Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Brand Scalers Terms of Service between the customer ("Customer") and Jugraj Solutions LLP("Brand Scalers"). It applies when Brand Scalers processes personal data contained in Customer's connected accounts on Customer's behalf.
1. Roles and instructions
Customer is the controller or data fiduciary and Brand Scalers is its processor or data processor for Customer Data. Brand Scalers will process Customer Data only to provide and secure the service, on Customer's documented instructions—including instructions submitted through the service—and as required by law. If an instruction appears unlawful, we will notify Customer where legally permitted.
2. Processing details
- Subject and purpose: operating, reporting on and securing connected marketing and commerce accounts.
- Duration: for the subscription term and the limited deletion periods in our Privacy Policy.
- Data subjects: Customer's authorised users and, only where a feature requires it, Customer's prospects or customers.
- Data types: account identifiers, campaign and store operations, performance metrics, product, inventory, order-status and transaction-summary data, and information Customer submits in chat.
- Shopify limitation: the initial Shopify integration does not request customer names, email addresses, phone numbers or postal addresses.
3. Confidentiality and security
We restrict access to authorised personnel bound by confidentiality, isolate workspaces, encrypt traffic in transit, encrypt connected-account credentials at rest, avoid logging access tokens, and maintain deletion, incident-response and access-control procedures appropriate to the risk. Additional detail is on our Security page.
4. Subprocessors and transfers
Customer authorises Brand Scalers to use hosting, database, communications, monitoring and artificial-intelligence service providers needed to deliver the service. We require subprocessors that process Customer Data to protect it under written obligations appropriate to their role. Processing may occur outside Customer's country; where applicable law requires a transfer mechanism, we will use a recognised lawful mechanism. Customer may request our current subprocessor information at kushagra@brandscalers.in.
5. Requests, incidents and assistance
Taking account of the nature of processing, we will reasonably assist Customer with verified data-subject requests, security obligations and regulator enquiries. We will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data and provide information reasonably available for Customer's response.
6. Return, deletion and audits
On disconnection or termination, we stop new access and delete or return Customer Data according to the Privacy Policy and Data Deletion page, unless law requires limited retention. On reasonable written request, we will provide information needed to demonstrate compliance and cooperate with a proportionate audit, subject to confidentiality, security and reasonable scope controls.
7. Customer responsibilities
Customer will provide lawful instructions, obtain necessary rights and consents, configure access appropriately, and avoid submitting sensitive or unnecessary personal data through chat. Customer must not use the service for unlawful surveillance, sale of personal data, or solely automated decisions producing legal or similarly significant effects.
8. Conflict and contact
If this DPA conflicts with the Terms on processing Customer Data, this DPA controls. Contact: Jugraj Solutions LLP, 3, Teja 309, My Home Navadweepa, Hitech City Road, HITEC City, Hyderabad, Rangareddy, Telangana, 500081, India, kushagra@brandscalers.in.