Book a demo

Legal

Data processing addendum

How Brandfora processes personal data on behalf of the partners who run stores on it, and the sub-processors involved.

Last updated 1 September 2026

These are working drafts, published so partners can review the substance early. They have not been through legal review — tell us what needs to change.

Draft for legal review. Written to match the platform’s real architecture so counsel is editing facts rather than inventing them. Not yet reviewed by a qualified lawyer, and not legal advice. Placeholders in [brackets] need a decision before this is offered for signature.

This addendum forms part of the platform agreement between Brandfora (“Processor”) and the partner running stores on the platform (“Controller”). Where it conflicts with the agreement on data protection, this addendum wins.

1. Roles

The Controller determines the purposes and means of processing personal data in its stores. Brandfora processes that data only on documented instructions — the agreement, this addendum, and the Controller’s use of the platform’s features are those instructions.

For personal data on brandfora.com itself, Brandfora is an independent controller. See the privacy notice.

2. Subject matter and scope

Subject matterProvision of the Brandfora commerce platform
DurationThe term of the agreement, plus the deletion window in §9
Nature and purposeHosting stores; processing orders; routing fulfillment; pricing and credit; design file handling; email notification; analytics
Categories of data subjectThe Controller’s buyers and store visitors; the Controller’s own staff and team members; where employee stores are used, the Controller’s customers’ employees
Categories of personal dataName, email, postal and delivery address, phone; order and transaction history; uploaded artwork and design files; account credentials and authentication factors; store budget and entitlement records; IP address and event logs
Special category dataNone is required by the platform. The Controller must not upload special category data. [Note: an employee-store roster could in principle carry it in a free-text field. Consider an explicit prohibition.]
Children’s dataNot knowingly processed. [Decision needed if any store type is aimed at under-16s — e.g. a school fundraising store.]

3. Brandfora’s obligations

We will:

  1. Process only on the Controller’s documented instructions, and tell them if we believe an instruction breaches data protection law.
  2. Ensure everyone authorised to process is bound by confidentiality.
  3. Implement the technical and organisational measures in §5.
  4. Respect the sub-processor conditions in §4.
  5. Assist the Controller with data subject requests, taking into account the nature of processing and the information available to us.
  6. Assist with data protection impact assessments and prior consultation.
  7. Delete or return personal data at the Controller’s choice on termination, per §9.
  8. Make available the information needed to demonstrate compliance, and allow audits under §8.

4. Sub-processors

The Controller gives general authorisation for the sub-processors below. We will give [30 days’] notice before adding or replacing one, and the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service without penalty.

Sub-processorPurposeLocationTransfer basis
Google Cloud PlatformHosting, database, object storage[region][SCCs / IDTA]
CloudflareCDN, edge caching, DDoS protectionGlobal edge[SCCs / IDTA]
StripePayment processing, Connect settlement[region][SCCs / IDTA]
ResendTransactional and notification email[region][SCCs / IDTA]
DesignMintEmbedded design studio and print-file generation[region][SCCs / IDTA]
BrandfetchBrand asset lookup during store activation[region][SCCs / IDTA]
TalkJSIn-platform messaging, where enabled[region][SCCs / IDTA]
ShipStationCarrier rates and label purchase, where enabled[region][SCCs / IDTA]

Fulfillment networks and blank suppliers connected by the Controller through the Integration Hub — for example FulfillEngine, TaylorOnDemand or SanMar — are engaged on the Controller’s own account and instruction. They are the Controller’s sub-processors, not ours, and the credentials remain the Controller’s.

Search indexing runs on infrastructure we operate; it is not a third-party processor, and no price, cost or MAP is ever written to the index.

5. Security measures

These describe the platform as built.

Tenant isolation. Each tenant has its own database, cache key prefix, object storage bucket, DNS zone and TLS certificate. Catalog, pricing, customers, theming and cache keys are per-tenant. Tenant resolution never trusts a client-supplied header, and a continuous integration check enforces that.

Access control. In-house TOTP multi-factor authentication on all three admin surfaces, with encrypted secrets, backup codes and step-up re-authentication on sensitive actions. Per-store OIDC single sign-on against the Controller’s own identity provider. Role-based access with owner, admin and member tiers, plus invitations, ownership transfer and an audit log.

Encryption. TLS in transit on every domain, with managed certificates and automatic renewal. Integration credentials encrypted at rest with AES-256-GCM. [Confirm and state the encryption-at-rest position for the primary database and object storage.]

Logging and monitoring. Append-only first-party event logging, a system log, and a partner API audit log. Raw analytics events are pruned after 90 days.

Resilience. [Backup frequency, retention and tested restore objectives — decision needed. State RPO and RTO only once they have actually been tested.]

Assurance. A SOC 2 readiness programme is underway, built on a verified 12-domain gap audit mapped across all five Trust Services Criteria. Brandfora is not currently SOC 2 certified and does not represent otherwise.

6. Data subject requests

Store operators can action access, correction, deletion and export from their own admin surface for most requests. Where a request reaches us directly we will forward it to the Controller without undue delay and will not respond on their behalf unless instructed.

7. Personal data breach

We will notify the Controller without undue delay and in any event within [48] hours of becoming aware of a personal data breach affecting their data, with the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures taken. We will not delay notification to complete an investigation.

8. Audit

The Controller may audit compliance [once in any 12-month period], on [30 days’] notice, during business hours, without disrupting operations, and subject to confidentiality. We may satisfy an audit with a current third-party report once one exists. Additional audits following a breach are permitted.

9. Deletion and return

On termination the Controller may export its data for [60 days]. After that window, data is removed on a documented lifecycle — suspend, then archive, then purge — including from backups on their normal rotation. We will certify deletion on request.

10. International transfers

Where personal data is transferred outside the UK or EEA, the transfer is made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with a transfer risk assessment and any supplementary measures that assessment requires.

11. Liability

Liability under this addendum is subject to the limitations in the agreement, except where data protection law does not permit that.