MuthoCommerce Data Processing Addendum
Version: 2026-08-03
Effective date: 3 August 2026
This Data Processing Addendum (DPA) forms part of the agreement between Merchant and MuthoCommerce. It applies when MuthoCommerce processes Merchant Personal Data to provide the Service. If this DPA conflicts with the Merchant Terms on that subject, this DPA controls. Mandatory data-protection law always controls.
1. Definitions and roles
Merchant Personal Data means personal data submitted to the Service by or for Merchant, or collected through Merchant's store, for which Merchant determines the business purpose. It includes shopper, prospect, recipient, order, delivery, review, loyalty, gift-card, inbox, support, social-channel, and merchant-generated profile data.
Data Incident means confirmed unauthorised destruction, loss, alteration, disclosure of, or access to Merchant Personal Data in MuthoCommerce's control. Unsuccessful attempts that do not compromise data—such as blocked scans or failed logins—are not Data Incidents.
The terms controller, data fiduciary, processor, data processor, data subject, and processing have the meanings given by applicable law. Merchant is the controller or data fiduciary and MuthoCommerce is its processor for Merchant Personal Data. Each party is independently responsible for data for which it determines its own purposes.
2. Merchant instructions and responsibilities
MuthoCommerce will process Merchant Personal Data only:
- to provide, secure, troubleshoot, and support the Service selected and configured by Merchant;
- on documented instructions in the agreement, product configuration, support request, API call, or lawful Authorised User action; and
- as required by law, in which case MuthoCommerce will notify Merchant before processing unless prohibited.
MuthoCommerce will promptly tell Merchant if an instruction appears to violate applicable data-protection law and may pause the affected processing while the parties resolve it.
Merchant is responsible for a lawful basis, transparent store privacy notice, required consent, data accuracy, data-subject communications, authorised-user permissions, and the lawfulness of instructions and connected services. Merchant will not submit full payment-card data, authentication passwords, one-time codes, government identity data, health data, biometric templates, precise continuous location, or other highly sensitive data unless the Service expressly supports that category and the parties document additional safeguards.
3. MuthoCommerce obligations
MuthoCommerce will:
- limit access to personnel who need it for the Service and bind them to confidentiality;
- maintain the security measures in Schedule 2 and test their effectiveness;
- maintain an accurate processing and subprocessor record;
- assist Merchant with data-subject rights, security assessments, breach duties, and regulator consultations reasonably related to the Service;
- not sell Merchant Personal Data, use it for unrelated advertising, or combine it with another merchant's identifiable data for that merchant's benefit;
- not use Merchant Personal Data to train a general-purpose AI model without a separate, express, written opt-in describing the data, model, purpose, retention, withdrawal effect, and benefit; and
- delete or return data as stated in section 9.
MuthoCommerce may create statistics that are irreversibly aggregated or anonymised so that no merchant or individual is reasonably identifiable, and may use those statistics for security, reliability, capacity, and product improvement.
4. Confidentiality and access
MuthoCommerce will apply least privilege, unique workforce identities, strong authentication, privileged multi-factor authentication, periodic access review, prompt access revocation, and logged production access. Production access to Merchant Personal Data must have a documented operational, support, security, or legal reason. Shared administrative credentials are prohibited except a controlled, logged emergency credential.
5. Subprocessors
Merchant gives general authorisation for subprocessors listed in the Subprocessors and Connected Services Notice. MuthoCommerce will contractually require each subprocessor to protect Merchant Personal Data to a standard no less protective than the relevant obligations in this DPA and remains responsible for its subprocessors to the extent required by law and the agreement.
MuthoCommerce will give at least 15 days' advance notice before a new subprocessor begins material processing, except an emergency replacement needed to protect availability or security. Merchant may object during that period on reasonable, documented data- protection grounds. The parties will try to resolve the risk through configuration, additional safeguards, or an alternative. If no reasonable resolution exists, Merchant may stop the affected feature or terminate the affected Service and receive a pro-rata refund of unused prepaid recurring fees for that Service. MuthoCommerce may withhold security-sensitive subcontractor details from public display but must make them available under confidentiality when legally required.
Merchant-selected payment, courier, social, messaging, analytics, or other connected providers are not MuthoCommerce subprocessors merely because the Service transmits data to them on Merchant's instruction. Their own terms and roles apply.
6. Data-subject requests
Taking account of the nature of processing, MuthoCommerce will provide self-service tools or reasonable assistance for access, correction, export, restriction, objection, and deletion. If MuthoCommerce receives a request concerning Merchant Personal Data, it will direct the requester to Merchant and notify Merchant unless prohibited or Merchant has authorised MuthoCommerce to respond. MuthoCommerce will not independently deny a request on Merchant's behalf.
Ordinary self-service assistance is included in the Service. MuthoCommerce may charge reasonable pre-agreed fees for exceptional custom work caused by Merchant's systems or instructions, but not for work required because of MuthoCommerce's breach.
7. Data Incidents
MuthoCommerce will maintain an incident-response process. After confirming a Data Incident, MuthoCommerce will notify Merchant without undue delay and, where reasonably practicable, within 48 hours. The notice will include, as information becomes available:
- the nature, date range, affected systems, data categories, and approximate number of affected records or people;
- likely consequences and risk assessment;
- containment, mitigation, recovery, and recurrence-prevention measures;
- a contact for coordinated response; and
- information reasonably needed for Merchant's notices to individuals or authorities.
