whizzQ Data Processing Addendum
Effective Date: September 15, 2026 Version: 2.0 Last Updated: September 15, 2026 This Data Processing Addendum ("DPA") forms part of the agreement between SCHEDMAD Private Limited, operator of the whizzQ platform ("SCHEDMAD", "whizzQ", "Processor", "we", "us" or "our"), and the business, professional, organisation or other commercial customer using whizzQ ("Merchant", "Data Fiduciary" or "you") to the extent SCHEDMAD processes Personal Data on behalf of the Merchant. This DPA supplements the whizzQ Business & Merchant Terms, the applicable Order Form and other agreements governing the Merchant's use of whizzQ. This DPA applies only to Processing for which the Merchant determines the purpose and means and SCHEDMAD processes Personal Data on the Merchant's documented instructions. It does not apply to Processing for which SCHEDMAD independently determines the purpose and means, including SCHEDMAD's independent marketplace, account administration, security, fraud prevention, payment administration, legal compliance, analytics or consented marketing activities.
1. Definitions
"Applicable Data Protection Law" means the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 as and when applicable to the relevant Processing, and any other binding Indian law concerning the protection or Processing of Personal Data that applies to the parties. "Data Fiduciary", "Data Principal", "Data Processor", "Personal Data" and "Processing" have the meanings given to those terms or their corresponding concepts under Applicable Data Protection Law. "Merchant-Originated Customer Information" means Personal Data initially provided, entered or imported into whizzQ by or on behalf of the Merchant for the Merchant's scheduling, CRM, appointment-management, communication or related business purposes. "Security Incident" means an actual breach of security resulting in unauthorised access to, disclosure, alteration, loss, destruction or other unauthorised Processing of Personal Data within the scope of this DPA. "Sub-processor" means another processor engaged by SCHEDMAD to Process Personal Data on behalf of the Merchant. "Services" means the whizzQ SaaS services described in the Business & Merchant Terms, applicable Order Form or other agreed service documentation.
2. Relationship with the Main Agreement
This DPA is incorporated into and forms part of the Merchant's agreement with SCHEDMAD. If there is a conflict between this DPA and the Business & Merchant Terms regarding Processing that falls within the scope of this DPA, this DPA will prevail for that Processing. If there is a conflict between this DPA and an expressly negotiated enterprise data-processing schedule signed by both parties, the more specific signed schedule will prevail for the Processing it expressly covers. Commercial, payment, marketplace, intellectual-property and other matters not specifically governed by this DPA remain governed by the applicable Merchant agreement.
3. Scope of Processor Processing
SCHEDMAD acts as a Data Processor only where it Processes Personal Data solely on behalf of the Merchant and according to the Merchant's documented instructions. Processor Processing may include, depending on the Merchant's configuration: storing Merchant-Originated Customer Information; maintaining appointment and scheduling records supplied by the Merchant; providing Merchant-requested CRM functionality; enabling staff or authorised-user access; transmitting Merchant-requested service communications; maintaining Merchant-configured customer records; and providing related SaaS support. The detailed Processing description appears in Schedule 1. Nothing in this DPA creates a blanket Processor relationship for all Personal Data appearing on or passing through whizzQ.
4. Processing Outside the Scope of this DPA
SCHEDMAD may independently determine the purpose and means of certain Processing. Such Processing is outside the Processor scope of this DPA and is governed by the whizzQ Privacy Notice, applicable law and other relevant terms. Examples include: operating whizzQ consumer accounts; operating the whizzQ marketplace; Marketplace Consumer discovery and recommendations; Platform security; fraud and abuse prevention; payment, refund and settlement administration; compliance with legal obligations; maintaining audit and transaction records; whizzQ account administration; Platform telemetry; de-identified or aggregated analytics; and whizzQ promotional Processing where the individual has independently provided the required consent. The fact that Personal Data was originally provided by the Merchant does not prevent SCHEDMAD from acting independently for a separate lawful purpose that has been appropriately disclosed and is otherwise permitted by law.
