arrow_backBackData Processing

Data Processing Agreement

Last updated · 3 September 2026

What changed on 3 September 2026

We added one section, Anonymous aggregate statistics, and made the wording of our obligations more precise so that it matches it. Nothing else changed, and nothing we already promised has been taken away.

The short version · we count activity across all cafés to build benchmarks and industry reporting, those counts carry no personal data and never name a café, and you can opt out by emailing us. The previous wording said we would never use one café's data to benefit another, which would have covered even anonymous counting, so we have said plainly what we do instead of quietly reading the old words more narrowly than they were written.

Why this exists

Under section 8(2) of the Digital Personal Data Protection Act, 2023, a Data Fiduciary may engage a Data Processor only under a valid contract. This is that contract. It forms part of our Terms of Service and applies automatically from the moment you accept them · there is nothing for you to sign.

Who is who

You, the café, are the Data Fiduciary. You decide what personal data to collect from your members and why. The obligations to give notice, obtain valid consent, honour your members' rights and answer their grievances are yours.

We are your Data Processor. Asif Rahim, trading as RESPAWNA, trading as RESPAWNA, processes that data only to provide the service, and only on your instructions.

For our own customer records · your name, your café's details, your billing history · we are the Data Fiduciary, and our Privacy Policy covers those.

What we process

Categories of data principal: your café's members and walk-in customers, and the staff accounts you create.

Categories of personal data: name, username, email address, phone number, an avatar if uploaded, session and visit history, invoices and line items, payment method recorded against an invoice, wallet balance and transactions, loyalty points, membership status, and event registrations.

Purpose and duration: to operate your café's console for as long as your subscription runs, plus the 30-day export window afterwards.

We do not collect card numbers or bank credentials from your members. Payments are taken at your counter and only the method used is recorded.

Our obligations

  • Process personal data only to provide the service and only on your documented instructions, which for most purposes are the settings you configure.
  • Never sell your members' personal data, and never use it for our own marketing.
  • Never let one café see another café's records, or identify another café from anything we publish. Anonymous aggregate statistics are the one narrow exception, and they are set out below.
  • Keep it confidential and limit access to personnel who need it for support or operations.
  • Apply reasonable security safeguards, described below.
  • Assist you in responding to your members' access, correction and erasure requests.
  • Notify you of a personal data breach without undue delay, so you can meet your own reporting duty.
  • Delete the data at the end of the agreement, as set out below.

Anonymous aggregate statistics

We count things across every café using RESPAWNA · hours played, session lengths, how busy a Friday is against a Tuesday, how often food is added to a session. We use those totals to build the benchmarks we show you inside your own console, and we may publish them as industry reporting.

This is the only thing we do with your data that is not purely for you, so here is exactly what it is and what it is not.

  • It contains no personal data. No name, no number, no email, no member, no staff account. Nothing that identifies a person survives the counting.
  • It never names your café, and we do not publish a figure that could point at one café. Nothing is published unless at least ten cafés sit behind the number.
  • It is not your records. Another café can never see your sessions, your members, your prices or your takings, in aggregate or otherwise.
  • We do not sell it, and we do not pass your underlying records to anyone as part of it.

Because genuinely anonymous data is not personal data, this sits outside the DPDP Act altogether. We are writing it into this agreement anyway, so that it is a promise you can hold us to rather than a silence you have to trust.

You can opt out at any time, with no effect on your subscription and no argument from us. Email [email protected] and we will exclude your café from every published and internal aggregate from that day. You keep your own benchmarks either way.

Security safeguards

Isolation between cafés is enforced in the database itself through row-level security on every table and inside every money operation · not by application code that could forget. That isolation is verified by an automated suite covering all tables and money functions, run on every build.

  • Encryption in transit for all connections.
  • Passwords stored only as salted hashes, never visible to us or to you.
  • Role-based access within your café: your staff see only what their role allows.
  • Member contact details and wallet balances are not readable by anonymous or other-tenant callers · this is enforced by policy and tested, not assumed.
  • Administrative access restricted, with retained access logs.

Sub-processors

We use these to deliver the service. You consent to them by accepting this agreement, and we remain responsible to you for what they do:

  • Supabase · database, authentication and file storage. Hosted in ap-south-1 (Mumbai), so your café's records rest in India.
  • Railway · application hosting.
  • Cloudflare · DNS and network protection.
  • Resend · transactional email such as password resets and staff invitations.
  • Razorpay · our subscription payments only. Your members' payments do not pass through it.

We will give at least 30 days' notice before adding a sub-processor that handles your members' personal data. If you object on reasonable grounds and we cannot resolve it, you may terminate without penalty and take a pro-rata refund.

Cross-border transfer

Your café's database is in Mumbai. Some sub-processors operate infrastructure outside India for hosting and email delivery. The Act permits transfers except to countries the Central Government restricts, and we do not transfer personal data to any restricted country.

Breach notification

If we become aware of a personal data breach affecting your café's data, we will tell you without undue delay and in any case within 48 hours, with what we know about what happened, which data is affected, the likely consequences and what we are doing about it.

You then notify your affected members and the Data Protection Board of India as the Act requires · as Data Fiduciary that duty is yours, and the Board expects it within 72 hours. Our 48-hour commitment exists to leave you time to meet it. We will give you whatever information you reasonably need for that report.

Assisting with your members' rights

If a member contacts us directly about their data, we will not act on it ourselves · we will point them to you and tell you it happened. The console gives you the tools to answer most requests yourself: member records are editable, accounts can be deleted, and reports export. If you need something the interface cannot do, ask and we will help within the timeframes on our contact page.

Children's data · your responsibility, and it is a real one

Gaming cafés have young customers, and the Act is strict about them. Section 9 requires verifiable parental consent before processing the personal data of anyone under 18, and prohibits tracking, behavioural monitoring and targeted advertising directed at children.

As Data Fiduciary this obligation is yours. It bears on how you use the marketing features in particular: segmenting members by their visit history and spending, and messaging them about offers, is behavioural processing that must not be applied to a member under 18. Do not include minors in campaigns.

Deletion and return

On termination, your data stays available for 30 days so you can export it. After that we delete it from live systems, and from backups as those age out on their normal cycle. We will confirm deletion in writing if you ask.

Audit

On reasonable written request, and not more than once a year, we will provide the information you reasonably need to confirm we are meeting this agreement · including the results of our isolation test suite. Where a regulator requires more, we will cooperate with that.

Liability and precedence

The limitation of liability in our Terms of Service applies to this agreement too. Where this agreement and the Terms conflict on the processing of personal data, this agreement prevails.