By using this website, you ("you" or "your") agree to abide by these Terms and Conditions, our Privacy Policy, and any other relevant policies and notices applicable to specific parts of the website. The terms "Website Owner," "we," "us," or "our" refer to STACKINTEL PRIVATE LIMITED, including its subsidiaries and affiliates, which provides the information on this website.
Continuing to browse and use this website signifies your acceptance of these terms and conditions of use, which, along with our privacy policy, govern StackIntel's relationship with you regarding this website.
"StackIntel," "us," or "we" refers to the website owner, whose registered/operational office is located at StackIntel Office, #201, 2nd Floor, Arc Plaza Industrial Estate, Veera Desai Road, Andheri West, Mumbai-400053, with contact number +91 81948 66666. "You" refers to the user or viewer of our website.
Your use of this website is subject to the following conditions:
This Data Protection Addendum ("Addendum") is an integral part of the STACKINTEL Private Limited Terms & Conditions (or other relevant agreement) that governs your access to and use of the Services. This Addendum applies to you ("Customer"), including any Affiliates authorized to use the Services.
The Parties agree that the terms and conditions outlined below will be added as an Addendum to the Agreement.
In this Addendum, the following terms have the meanings set out below:
Terms like 'Business,' 'Business Purpose,' 'commercial purpose,' 'Contractor,' 'Controller,' 'Data Subject,' 'Personal Data,' 'Personal Data Breach,' 'Process,' 'Processor,' 'Sell,' 'Service Provider,' 'Share,' 'Subprocessor,' 'Supervisory Authority,' and 'Third Party' hold the same meanings as defined in applicable Data Protection Laws.
Capitalized terms not defined in this Addendum have the meanings given to them in the Agreement.
The Parties acknowledge and agree that for the processing of Customer Personal Data, the Customer acts as a Business or Controller, and STACKINTEL Private Limited acts as a Service Provider or Processor, as further detailed in Annex 1. This Addendum applies only to the processing of Customer Personal Data by STACKINTEL Private Limited in these roles.
The Customer is solely responsible for timely communication with its Affiliates or relevant Controllers receiving the Services, as needed to comply with applicable Data Protection Laws.
Annex 1 of this Addendum outlines the parties' understanding of the subject matter and details of Customer Personal Data processing by STACKINTEL Private Limited. Annex 1 may be reasonably amended by mutual written agreement to meet requirements. It does not create obligations or rights for any party.
The purpose of processing under this Addendum is to provide the Services as per the Agreement and any Order Form(s).
The Customer must comply with all applicable Data Protection Laws when performing this Addendum and processing Customer Personal Data. When accessing and using the Services, the Customer will process Customer Personal Data within the Services and provide STACKINTEL Private Limited with instructions in line with applicable Data Protection Laws. The Customer is solely responsible for complying with Data Protection Laws regarding the collection and transfer of Customer Personal Data to STACKINTEL Private Limited. The Customer agrees not to provide STACKINTEL Private Limited with health, religious, or any other special categories of data as per applicable laws.
STACKINTEL Private Limited will comply with all applicable Data Protection Laws when processing Customer Personal Data and will:
When Customer Personal Data is transferred from Customer and/or its Affiliates (as exporter) to STACKINTEL Private Limited (as importer) in a Restricted Transfer subject to relevant Area Law, the transfer will be governed by the appropriate Controller to Processor Contractual Clauses.
The provisions of this Addendum are supplementary to the Agreement. If there's any inconsistency, this Addendum's provisions will prevail. Should any provision of this Addendum and/or the Agreement contradict the Controller to Processor Contractual Clauses, the Controller to Processor Contractual Clauses will take precedence.
To the extent permitted by law, the Customer agrees to (a) defend STACKINTEL Private Limited and its Affiliates ("Indemnified Parties") against any third-party claims, demands, suits, or proceedings ("Claim"), and (b) indemnify and hold harmless the Indemnified Parties from all losses, damages, liabilities, fines, penalties, settlements, and costs (including reasonable legal and consultancy fees) incurred due to any breach by the Customer of this Addendum or its obligations under applicable Data Protection Laws. STACKINTEL Private Limited may participate in the defense and/or settlement of a Claim under this Section 7.1 with its own counsel at its own expense.
The Parties agree that if any part of this Addendum is deemed unlawful or unenforceable by a court, it will not invalidate or render unenforceable any other part of this Addendum.
This Addendum considers and adheres to the following principles:
If a Data Subject wishes to exercise their data subject rights under applicable Data Protection Law (e.g., right to access, correct, and/or erase Personal Data controlled by STACKINTEL Private Limited), they can submit such requests by contacting STACKINTEL Private Limited's Data Protection Officer (DPO) below. Concerns or complaints related to Customer Personal Data can also be directed to the DPO:
Name: Salil Chaturvedi
Email ID: Salil@stackintel.in
No temporary files are generated during processing.
