Legal

Data Processing Agreement (DPA)

Last updated: 10 July 2026

This Data Processing Agreement (“DPA”) supplements the SolarisCRM Terms of Service and applies to any Customer whose use of SolarisCRM involves the processing of Personal Data of individuals in a jurisdiction with applicable data protection law, including the EU GDPR, UK GDPR, India's DPDP Act 2023, and equivalent laws.

1. Parties + definitions

  • Processor — Stellavix (“we”, “us”)
  • Controller — the SolarisCRM Customer (“you”)
  • Personal Data — any information relating to an identified or identifiable natural person that you upload to or generate within SolarisCRM
  • Sub-processors — third parties we engage to process Personal Data on our behalf; listed at Section 8 below

2. Scope + duration

This DPA applies for as long as you have an active SolarisCRM subscription and any Personal Data remains under our processing. Termination of your subscription triggers the deletion procedure described in Data Deletion.

3. Categories of data + data subjects

You determine what Personal Data you upload. Typical categories:

  • Contact details of leads, prospects, and customers (name, email, phone, company)
  • Communication content — emails, WhatsApp messages, notes, activities
  • Deal + pipeline data associated with individuals
  • Product usage metadata generated by your team's actions inside SolarisCRM

Data subjects include your employees who use the app and the individuals represented in the CRM records you create.

4. Purpose + instructions

We process Personal Data only:

  • To provide the SolarisCRM service to you under the Terms of Service
  • To carry out documented instructions from you through the SolarisCRM UI or written support requests
  • To comply with legal obligations that apply to us

We will not use your data for our own marketing, ML training, or any purpose beyond delivering the service unless you give explicit consent.

5. Security measures

  • All data in transit encrypted via HTTPS/TLS 1.2+
  • Data at rest encrypted on AWS RDS + S3 (SSE-AES256)
  • WhatsApp Business Platform access tokens encrypted with Fernet at the column level
  • PII masking applied to outbound WhatsApp message bodies before database write
  • Role-based access control on all admin endpoints
  • Per-organisation multi-tenant isolation — every DB query scoped by organization_id
  • Audit trail on every WhatsApp send + permission change
  • Rate limiting + circuit breakers on external calls
  • Regular security review of dependencies

6. Confidentiality

Stellavix personnel with access to Personal Data are bound by contractual confidentiality obligations. Access is granted only on a need-to-know basis and is logged.

7. Data subject rights

You are responsible for responding to data subject requests. SolarisCRM provides in-product tools to help you comply:

  • Access + export — Settings → Data → Export delivers a CSV/JSON dump per contact or account-wide
  • Correction — inline editing on every record
  • Erasure — Data Deletion flow, plus the per-contact WhatsApp erase action
  • Objection / restriction — contact opt-out toggle (STOP keyword auto-processing)

8. Sub-processors

We use the following sub-processors to deliver the service. Each has its own data processing terms which we've reviewed.

  • Amazon Web Services (AWS) — infrastructure hosting, RDS (Postgres), S3, SES for transactional email. Region: ap-south-1 (Mumbai).
  • Meta Platforms (WhatsApp Business Platform) — messaging delivery. Meta is a joint processor for WhatsApp message content.
  • Stripe — payment processing, PCI DSS Level 1.
  • Google (Firebase) — authentication + session management.
  • Anthropic (Claude API) — AI assist features: suggested reply, summarisation, intent classification. Data sent under enterprise no-training terms.
  • Sentry — error tracking. PII scrubbing enabled on all events.

We give you 30 days' notice before adding new sub-processors that process your Personal Data. You may object to a new sub-processor; if we cannot resolve the objection, you may terminate the subscription without penalty.

9. Data breach notification

We notify you without undue delay — and no later than 72 hours after we become aware — of any confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to your Personal Data. Notifications go to your workspace admin's email plus rishi@stellavix.in.

10. International transfers

SolarisCRM data is stored in ap-south-1 (Mumbai, India). Where sub-processors transfer data outside your jurisdiction (e.g., Meta's global infrastructure), we rely on their standard contractual clauses and equivalent transfer safeguards.

11. Return + deletion

On termination we return or delete Personal Data per the Data Deletion procedure. Backups are purged within 90 days.

12. Audits

We provide audit information on written request, including security certifications, penetration test summaries, and this DPA. Physical audits of our facilities can be arranged with 30 days' notice, no more than once per year, at your cost.

13. Liability

Liability under this DPA is capped as set out in the Terms of Service, without prejudice to statutory rights that cannot be limited.

14. Governing law

This DPA is governed by the laws of India. Any disputes are subject to the exclusive jurisdiction of the courts of Gujarat, India.

15. Acceptance

You accept this DPA either by:

  • Continuing to use SolarisCRM after being notified of this DPA, or
  • Explicitly acknowledging inside the app via the WhatsApp Admin → DPA tab, which records your acceptance with a version + timestamp + user ID

16. Contact

rishi@stellavix.in
Stellavix
552, Dr. Ambedkar Street, Devsar
Bilimora, Gujarat – 396380
India

© 2026 Stellavix. All rights reserved.