1. Parties and how this agreement is made
This agreement is between:
- You, the merchant who has accepted the Patrata Terms of Service (the “Merchant”); and
- CredSetu Technologies Private Limited, CIN U62090ME2026PTC475450, registered office C/o Renuka Khot, 143/8, Hirdao Road, Lonar, Buldhana – 443302, Maharashtra, which operates the Patrata application (“Patrata”).
It is made when you tick “I agree” to the Terms of Service, of which it forms part. It applies for as long as Patrata processes Merchant Data, and the obligations in Sections 8, 11, 14 and 15 continue after it ends.
2. Definitions
| Merchant Data | Personal data about the Merchant’s own customers that the Merchant records in, or generates through, Patrata — names, mobile numbers, credit transactions, repayments, due dates, and the record of consent taken. |
| Data Principal | The individual the data is about — here, the Merchant’s customer. |
| Data Fiduciary | The person who determines the purpose and means of processing. For Merchant Data, that is the Merchant. |
| Data Processor | A person who processes personal data on behalf of a Data Fiduciary. For Merchant Data, that is Patrata. |
| Data Protection Law | The Digital Personal Data Protection Act 2023 and the Rules under it, as and when each provision commences; the Information Technology Act 2000 and the SPDI Rules 2011 while they remain in force; and any other Indian law on personal data that applies to the processing. |
| Personal Data Breach | Any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises its confidentiality, integrity or availability. |
| Sub-processor | A third party engaged by Patrata to process Merchant Data. |
3. Which data this covers, and which it does not
| Activity | Covered by this agreement? |
|---|---|
| Storing and displaying the Merchant’s ledger; recording repayments; calculating that Merchant’s own totals; preparing a reminder at the Merchant’s instruction | Yes. Patrata acts as Processor. |
| Delivering a reminder to a customer | Not applicable. In version 1.0 the Merchant sends the reminder himself, from his own phone. Patrata only drafts the wording, which is Processor activity and is covered. |
| Trust Score, Trust Bands, cross-shop checks, payment timing alerts | Not active. None runs in version 1.0. If any is enabled, Patrata is Fiduciary for it and it runs only on the customer’s own consent given to Patrata. |
| Identity verification | Not active. No verification is performed and no verification vendor is engaged. |
| The Merchant’s own account, billing and Merchant Reliability Score | No. Patrata is Fiduciary for data about the Merchant. |
Where Patrata acts as Fiduciary, its obligations to the individual are set out in the Privacy Policy and are owed directly to that individual, not through the Merchant.
4. Roles
For Merchant Data, the Merchant is the Data Fiduciary and Patrata is the Data Processor.
5. Our obligations as your Processor
Patrata will:
- process Merchant Data only on your documented instructions. Your use of the app’s features is your instruction; anything else must be in writing. The instructions are summarised in Annexure A;
- not process Merchant Data for its own purposes, and in particular not use Merchant Data to train any model, build any product, or generate any commercial insight for itself, except as irreversibly anonymised statistics from which no individual can be identified;
- not sell, rent or licence Merchant Data to anyone;
- tell you if, in its opinion, an instruction from you would breach Data Protection Law, and may decline to carry it out until the point is resolved;
- keep Merchant Data secure, as set out in Section 7 and Annexure C;
- make sure everyone who handles Merchant Data is bound to confidentiality (Section 8);
- engage sub-processors only as permitted by Section 9;
- help you meet your obligations to your customers (Section 10);
- tell you about breaches (Section 11);
- return or delete Merchant Data when this agreement ends (Section 14).
6. Your obligations as Fiduciary
You will:
- obtain and record each customer’s consent using the consent step in the app, before creating their record, and give them the notice the app provides;
- make sure Merchant Data you enter is accurate, and correct it promptly when you learn it is wrong — including marking payments as received;
- record only what you actually need: name, mobile number and the transaction. Do not enter identity numbers, health information, caste or community, photographs of documents, or notes about a person’s character;
- not instruct us to do anything that would breach Data Protection Law;
- respond to your customers’ requests about their data, using the tools in the app and our help under Section 10;
- keep your login secure and not share your account.
7. Security
Patrata will take reasonable security safeguards to prevent a Personal Data Breach, appropriate to the nature of the data and the harm that could result. The measures in place are listed in Annexure C. We may change them, but not in a way that materially reduces protection.
You acknowledge that no system is completely secure, and that a large part of practical security sits with you: your phone, your login, and who you let use your account.
8. Confidentiality and our people
Patrata will make sure that everyone authorised to process Merchant Data — employees, contractors and interns alike — is bound by a written confidentiality obligation that survives the end of their engagement, is trained on handling personal data, and is given access only to what their role requires. Access is logged.
Patrata will not disclose Merchant Data to any authority unless legally compelled. Where we are compelled and are permitted to tell you, we will, before disclosing if possible.
9. Sub-processors
You give Patrata general authorisation to engage the sub-processors listed in Annexure B.
- Each sub-processor is engaged under a written contract imposing obligations no less protective than this agreement.
- Patrata remains fully responsible to you for its sub-processors’ acts and omissions.
- We will give you at least 30 days’ notice in the app before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within those 30 days; if we cannot resolve it, you may terminate and receive a pro-rata refund of your unused term.