An initial notice may be incomplete and will be supplemented. Notice is not an admission of fault. MuthoCommerce will preserve evidence, investigate, contain, remediate, and cooperate. MuthoCommerce will not notify Merchant's shoppers or make a public statement naming Merchant without Merchant's approval unless law requires it; when law permits, the parties will coordinate content and timing.
Merchant must notify MuthoCommerce promptly of compromised Merchant credentials, misconfigured permissions, unlawful instructions, or an incident in a connected service that could affect the Service.
8. International processing and government access
MuthoCommerce will process data in approved locations recorded in the subprocessor notice and implement the transfer assessment, contractual safeguard, consent, approval, or other mechanism required by applicable law. MuthoCommerce will not materially relocate Merchant Personal Data without the notice required for a new processing location.
MuthoCommerce will assess government demands for facial validity and jurisdiction, seek narrowing where appropriate, disclose only the required data, document the response, and notify Merchant before disclosure unless prohibited or an emergency makes prior notice impracticable. MuthoCommerce will challenge a demand when there is a reasonable legal basis and doing so would not create disproportionate risk.
9. Return and deletion
During the subscription and 30-day post-deactivation recovery period, Merchant may use available export tools. MuthoCommerce will not condition a standard export on waiver of rights or payment of a disputed amount, although valid undisputed amounts remain due.
After the recovery period, MuthoCommerce will delete or irreversibly anonymise Merchant Personal Data from active systems unless law or a documented legal hold requires a limited record. Residual encrypted disaster-recovery copies will be isolated from normal use and targeted to expire within 90 additional days where MuthoCommerce controls the schedule, or remain blocked until a subprocessor's fixed secure recovery cycle overwrites them. If restored, the deletion instruction will be re-applied before ordinary processing resumes. MuthoCommerce will make deletion confirmation available to the Owner.
MuthoCommerce may retain account tombstones, invoices, acceptance evidence, security events, complaints, and other records for the specific periods in the Privacy Notice. Retained records remain protected, access-restricted, and unavailable for product marketing or renewed operational use.
10. Audit and compliance information
MuthoCommerce will maintain records reasonably sufficient to demonstrate compliance and, on request no more than once each year, provide Merchant with a current security questionnaire, relevant policies, test summaries, or independent assurance reports that MuthoCommerce actually holds. MuthoCommerce will not label a self-assessment as an independent certification.
If that information is insufficient following a substantiated Data Incident, regulator demand, or reasonable evidence of material non-compliance, Merchant may request a focused audit by an independent qualified auditor under confidentiality. Audits must avoid other customers' data, source code, vulnerability exploitation, and unreasonable service disruption. Merchant bears the cost unless the audit finds a material MuthoCommerce breach, in which case MuthoCommerce bears reasonable audit cost.
11. Liability and termination
Liability under this DPA is governed by the Merchant Terms unless a signed Order Form expressly establishes a different data-protection cap. Termination of the agreement does not end sections concerning confidentiality, incident cooperation, audit for a pre-termination period, retained records, deletion, or liability.
Schedule 1 — Processing details
| Item | Description |
|---|---|
| Subject | Hosted commerce, storefront, order, customer, marketing, communication, analytics, integration, automation, search, and support services configured by Merchant |
| Duration | Subscription term, 30-day recovery period, and limited residual/required retention described above |
| Frequency | Continuous or event-driven according to Merchant use |
| People | Shoppers, prospects, recipients, reviewers, loyalty members, gift-card recipients, conversation participants, Merchant personnel, suppliers, and other contacts submitted by Merchant |
| Data | Contact and account details; addresses; order, cart, product-interest, fulfilment, payment-status and refund metadata; messages and social identifiers; reviews; loyalty and gift-card records; preferences; device and event data; support data; Merchant-defined custom fields |
| Special data | Not intended unless a feature and signed terms expressly authorise it; full card data, credentials, one-time codes, and unsupported sensitive data are prohibited |
| Operations | Collect, record, organise, structure, store, retrieve, consult, use, transmit, match, restrict, export, delete, anonymise, and secure |
| Purpose | Provide and protect the features selected and instructed by Merchant |
Schedule 2 — Minimum security measures
MuthoCommerce will maintain measures appropriate to the nature and risk of the Service, including:
- Architecture and tenancy: server-enforced tenant context; separation of platform/control-plane and merchant data; authorisation checks at data access; tests for cross-tenant access; no authorisation based solely on cache or client state.
- Encryption and secrets: TLS for data in transit; provider-supported encryption at rest; managed secrets rather than source code; credential rotation after exposure; no logging of passwords, tokens, cookies, PINs, one-time codes, or full payment credentials.
- Identity and access: unique workforce accounts, least privilege, privileged MFA, approval for production access, quarterly access review, prompt offboarding, and logged high-risk administrative actions.
- Application security: code review, dependency and vulnerability review, input validation, output encoding, CSRF and session controls, rate limiting, webhook signature verification, idempotency for repeated events, and security testing proportional to change risk.
- Operations: monitored availability and security signals, tamper-resistant incident records, controlled change and deployment, backups, documented recovery objectives, and at least annual restoration testing.
- Data minimisation: purpose-based collection, scoped API permissions, production-data restrictions in development and testing, masked or synthetic test data where reasonably possible, and enforced retention jobs.
- Vendor security: risk review before material processing, written data and security terms, location and access record, incident cooperation, termination handling, and periodic reassessment.
- Incident readiness: named response roles, severity criteria, evidence preservation, containment, legal and customer notification decision records, post-incident review, and tracked remediation.
These are contractual controls, not a claim of ISO 27001, SOC 2, PCI DSS, or another certification. A certification will be claimed only when independently verified, applicable to the Service, and current.