1. Scope and priority
This Data Processing Addendum (“DPA”) forms part of every agreement under which Showroom 360 processes personal data in Dealership Data on behalf of a Dealership. It applies for the subscription, trial, post-expiry retention, support, export, deletion, and any longer processing required by law.
If this DPA conflicts with the Terms about processing Dealership Data, this DPA controls. Capitalised terms not defined here have the meanings in the Terms.
2. Roles and instructions
The Dealership determines the purpose and means of processing Dealership Data and acts as the Data Fiduciary or equivalent responsible party. Showroom 360 acts as Data Processor and processes only on the Dealership’s documented lawful instructions in the agreement, product configuration, authorised support requests, and use of the service, unless law requires otherwise.
If we believe an instruction violates applicable data-protection law or creates a material security or legal risk, we may pause the affected processing, notify the Dealership where lawful, and request a lawful alternative. We do not independently determine the lawfulness of every custom field, document, recipient, or Dealership instruction.
3. Processing details
- Subject matter: operation of a multi-tenant dealership CRM, document storage, workflow, reporting, support, security, export, retention, and deletion.
- Duration: the trial or subscription, any payment grace, 90-day post-expiry retention, deletion and backup cycle, and any documented legal hold.
- Nature: collection through authorised users, recording, organisation, storage, retrieval, consultation, transmission, campaign orchestration through connected accounts, support access, scanning, backup, export, restriction, return, and deletion.
- Purposes: providing, securing, supporting, maintaining, and administering the service under the Dealership’s instructions.
- Data subjects: Dealership users, employees, owners, leads, prospects, customers, vehicle owners, contacts, and persons whose information the Dealership lawfully submits.
- Data categories: identity and contact details, employment and role, vehicle interests and ownership, lead source and status, notes, activities, communications, custom fields, uploaded documents, identifiers, audit events, and other Dealership-selected information, excluding prohibited categories under the Terms.
4. Dealership obligations
The Dealership will provide every notice, lawful purpose or basis, consent or other permission, preference check, alternative identity method, access control, accuracy process, retention decision, and response required for its processing. It will give instructions only through authorised users and will not direct us to process prohibited data or act unlawfully.
The Dealership is responsible for assessing whether Showroom 360 and this DPA are suitable for its use, including its intended identity and finance documents, communications, statutory records, and regulatory obligations.
5. Personnel confidentiality and support access
Authorised personnel who process Dealership Data are bound by confidentiality and may use application or direct administrative access only as reasonably needed for support, security, maintenance, or legal compliance. Access is limited by internal authorisation and purpose, but a customer-authorised, time-limited support-access workflow is not guaranteed unless the product or Order expressly states that it is enabled.
We investigate suspected misuse of administrative access and preserve available evidence where reasonably practicable. The Dealership should not disclose credentials, OTPs, payment secrets, or unnecessary customer documents when requesting support.
6. Security measures
Showroom 360 maintains reasonable technical and organisational safeguards appropriate to the nature, scope, context, purpose, and risk of processing. The safeguards are reviewed as the service changes and may be replaced with controls that are materially equivalent or stronger.
- Hosting of the production service and primary Dealership Data in AWS ap-south-1 (Mumbai), with the production database placed in restricted private network infrastructure.
- Encryption in transit using current supported secure transport. Supported uploaded documents are stored in private object storage protected with customer-managed encryption, versioning, public-access blocking, and secure-transport enforcement.
- Tenant, branch, role, and user access controls in the application, together with restricted administrative access and multi-factor protection where configured.
- Private object storage, public-access blocking, secure-transport enforcement, versioning, malware scanning, file validation, and restricted expiring access for supported documents.
- AWS and application security, authentication, administrative, and operational logs generated by the relevant services, with access restricted to authorised personnel.
- AWS-managed automated database backups and database deletion protection, together with provider and application recovery mechanisms appropriate to the relevant component.
- Credential and secret protection, upload validation, available audit evidence, and incident escalation and response as required by the circumstances and applicable law.
7. Subprocessors
The Dealership authorises the subprocessors listed below and any replacement or additional subprocessor engaged under this section. We contractually restrict subprocessors to the relevant service and require protection appropriate to the processing.
