Legal & data

Data Processing Addendum

The responsibilities when CustomerHub processes shopper information on a merchant’s behalf.

Last updated

All policies

1. Parties and scope

This addendum is between the merchant identified in its Shopify subscription or signed agreement (“Merchant”) and CustomerHub Pty Ltd (“CustomerHub”). It applies when CustomerHub processes personal data for the Merchant in providing C:Hub and the relevant data-protection law requires a processing agreement.

The Merchant is the controller, or a processor authorized by its controller; CustomerHub acts as processor or subprocessor as appropriate. Each party remains responsible for its own independent processing. This addendum applies in accordance with the parties? agreement, processing schedule and applicable transfer arrangements.

2. Instructions and confidentiality

CustomerHub will process covered personal data only on documented Merchant instructions, including the agreed service configuration and lawful written requests, unless law requires otherwise. Where legally permitted, CustomerHub will inform the Merchant of a legal requirement to process outside those instructions and will flag an instruction it reasonably considers unlawful.

CustomerHub will restrict authorized processing to persons bound by confidentiality obligations appropriate to their access. Covered shopper data will not be used for unrelated advertising or sold outside the agreed service purposes.

3. Safeguards and assistance

CustomerHub will apply technical and organisational measures appropriate to the processing risk, taking account of the data, service and applicable law. The agreed measures are recorded in the applicable processing schedule; the website security overview alone is not a complete contractual security annex.

Taking account of the service and information available, CustomerHub will assist the Merchant with individual-rights requests, data protection impact assessments, security obligations and required consultation with regulators. The Merchant is responsible for its collection notices, lawful instructions and responses as controller, except where CustomerHub has a direct legal duty.

4. Subprocessors

The Merchant’s written authorization must identify or refer to an agreed register of subprocessors. CustomerHub will impose appropriate written data-protection obligations on an authorized subprocessor and remain responsible for its performance to the extent required by applicable law.

Under a general written authorization, CustomerHub will notify the Merchant of intended additions or replacements and allow a reasonable opportunity to object on data-protection grounds before the change. The parties will agree a practical resolution, including discontinuing affected processing where necessary. Our service-provider information describes the services used. The Merchant?s agreement identifies the applicable authorized subprocessors.

5. Personal data incidents

CustomerHub will notify the Merchant without undue delay after becoming aware of a personal data breach affecting covered data. Available information should describe the nature of the incident, affected data, likely consequences, contact point and mitigation. Further details may follow as the investigation develops.

CustomerHub will cooperate with the Merchant’s legally required assessment and notifications. Notification does not by itself constitute an admission of liability. Nothing here delays a party’s own mandatory reporting obligations.

6. Return, deletion, information and transfers

At the end of covered services, CustomerHub will, at the Merchant’s choice, return or delete covered personal data and delete remaining copies unless applicable law requires retention. The agreed schedule must address practical export, operational records and backup deletion. Retained data must remain protected and used only for the lawful retention purpose.

CustomerHub will provide information reasonably needed to demonstrate these obligations and allow and contribute to appropriate audits or inspections by the Merchant or its authorized auditor. Arrangements should protect other merchants, confidentiality and service security without preventing a necessary audit.

Where an international transfer requires an approved safeguard, the parties must adopt the appropriate transfer instrument and complete its required details before that transfer. Any required EU standard contractual clauses, UK IDTA or UK Addendum must be agreed separately.

7. Processing schedule

Questions about this document?

support@customerhubapp.com