Skip to content
KanchanFlow
Legal

Data processing addendum

Last updated 2026-09-01. Processor: Soor LLC, 16192 Coastal Hwy, Lewes, DE 19958, USA.

Diagram titled "Data processing", showing the seven RFQ-to-order stages from enquiry intake through to accepted order.

In short

This addendum governs how Soor LLC processes personal data for customers of KanchanFlow, its RFQ-to-Order CRM. It sets our role as processor, names every sub-processor, applies standard contractual clauses to restricted transfers, and commits us to notifying a personal data breach within 72 hours.

This is our published policy. It is not legal advice, and it does not replace a signed agreement — for a negotiated MSA or DPA, contact [email protected].

In plain English

The customer records in your workspace belong to you. You decide what goes in and why; we only process it to run the service and to follow your instructions. We name everyone else who touches it, we tell you before adding a new one, we keep it in the USA unless your contract says otherwise, we tell you within 72 hours if something goes wrong, and we give it all back and delete it when you leave.

1. Roles

For the business records you load into KanchanFlow — your accounts, contacts, RFQs, drawings, quotes, orders and the personal data of your customers' staff — you are the controller and Soor LLC is the processor. We process that data only on your documented instructions, which are the subscription itself, this addendum, and any configuration you set in the product. If we ever believe an instruction breaks applicable data protection law, we will tell you rather than quietly comply.

For your own account data — the names and work emails of your users, billing details and support correspondence — we are the controller, and the privacy policy applies.

2. Scope of processing

Subject matter: provision of the KanchanFlow RFQ-to-Order CRM. Duration: the term of the subscription, plus the 30-day export window after it ends. Nature and purpose: storage, structuring, retrieval, transmission and machine-assisted extraction of RFQ, quote and order records. Categories of data subject: your employees, and the employees of your customers, prospects and dealers. Categories of personal data: business contact details, job role, correspondence content, and any personal data you choose to place in free-text or attached files. We do not require, and ask you not to load, special category data.

3. Confidentiality and staff

Our personnel are bound by confidentiality obligations that survive their engagement. Production access is scoped to what a role needs, is time-bound, is logged, and does not include standing access to customer databases. Support staff access a workspace only to resolve a request, and that access is recorded.

4. Sub-processors

You give general authorisation for the sub-processors below. We impose data protection obligations on each of them that are no less protective than this addendum, and we remain liable to you for their performance. We give at least 30 days' notice by email before adding or replacing one; if you reasonably object on data protection grounds, you may terminate the affected service without penalty for the unused remainder of the term.

The current list is also published in the Trust Center and kept in step with it.
Sub-processorPurposeRegion
Amazon Web ServicesHosting, database, storage and backupsUSA
Meta PlatformsWhatsApp Business Platform message deliveryUSA / global
StripeUSD subscription billingUSA
RazorpayINR subscription billingIndia
Microsoft Azure Document IntelligenceOCR of RFQ attachments and purchase ordersUSA
Transactional email providerProduct and notification email deliveryUSA

The same list, with fuller descriptions, is on the Trust Center. Razorpay processes billing data only and never touches RFQ, quote or customer records.

5. International transfers

Customer data is stored in the USA by default at every tier, on AWS US-East and US-West, with no offshore replication. EU or India residency is available on Enterprise by contract. Where processing involves a restricted transfer of personal data out of the EEA or the UK, the parties incorporate the European Commission's standard contractual clauses (Module Two, controller to processor) and, for UK transfers, the UK International Data Transfer Addendum, together with a transfer risk assessment available on request. We will co-operate with any supplementary measures reasonably required.

6. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or better) and at rest (AES-256), role-based access control, audit logging, encrypted daily backups with point-in-time recovery, a 4-hour RTO and 1-hour RPO target, and an independently audited SOC 2 Type II control environment. The full description is in the Trust Center and forms part of this addendum by reference.

7. Breach notification

We will notify you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate number of records and data subjects affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. We will provide updates as the investigation progresses, and we will not delay an initial notice merely because the picture is incomplete.

8. Assistance, audit and data subject requests

We will assist you, taking into account the nature of processing, with data subject requests, data protection impact assessments and consultations with a supervisory authority. If a data subject contacts us directly about data in your workspace, we will route them to you rather than answer for you. On request, and no more than once a year unless a regulator requires otherwise, we will provide our SOC 2 Type II report and respond to a reasonable security questionnaire; on-site audit rights are available under a negotiated Enterprise agreement.

9. Return and deletion

You can export your records in CSV and JSON at any time during the subscription. After termination we retain your data for 30 days so an export can be completed, then delete it. Backups containing it age out within a further 30 days on their normal cycle. We will confirm deletion in writing on request.

10. Order of precedence and governing law

This addendum forms part of the terms of service and prevails over them to the extent of any conflict about the processing of personal data. A negotiated DPA signed by both parties prevails over this published version. This addendum is governed by the laws of the State of Delaware, USA. Contracting entity: Soor LLC, 16192 Coastal Hwy, Lewes, DE 19958, USA. Privacy contact: [email protected]; security contact: [email protected].

Need a negotiated DPA?

Enterprise customers can sign a custom data processing agreement. Ask sales and we will tell you upfront what we can and cannot move on.

  • Delaware LLC
  • SOC 2 Type II
  • USA Data Centers (AWS)