Version 1.1 — Last updated: 25 July 2026
Between Margifi (Data Processor) and you, the Client (Data Fiduciary), under the DPDP Act 2023.
This agreement sets out how Margifi handles your end-customers' personal data when providing the Margifi analytics service. It defines Margifi's obligations as a Data Processor, the data categories we touch, the sub-processors we use, and your rights as the Data Fiduciary. This DPA forms part of, and is read together with, the Margifi Terms of Service — in any conflict on data-processing matters, this DPA prevails.
This Data Processing Agreement ("DPA") is entered into between:
Data Controller / Data Fiduciary: The Client entity subscribing to the Margifi Service, as identified in the Client's Margifi account registration ("Controller"); and
Data Processor: Margifi Limited, 230, Ayodhyapuram Residency, Nr Valak Patiya, Valak, Surat City, PO: Sarthana, Dist: Surat, Gujarat 395006, India ("Processor" or "Margifi").
This DPA forms part of, and is incorporated into, the Terms of Service between the Controller and Margifi ("Main Agreement"). In the event of any conflict between this DPA and the Main Agreement on matters of data processing and protection, this DPA shall prevail.
The following terms have the meanings given below throughout this DPA. All other capitalised terms not defined here have the meanings given in the Main Agreement.
Applicable Data Protection Law — The Digital Personal Data Protection Act, 2023, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and any other Indian law or regulation relating to the processing of personal data that applies to the activities of the parties under this DPA.
Data Breach — Any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA.
Data Fiduciary — As defined under the DPDP Act, 2023 — an entity that determines the purpose and means of processing Personal Data. In this DPA, the Controller is the Data Fiduciary in respect of Personal Data of the Data Principals.
Data Principal — As defined under the DPDP Act, 2023 — the natural person to whom the Personal Data relates. In this DPA, Data Principals include the end-customers of the Controller whose data may flow through the Margifi Platform.
Data Processor — An entity that processes Personal Data on behalf of and under the instructions of a Data Fiduciary. Margifi acts as a Data Processor in relation to the Controller's Personal Data processed through the Platform.
Personal Data — As defined under the DPDP Act, 2023 — any data about an individual who is identifiable by or in relation to such data.
Processing — Any operation or set of operations performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.
Sub-Processor — Any third party engaged by Margifi to process Personal Data in connection with the provision of the Service.
This DPA governs Margifi's processing of Personal Data on behalf of the Controller in connection with the provision of the Margifi analytics Service as described in the Main Agreement.
Margifi will process Personal Data by performing the following operations:
Margifi will process Personal Data for the duration of the Subscription Term under the Main Agreement, and for the thirty (30) day Data Retention Window following termination, unless earlier deletion is requested by the Controller.
The following categories of Personal Data belonging to the Controller's end-customers may be processed by Margifi in the course of providing the Service:
Order IDs and transaction reference numbers used to match fulfilled orders to advertising conversions. These may, in some cases, be linked to customer identifiers assigned by the Controller's Shopify store.
Data points such as device identifiers, click IDs, or session tokens received from Meta Ads or Google Ads, used to attribute orders to specific advertising campaigns. These are processed ephemerally for attribution matching and are not stored in identifiable form.
Shipment identifiers and delivery outcome data (delivered, RTO, NDR) received from Delhivery or Shiprocket. This data may indirectly contain customer location information at a city or pin code level.
Transaction amounts and payment status data received from Razorpay or Cashfree, used for revenue reconciliation. Raw payment instrument details (card numbers, UPI IDs) are not received by Margifi — only settlement-level aggregates.
Names, email addresses, and company information of the Controller's authorised Users who access the Margifi Dashboard on behalf of the Controller.
Where the Controller subscribes to Margifi, Margifi also processes a derived network signal: a one-way hashed and encrypted representation of the end-customer's phone number ("COD Intelligence contact_network record"). This record is used solely to compute a COD delivery reliability signal across the Margifi network of brands.
Raw phone numbers are never stored by Margifi in identifiable form. The contact_network record includes: a hashed phone identifier, a delivery rate signal, a risk flag, and a brands_ordered count. No personally identifiable information is reconstructable from this hash.
For the full privacy-first architecture of COD Intelligence, see COD Intelligence →
Margifi shall process Personal Data only for the following purposes:
Margifi shall not process Personal Data for any purpose other than those listed above without the prior documented instruction of the Controller, except where required by applicable Indian law — in which case Margifi will inform the Controller of such legal requirement before processing, unless legally prohibited from doing so.
