Data Processing Addendum

Last updated: July 23, 2026  |  celerp.com

1. Scope and roles

This Data Processing Addendum (“Addendum”) forms part of the Terms of Service and applies where we process personal data relating to your customers contained in data synced from a connected store or platform (“Connected Store Data”) on your behalf. You are the controller and we are the processor of Connected Store Data. By connecting a store or platform you accept this Addendum. We process Connected Store Data only for the duration of the connection and only to provide the sync functionality you configure.

2. Our obligations

We will: (a) process Connected Store Data only on your documented instructions, including the sync configuration you set, unless required to do otherwise by applicable law; (b) ensure that persons authorised to process it are bound by confidentiality; and (c) implement appropriate technical and organisational measures to protect it. As described in our Privacy Policy, Connected Store Data is transmitted to your self-hosted instance and is not retained on our servers.

3. Sub-processors

You authorise us to engage sub-processors to provide the Service. We will inform you of any intended addition or replacement of a sub-processor and give you the opportunity to object on reasonable data-protection grounds; if you object, your remedy is to disconnect the affected integration.

4. Assistance and data subject requests

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations to respond to requests from data subjects and to meet your security, breach-notification, and data-protection-impact-assessment duties. Because Connected Store Data resides on your instance and is not retained on our servers, such assistance is limited to honouring the connected platform’s deletion and redaction requests and to deleting stored connection credentials.

5. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Connected Store Data we process for you.

6. Deletion

On termination of a connection we delete the stored credentials for it. We hold no copy of Connected Store Data to return or delete.

7. Audit

We will make available information reasonably necessary to demonstrate compliance with this Addendum. Any audit is limited to once in any twelve-month period, on at least 30 days’ written notice, during business hours, subject to confidentiality and at your cost, except where applicable law requires otherwise.

8. Liability and governing law

Liability under this Addendum is subject to the limitations and exclusions in the Terms of Service, which also govern this Addendum.