5. Merchant Instructions
SCHEDMAD will Process Personal Data within the scope of this DPA only on the Merchant's documented instructions, except where Processing is required by applicable law. The parties agree that the Merchant's documented instructions include: this DPA; the Business & Merchant Terms; the applicable Order Form; the Merchant's use and configuration of the Services; support requests; API or product instructions initiated by authorised Merchant users; and other written instructions agreed by the parties. SCHEDMAD is not required to follow an instruction that is technically impossible, inconsistent with the Services, unlawful, or would require SCHEDMAD to breach an obligation applicable to it. If SCHEDMAD reasonably believes a Merchant instruction infringes Applicable Data Protection Law, SCHEDMAD may suspend the affected instruction and notify the Merchant, unless prohibited from doing so by law.
6. Merchant Responsibilities as Data Fiduciary
The Merchant remains responsible for determining whether its Processing of Personal Data is lawful. The Merchant represents and warrants that, for Personal Data placed into whizzQ for Processor Processing, it has provided all notices and obtained all consents or other permissions required by Applicable Data Protection Law. The Merchant is responsible for the accuracy, quality, lawfulness and relevance of Personal Data supplied to SCHEDMAD. The Merchant must not instruct SCHEDMAD to Process Personal Data for an unlawful, misleading or incompatible purpose. The Merchant remains responsible for responding to Data Principals and for determining whether a request should be granted, except to the extent SCHEDMAD has an independent legal obligation.
7. Data Minimisation and Purpose Limitation
The Merchant should provide only Personal Data reasonably necessary for the relevant Merchant purpose and supported whizzQ functionality. SCHEDMAD will not knowingly use Personal Data within the scope of this DPA for an unrelated Processor purpose. Where reasonably practicable, SCHEDMAD may implement product controls, field limitations or technical restrictions intended to reduce unnecessary collection.
8. Healthcare and Clinical Data Restriction
The ordinary whizzQ scheduling platform is not presently intended to function as an electronic health record, clinical record repository or medical document-management system. The Merchant must not intentionally upload or require consumers to submit diagnoses, prescriptions, clinical histories, medical reports, laboratory reports or other clinical records through ordinary whizzQ booking fields unless SCHEDMAD expressly introduces functionality designed for that type of data and the parties agree any additional terms required for such Processing. Appointment metadata relating to a healthcare service, such as practitioner, service, date, time, location and booking status, may nevertheless be processed as ordinary appointment information.
9. Confidentiality of Personnel
SCHEDMAD will restrict access to Personal Data within the scope of this DPA to personnel who reasonably require access to provide, secure, maintain or support the Services. SCHEDMAD will take reasonable steps to ensure such personnel are subject to contractual, statutory or professional confidentiality obligations appropriate to their role. Access rights should be reviewed and revoked when no longer reasonably required.
10. Security Measures
SCHEDMAD will implement reasonable technical and organisational safeguards appropriate to the nature of the Personal Data and the risks associated with the Processing. Measures may include, as appropriate: logical access controls; authentication; role-based permissions; secure transmission; encryption where appropriate; logging and monitoring; backup processes; vulnerability management; change management; security testing; administrative access restrictions; incident-response procedures; and confidentiality controls. The security measures described in Schedule 2 are indicative baseline measures and may evolve to address technology, risk, regulatory requirements and service architecture. No security measure can guarantee absolute prevention of every unauthorised event.
11. Merchant Security Responsibilities
The Merchant remains responsible for security within its own environment and for access it grants to the Services. The Merchant must maintain reasonable controls over passwords, OTPs, devices, Authorised Users, API credentials, exported Personal Data and internal access permissions. The Merchant must promptly revoke access when personnel no longer require it and must notify SCHEDMAD without undue delay after becoming aware of a compromise materially affecting whizzQ or Personal Data processed through the Services.
12. Sub-processors
The Merchant gives SCHEDMAD general authorisation to engage Sub-processors reasonably necessary to provide, secure, support or maintain the Services. Sub-processors may include providers of cloud infrastructure, hosting, messaging, customer support, security, monitoring, authentication, analytics used for service operation, and other technical infrastructure. For Processor Processing, SCHEDMAD will seek to impose data-protection obligations on relevant Sub-processors that are appropriate to the services they perform. SCHEDMAD remains responsible for managing its contractual relationship with its Sub-processors to the extent required by Applicable Data Protection Law. Third parties that independently determine the purposes and means of their Processing, such as independent payment providers in relation to their regulated payment activities, are not necessarily Sub-processors merely because they integrate with whizzQ.
