Delivering to
← Back to Bazaar

Bazaar.in Data Processing and Privacy Addendum

Seller and service-provider obligations when processing Platform personal data

1. Scope, Parties and Precedence

1.1Bazaar.in provides the Platform, including marketplace technology, administration, support, verification and related services. Bazaar.in is not treated as the product seller unless expressly identified as seller of record for a transaction.

1.2References to Bazaar.in, the Platform, we, us or our mean Bazaar.in.

1.3This Addendum supplements the Seller Agreement and applies whenever a Seller or approved provider processes Buyer, Seller, employee or Platform personal data. Mandatory data law prevails over conflicting commercial terms.

2. Data Roles and Instructions

2.1Each party acts in the role assigned by applicable law for the particular purpose. A Seller processing Buyer data only to fulfil a Platform order must follow Bazaar.in's documented instructions; a Seller remains independently responsible for tax, warranty and other processing required by law.

2.2No party may process data for an incompatible purpose or combine it with unrelated marketing databases.

3. Data and Processing Schedule

3.1Data subjects include Buyers, Sellers, representatives, delivery recipients and support contacts. Data includes identity, contact, address, order, delivery, payment status, KYC, tax, communication, device, VMS and fraud information.

3.2Permitted operations are collection, access, storage, use, disclosure, correction, return, deletion and other processing strictly needed for authorized services.

4. Confidentiality and Access

4.1Access must be limited to trained personnel with a need to know and binding confidentiality duties. Shared credentials and unauthorized exports are prohibited.

4.2Parties must maintain an access record and promptly revoke access after role change or termination.

5. Security Measures

5.1Required controls include risk-appropriate encryption, authentication, device and endpoint security, secure transmission, backups, logging, vulnerability management, incident response and physical safeguards.

5.2No Seller may request payment passwords, PINs or unnecessary identity documents from a Buyer.

6. Incident and Breach

6.1The processing party must notify Bazaar.in without undue delay and, where practicable, within twenty-four (24) hours after awareness of a suspected breach. Notice must describe data, persons, systems, timing, impact, containment and contact.

6.2The processing party must preserve evidence, mitigate, cooperate and make no public statement naming Bazaar.in without authorization unless law requires it.

7. Subprocessors and Transfers

7.1A party may use only approved subprocessors under written obligations at least equivalent to this Addendum and remains responsible for their performance.

7.2Cross-border processing is allowed only where legally permitted and supported by required safeguards. Location and material subprocessor changes must be disclosed as agreed.

8. Rights, Complaints and Regulatory Assistance

8.1Parties must promptly assist authenticated rights requests, complaints, audits, impact assessments and regulator inquiries. A Seller must not respond on Bazaar.in's behalf without authorization.

8.2Requests and disclosures must be logged and minimized.

9. Retention, Return and Deletion

9.1Data may be retained only for the authorized service and applicable legal period. On termination or instruction, data must be returned or securely deleted unless law requires retention.

9.2Deletion must include copies and exports where feasible; retained legal copies remain restricted and are deleted when the hold ends.

10. Audit, Remediation and Indemnity

10.1Bazaar.in may request reasonable security evidence and conduct proportionate audits with confidentiality and business-continuity safeguards. Material gaps require a time-bound remediation plan.

10.2The breaching party indemnifies affected Bazaar.in entities for third-party loss caused by its unlawful processing, subject to causation, mitigation and fair defence procedures. Non-excludable liability remains unaffected.

11. Termination and Survival

11.1Material or repeated data breach may justify access restriction or termination after proportionate review, with emergency action for serious risk.

11.2Confidentiality, security, deletion, audit, indemnity and legal cooperation survive while data or related liability remains.

Contact Information

This contact block identifies the Bazaar.in support office. It does not replace any separate statutory notice address that the Legal Department determines must be published.

For support, contact support@bazaar.in.