Legal
Data Processing Agreement (DPA)
Last updated: 10 July 2026
This Data Processing Agreement (“DPA”) supplements the SolarisCRM Terms of Service and applies to any Customer whose use of SolarisCRM involves the processing of Personal Data of individuals in a jurisdiction with applicable data protection law, including the EU GDPR, UK GDPR, India's DPDP Act 2023, and equivalent laws.
1. Parties + definitions
- Processor — Stellavix (“we”, “us”)
- Controller — the SolarisCRM Customer (“you”)
- Personal Data — any information relating to an identified or identifiable natural person that you upload to or generate within SolarisCRM
- Sub-processors — third parties we engage to process Personal Data on our behalf; listed at Section 8 below
2. Scope + duration
This DPA applies for as long as you have an active SolarisCRM subscription and any Personal Data remains under our processing. Termination of your subscription triggers the deletion procedure described in Data Deletion.
3. Categories of data + data subjects
You determine what Personal Data you upload. Typical categories:
- Contact details of leads, prospects, and customers (name, email, phone, company)
- Communication content — emails, WhatsApp messages, notes, activities
- Deal + pipeline data associated with individuals
- Product usage metadata generated by your team's actions inside SolarisCRM
Data subjects include your employees who use the app and the individuals represented in the CRM records you create.
4. Purpose + instructions
We process Personal Data only:
- To provide the SolarisCRM service to you under the Terms of Service
- To carry out documented instructions from you through the SolarisCRM UI or written support requests
- To comply with legal obligations that apply to us
We will not use your data for our own marketing, ML training, or any purpose beyond delivering the service unless you give explicit consent.
5. Security measures
- All data in transit encrypted via HTTPS/TLS 1.2+
- Data at rest encrypted on AWS RDS + S3 (SSE-AES256)
- WhatsApp Business Platform access tokens encrypted with Fernet at the column level
- PII masking applied to outbound WhatsApp message bodies before database write
- Role-based access control on all admin endpoints
- Per-organisation multi-tenant isolation — every DB query scoped by
organization_id - Audit trail on every WhatsApp send + permission change
- Rate limiting + circuit breakers on external calls
- Regular security review of dependencies
6. Confidentiality
Stellavix personnel with access to Personal Data are bound by contractual confidentiality obligations. Access is granted only on a need-to-know basis and is logged.
7. Data subject rights
You are responsible for responding to data subject requests. SolarisCRM provides in-product tools to help you comply:
- Access + export — Settings → Data → Export delivers a CSV/JSON dump per contact or account-wide
- Correction — inline editing on every record
- Erasure — Data Deletion flow, plus the per-contact WhatsApp erase action
- Objection / restriction — contact opt-out toggle (STOP keyword auto-processing)
8. Sub-processors
We use the following sub-processors to deliver the service. Each has its own data processing terms which we've reviewed.
- Amazon Web Services (AWS) — infrastructure hosting, RDS (Postgres), S3, SES for transactional email. Region: ap-south-1 (Mumbai).
- Meta Platforms (WhatsApp Business Platform) — messaging delivery. Meta is a joint processor for WhatsApp message content.
- Stripe — payment processing, PCI DSS Level 1.
- Google (Firebase) — authentication + session management.
- Anthropic (Claude API) — AI assist features: suggested reply, summarisation, intent classification. Data sent under enterprise no-training terms.
- Sentry — error tracking. PII scrubbing enabled on all events.
We give you 30 days' notice before adding new sub-processors that process your Personal Data. You may object to a new sub-processor; if we cannot resolve the objection, you may terminate the subscription without penalty.
9. Data breach notification
We notify you without undue delay — and no later than 72 hours after we become aware — of any confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to your Personal Data. Notifications go to your workspace admin's email plus rishi@stellavix.in.
10. International transfers
SolarisCRM data is stored in ap-south-1 (Mumbai, India). Where sub-processors transfer data outside your jurisdiction (e.g., Meta's global infrastructure), we rely on their standard contractual clauses and equivalent transfer safeguards.
11. Return + deletion
On termination we return or delete Personal Data per the Data Deletion procedure. Backups are purged within 90 days.
12. Audits
We provide audit information on written request, including security certifications, penetration test summaries, and this DPA. Physical audits of our facilities can be arranged with 30 days' notice, no more than once per year, at your cost.
13. Liability
Liability under this DPA is capped as set out in the Terms of Service, without prejudice to statutory rights that cannot be limited.
14. Governing law
This DPA is governed by the laws of India. Any disputes are subject to the exclusive jurisdiction of the courts of Gujarat, India.
15. Acceptance
You accept this DPA either by:
- Continuing to use SolarisCRM after being notified of this DPA, or
- Explicitly acknowledging inside the app via the WhatsApp Admin → DPA tab, which records your acceptance with a version + timestamp + user ID
16. Contact
rishi@stellavix.in
Stellavix
552, Dr. Ambedkar Street, Devsar
Bilimora, Gujarat – 396380
India