13. Current Service Providers and Integrations
Depending on the Merchant's configuration, whizzQ currently uses or may use providers including Razorpay for payment infrastructure, MSG91 for SMS communications, and Meta / WhatsApp Cloud API for supported messaging functionality. Whether a particular provider acts as a Sub-processor, independent Data Fiduciary/controller-equivalent, or other third party depends on the particular Processing activity and that provider's legal role. SCHEDMAD may change service providers where reasonably necessary without requiring an amendment to this DPA, subject to its obligations under Applicable Data Protection Law.
14. Sub-processor Information
Upon reasonable written request, SCHEDMAD may provide the Merchant with available information concerning categories of relevant Sub-processors used for Processor Processing. For enterprise arrangements where an Order Form expressly requires advance notice of material Sub-processor changes, SCHEDMAD will provide such notice in the agreed manner. A Merchant objection to a new Sub-processor must be based on reasonable data-protection grounds. The parties will work in good faith to identify a commercially reasonable solution, which may include disabling an affected optional feature where technically feasible.
15. Data Principal Requests
If SCHEDMAD receives a request from a Data Principal concerning Personal Data for which SCHEDMAD acts solely as the Merchant's Data Processor, SCHEDMAD may direct the Data Principal to the Merchant unless SCHEDMAD is required by law to respond directly. Taking into account the nature of the Processing and functionality available in the Services, SCHEDMAD will provide reasonable assistance to enable the Merchant to address applicable requests for access information, correction, completion, updating, erasure, grievance handling or other rights recognised under Applicable Data Protection Law. The Merchant remains responsible for evaluating the legal validity of the request and communicating the final decision to the Data Principal where it is the responsible Data Fiduciary. Reasonable additional fees may apply to unusually burdensome assistance beyond standard Platform functionality where permitted by the parties' commercial agreement.
16. Correction, Updating and Erasure
The Services may provide functionality allowing the Merchant or authorised users to update, correct or delete certain Merchant-Originated Customer Information. Where a valid erasure instruction is received and the relevant Personal Data is no longer required for another lawful purpose, SCHEDMAD will take reasonable steps to erase or render the relevant Processor copy unavailable in accordance with its technical processes. Deletion from active production systems may not immediately remove information from backups, disaster-recovery copies, security logs or legally required records. Such residual information will remain protected and will be removed, overwritten or otherwise handled according to applicable retention processes. This clause does not require SCHEDMAD to erase data it independently retains for a separate lawful purpose outside the scope of this DPA.
17. Data Portability and Export Assistance
To the extent supported by the Services and required by the applicable agreement, SCHEDMAD may provide export functionality or reasonable assistance for Personal Data within the Merchant's Processor scope. Marketplace Consumer data and other information outside the Processor scope remains subject to the Business & Merchant Terms and whizzQ Privacy Notice. The Merchant must protect exported Personal Data after receipt. SCHEDMAD is not responsible for the Merchant's subsequent handling of an export.
18. Security Incidents
SCHEDMAD will maintain procedures for identifying, assessing and responding to Security Incidents affecting Personal Data within the scope of this DPA. After becoming aware of a confirmed Security Incident materially affecting Processor Personal Data, SCHEDMAD will notify the Merchant without undue delay to the extent required by Applicable Data Protection Law or reasonably necessary for the Merchant to meet its own legal obligations. The notification may be provided in phases as information becomes available and may include, where known: the nature of the incident; categories of affected information; approximate scope; likely consequences; containment or remediation measures; and a contact point for follow-up. Notification of a Security Incident does not constitute an admission of fault or liability by SCHEDMAD.
19. Regulatory and Data Principal Breach Notifications
Where the Merchant is the responsible Data Fiduciary for the affected Processing, the Merchant remains responsible for determining and making notifications to Data Principals, the Data Protection Board of India or other authorities, except to the extent law expressly places a direct notification obligation on SCHEDMAD. SCHEDMAD will provide reasonable information in its possession to assist the Merchant with legally required notifications. SCHEDMAD may independently notify authorities or individuals where it has a separate legal obligation to do so.