Description of Processing Activities for Customer Personal Data
Name: Customer (as defined in the Agreement)
Address: As specified in the relevant Order Form.
Role (controller/processor): As specified in the relevant Order Form.
Activities relevant to the data transferred under these Clauses: Recipient of Services from STACKINTEL Private Limited under the Agreement.
Signature and date: Set out in the Agreement.
Contact person's name, position and contact details: Controller
Name: STACKINTEL Private Limited
Address: #201, 2nd Floor, Arc Plaza Industrial Estate, Veera Desai Road, Andheri West, Mumbai-400053
Role (controller/processor): Processor
Activities relevant to the data transferred under these Clauses: Provision of Services to the Customer under the Agreement.
Signature and date: Set out in the Agreement.
Contact person's name, position and contact details: Salil Chaturvedi Salil@stackintel.in Founder & CEO
The competent supervisory authority/ies in accordance with Applicable Data Protection Clause: Data Protection Authority
Subject matter and duration of the Processing of the Personal Data
The processing of personal data involves onboarding customers to our applications, completing KYC (Know Your Customer) procedures, and creating behavioral analytics for customers. This processing will last as long as needed to achieve its purpose, typically for the entire customer or employee relationship, with data retention for a specified period after relationship termination, as per legal and company policies.
The nature and purpose of the Processing of the Personal Data
Nature: StackIntel primarily processes personal data for fintech services and related products. Our focus is on verifying customer identity to prevent fraud and on collecting and maintaining information about individuals and businesses. Purpose: The purpose of processing personal data in fintech is to facilitate secure and efficient financial transactions, provide personalized financial services, and ensure regulatory compliance. Personal data is often used for identity verification, risk assessment, and enhancing user experiences.
The categories of Data Subject to whom the Customer Personal Data relates
The types of data include:
The types of Customer Personal Data to be Processed
Personal identification information: This may include names, date of birth, gender, contact details (e.g., mobile numbers, email addresses), and residential addresses.
Financial information: This may involve bank account details and financial transaction records.
Employment information: Details related to employment history, occupation, and employer information.
Geolocation data: We may collect location data through mobile applications or other means.
Special categories of data
None
The obligations and rights of Client
The Client's obligations and rights are detailed in the Terms and this Addendum.
Data exporter (as applicable)
The data exporter is: The Client of the Company who uses the Services.
Data importer (as applicable)
The data importer is: STACKINTEL Private Limited, a company that provides services to the client, requiring access to the client's query data.
Processing operations (as applicable)
The transferred personal data will undergo the following basic processing activities: provision of Company Services to Client. To provide people data, the Company receives identifying Personal Data, allowing it to query, cleanse, standardize, enrich, send to additional data providers when necessary, and store the query information.
This section describes the technical and organizational security measures implemented by STACKINTEL Private Limited as the data processor/data importer. These measures are designed to ensure an appropriate level of security, considering the nature, scope, context, purpose of processing, and risks to individuals' rights and freedoms.
4.1. Security
Security Management System.
Organization. STACKINTEL Private Limited appoints qualified security personnel responsible for developing, implementing, and maintaining the Information Security Program.
Policies. Management reviews and supports all security-related policies to ensure the security, availability, integrity, and confidentiality of Customer Personal Data. These policies are updated at least annually.
Assessments. STACKINTEL Private Limited hires a reputable independent third-party to perform annual risk assessments of all systems containing Customer Personal Data.
Risk Treatment. STACKINTEL Private Limited maintains a formal and effective risk treatment program, including penetration testing, vulnerability management, and patch management, to identify and protect against potential threats to Customer Personal Data security, integrity, or confidentiality.
Vendor Management. STACKINTEL Private Limited maintains an effective vendor management program.
Incident Management. STACKINTEL Private Limited regularly reviews security incidents, including determining root causes and corrective actions.
Standards. STACKINTEL Private Limited operates an information security management system compliant with ISO/IEC 27001:2013.
4.2. Personnel Security.
STACKINTEL Private Limited personnel must adhere to company guidelines on confidentiality, business ethics, appropriate usage, and professional standards. STACKINTEL Private Limited conducts reasonably appropriate background checks (employment history, criminal records) on employees with access to Customer data, as legally permissible and in line with local labor laws, customary practice, and regulations.
Personnel are required to sign a written confidentiality agreement upon hiring and to protect Customer Personal Data at all times. They must acknowledge receipt of and compliance with STACKINTEL Private Limited's confidentiality, privacy, and security policies. Personnel receive privacy and security training on implementing and complying with the Information Security Program. Those handling Customer Personal Data must complete additional role-appropriate requirements (e.g., certifications). STACKINTEL Private Limited's personnel will not process Customer Personal Data without authorization.