10. Helping you answer your customers
If a customer contacts us directly about data that belongs to your ledger, we will not answer on your behalf. We will tell them to contact you, and tell you within 3 working days that they approached us.
Patrata will give you, at no charge, the tools and reasonable help you need to:
- give a customer a copy of what you hold about them;
- correct or complete a record;
- delete a record, subject to amounts still owed and records the law requires you to keep;
- act on a withdrawal of consent;
- handle a dispute about a transaction.
Where a request cannot be completed through the app, write to info@credsetu.in and we will do it by hand within 7 working days, so that you can meet your own deadline to the customer.
11. Personal data breaches
If Patrata becomes aware of a Personal Data Breach affecting Merchant Data, Patrata will:
- notify you without undue delay and in any event within 24 hours of becoming aware;
- tell you what happened, what data was involved, how many people are affected so far as known, the likely consequences, and what we are doing about it;
- keep you updated as we learn more, and give you what you reasonably need to meet your own notification duties;
- take reasonable steps to contain the breach and reduce harm;
- report to CERT-In within six hours where the Directions of 28 April 2022 require it, and to the Data Protection Board of India once Section 8(6) of the DPDP Act commences.
Notifying you is not an admission of fault by either party.
12. Location of data
Merchant Data is stored and processed on servers located in India. Patrata will not transfer Merchant Data outside India without telling you first, and will do so only to a country permitted under Indian law and with appropriate safeguards.
13. Information and audit
On written request, and not more than once in any twelve months unless there has been a breach, Patrata will give you the information reasonably necessary to show it is meeting this agreement — normally a written description of controls, and where available a current third-party security report.
Given that Patrata serves many small merchants, an on-site audit of our systems by an individual merchant is not practical and is not offered. If you are not satisfied with the information given, you may terminate and receive a pro-rata refund of your unused term.
14. Return and deletion
- You may export your ledger at any time while your account is open, and for 30 days after it closes.
- After that 30-day window, Patrata will delete Merchant Data, or irreversibly anonymise it, within 90 days, and will instruct its sub-processors to do the same.
- Patrata may keep Merchant Data for longer only where a law requires it, and only for as long as that law requires. Anything kept on that basis stays subject to Sections 7 and 8.
- On request we will confirm deletion in writing.
Records that Patrata holds as Fiduciary in its own right — consent records, message delivery and opt-out records, verification results — are kept on the schedule in the Privacy Policy and are not deleted by your account closing, because they are our evidence that permission existed.
15. Liability
Each party is responsible for its own compliance. Patrata is liable to you for its own breach of this agreement and for its sub-processors. You are liable to us for loss caused by your entering data without consent, entering inaccurate data, or instructing us to do something unlawful.
The liability cap in Section 20 of the Terms of Service applies to this agreement as well, and the two are not cumulative. That cap does not apply to Patrata’s own failure to keep data secure, to fraud, or to anything that cannot be limited under Indian law.
16. Term, changes and governing law
This agreement runs for as long as Patrata processes Merchant Data. We may update it; for a material change we will give at least 14 days’ notice in the app and ask you to accept the updated version. If you do not accept, you may terminate and receive a pro-rata refund of your unused term.
Where this agreement and the Terms of Service conflict on a data protection point, this agreement prevails. On everything else, the Terms prevail.
Governed by the laws of India, with the courts named in Section 24 of the Terms of Service.
Annexure A — details of processing
| Subject matter | Providing the Patrata application to the Merchant. |
| Duration | For as long as the Merchant’s account is open, plus the return and deletion periods in Section 14. |
| Nature and purpose | Storing, organising, displaying, retrieving, structuring and erasing the Merchant’s customer credit records; preparing reminder messages at the Merchant’s instruction; producing the Merchant’s own totals and dashboard. |
| Types of personal data | Name; mobile number; credit amounts, dates and due dates; repayment records; consent records including the text, language, version and time. |
| Categories of Data Principal | The Merchant’s own credit customers, all of whom are adults aged 18 or over. |
| Sensitive categories | Financial information (transaction and repayment records), treated as sensitive personal data under Rule 3 of the SPDI Rules 2011. |
| Documented instructions | The Merchant’s use of the app’s features, plus any written instruction given to info@credsetu.in. |
Annexure B — sub-processors
Current as at the effective date at the top of this page. Changes are notified under Section 9.
| Category | What they do | Sees Merchant Data? |
|---|---|---|
| Cloud hosting, storage and database | Runs the application and stores the ledger | Yes |
| One-time password delivery | Sends the login code to the Merchant’s phone | Merchant’s mobile number only |
| Website delivery and security | Serves and protects the public website | No |
| Payment processing | Takes subscription payments from the Merchant | No — Merchant billing data only |
| Error and performance monitoring | Technical logs and crash reports | Technical logs only |
Annexure C — security measures
These are the measures in place today. Nothing is listed here that cannot currently be evidenced.
- Encryption in transit (TLS) for all traffic between the app, the website and our servers.
- Role-based access control; least privilege; access reviewed at least every six months.
- One-time-password authentication for merchants; multi-factor authentication on administrative accounts.
- Logging and monitoring of access to personal data.
- Written confidentiality obligations and data handling training for everyone with access, including contractors and interns.
- Backups, with restore tested at least annually.
- A documented incident response procedure with named owners and the timelines in Section 11.
- Internal Information Security Policy, reviewed every six months.