20. Assistance with Compliance
Taking into account the nature of the Services and information reasonably available to SCHEDMAD, SCHEDMAD will provide reasonable assistance with the Merchant's compliance obligations relating to Processor Processing where required by Applicable Data Protection Law. Such assistance may include information concerning security controls, Processing categories, Sub-processors, incident response, deletion functionality and Data Principal request handling. SCHEDMAD is not the Merchant's legal adviser and does not undertake responsibility for the Merchant's independent compliance programme.
21. Audit and Compliance Information
Upon reasonable written request, SCHEDMAD will make available information reasonably necessary to demonstrate compliance with its Processor obligations under this DPA. Where the Merchant reasonably requires additional verification because of a material compliance concern, the parties may agree to an audit or independent assessment subject to appropriate confidentiality, security, scope and cost controls. Audits must not unreasonably disrupt SCHEDMAD's operations, expose information belonging to other customers, compromise Platform security or require disclosure of source code or trade secrets. Unless required by law or arising from a confirmed material breach by SCHEDMAD, the Merchant will bear its own audit costs and any reasonable extraordinary costs incurred by SCHEDMAD in supporting a bespoke audit.
22. Government and Legal Requests
If SCHEDMAD receives a legally binding request for Personal Data within the scope of this DPA, SCHEDMAD may disclose the information to the extent required by law. Where legally permitted and reasonably practicable, SCHEDMAD may notify the Merchant of the request before disclosure. SCHEDMAD is not required to challenge a lawful government, court or regulatory request on the Merchant's behalf.
23. Cross-Border Processing
SCHEDMAD may use technology or service providers with systems, affiliates or personnel outside India where such Processing is permitted by Applicable Data Protection Law. SCHEDMAD will not knowingly transfer Personal Data in a manner prohibited by a binding restriction issued under Indian law. Where additional contractual or organisational measures become legally required for particular cross-border Processing, the parties will cooperate in good faith to implement measures reasonably necessary for continued lawful provision of the Services.
24. Data Location
Unless an Order Form expressly commits to a specific hosting region, this DPA does not create a contractual data-localisation guarantee. SCHEDMAD may determine hosting and processing locations consistent with applicable law, security requirements, service availability and infrastructure architecture. Enterprise customers requiring a specific residency commitment must have that requirement expressly stated in an applicable Order Form or data-residency schedule.
25. Retention During the Services
SCHEDMAD may retain Personal Data within the scope of this DPA for the period reasonably required to provide the Services and fulfil the Merchant's documented instructions. Retention may also be affected by backup cycles, dispute holds, security requirements and legal obligations. The Merchant is responsible for configuring or instructing deletion where the Platform provides applicable controls.
26. Return or Deletion on Termination
Following termination of the relevant Services, and subject to the Merchant's request and the applicable agreement, SCHEDMAD will return, make available for export, delete or render inaccessible Personal Data within the Processor scope within a reasonable period, unless retention is required or permitted by applicable law. SCHEDMAD may retain Personal Data in backups for a limited period until overwritten or deleted in accordance with normal backup processes, provided the retained data remains subject to appropriate protection. This obligation does not apply to Personal Data that SCHEDMAD independently retains outside the scope of this DPA for lawful marketplace, payment, security, legal, audit or other independent purposes. Any post-termination data export may be subject to entitlement verification, technical feasibility and reasonable service charges where permitted under the applicable agreement.
27. De-identification and Aggregated Information
Nothing in this DPA prevents SCHEDMAD from creating and using aggregated, statistical or appropriately de-identified information that no longer constitutes Personal Data under applicable law. Such information may be used for Platform analytics, service improvement, benchmarking, fraud prevention, capacity analysis, product development and marketplace intelligence. SCHEDMAD will not rely on this clause to circumvent obligations applicable to information that remains identifiable Personal Data.
