Last updated: September 25, 2026
What this addendum covers
This addendum forms part of the terms of service between Arihance System Private Limited (“we”) and the customer business (“you”). It applies to the personal data you, or people you authorize, enter into grewray about other people: your customers, prospects, staff and suppliers.
Our roles
For that data, you are the data fiduciary (the controller, under the GDPR): you decide what is collected and why. We are your data processor: we process it only to provide grewray to you. You are responsible for having a lawful basis for the data, including consent where the law requires it and a parent's or guardian's verifiable consent for a child.
Your instructions
We process the data only on your documented instructions, which are these terms, this addendum and the way you use and configure grewray. We do not use it for our own purposes, never sell it, and never combine it with another business's data. If we believe an instruction breaks the law, we will tell you.
Confidentiality
Everyone at Vanvora who can reach customer data is bound to keep it confidential, and reaches it only when their work requires it, such as a migration you asked for or support you requested. Support access to a business is time-limited, approved by a named person, and recorded.
Security measures
- Four independent isolation layers, from the application down to the database, so one business can never reach another's data.
- Encryption in transit and at rest.
- Two-factor sign-in required for owners and admins, and access decided by role.
- Sessions that end immediately when a person is removed or signs out everywhere.
- An append-only record of sign-ins and sensitive changes.
- Point-in-time backups that allow a restore to within 5 minutes, kept 30 days and restore-tested every quarter.
Sub-processors
You authorize the sub-processors listed on our sub-processors page. Each is bound by written terms that protect the data at least as well as this addendum. We tell account owners at least 30 days before a new sub-processor starts handling customer data. If you object on reasonable grounds and we cannot address the objection, you may cancel with effect from the date the change applies.
Helping you meet your obligations
We help you answer requests from the people whose data you hold: access, correction, erasure and portability. Most can be done directly in grewray, including a full export. If a request reaches us directly, we pass it to you and do not answer it ourselves unless you ask us to.
Personal data breaches
If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and in any case within 24 hours, with what we know, what we are doing, and what you may need to do, so you can meet your own duties to inform the people affected and the Data Protection Board of India, or any other authority. We update you as we learn more.
Deletion and return
You can export all of the data at any time. When your subscription ends, the business stays readable and exportable for 30 days, then we delete the data, and it leaves our backups within a further 30 days, unless the law requires us to keep something longer.
Information and audits
On request, we give you the information you reasonably need to show that this addendum is being met, including a description of our security measures. For anything more, such as a questionnaire or an audit, we will agree the scope, timing and cost with you in writing, not more than once a year unless a breach or a regulator requires it.
International transfers
Data may be processed outside India by our sub-processors, never in a country the Government of India has restricted. For customers in the European Union or the United Kingdom, transfers rely on standard contractual clauses or another recognized safeguard.
Details of the processing
- Subject matter
- Providing grewray to the customer.
- Duration
- The subscription, plus the 30-day export window and up to 30 days in backups.
- Nature and purpose
- Hosting, storing, organizing, displaying, sending and backing up data so the customer can run its business.
- Types of personal data
- Names, contact details, addresses, job and booking details, invoices and payments, notes, files and messages the customer enters.
- Data principals
- The customer's own customers, prospects, staff, suppliers and the people who use its account.
Contact
Questions about this addendum, or a signed copy for your records, can be requested at hello@grewray.com.