Agreement: Seller Data Protection Addendum (DPA) Forms part of: the Horeka Seller Agreement Version: 1.0 | Effective: 7 August 2026
To fulfil orders, sellers receive personal data about customers — name, delivery address, telephone number and order contents. This Addendum governs what a seller may and may not do with it. It is binding on every seller and is drafted to satisfy the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
1. Roles
Horeka
Data Fiduciary — determines the purpose and means of processing customer personal data
Seller
Data Processor — processes customer personal data solely on Horeka’s documented instructions, for the purpose of fulfilling orders
Customer
Data Principal
The seller is a Data Fiduciary in its own right for data it collects independently of the Platform. This Addendum applies only to data received through the Platform.
2. What sellers receive
Data
Purpose
Shared when
Customer name
Address the package; verify the recipient
On order acceptance
Delivery address
Fulfil delivery
On order acceptance
Contact number
Coordinate delivery; resolve fulfilment issues
On order acceptance; masked where technically supported
Order contents and value
Pick, pack, invoice
On order acceptance
Buyer GSTIN
Issue a compliant B2B tax invoice
Where the customer supplies it
Complaint details
Investigate and resolve
On escalation
Sellers never receive: payment card or bank details, UPI credentials, login credentials, browsing or search history, other customers’ data, or any data relating to orders they did not fulfil.
3. Permitted purposes — an exhaustive list
A seller may use customer personal data received through the Platform only to:
Fulfil and deliver the specific order it relates to;
Issue the tax invoice for that order;
Communicate with the customer about that specific order;
Process a return, replacement, refund or warranty claim for that order;
Comply with a legal obligation, including tax record-keeping;
Respond to a lawful demand from a competent authority.
4. Prohibited uses
The seller must not:
Use customer data for marketing, promotion or remarketing of any kind — including SMS, WhatsApp, email, telephone calls or postal mail — without the customer’s own independent, freely given, specific and informed consent obtained outside the Platform;
Add customers to any mailing, WhatsApp or broadcast list;
Sell, rent, license, transfer or disclose customer data to any third party, including affiliates, other sellers, data brokers or advertising networks;
Use the data to divert the customer off-platform, or to solicit direct trade;
Contact a customer about a review, or to request its modification or removal;
Retain the data beyond the periods in Section 6;
Combine the data with other datasets to profile customers;
Transfer the data outside India without Horeka’s prior written consent;
Use the data to train any AI or machine learning model;
Process the data for any purpose not listed in Section 3.
Breach of this Section is a material breach of the Seller Agreement and grounds for immediate termination under Section 4 of the Performance Policy, in addition to liability under the DPDP Act.
5. Security obligations
The seller must implement reasonable security safeguards to prevent personal data breach, as required by Section 8(5) of the DPDP Act, including at minimum:
Access control — data accessible only to personnel who need it to fulfil orders; individual named accounts, never shared logins;
Credential hygiene — strong unique passwords and, where offered, multi-factor authentication on the seller dashboard;
Device security — up-to-date operating systems, screen locks, and encryption on any device storing customer data;
No informal copies — customer data must not be copied into personal notebooks, personal phones, unsecured spreadsheets, or personal messaging accounts;
Secure disposal — shredding of printed labels, invoices and manifests once no longer required;
Staff obligations — everyone with access bound by written confidentiality obligations and briefed on these rules;
Sub-processors — no engagement of any sub-processor, including a third-party courier, without Horeka’s prior written consent and equivalent contractual obligations flowed down.
6. Retention
Data
Retain for
Delivery details — name, address, phone
Until the order is delivered and the returns window has closed, then delete
Invoice and transaction records
8 years, as required by the CGST Act and the Companies Act, 2013
Complaint and dispute records
3 years from resolution
Anything else
Delete immediately
Retention for tax purposes does not permit use for any purpose in Section 4. On termination of the Seller Agreement, the seller must delete or return all customer personal data within 30 days, except records it is legally required to retain, and certify deletion in writing on request.
7. Data breach — 24-hour notification
On becoming aware of any personal data breach affecting data received through the Platform — unauthorised access, disclosure, loss, alteration or destruction — the seller must:
Notify Horeka at [email protected] with the subject line SECURITY — DATA BREACHwithin 24 hours, without waiting for a full investigation;
Provide the nature of the breach, categories and approximate number of individuals affected, likely consequences, and remedial measures taken;
Take immediate steps to contain it and preserve evidence;
Cooperate fully with Horeka’s investigation and with any notification Horeka must make to the Data Protection Board of India or to affected customers;
Not notify customers or make any public statement about the breach without Horeka’s prior written agreement, save where independently required by law.
Penalties under the DPDP Act for failure to prevent a personal data breach reach ₹250 crore. The seller is liable for penalties attributable to its own acts or omissions and indemnifies Horeka accordingly under clause 11.2 of the Seller Agreement.
8. Assisting with Data Principal rights
Customers have rights under the DPDP Act to access, correct, complete, update and erase their personal data, and to grievance redressal. Where Horeka receives such a request and it concerns data held by a seller, the seller must assist and respond within 7 days of Horeka’s request, at no charge.
Sellers must not respond directly to a Data Principal request received through the Platform — forward it to [email protected] so that identity can be verified and a consistent response given.
9. Audit
Horeka may, on reasonable notice and no more than once a year unless a breach is suspected, audit the seller’s compliance with this Addendum through a questionnaire, evidence review, or an on-site inspection. The seller will cooperate and provide reasonable access. Where a breach is suspected, Horeka may audit immediately and suspend data flow pending the outcome.
10. Children’s data
Horeka’s services are not directed at children under 18. Where a seller becomes aware that it holds the personal data of a child received through the Platform, it must notify [email protected] immediately and must not process it further. Behavioural monitoring and targeted advertising directed at children are prohibited outright under Section 9 of the DPDP Act.
11. Liability and precedence
The seller indemnifies Horeka against all claims, penalties, fines and costs arising from its breach of this Addendum. Liability under this Addendum is not subject to the cap in clause 12.3 of the Seller Agreement. In the event of conflict, this Addendum prevails over the Seller Agreement on data protection matters.