- Amazon Web Services — application hosting, database, object storage, email infrastructure, logging, backup, network, encryption, and security services; primary production region ap-south-1 (Mumbai).
- Razorpay — checkout, payment mandates, recurring charges, refunds, payment verification, fraud controls, and billing-provider records. Razorpay ordinarily processes payment information for its own regulated purposes as well as providing services to us.
- A Dealership-selected communication provider — campaigns and related delivery data under the Dealership-owned provider account and provider terms; the Dealership, not Showroom 360, selects and authorises that provider.
8. Subprocessor changes
We give reasonable advance notice of a new core subprocessor that will process Dealership Data. The Dealership may object within 10 days on reasonable documented data-protection grounds. The parties will try to resolve the objection. If no commercially reasonable alternative exists, the Dealership may stop the affected future processing or cancel renewal; an objection does not create a refund for the current paid term unless applicable law requires it.
9. Individual requests and compliance assistance
Taking into account the nature of processing and information available to us, we provide reasonable assistance for access, correction, updating, erasure, grievance, consent-withdrawal, breach, assessment, regulator, and other obligations applicable to the Dealership. We may route a direct request to the Dealership and will not independently respond about Dealership Data unless authorised or legally required.
Assistance available through standard product and support is included. Unusually burdensome, repetitive, custom, or legally unnecessary work may require a written scope and reasonable charge disclosed in advance.
10. Personal-data incidents
On becoming aware of a reasonably credible personal-data incident involving Dealership Data, we begin investigation and notify the affected Dealership without undue delay and, where practicable, within 24 hours. A delay beyond that target does not by itself establish liability where containment, safety, law-enforcement instructions, or reliable fact gathering reasonably requires more time.
We provide information reasonably available about the nature, timing, affected data and people, likely consequences, containment, mitigation, recommended actions, and contact point, and provide material updates. Notification is not an admission of fault. Each party remains responsible for notices owed in its legal role, and we may notify authorities or individuals directly where law requires.
11. Return, export, retention, and deletion
During active access, authorised owners may use the available lead-workbook export. After paid access and grace end, we ordinarily retain Dealership Data for up to 90 days and, on one verified owner request, provide one support-assisted export of data that is reasonably retrievable using our then-available tools and formats without requiring resubscription. This is not a promise that every internal log, provider record, derived metric, or unsupported format can be exported.
Current in-product deletion removes supported records from ordinary use and archives them; it does not by itself confirm permanent erasure. Following a verified permanent-erasure request or expiry of the applicable account-retention period, we initiate deletion or irreversible de-identification of reasonably retrievable operational data. Completion is subject to legal holds, security evidence, disputes, technical dependencies, and residual protected backups expiring through the backup cycle.
We may retain narrowly separated information required for law, tax, security, fraud, disputes, or legal claims and continue to protect it. On request, we provide reasonable confirmation that the applicable return or delete process completed.
12. Audit information
On reasonable written request no more than once in a 12-month period, we provide available information reasonably necessary to demonstrate compliance with this DPA, such as current security summaries, relevant policies, or independent reports when available and legally shareable. Additional audit activity requires reasonable notice, confidentiality, minimal disruption, no access to another customer’s information, and reimbursement of reasonable costs unless a confirmed material breach by us caused the audit.
The Dealership may not conduct penetration testing, access source code, obtain credentials, or inspect multi-tenant production systems. A regulator’s mandatory authority is unaffected.
13. Location and legally required disclosure
Primary production Dealership Data is hosted in AWS ap-south-1 (Mumbai). Service providers may process limited operational, support, security, or payment information from other locations where lawful and protected. We do not appoint an AI model provider to process Dealership Data unless the agreement and subprocessor notice are updated.
If law requires disclosure of Dealership Data, we disclose only what is required and, where lawful, notify the Dealership and reasonably cooperate with a protective request.
14. Liability and termination
The liability exclusions and aggregate cap in the Terms apply to this DPA, including privacy, confidentiality, security, processor, incident, assistance, audit, return, and deletion claims, to the maximum extent permitted by law.
Termination of the DPA does not require deletion contrary to an active subscription, recovery period, legal hold, or required retention. The return, deletion, confidentiality, audit, dispute, and liability provisions survive as needed to complete processing and resolve claims.