Draft for legal review. Written to match the platform’s real architecture so counsel is editing facts rather than inventing them. Not yet reviewed by a qualified lawyer, and not legal advice. Placeholders in [brackets] need a decision before this is offered for signature.
This addendum forms part of the platform agreement between Brandfora (“Processor”) and the partner running stores on the platform (“Controller”). Where it conflicts with the agreement on data protection, this addendum wins.
1. Roles
The Controller determines the purposes and means of processing personal data in its stores. Brandfora processes that data only on documented instructions — the agreement, this addendum, and the Controller’s use of the platform’s features are those instructions.
For personal data on brandfora.com itself, Brandfora is an independent controller. See the privacy notice.
2. Subject matter and scope
| Subject matter | Provision of the Brandfora commerce platform |
| Duration | The term of the agreement, plus the deletion window in §9 |
| Nature and purpose | Hosting stores; processing orders; routing fulfillment; pricing and credit; design file handling; email notification; analytics |
| Categories of data subject | The Controller’s buyers and store visitors; the Controller’s own staff and team members; where employee stores are used, the Controller’s customers’ employees |
| Categories of personal data | Name, email, postal and delivery address, phone; order and transaction history; uploaded artwork and design files; account credentials and authentication factors; store budget and entitlement records; IP address and event logs |
| Special category data | None is required by the platform. The Controller must not upload special category data. [Note: an employee-store roster could in principle carry it in a free-text field. Consider an explicit prohibition.] |
| Children’s data | Not knowingly processed. [Decision needed if any store type is aimed at under-16s — e.g. a school fundraising store.] |
3. Brandfora’s obligations
We will:
- Process only on the Controller’s documented instructions, and tell them if we believe an instruction breaches data protection law.
- Ensure everyone authorised to process is bound by confidentiality.
- Implement the technical and organisational measures in §5.
- Respect the sub-processor conditions in §4.
- Assist the Controller with data subject requests, taking into account the nature of processing and the information available to us.
- Assist with data protection impact assessments and prior consultation.
- Delete or return personal data at the Controller’s choice on termination, per §9.
- Make available the information needed to demonstrate compliance, and allow audits under §8.
4. Sub-processors
The Controller gives general authorisation for the sub-processors below. We will give [30 days’] notice before adding or replacing one, and the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service without penalty.
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Google Cloud Platform | Hosting, database, object storage | [region] | [SCCs / IDTA] |
| Cloudflare | CDN, edge caching, DDoS protection | Global edge | [SCCs / IDTA] |
| Stripe | Payment processing, Connect settlement | [region] | [SCCs / IDTA] |
| Resend | Transactional and notification email | [region] | [SCCs / IDTA] |
| DesignMint | Embedded design studio and print-file generation | [region] | [SCCs / IDTA] |
| Brandfetch | Brand asset lookup during store activation | [region] | [SCCs / IDTA] |
| TalkJS | In-platform messaging, where enabled | [region] | [SCCs / IDTA] |
| ShipStation | Carrier rates and label purchase, where enabled | [region] | [SCCs / IDTA] |
Fulfillment networks and blank suppliers connected by the Controller through the Integration Hub — for example FulfillEngine, TaylorOnDemand or SanMar — are engaged on the Controller’s own account and instruction. They are the Controller’s sub-processors, not ours, and the credentials remain the Controller’s.
Search indexing runs on infrastructure we operate; it is not a third-party processor, and no price, cost or MAP is ever written to the index.
5. Security measures
These describe the platform as built.
Tenant isolation. Each tenant has its own database, cache key prefix, object storage bucket, DNS zone and TLS certificate. Catalog, pricing, customers, theming and cache keys are per-tenant. Tenant resolution never trusts a client-supplied header, and a continuous integration check enforces that.
Access control. In-house TOTP multi-factor authentication on all three admin surfaces, with encrypted secrets, backup codes and step-up re-authentication on sensitive actions. Per-store OIDC single sign-on against the Controller’s own identity provider. Role-based access with owner, admin and member tiers, plus invitations, ownership transfer and an audit log.
Encryption. TLS in transit on every domain, with managed certificates and automatic renewal. Integration credentials encrypted at rest with AES-256-GCM. [Confirm and state the encryption-at-rest position for the primary database and object storage.]
Logging and monitoring. Append-only first-party event logging, a system log, and a partner API audit log. Raw analytics events are pruned after 90 days.
Resilience. [Backup frequency, retention and tested restore objectives — decision needed. State RPO and RTO only once they have actually been tested.]
Assurance. A SOC 2 readiness programme is underway, built on a verified 12-domain gap audit mapped across all five Trust Services Criteria. Brandfora is not currently SOC 2 certified and does not represent otherwise.
6. Data subject requests
Store operators can action access, correction, deletion and export from their own admin surface for most requests. Where a request reaches us directly we will forward it to the Controller without undue delay and will not respond on their behalf unless instructed.
7. Personal data breach
We will notify the Controller without undue delay and in any event within [48] hours of becoming aware of a personal data breach affecting their data, with the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures taken. We will not delay notification to complete an investigation.
8. Audit
The Controller may audit compliance [once in any 12-month period], on [30 days’] notice, during business hours, without disrupting operations, and subject to confidentiality. We may satisfy an audit with a current third-party report once one exists. Additional audits following a breach are permitted.
9. Deletion and return
On termination the Controller may export its data for [60 days]. After that window, data is removed on a documented lifecycle — suspend, then archive, then purge — including from backups on their normal rotation. We will certify deletion on request.
10. International transfers
Where personal data is transferred outside the UK or EEA, the transfer is made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with a transfer risk assessment and any supplementary measures that assessment requires.
11. Liability
Liability under this addendum is subject to the limitations in the agreement, except where data protection law does not permit that.