Data Processing Addendum
Last updated: October 5, 2026
This Addendum forms part of the Terms of Service between you and Seller63 LLC. It applies automatically, without signature, to the extent Data Protection Law applies to Personal Data that Seller63 processes on your behalf. Capitalized terms not defined here have the meaning given in the Terms.
1. Definitions
"Data Protection Law" means the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act and comparable US state privacy laws, each as it applies to the processing concerned. "Personal Data" means information within Customer Data that relates to an identified or identifiable person. "Subprocessor" means a third party we engage to process Personal Data on your behalf.
2. Roles and scope
For Personal Data within Customer Data, you are the controller (or business) and Seller63 is the processor (or service provider). For account information and usage data, Seller63 is an independent controller as described in the Privacy Policy, and this Addendum does not apply.
You are responsible for the lawfulness of your instructions and of the Personal Data you make available to us, including any notice or permission the law requires you to give or obtain.
The details of the processing are in Annex 1.
3. Our obligations
We will:
- process Personal Data only on your documented instructions, which are the Terms, this Addendum and your use of the Service, and tell you if we believe an instruction breaks the law;
- make sure everyone we authorize to process Personal Data is bound by confidentiality;
- apply the security measures in Annex 2, which we may update provided the overall level of protection does not materially decrease;
- pass to you any request we receive from an individual about Personal Data, and not answer it ourselves unless the law requires us to;
- help you, as far as the nature of the processing allows, to respond to requests from individuals and to carry out impact assessments or regulator consultations the law requires of you;
- notify you without undue delay, and in any case within 72 hours, after we become aware of a breach of security leading to the loss, alteration or unauthorized disclosure of or access to Personal Data, and give you the information you reasonably need to meet your own obligations;
- delete Personal Data as described in sections 4 and 15 of the Terms, and send you the exports section 15 describes if you ask for them.
4. Subprocessors
You authorize us to use the Subprocessors named in section 7 of the Privacy Policy, which is the current list. We impose data-protection duties on each of them that are at least as protective as this Addendum, and we remain responsible for their performance.
We will email the account owner at least 30 days before adding or replacing a Subprocessor. You may object on reasonable data-protection grounds within 14 days of that notice. If you do not object in that time, the change is accepted. If we cannot resolve the objection, you may close your account before the change takes effect and receive a refund of prepaid fees for the unused period. That is your only remedy for a Subprocessor change.
5. International transfers
Personal Data is processed in the United States. Where Data Protection Law requires a transfer mechanism for a transfer from you to Seller63:
- the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated by reference, with you as exporter and Seller63 as importer; the optional docking clause and optional redress language do not apply; clause 9 uses general authorization with the notice period in section 4; the governing law and courts are those of Ireland; and the Annexes to this Addendum complete the Clauses' annexes;
- for transfers subject to UK law, the UK International Data Transfer Addendum to those Clauses applies;
- for transfers subject to Swiss law, the Clauses apply with the adjustments Swiss law requires.
If the Clauses and this Addendum conflict, the Clauses prevail.
6. Information and audits
On request, and no more than once in any 12 months, we will answer a reasonable written security questionnaire and provide the documentation needed to show we comply with this Addendum. Any audit beyond that takes place only where a supervisory authority requires it or after a breach notified under section 3. It is conducted remotely, on at least 30 days' written notice, at your cost, and under a confidentiality agreement.
7. California and other US states
We act as your service provider. We will not sell or share Personal Data; will not retain, use or disclose it for any purpose other than providing the Service to you, or outside our direct business relationship with you; and will not combine it with personal data from other sources, except as those laws allow a service provider to do. We will tell you if we can no longer meet these obligations.
8. Liability and precedence
Each party's liability under this Addendum is subject to the limits in section 13 of the Terms, which apply to this Addendum and the Terms together and not separately. If this Addendum and the Terms conflict on a data-protection matter, this Addendum prevails.
Annex 1 — Details of processing
| Item | Detail |
|---|---|
| Subject matter and purpose | Providing the Service: retrieving, storing, calculating and displaying your Amazon business data and the data you enter |
| Duration | While your account is open, plus the deletion period in the Terms |
| Nature of processing | Collection through Amazon's APIs, hosting, calculation, display, export, backup, deletion |
| People concerned | People identifiable from your business data (for example a sole trader); Amazon buyers only indirectly, through order numbers |
| Types of Personal Data | Amazon order numbers with dates, products and amounts. No buyer names, addresses, phone numbers or email addresses |
| Special categories | None |
| Frequency of transfer | Continuous |
Annex 2 — Security measures
- Hosting on Google Cloud in the United States (us-central1).
- Encryption in transit (TLS 1.2 or higher) for connections over the internet; encryption at rest (AES-256) for databases, warehouse and file storage.
- Tenant isolation: row-level security in the application database, verified by automated tests on every code change.
- Authentication through a dedicated identity provider; access to each account limited to its invited users, with per-section view and edit permissions.
- Separate service accounts and database roles for request handling and for data ingestion.
- Application credentials held in a secrets manager.
- No buyer-identifying data by design: requests to Amazon leave out buyer and recipient details, and incoming order data is checked before storage.
- Daily database backups with point-in-time recovery.
- Automated alerting on failed jobs; administrative access to cloud infrastructure logged.
- Production access limited to authorized personnel under confidentiality duties.
- Breach notification as described in section 3.