Patrata

Data Processing Agreement

Version 2.0 · Effective 7 September 2026 · Patrata is operated by CredSetu Technologies Private Limited (CIN: U62090ME2026PTC475450)

In one paragraph. Your customer ledger is your record about your own customers. The law makes you responsible for it. We hold it for you, and this agreement is our written promise about what we will and will not do with it — we act only on your instructions, we keep it secure, we do not use it for our own purposes, and we give it back or delete it when you leave. Where Patrata does something in its own right rather than for you — the Trust Score, the network, identity verification — this agreement does not apply and we carry that responsibility ourselves.

1. Parties and how this agreement is made

This agreement is between:

  • You, the merchant who has accepted the Patrata Terms of Service (the “Merchant”); and
  • CredSetu Technologies Private Limited, CIN U62090ME2026PTC475450, registered office C/o Renuka Khot, 143/8, Hirdao Road, Lonar, Buldhana – 443302, Maharashtra, which operates the Patrata application (“Patrata”).

It is made when you tick “I agree” to the Terms of Service, of which it forms part. It applies for as long as Patrata processes Merchant Data, and the obligations in Sections 8, 11, 14 and 15 continue after it ends.

2. Definitions

Merchant DataPersonal data about the Merchant’s own customers that the Merchant records in, or generates through, Patrata — names, mobile numbers, credit transactions, repayments, due dates, and the record of consent taken.
Data PrincipalThe individual the data is about — here, the Merchant’s customer.
Data FiduciaryThe person who determines the purpose and means of processing. For Merchant Data, that is the Merchant.
Data ProcessorA person who processes personal data on behalf of a Data Fiduciary. For Merchant Data, that is Patrata.
Data Protection LawThe Digital Personal Data Protection Act 2023 and the Rules under it, as and when each provision commences; the Information Technology Act 2000 and the SPDI Rules 2011 while they remain in force; and any other Indian law on personal data that applies to the processing.
Personal Data BreachAny unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises its confidentiality, integrity or availability.
Sub-processorA third party engaged by Patrata to process Merchant Data.

3. Which data this covers, and which it does not

This agreement covers Merchant Data only. It does not cover anything Patrata does in its own right.
ActivityCovered by this agreement?
Storing and displaying the Merchant’s ledger; recording repayments; calculating that Merchant’s own totals; preparing a reminder at the Merchant’s instructionYes. Patrata acts as Processor.
Delivering a reminder to a customerNot applicable. In version 1.0 the Merchant sends the reminder himself, from his own phone. Patrata only drafts the wording, which is Processor activity and is covered.
Trust Score, Trust Bands, cross-shop checks, payment timing alertsNot active. None runs in version 1.0. If any is enabled, Patrata is Fiduciary for it and it runs only on the customer’s own consent given to Patrata.
Identity verificationNot active. No verification is performed and no verification vendor is engaged.
The Merchant’s own account, billing and Merchant Reliability ScoreNo. Patrata is Fiduciary for data about the Merchant.

Where Patrata acts as Fiduciary, its obligations to the individual are set out in the Privacy Policy and are owed directly to that individual, not through the Merchant.

4. Roles

For Merchant Data, the Merchant is the Data Fiduciary and Patrata is the Data Processor.

What being the Fiduciary actually means for you. When Section 8(1) of the DPDP Act commences on 13 May 2027, you will be responsible for complying with that Act in respect of Merchant Data “irrespective of any agreement to the contrary”. That phrase means this agreement cannot move your responsibility onto us, and no other contract can either. What this agreement does is bind us to do our part properly, and give you a remedy if we do not. It does not, and cannot, make us answerable to your customer in your place.

5. Our obligations as your Processor

Patrata will:

  1. process Merchant Data only on your documented instructions. Your use of the app’s features is your instruction; anything else must be in writing. The instructions are summarised in Annexure A;
  2. not process Merchant Data for its own purposes, and in particular not use Merchant Data to train any model, build any product, or generate any commercial insight for itself, except as irreversibly anonymised statistics from which no individual can be identified;
  3. not sell, rent or licence Merchant Data to anyone;
  4. tell you if, in its opinion, an instruction from you would breach Data Protection Law, and may decline to carry it out until the point is resolved;
  5. keep Merchant Data secure, as set out in Section 7 and Annexure C;
  6. make sure everyone who handles Merchant Data is bound to confidentiality (Section 8);
  7. engage sub-processors only as permitted by Section 9;
  8. help you meet your obligations to your customers (Section 10);
  9. tell you about breaches (Section 11);
  10. return or delete Merchant Data when this agreement ends (Section 14).