28. Artificial Intelligence and Automated Features
Where the Merchant uses AI-enabled or automated whizzQ functionality, Processor Personal Data will remain subject to this DPA to the extent SCHEDMAD processes it solely on the Merchant's instructions. SCHEDMAD does not acquire an unrestricted right to train general-purpose AI models using identifiable Merchant-Originated Customer Information merely because that information is processed through whizzQ. Where SCHEDMAD wishes to use identifiable Personal Data for a materially different AI-training purpose, it must have an independent lawful basis and provide any notice or obtain any consent required by applicable law. SCHEDMAD may use aggregated, statistical or appropriately de-identified information for improving algorithms, models, analytics and Platform functionality.
29. Communications Processing
Where the Merchant instructs whizzQ to send appointment reminders, booking notifications or other communications to Merchant-Originated Customers, SCHEDMAD may process the relevant contact information as Processor for the Merchant-requested communication. The Merchant remains responsible for ensuring that the communication is lawful and that any required consent, registration, template approval or preference is in place. Where whizzQ sends its own promotional communications pursuant to the Consumer's separate whizzQ consent, that Processing is outside the Processor scope of this DPA.
30. Marketplace Consumer Data
Marketplace Consumer Personal Data is not automatically Processor data merely because the Consumer books the Merchant. SCHEDMAD may independently process Marketplace Consumer information for marketplace account administration, booking facilitation, fraud prevention, security, payment administration, legal compliance, recommendations and other purposes described in the Privacy Notice. The Merchant may also independently process the relevant booking information for service fulfilment and its own lawful transactional purposes. This DPA does not grant the Merchant ownership of, or unrestricted rights to export or use, the wider whizzQ Marketplace Consumer database.
31. Payment Information
Payment providers such as Razorpay may independently determine purposes and means for regulated payment, KYC, fraud, banking or settlement activities. Accordingly, payment providers are not automatically treated as SCHEDMAD Sub-processors for all payment activity. SCHEDMAD's own Processing of transaction metadata for Merchant instructions may fall within or outside this DPA depending on the purpose, while SCHEDMAD's independent payment reconciliation, commission, fraud, legal and settlement purposes remain outside the Processor scope.
32. Liability
Liability arising under this DPA is subject to the exclusions, limitations and caps set out in the Business & Merchant Terms or applicable Order Form, except to the extent Applicable Data Protection Law prohibits such limitation. Nothing in this DPA limits payment obligations, liability for fraud or wilful misconduct, or another category of liability that cannot lawfully be limited. The parties acknowledge that regulatory liability may be imposed directly by law and cannot be contractually reassigned against a regulator merely by agreement between the parties.
33. Indemnity
Any indemnity relating to unlawful Merchant instructions, Merchant failure to obtain required consent, misuse of exported Personal Data or other Merchant data-protection breach will be governed by the Business & Merchant Terms. SCHEDMAD does not assume responsibility for the Merchant's independent Processing merely because the Merchant uses whizzQ. Nothing in this section prejudices either party's rights where the other party breaches obligations expressly assumed under this DPA.
34. Term and Termination
This DPA begins when SCHEDMAD first Processes Personal Data on behalf of the Merchant and continues for so long as such Processor Processing continues. Termination of the main Merchant agreement terminates this DPA except for provisions that by their nature survive, including confidentiality, retention, deletion, liability and audit obligations relating to Processing performed before termination.
35. Changes Required by Law
SCHEDMAD may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Law, regulatory guidance, service architecture or Processor obligations. Material amendments that substantially change the parties' data-protection responsibilities will be communicated through reasonable means and, where required by law or an applicable negotiated agreement, will require appropriate acceptance. An update will not retroactively authorise Processing that was unlawful when performed.
36. Governing Law and Jurisdiction
This DPA is governed by the laws of India. Subject to mandatory statutory rights and forums and any valid arbitration provision in an applicable enterprise agreement, disputes arising from this DPA are subject to the jurisdiction of competent courts at Vadodara, Gujarat, India.
37. Contact
SCHEDMAD Private Limited Operator of whizzQ Registered / Business Address: S-7, Second Floor, National Plaza, R.C. Dutt Road, Alkapuri, Vadodara, Gujarat 390007 Privacy / Legal Contact: legal@whizzq.app General Support: help@whizzq.app Contractual Jurisdiction: Vadodara, Gujarat, India, subject to applicable mandatory law.