Margifi is bound by the following obligations in relation to the Personal Data it processes on the Controller's behalf:
Margifi will process Personal Data only on documented instructions from the Controller (including as set out in the Main Agreement and this DPA) and will not process Personal Data in a manner inconsistent with such instructions.
Margifi will ensure that all personnel authorised to process Personal Data under this DPA are bound by appropriate confidentiality obligations and receive adequate data protection training.
Margifi implements and maintains the following measures to protect Personal Data:
Margifi will provide reasonable assistance to the Controller in:
Upon termination of the Main Agreement, or upon the Controller's request, Margifi will delete or return all Personal Data in its possession within thirty (30) days, and will confirm in writing that deletion has been completed.
Margifi may retain anonymised or aggregated data that is no longer attributable to any individual or to the Controller.
In the event of a Data Breach, Margifi will notify the Controller within 72 hours of becoming aware and will provide:
Margifi will cooperate with the Controller in any investigation and in notifications to the Data Protection Board of India as required under the DPDP Act.
The Controller grants Margifi general authorisation to engage Sub-Processors, subject to the conditions in this clause.
As at the Effective Date of this DPA, Margifi uses the following Sub-Processors in connection with the Service:
Margifi will notify the Controller in writing at least fourteen (14) days before engaging any new Sub-Processor or replacing an existing Sub-Processor. The Controller has the right to object within ten (10) days of such notification. If the Controller objects and Margifi cannot reasonably accommodate the objection, the Controller may terminate the Main Agreement without penalty by providing thirty (30) days' notice.
Margifi will enter into written agreements with each Sub-Processor imposing data protection obligations no less protective than those set out in this DPA.
Margifi remains responsible to the Controller for the performance of all Sub-Processors' obligations under this DPA.
As Data Fiduciary, the Controller represents and warrants that:
The Controller acknowledges that certain Sub-Processors used by Margifi — including Supabase, Vercel, DigitalOcean, PostHog, OpenRouter, Resend, Meta, and Google — operate infrastructure outside India. This means Personal Data processed under this DPA may be transferred to and processed in countries other than India.
Margifi will ensure that any international transfer of Personal Data is made subject to appropriate contractual, technical, or other safeguards, consistent with the requirements of Applicable Data Protection Law once the cross-border data transfer provisions of the DPDP Act are notified by the Government of India.
Margifi transfers personal data only to countries that are not restricted by the Central Government under Section 16 of the DPDP Act, 2023, under contractual data-protection safeguards.
The Controller may, upon providing Margifi with at least thirty (30) days' prior written notice and at the Controller's own cost, conduct an audit of Margifi's data processing activities and security measures under this DPA. Such audit shall be conducted no more than once per calendar year, during normal business hours, and in a manner that minimises disruption to Margifi's operations.
In lieu of a direct audit, Margifi may satisfy the Controller's audit request by providing a current third-party security certification or independent audit report covering the relevant systems, where such report adequately addresses the Controller's concerns.
Any information obtained by the Controller in the course of an audit shall be treated as Confidential Information of Margifi.
To the extent that a Data Breach is caused by Margifi's failure to comply with its obligations under this DPA or Applicable Data Protection Law, Margifi shall bear liability for penalties, fines, and damages attributable to that failure, subject to the limitations of liability in the Main Agreement.
To the extent that a Data Breach is caused by the Controller's instructions, actions, or failure to maintain secure API credentials, the Controller shall bear responsibility for resulting penalties, fines, and damages.
This DPA is effective from the Effective Date specified above and continues until the termination or expiry of the Main Agreement.
Upon termination of the Main Agreement for any reason, this DPA terminates simultaneously, subject to Margifi's obligation to delete or return Personal Data as set out in Clause 6 (Deletion & Return).
Clauses 1, 5.5, 5.7, 8, 10, and 12 shall survive termination of this DPA.
This DPA shall be governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and any rules and regulations made thereunder.
Any disputes arising under this DPA that are not resolved in accordance with the dispute resolution mechanism in the Main Agreement shall be subject to the exclusive jurisdiction of the courts at Surat, Gujarat, India.
Contact us at admin@margifi.com
For general privacy questions, see our Privacy Policy. For information on how COD Intelligence handles cross-brand COD data, see COD Intelligence.