6. Your obligations as Fiduciary

You will:

  1. obtain and record each customer’s consent using the consent step in the app, before creating their record, and give them the notice the app provides;
  2. make sure Merchant Data you enter is accurate, and correct it promptly when you learn it is wrong — including marking payments as received;
  3. record only what you actually need: name, mobile number and the transaction. Do not enter identity numbers, health information, caste or community, photographs of documents, or notes about a person’s character;
  4. not instruct us to do anything that would breach Data Protection Law;
  5. respond to your customers’ requests about their data, using the tools in the app and our help under Section 10;
  6. keep your login secure and not share your account.

7. Security

Patrata will take reasonable security safeguards to prevent a Personal Data Breach, appropriate to the nature of the data and the harm that could result. The measures in place are listed in Annexure C. We may change them, but not in a way that materially reduces protection.

You acknowledge that no system is completely secure, and that a large part of practical security sits with you: your phone, your login, and who you let use your account.

8. Confidentiality and our people

Patrata will make sure that everyone authorised to process Merchant Data — employees, contractors and interns alike — is bound by a written confidentiality obligation that survives the end of their engagement, is trained on handling personal data, and is given access only to what their role requires. Access is logged.

Patrata will not disclose Merchant Data to any authority unless legally compelled. Where we are compelled and are permitted to tell you, we will, before disclosing if possible.

9. Sub-processors

You give Patrata general authorisation to engage the sub-processors listed in Annexure B.

  • Each sub-processor is engaged under a written contract imposing obligations no less protective than this agreement.
  • Patrata remains fully responsible to you for its sub-processors’ acts and omissions.
  • We will give you at least 30 days’ notice in the app before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within those 30 days; if we cannot resolve it, you may terminate and receive a pro-rata refund of your unused term.

10. Helping you answer your customers

If a customer contacts us directly about data that belongs to your ledger, we will not answer on your behalf. We will tell them to contact you, and tell you within 3 working days that they approached us.

Patrata will give you, at no charge, the tools and reasonable help you need to:

  • give a customer a copy of what you hold about them;
  • correct or complete a record;
  • delete a record, subject to amounts still owed and records the law requires you to keep;
  • act on a withdrawal of consent;
  • handle a dispute about a transaction.

Where a request cannot be completed through the app, write to info@credsetu.in and we will do it by hand within 7 working days, so that you can meet your own deadline to the customer.

11. Personal data breaches

If Patrata becomes aware of a Personal Data Breach affecting Merchant Data, Patrata will:

  • notify you without undue delay and in any event within 24 hours of becoming aware;
  • tell you what happened, what data was involved, how many people are affected so far as known, the likely consequences, and what we are doing about it;
  • keep you updated as we learn more, and give you what you reasonably need to meet your own notification duties;
  • take reasonable steps to contain the breach and reduce harm;
  • report to CERT-In within six hours where the Directions of 28 April 2022 require it, and to the Data Protection Board of India once Section 8(6) of the DPDP Act commences.

Notifying you is not an admission of fault by either party.

12. Location of data

Merchant Data is stored and processed on servers located in India. Patrata will not transfer Merchant Data outside India without telling you first, and will do so only to a country permitted under Indian law and with appropriate safeguards.

13. Information and audit

On written request, and not more than once in any twelve months unless there has been a breach, Patrata will give you the information reasonably necessary to show it is meeting this agreement — normally a written description of controls, and where available a current third-party security report.

Given that Patrata serves many small merchants, an on-site audit of our systems by an individual merchant is not practical and is not offered. If you are not satisfied with the information given, you may terminate and receive a pro-rata refund of your unused term.

14. Return and deletion

  • You may export your ledger at any time while your account is open, and for 30 days after it closes.
  • After that 30-day window, Patrata will delete Merchant Data, or irreversibly anonymise it, within 90 days, and will instruct its sub-processors to do the same.
  • Patrata may keep Merchant Data for longer only where a law requires it, and only for as long as that law requires. Anything kept on that basis stays subject to Sections 7 and 8.
  • On request we will confirm deletion in writing.

