1. Parties and scope
This addendum is between the merchant identified in its Shopify subscription or signed agreement (“Merchant”) and CustomerHub Pty Ltd (“CustomerHub”). It applies when CustomerHub processes personal data for the Merchant in providing C:Hub and the relevant data-protection law requires a processing agreement.
The Merchant is the controller, or a processor authorized by its controller; CustomerHub acts as processor or subprocessor as appropriate. Each party remains responsible for its own independent processing. This addendum applies in accordance with the parties? agreement, processing schedule and applicable transfer arrangements.
2. Instructions and confidentiality
CustomerHub will process covered personal data only on documented Merchant instructions, including the agreed service configuration and lawful written requests, unless law requires otherwise. Where legally permitted, CustomerHub will inform the Merchant of a legal requirement to process outside those instructions and will flag an instruction it reasonably considers unlawful.
CustomerHub will restrict authorized processing to persons bound by confidentiality obligations appropriate to their access. Covered shopper data will not be used for unrelated advertising or sold outside the agreed service purposes.
3. Safeguards and assistance
CustomerHub will apply technical and organisational measures appropriate to the processing risk, taking account of the data, service and applicable law. The agreed measures are recorded in the applicable processing schedule; the website security overview alone is not a complete contractual security annex.
Taking account of the service and information available, CustomerHub will assist the Merchant with individual-rights requests, data protection impact assessments, security obligations and required consultation with regulators. The Merchant is responsible for its collection notices, lawful instructions and responses as controller, except where CustomerHub has a direct legal duty.
4. Subprocessors
The Merchant’s written authorization must identify or refer to an agreed register of subprocessors. CustomerHub will impose appropriate written data-protection obligations on an authorized subprocessor and remain responsible for its performance to the extent required by applicable law.
Under a general written authorization, CustomerHub will notify the Merchant of intended additions or replacements and allow a reasonable opportunity to object on data-protection grounds before the change. The parties will agree a practical resolution, including discontinuing affected processing where necessary. Our service-provider information describes the services used. The Merchant?s agreement identifies the applicable authorized subprocessors.
5. Personal data incidents
CustomerHub will notify the Merchant without undue delay after becoming aware of a personal data breach affecting covered data. Available information should describe the nature of the incident, affected data, likely consequences, contact point and mitigation. Further details may follow as the investigation develops.
CustomerHub will cooperate with the Merchant’s legally required assessment and notifications. Notification does not by itself constitute an admission of liability. Nothing here delays a party’s own mandatory reporting obligations.
6. Return, deletion, information and transfers
At the end of covered services, CustomerHub will, at the Merchant’s choice, return or delete covered personal data and delete remaining copies unless applicable law requires retention. The agreed schedule must address practical export, operational records and backup deletion. Retained data must remain protected and used only for the lawful retention purpose.
CustomerHub will provide information reasonably needed to demonstrate these obligations and allow and contribute to appropriate audits or inspections by the Merchant or its authorized auditor. Arrangements should protect other merchants, confidentiality and service security without preventing a necessary audit.
Where an international transfer requires an approved safeguard, the parties must adopt the appropriate transfer instrument and complete its required details before that transfer. Any required EU standard contractual clauses, UK IDTA or UK Addendum must be agreed separately.
7. Processing schedule
| Item | Description |
|---|---|
| Subject and purpose | Providing, configuring, supporting and securing the merchant’s C:Hub account experience and its enabled actions. |
| People concerned | The merchant’s customers, relevant store users and persons whose information the merchant lawfully supplies. |
| Data categories | Customer identifiers/contact details, addresses, orders/fulfilment, supported profile and registration fields, preferences, product activity, files and relevant service context. |
| Operations | Receiving, retrieving, displaying, updating, storing, transmitting, supporting, returning and deleting information as applicable to the configured service. |
| Duration | During the agreed service and any lawful, documented retention following termination. |
| Sensitive information | Not authorized by this standard addendum; a separate appropriate arrangement is required. |
| Store-specific arrangements | The parties? agreement and any applicable schedules record authorized providers and locations, security measures, retention/export/deletion and backup arrangements, required transfer instruments and contact details. |
Questions about this document?
support@customerhubapp.com