4.3. Access Controls
Access Management. STACKINTEL Private Limited has a formal access management process for requesting, reviewing, approving, and provisioning access for all personnel. This limits access to Customer Personal Data and relevant systems to properly authorized persons on a "need for such access" basis. Access reviews are conducted periodically to ensure only essential personnel retain access.
Infrastructure Security Personnel. STACKINTEL Private Limited has a security policy for its personnel and requires security training as part of its personnel training package. STACKINTEL Private Limited's infrastructure security personnel are responsible for ongoing monitoring of its security infrastructure, Services review, and responding to security incidents.
Access Control and Privilege Management. STACKINTEL Private Limited's and Customer's administrators and end users must authenticate using a Multi-Factor authentication system or a single sign-on system to use the Services.
Internal Data Access Processes and Policies - Access Policy. STACKINTEL Private Limited's internal data access policies protect against unauthorized access, use, disclosure, alteration, or destruction of Customer Personal Data. Systems are designed to allow only authorized persons to access data based on "least privileged" and "need to know" principles, preventing unauthorized access. Unique user IDs, strong passwords, two-factor authentication, and monitored access lists minimize unauthorized account use. Access rights are granted or modified based on job responsibilities, duty requirements, need-to-know basis, and in accordance with STACKINTEL Private Limited's internal policies and training. Approvals are managed by workflow tools with audit records. System access is logged for accountability. Password policies (complexity, expiry, lockout, reuse restrictions, re-prompting after inactivity) follow industry standards where passwords are used for authentication.
4.4. Data Centre and Network Security
Data Centres.
Infrastructure. STACKINTEL Private Limited uses AWS as its data center.
Resiliency. Multi-Availability Zones are enabled on AWS, and STACKINTEL Private Limited conducts regular Backup Restoration Testing to ensure resiliency.
Server Operating Systems. STACKINTEL Private Limited's servers are customized and hardened for the application environment and Services security. A code review process is employed to enhance the security of code used for Services and production environments.
Disaster Recovery. STACKINTEL Private Limited replicates data across multiple systems to protect against accidental destruction or loss. Disaster recovery programs are designed, regularly planned, and tested.
Security Logs. STACKINTEL Private Limited's systems log to their respective system log facilities to support security audits and to monitor and detect actual or attempted attacks or intrusions.
Vulnerability Management. STACKINTEL Private Limited regularly performs vulnerability scans on all infrastructure components of its production and development environments. Vulnerabilities are remediated based on risk, with Critical, High, and Medium security patches installed as soon as commercially feasible.
Networks and Transmission.
Data Transmission. Transmissions in the production environment occur via Internet standard protocols.
External Attack Surface. AWS Security Group, acting as a virtual firewall, is in place for the Production environment on AWS.
Incident Response. STACKINTEL Private Limited maintains incident management policies and procedures, including detailed security incident escalation procedures. STACKINTEL Private Limited monitors various communication channels for security incidents, and its security personnel promptly react to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes.
Encryption Technologies. STACKINTEL Private Limited makes HTTPS encryption (SSL/TLS) available for data in transit.
4.5. Data Storage, Isolation, Authentication, and Destruction.
STACKINTEL Private Limited stores data in a multi-tenant environment on AWS servers. Data, the Services database, and file system architecture are replicated across multiple AWS availability zones. STACKINTEL Private Limited logically isolates data from different customers. A central authentication system is used across all Services to enhance uniform data security. STACKINTEL Private Limited ensures secure disposal of Customer Data through various data destruction processes.
STACKINTEL Private Limited's Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Running the Production environment including the Application and Databases | India |
| Microsoft | Email services | India |
| Tally | Invoicing & ERP solution | India |
| Zoho | Invoicing solution | India |
| Razorpay | Payment Gateway | India |
| Github | Code version control | US |
| Slack | Messaging | US |
As a merchant, we are not liable for any loss or damage resulting directly or indirectly from the denial of authorization for any transaction where the Cardholder has exceeded the pre-set limit mutually agreed upon with our acquiring bank.
To use certain features of our services, you may need to create an account. You agree to provide accurate, current, and complete registration information and to keep it updated. You are responsible for protecting your password and for all activities under your account, whether authorized or not.
Either party can terminate this agreement with 90 days' written notice. Immediate termination may occur if:
To the maximum extent permitted by applicable law, StackIntel will not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits or revenue, whether direct or indirect. This also includes any loss of data, use, goodwill, or other intangible losses resulting from (a) your access to or inability to use the services; (b) any third-party conduct or content on the services; (c) any content obtained from the services; and (d) unauthorized access, use, or alteration of your transmissions or content.
We reserve the right to modify or replace these Terms at any time, at our sole discretion. If a change is significant, we will provide at least 30 days' notice before the new terms take effect. What constitutes a material change will be determined solely by us. By continuously using or accessing our Service after any revisions become effective, you agree to be bound by the updated terms.
For any inquiries, contact our support team:
support@stackIntel.in