Data processing agreement

Fiftify Inc. · Last updated: September 11, 2026

This Data Processing Agreement ("DPA") forms part of the Fiftify Terms of Service between Fiftify Inc. ("Fiftify") and the customer ("Customer") and applies where Fiftify processes personal data on the Customer's behalf. "Customer Personal Data" means personal data processed by Fiftify on behalf of the Customer in connection with the Services. A countersigned copy is available on request at [email protected].

1. Scope and roles

The Customer acts as the controller of Customer Personal Data, and Fiftify acts as its processor, regardless of whether the data enters the Services from a connected sales channel, an integration or API, a file import, or manual entry. For personal data that Fiftify processes for its own purposes, such as Customer account, billing, and support information, Fiftify acts as an independent controller under the Privacy Policy.

2. Details of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Appendix 1. The Customer will not intentionally submit special categories of personal data to the Services unless otherwise agreed in writing.

3. Customer instructions

Fiftify processes Customer Personal Data only on the Customer's documented instructions, including as configured through the Services, unless required otherwise by law. Fiftify will inform the Customer if, in its opinion, an instruction infringes applicable data protection law, unless prohibited by applicable law.

4. Confidentiality

Persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data protection training. Such persons process Customer Personal Data only as necessary to perform their authorized duties.

5. Security

Fiftify implements and maintains appropriate technical and organizational measures to protect Customer Personal Data, as described in Appendix 2 and on the Security page.

6. Subprocessors

The Customer authorizes Fiftify to engage the subprocessors listed in Appendix 3, published at fiftify.com/subprocessors. Fiftify will provide at least 30 days' prior notice before appointing a new subprocessor by updating that page and, where applicable, notifying the Customer using the notification method described there. The Customer may object on reasonable data protection grounds within 15 days after receiving notice; Fiftify will use commercially reasonable efforts to address the objection, and if it cannot be resolved, the Customer may terminate the affected Services. Fiftify will impose on each subprocessor data protection obligations no less protective than those applicable to Fiftify under this DPA, to the extent required by applicable law, and remains responsible for the performance of its subprocessors to the extent required by applicable data protection law.

7. Data subject requests

Taking into account the nature of the processing, Fiftify will assist the Customer with appropriate technical and organizational measures in responding to data subject requests (access, correction, deletion, portability, objection). If a data subject contacts Fiftify directly regarding Customer Personal Data, Fiftify will, where permitted by law, promptly notify the Customer and provide reasonable assistance in responding to the request.

8. Personal data breaches

Fiftify will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will include, to the extent reasonably available, the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address it. The parties will reasonably cooperate in investigating, mitigating, and remediating the breach.

9. Assistance

Taking into account the nature of the processing and the information available to Fiftify, Fiftify will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent required.

10. International transfers

Fiftify may process Customer Personal Data in the United States and other countries. Where personal data protected by EEA, UK, or Swiss data protection law is transferred to a country without an adequacy decision, the transfer mechanisms in Section 14 apply.

11. Audits

Fiftify will make available information reasonably necessary to demonstrate compliance with this DPA and will allow audits conducted by the Customer or an independent auditor on reasonable notice, no more than once per year, except where an additional audit is reasonably necessary following a personal data breach or material non-compliance with this DPA, and in a manner that does not compromise the security of other customers.

12. Return and deletion

During the term, Fiftify will delete or return Customer Personal Data upon the Customer's documented instruction, unless applicable law requires continued retention. Following termination, the Customer may access and export its data for 30 days, as described in the Terms of Service. Fiftify will delete Customer Personal Data within 30 days after the end of that export period, and residual copies in backups within 90 days thereafter; such backup copies will not be restored or otherwise processed except as required for disaster recovery or legal obligations. Where retention is required by law, Fiftify will isolate and protect the retained data and will not process it except as required by law.

13. Customer responsibilities

The Customer is responsible for: providing lawful instructions to Fiftify; ensuring it has an appropriate legal basis for the processing of Customer Personal Data; providing required privacy notices to data subjects; responding to data subject requests; determining the purposes and means of the processing; and ensuring that Customer Personal Data submitted to the Services is appropriate for the purposes for which the Services are provided.

14. SCCs and transfer mechanisms

The EU Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 ("SCCs") are incorporated into this DPA by reference; Module Two (controller to processor) applies, with the Customer as data exporter and Fiftify as data importer. Appendix 1 supplies the information required by Annex I of the SCCs, Appendix 2 supplies Annex II, and Appendix 3 supplies Annex III. For transfers subject to UK data protection law, the SCCs apply as amended by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner. For transfers subject to Swiss data protection law, the SCCs apply as adapted for Switzerland: references to the GDPR are understood as references to the Swiss Federal Act on Data Protection, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

15. Liability and precedence

Except as otherwise required by applicable data protection law, each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service. In case of conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.

Appendix 1: details of processing

Parties. Data exporter: the Customer, a user of the Fiftify Services acting as controller. Data importer: Fiftify Inc., 1111B S Governors Ave STE 23190, Dover, DE 19904, USA, acting as processor.

Subject matter and nature of processing. Hosting, syncing, and displaying order, inventory, and fulfillment data; generating picking, packing, and shipping workflows; producing shipping labels and documents; providing related support.

Duration. The term of the Customer's subscription plus the deletion period in Section 12.

Categories of data subjects. The Customer's buyers, recipients, and contacts, and the Customer's staff users, in each case to the extent their personal data is included in Customer Personal Data.

Categories of personal data. Names, contact details, shipping and billing information, order information and identifiers, fulfillment and shipment information (including delivery instructions, carrier and tracking information), and staff user information such as name, email address, user identifiers, and activity logs. No special categories of data are intended to be processed.

Frequency. Continuous, for the duration of the Services.

Competent supervisory authority. The supervisory authority of the EEA member state in which the Customer is established or, where the Customer is not established in the EEA, the supervisory authority determined in accordance with Clause 13 of the SCCs.

Appendix 2: technical and organizational measures

Encryption of Customer Personal Data in transit (TLS) and at rest; multi-factor authentication and role-based access controls for administrative access; logical separation of customer data; network and application monitoring; vulnerability management and testing; secure backups and disaster recovery procedures; personnel confidentiality obligations and data protection training; a documented incident response process. Further detail is published on the Security page.

Appendix 3: subprocessors

The current list of subprocessors, their purposes, and locations is published at fiftify.com/subprocessors and forms Annex III of the SCCs. New subprocessors are announced as described in Section 6.