DATA PROCESSING AGREEMENT

Last updated September 21, 2026

This Data Processing Agreement (the "DPA") forms part of the Terms of Service between MarketplaceHub Ltd, a company registered in England and Wales under company number 13815249, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("MarketplaceHub", "we", "us") and the customer who has accepted those Terms (the "Merchant", "you").

It applies whenever we process personal data on your behalf, and it takes precedence over anything in the Terms of Service that conflicts with it. It does not replace our Privacy Policy, which describes the personal data we hold about you as an account holder and for which we are the controller.

1. DEFINITIONS

"Data Protection Law" means the UK GDPR and the Data Protection Act 2018, and, where they apply to the processing, Regulation (EU) 2016/679 (the "EU GDPR") and any other applicable law on the protection of personal data.

"controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given to them in Data Protection Law.

"Merchant Personal Data" means personal data that we process on your behalf under the Terms of Service. In practice it is the personal data attached to the orders, listings and messages of the sales channels you connect.

"Services" means the MarketplaceHub platform as described in the Terms of Service.

2. ROLES, AND WHAT WE MAY DO WITH THE DATA

For Merchant Personal Data you are the controller and we are the processor. You decide why it is processed; we act only on your documented instructions.

Your instructions are: the Terms of Service, this DPA, the settings you choose in the platform, and anything else you ask us to do in writing that we agree to. Using a feature is an instruction to perform it.

We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may also process Merchant Personal Data where a law we are subject to requires it; where that law permits, we will tell you before we do.

We do not use Merchant Personal Data for our own purposes. No marketing, no personalisation, no profiling, no advertising, no training of models on it, and we do not sell it or disclose it to anyone for their own use. We do not combine it with data from other merchants.

Aggregated statistics that cannot identify any person or any merchant — for example, counts of orders processed platform-wide — are not Merchant Personal Data and we may use them to operate and improve the Services.

3. SUBJECT MATTER, DURATION, NATURE AND PURPOSE

Subject matter and duration. The processing lasts for as long as you have an account with us, plus the retention periods in section 9.

Nature and purpose. Collecting orders and listings from the sales channels you connect, storing them, showing them to you in one place, and carrying your decisions — shipment, tracking, cancellation, refund, price and stock changes — back to those channels.

Categories of data subject. Your customers and prospective customers, and the people you authorise to use your account.

Categories of personal data. For a customer: the recipient's name and shipping address, a contact phone number and email address attached to the order, and the contents, totals, currency and refunds of that order. For a user of your account: name, email address and authentication data.

We request the minimum. We do not ask the marketplaces for their customer or buyer profile objects, and we do not request a store's full order history — only the recent orders needed to keep your workspace current. We never hold payment card details.

No special category data. The Services are not designed for personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation, or criminal convictions. Do not put such data into them.

4. CONFIDENTIALITY

We give access to Merchant Personal Data only to people who need it to provide or support the Services. Those people are bound by written confidentiality obligations that survive the end of their engagement, and they are made aware of the confidential nature of the data.

5. SECURITY MEASURES

We implement appropriate technical and organisational measures to protect Merchant Personal Data. The measures in force are:

  • Encryption before storage. Customer names, phone numbers, email addresses and shipping addresses are encrypted with AES-256 before they are written to the database, under a key held in a managed key vault and never stored next to the data. Searching for a customer encrypts the search term and compares encrypted values, so the plain text is never written and never queried.
  • Encryption in transit. TLS on every connection — to us, between our own services, and onward to the sales channels.
  • Separation per merchant. Each merchant's data is held in its own database.
  • Restricted database access. Reaching the production database requires a TLS client certificate, not only a username and password.
  • Encrypted backups. Backups are encrypted at rest with AES-256 and permit no anonymous access.
  • Separated environments. Development and production data are kept apart, with separate credential stores. Production data is not copied into development.
  • Access control and logging. Reaching production requires a private network connection as well as an account, and staff accounts hold only the roles their work needs. Access to personal data is logged, and the logs are retained.
  • Authentication. Accounts support passkeys, two-factor authentication and sign-in with Google or Amazon, and enforce password strength requirements.
  • Dependency monitoring. Every build checks our dependencies — the ones we name and the ones they in turn pull in — against the public vulnerability database, and a published advisory raises an update on its own.
  • Incident response. We maintain a documented security incident response procedure covering severity, roles, escalation and required actions.

We may change these measures, but not in a way that materially reduces the overall level of protection. The current version of this page is the current set.

We are not certified against ISO 27001 and have not undergone a third-party security audit or penetration test. We say so here rather than leave it to be assumed: we use ISO 27001 as the framework our internal Data Protection Policy is built on, which is a statement of practice and not of certification.

6. SUB-PROCESSORS

You give us general authorisation to engage sub-processors for the purposes in section 3. We impose data protection obligations on each of them that are no less protective than this DPA, and we remain fully liable to you for their performance.

Our sub-processors today:

Sub-processor What it does Where
DigitalOcean, LLC Hosting for the platform and the managed database, and for the message broker, cache, search index and log store that run inside it. All Merchant Personal Data at rest is here. United States
Microsoft Corporation (Azure) File and image storage; the key vault holding encryption keys and credentials; real-time browser messaging; transactional email delivery; and the AI service that classifies product listings. Product data reaches the AI service; customer identity does not. United Kingdom and United States
Amazon Web Services, Inc. The message queue Amazon Selling Partner API order notifications arrive on. It carries order and seller identifiers, not customer identity. United States
Stripe, Inc. Subscription billing. It receives your billing details and order values. No part of a customer's identity is used for billing or held in our billing records. United States
Cloudflare, Inc. Content delivery, DNS and protection against network attacks. Every public request passes through it in transit. Global edge network

The sales channels you connect — Amazon, eBay, Shopify, Etsy and any others — are not our sub-processors. You have your own relationship with each of them, and we exchange data with them because you told us to.