Records that Patrata holds as Fiduciary in its own right — consent records, message delivery and opt-out records, verification results — are kept on the schedule in the Privacy Policy and are not deleted by your account closing, because they are our evidence that permission existed.

15. Liability

Each party is responsible for its own compliance. Patrata is liable to you for its own breach of this agreement and for its sub-processors. You are liable to us for loss caused by your entering data without consent, entering inaccurate data, or instructing us to do something unlawful.

The liability cap in Section 20 of the Terms of Service applies to this agreement as well, and the two are not cumulative. That cap does not apply to Patrata’s own failure to keep data secure, to fraud, or to anything that cannot be limited under Indian law.

16. Term, changes and governing law

This agreement runs for as long as Patrata processes Merchant Data. We may update it; for a material change we will give at least 14 days’ notice in the app and ask you to accept the updated version. If you do not accept, you may terminate and receive a pro-rata refund of your unused term.

Where this agreement and the Terms of Service conflict on a data protection point, this agreement prevails. On everything else, the Terms prevail.

Governed by the laws of India, with the courts named in Section 24 of the Terms of Service.

Annexure A — details of processing

Subject matterProviding the Patrata application to the Merchant.
DurationFor as long as the Merchant’s account is open, plus the return and deletion periods in Section 14.
Nature and purposeStoring, organising, displaying, retrieving, structuring and erasing the Merchant’s customer credit records; preparing reminder messages at the Merchant’s instruction; producing the Merchant’s own totals and dashboard.
Types of personal dataName; mobile number; credit amounts, dates and due dates; repayment records; consent records including the text, language, version and time.
Categories of Data PrincipalThe Merchant’s own credit customers, all of whom are adults aged 18 or over.
Sensitive categoriesFinancial information (transaction and repayment records), treated as sensitive personal data under Rule 3 of the SPDI Rules 2011.
Documented instructionsThe Merchant’s use of the app’s features, plus any written instruction given to info@credsetu.in.

Annexure B — sub-processors

Current as at the effective date at the top of this page. Changes are notified under Section 9.

CategoryWhat they doSees Merchant Data?
Cloud hosting, storage and databaseRuns the application and stores the ledgerYes
One-time password deliverySends the login code to the Merchant’s phoneMerchant’s mobile number only
Website delivery and securityServes and protects the public websiteNo
Payment processingTakes subscription payments from the MerchantNo — Merchant billing data only
Error and performance monitoringTechnical logs and crash reportsTechnical logs only
Named list pending. The specific provider names and their locations are being confirmed and will be inserted here before this agreement is presented to any merchant for acceptance. A general authorisation under Section 9 to an unnamed list is not adequate authorisation, so this Annexure must be completed — not left as categories — before signature.
Identity verification is not sub-processed and no verification vendor is engaged, because the feature is not active. If it is ever enabled, Patrata must perform it on its own account: Regulation 16A(2) of the Aadhaar (Authentication and Offline Verification) Regulations 2021 prohibits any entity from performing offline verification on behalf of another.

Annexure C — security measures

These are the measures in place today. Nothing is listed here that cannot currently be evidenced.

  • Encryption in transit (TLS) for all traffic between the app, the website and our servers.
  • Role-based access control; least privilege; access reviewed at least every six months.
  • One-time-password authentication for merchants; multi-factor authentication on administrative accounts.
  • Logging and monitoring of access to personal data.
  • Written confidentiality obligations and data handling training for everyone with access, including contractors and interns.
  • Backups, with restore tested at least annually.
  • A documented incident response procedure with named owners and the timelines in Section 11.
  • Internal Information Security Policy, reviewed every six months.
Under completion, and deliberately not promised yet: encryption of data at rest, log retention for 180 days within Indian jurisdiction, and a managed secret store with scheduled credential rotation. Each is a contractual promise to every merchant who signs, so none is listed above until it is confirmed in writing and evidenced. Add them here when they are true — not before.
Status of this draft. This document has not been reviewed by an advocate. It is written to be reviewed rather than written from scratch, which is the cheaper and faster way to buy the same protection. Do not present it to a merchant as a settled agreement until counsel has signed it off. Section 8(2) of the DPDP Act requires a valid contract, and Section 8(1) means a defective one leaves the merchant exposed while making him believe he is not.