Merchant in a machine-readable format (CSV or JSON) or delete all personal data from our systems.
Return or deletion will be completed within 30 days of the termination date or request, subject to the legal retention obligations described in the Data Deletion Policy. SR Innovations will provide written confirmation when deletion is complete.
Data Protection Contact
For all data processing enquiries, including requests to review this Policy, to discuss specific processing activities, or to raise a complaint about how we handle personal data:
SR Innovations — Data Protection
legal@srinnov.comMortimer Wheeler House, 46 Eagle Wharf Road, London N1 7ED
We respond to all data protection enquiries within 5 business days. Where a response requires legal review, we will acknowledge receipt within 24 hours and provide a substantive response within 14 days.
This Policy is incorporated by reference into the SR Innovations Merchant Partner Agreement. In the event of conflict, the Merchant Partner Agreement prevails for commercial terms; this Policy prevails for data protection obligations.