These Data Processing Terms describe how Mystical Glow Hub (โMGH Booksโ) processes the business data you enter (about your customers, suppliers, employees and transactions) on your behalf. For this data you are the Data Fiduciary and we act as a Data Processor under the Digital Personal Data Protection Act, 2023.
1. Roles
You determine the purposes and means of processing the business data you enter and are responsible for having a lawful basis to provide it. We process that data only to provide the Services and on your documented instructions (which include using the features of the Services).
2. Scope & purpose of processing
- Subject matter: provision of the MGH Books Services.
- Nature & purpose: hosting, storing, processing, computing, presenting, backing up and exporting your business records so you can run your business.
- Types of data: party details (e.g. names, GSTIN, contact), items, invoices, payments, payroll and accounting records you choose to enter.
- Data principals: your customers, suppliers and employees as applicable.
3. Our obligations
- Process the data only to provide the Services and per your instructions, unless required by law.
- Apply appropriate technical and organisational security measures (encryption in transit, access controls, audit logging, backups).
- Ensure persons authorised to process the data are bound by confidentiality.
- Assist you, taking into account the nature of processing, to respond to data principal requests and to meet your security and breach-notification obligations.
- Notify you without undue delay on becoming aware of a personal data breach affecting your data.
4. Sub-processors
We may engage sub-processors (e.g. hosting, infrastructure and payment providers) to help deliver the Services. We impose data-protection obligations on them consistent with these Terms and remain responsible for their performance of the data-processing tasks we delegate.
5. Data principal requests
Where a data principal contacts us about data we process on your behalf, we will direct them to you and assist you, as reasonably required, to respond โ including helping you access, correct, export or delete the relevant data via the Services.
6. Security & breach response
We maintain security measures described in our Security page and Privacy Policy. No method is fully secure; our liability in respect of data, including any loss or breach, is subject to the limitations in our Terms of Service. You remain responsible for your own access controls and for maintaining independent backups of critical data.
7. Return & deletion
On termination, you may export your data before access ends. We will delete or anonymise business data after the applicable retention period, except where retention is required by law.
8. Contact
For data-processing queries, contact our Grievance Officer at supportbooks@mghaiapps.com.