This Data Processing Addendum (“Addendum”) forms part of the Terms of Service and applies where we process personal data relating to your customers contained in data synced from a connected store or platform (“Connected Store Data”) on your behalf. You are the controller and we are the processor of Connected Store Data. By connecting a store or platform you accept this Addendum. We process Connected Store Data only for the duration of the connection and only to provide the sync functionality you configure.
We will: (a) process Connected Store Data only on your documented instructions, including the sync configuration you set, unless required to do otherwise by applicable law; (b) ensure that persons authorised to process it are bound by confidentiality; and (c) implement appropriate technical and organisational measures to protect it. As described in our Privacy Policy, Connected Store Data is transmitted to your self-hosted instance and is not retained on our servers.
You authorise us to engage sub-processors to provide the Service. We will inform you of any intended addition or replacement of a sub-processor and give you the opportunity to object on reasonable data-protection grounds; if you object, your remedy is to disconnect the affected integration.
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations to respond to requests from data subjects and to meet your security, breach-notification, and data-protection-impact-assessment duties. Because Connected Store Data resides on your instance and is not retained on our servers, such assistance is limited to honouring the connected platform’s deletion and redaction requests and to deleting stored connection credentials.
We will notify you without undue delay after becoming aware of a personal data breach affecting Connected Store Data we process for you.
On termination of a connection we delete the stored credentials for it. We hold no copy of Connected Store Data to return or delete.
We will make available information reasonably necessary to demonstrate compliance with this Addendum. Any audit is limited to once in any twelve-month period, on at least 30 days’ written notice, during business hours, subject to confidentiality and at your cost, except where applicable law requires otherwise.
Liability under this Addendum is subject to the limitations and exclusions in the Terms of Service, which also govern this Addendum.