Schedule 1 - Details of Processor Processing
Subject Matter: Processing of Personal Data supplied or controlled by the Merchant to enable whizzQ SaaS scheduling, appointment-management, Merchant CRM, communication and related business functionality. Duration: For the duration of the applicable Merchant Services plus any reasonable technical deletion, backup or transition period, subject to legal retention requirements. Nature of Processing: Collection on Merchant instruction, receipt, recording, organisation, structuring, storage, retrieval, consultation, transmission, updating, deletion and other operations necessary to provide the relevant Services. Purposes: Merchant scheduling; appointment administration; customer-management functionality; Merchant-requested service communications; Merchant staff and authorised-user administration; support and related SaaS operations. Categories of Data Principals: Merchant customers; prospective customers entered by the Merchant; Merchant employees, staff, contractors and authorised users; and other individuals whose Personal Data the Merchant lawfully places into the Services. Categories of Personal Data: Name; mobile number; email address; customer identifiers; appointment and service information; scheduling information; Merchant-provided notes; communication records; staff and authorised-user information; and other Personal Data entered by the Merchant into supported fields. Excluded / Restricted Data: Clinical records, diagnoses, prescriptions, medical reports, financial account credentials, government identification numbers or other data not reasonably necessary for ordinary whizzQ functionality should not be uploaded unless a specific supported feature and appropriate agreement expressly allows it. Special Instructions: The Merchant's configuration and authorised use of the Services constitute documented instructions, subject to this DPA and applicable law.
Schedule 2 - Indicative Security Measures
Access Control: Role-based or need-based access to production and administrative systems where appropriate. Authentication: Authentication controls for user and administrative access, including OTP or equivalent controls where supported. Transmission Security: Use of secure network protocols for transmission of Personal Data where appropriate. Encryption: Encryption or equivalent safeguards for relevant data at rest and/or in transit where technically appropriate and supported by the applicable architecture. Logging and Monitoring: Operational, access, security and diagnostic logging appropriate to the relevant system. Backup and Recovery: Backup and recovery procedures appropriate to service continuity requirements. Vulnerability Management: Reasonable processes for identifying, prioritising and addressing material vulnerabilities. Change Management: Reasonable controls over production changes and software deployment. Incident Response: Procedures for triage, containment, remediation, investigation and communication of material security incidents. Personnel Controls: Confidentiality obligations and access restriction for personnel with relevant system access. Sub-processor Management: Reasonable contractual and security due diligence appropriate to relevant third-party service providers. Data Minimisation and Retention: Controls designed to avoid unnecessary retention and to support deletion or de-identification where applicable. Security measures may evolve over time provided the overall level of protection is not materially reduced without legitimate technical, legal or security reason.
Schedule 3 - Processing Role Matrix
Merchant-Originated customer records used solely for Merchant scheduling/CRM: Merchant = Data Fiduciary; SCHEDMAD = Data Processor. Merchant-requested appointment reminders to Merchant-Originated Customers: Merchant = Data Fiduciary; SCHEDMAD = Data Processor for the communication-processing activity. Marketplace Consumer account registration: SCHEDMAD = independent Data Fiduciary; outside this DPA. Marketplace discovery and cross-category recommendations based on whizzQ consent: SCHEDMAD = independent Data Fiduciary; outside this DPA. Merchant service fulfilment records: Merchant and SCHEDMAD may each process for their own purposes; role depends on the specific Processing. Platform security, fraud detection and abuse prevention: SCHEDMAD = independent Data Fiduciary; outside this DPA. Razorpay Route payment, refund and settlement administration: roles vary by Processing purpose and payment-provider function; not automatically Processor Processing. whizzQ Platform analytics using appropriately de-identified or aggregated information: outside Personal Data Processor scope where the information no longer constitutes Personal Data. Merchant staff account information used to administer access to whizzQ: role depends on the purpose; SCHEDMAD may independently process account/security information while processing some Merchant staff data on Merchant instruction.