Changes. We will give you at least 30 days' notice before a new sub-processor starts processing Merchant Personal Data, by updating this page and emailing the address on your account. If you have a reasonable objection on data protection grounds, tell us at [email protected] within those 30 days and we will work with you in good faith to find a solution. If we cannot, you may terminate the affected Services without penalty and receive a pro-rata refund of fees paid for the unused period.

7. INTERNATIONAL TRANSFERS

Merchant Personal Data is stored in the United States and may be accessed from the United Kingdom. Where a transfer leaves the UK or the EEA to a country without an adequacy decision, it is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor) together with the UK International Data Transfer Addendum issued by the Information Commissioner's Office.

By accepting the Terms of Service you enter into those clauses with us, with you as data exporter and MarketplaceHub as data importer, and the details in sections 3, 5 and 6 of this DPA supply their annexes. Where you need a signed copy for your own records, ask us at [email protected].

8. ASSISTANCE: DATA SUBJECT RIGHTS, DPIAs AND REGULATORS

Requests from data subjects. If a data subject contacts us directly about Merchant Personal Data, we will not respond to the substance ourselves. We will tell them to contact you and let you know within 5 business days. The platform lets you search, export and erase a customer's details yourself; where a request needs more than that, we will help you at no charge.

Deletion channels. Where a sales channel provides one, we implement it. For Shopify we support the three mandatory privacy webhooks: a request for a customer's data, a request to erase a customer, and a request to erase a shop. You may also ask us directly at [email protected].

Impact assessments and prior consultation. We will give you reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, to the extent they relate to our processing and taking into account the information available to us.

Regulators. If a supervisory authority contacts us about Merchant Personal Data, we will tell you promptly unless the law forbids it.

9. RETENTION, RETURN AND DELETION

While your account is open. Customer identity is erased 24 months after the most recent order that uses it, and sooner where the sales channel an order came from requires it: 30 days for orders from Amazon, which is Amazon's own rule for data obtained through its API. A scheduled process removes the name, phone number, email address and shipping address and leaves the order itself intact, because orders are a financial record both of us need to keep. This runs automatically; it is not something either of us has to remember.

Where a customer has ordered more than once, each order counts on the rule for the channel it came from, and the details are kept until the last of those periods has passed. A shorter channel rule never shortens the period for orders placed somewhere else.

Getting your data out. While your account is open you can read your orders, products and their details at any time through our REST API, which returns JSON.

When this agreement ends. On termination, and on written request made within 30 days of it, we will return Merchant Personal Data in a machine-readable format. After that period, or straight away if you ask us to, we delete it. Deletion completes within 90 days of termination.

Backups. Backups run on a rolling seven-day window, so deleted data can remain in a backup for at most seven days after deletion and then ages out on its own. Backups are not restored selectively; while data remains in one it stays encrypted and is not processed for any other purpose.

We may keep Merchant Personal Data where a law requires it, for as long as that law requires and for no other purpose.

10. PERSONAL DATA BREACH

We will notify you of a personal data breach affecting Merchant Personal Data without undue delay, and in any event within 72 hours of becoming aware of it. Notification goes to the email address on your account.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point. Where we cannot provide all of that at once, we will send what we have and the rest as it becomes available rather than waiting.

We will not make any public statement identifying you as affected without first consulting you, unless the law requires it. Notifying a supervisory authority or your data subjects is your decision as controller; we will give you the information you need to make it.

11. AUDIT AND INFORMATION RIGHTS

We will make available to you the information necessary to demonstrate that we meet our obligations under Article 28 of the UK GDPR. In the first instance that means answering your questions and providing our documentation, which is usually enough and is always faster.

Where it is not enough, you may audit our processing, or appoint an independent auditor who is not a competitor of ours to do so, on 30 days' written notice, no more than once in any twelve-month period — and additionally after a personal data breach affecting your data, or where a supervisory authority requires it. An audit takes place during business hours, must not unreasonably disrupt our operations, must not access another merchant's data, and is subject to confidentiality. You bear your own costs; we bear ours.

12. LIABILITY

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. Nothing in this DPA limits either party's liability to a data subject under Data Protection Law.

13. CHANGES, TERM AND LAW

This DPA takes effect when you accept the Terms of Service and continues for as long as we process Merchant Personal Data. Sections 4, 9, 10, 11 and 12 survive its end.

We may update this DPA where a change in law, in the Services or in our sub-processors requires it. We will give at least 30 days' notice of a material change by updating this page and emailing the address on your account. Changes will not materially reduce the protections here.

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction — except that where the Standard Contractual Clauses in section 7 specify a governing law or forum for a matter, those apply to that matter.

14. CONTACT

Data protection questions, sub-processor objections, audit requests and deletion requests: [email protected], or by post to:

MarketplaceHub Ltd
71-75 Shelton Street
Covent Garden
London, WC2H 9JQ
United Kingdom

Registered in England and Wales, company number 13815249