Data Processing Agreement

Last updated: June 12, 2026

Controller-processor contract under GDPR Art. 28 (and equivalent data-protection laws) for Sellers whose connected sales channels route end-consumer personal data through ArtizIQ. Complements our Terms of Service and Privacy Policy.

Parties and Definitions

This Data Processing Agreement ("DPA") is entered into between the customer identified in the applicable ArtizIQ subscription or platform agreement (the "Controller") and ArtizIQ LLC, a limited liability company organized under the laws of the State of Texas, United States, with its principal place of business in Houston, Texas (the "Processor"), collectively the "Parties". This DPA forms part of, and is incorporated by reference into, the Terms of Service and any related order form (the "Principal Agreement"). In case of conflict, this DPA prevails with respect to processing of Personal Data.

Capitalized terms have the meanings given in Article 4 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, equivalent terms under other applicable data-protection laws. "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority", and "Personal Data Breach" bear their GDPR meanings. "Standard Contractual Clauses" or "SCCs" means the clauses set out in Commission Implementing Decision (EU) 2021/914.

Subject Matter and Duration

The subject matter of the Processing is the provision of the ArtizIQ marketplace platform to the Controller, including catalogue browsing, listing creation, order orchestration, artisan assignment, payment/payout facilitation, shipping label generation, and related communications. The duration of the Processing corresponds to the term of the Principal Agreement, plus any post-termination period required for data return, deletion, or legal retention as set out in Return and Deletion.

Nature and Purpose of Processing

The Processor will Process Personal Data solely for the purpose of performing the services described in the Principal Agreement and on the documented instructions of the Controller. Documented instructions include this DPA, the configuration and use of the platform by the Controller, and any further written instructions agreed between the Parties. The nature of the Processing includes collection, recording, organization, structuring, storage, consultation, use, disclosure by transmission, alignment, restriction, erasure, and destruction, as necessary to operate the platform.

The Processor will not Process Personal Data for its own purposes, sell Personal Data, or combine it with data from other sources except as strictly necessary to provide the service, comply with law, or with the Controller's prior written consent. Aggregated or anonymized data derived from Personal Data may be used to operate and improve the platform, provided that such data cannot be re-identified by reasonable means.

Categories of Data Subjects

Depending on Controller configuration and use, categories of Data Subjects may include:

Categories of Personal Data

Categories may include: identification and contact data (name, email, postal address, phone number); account credentials (hashed passwords, tokens); order and transaction data (order ID, product, price, quantity, fulfilment status); shipping and delivery data (recipient name, address, tracking number); payment metadata (last four digits of card, payout reference — full card numbers are handled exclusively by the payment partner); communications and support data; technical data (IP address, device identifiers, log records). Special categories of data (GDPR Art. 9) are not intended to be Processed through the platform; the Controller must not submit such data unless separately agreed in writing.

Processor Obligations

The Processor shall: (a) Process Personal Data only on documented instructions of the Controller, including with regard to international transfers, unless otherwise required by Union or Member State law, in which case the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest; (b) ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (c) implement the technical and organizational measures set out in Annex B; (d) respect the conditions for engaging subprocessors set out in Subprocessors; (e) assist the Controller in responding to Data Subject requests; (f) assist the Controller in complying with its obligations under GDPR Arts. 32-36; (g) at the Controller's choice, delete or return Personal Data at the end of the services; (h) make available information necessary to demonstrate compliance and allow for audits in accordance with Audit Rights.

The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.

Confidentiality

The Processor ensures that any person acting under its authority who has access to Personal Data is bound by a written obligation of confidentiality that survives termination of the employment or engagement. Access is granted on a need-to-know basis and is subject to the access-control measures described in our Security page. Personnel receive data-protection and security training on onboarding and at regular intervals thereafter.

Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures are described in Annex B and on our Security page, and include pseudonymization and encryption of Personal Data; ongoing confidentiality, integrity, availability, and resilience of Processing systems; the ability to restore availability and access in a timely manner in a physical or technical incident; and a process for regularly testing, assessing, and evaluating the effectiveness of the measures.

Subprocessors

The Controller grants the Processor general written authorization to engage subprocessors to Process Personal Data on the Controller's behalf, subject to the conditions in this Section. A current list of subprocessors, including name, role, and processing location, is set out in Annex C and is updated from time to time.

Before engaging a new subprocessor or replacing an existing one, the Processor shall provide the Controller with at least thirty (30) days' prior notice (by email, in-product notification, or through the Annex C page). The Controller may object on reasonable data-protection grounds within that period. If the Parties cannot agree on a resolution, the Controller may terminate the affected portion of the Principal Agreement without penalty, and the Processor shall refund any prepaid fees for the unused portion of the term.

The Processor shall impose on each subprocessor data-protection obligations no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures, and shall remain fully liable to the Controller for the performance of each subprocessor's obligations.

Assistance with Data Subject Rights

Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, to fulfil the Controller's obligation to respond to requests to exercise Data Subject rights under GDPR Chapter III (rights of access, rectification, erasure, restriction, portability, objection, and rights related to automated individual decision-making), and equivalent rights under other applicable data-protection laws.

If a Data Subject submits a request directly to the Processor, the Processor shall, without undue delay, forward the request to the Controller and shall not respond to the Data Subject directly except to confirm receipt and refer them to the Controller, unless authorized or required to do otherwise.

Personal Data Breach Notification

The Processor shall notify the Controller of any Personal Data Breach affecting the Controller's Personal Data without undue delay and, in any event, within seventy-two (72) hours of becoming aware of it. The notification shall describe, to the extent known at that time: (i) the nature of the breach, including categories and approximate number of Data Subjects and records concerned; (ii) the likely consequences; (iii) the measures taken or proposed to address the breach and mitigate its adverse effects; and (iv) the contact point for further information. The Processor shall supplement the initial notification with further information as it becomes available.

The Processor shall cooperate with the Controller and take reasonable steps as directed by the Controller to assist in the investigation, mitigation, and remediation of the breach, and to support the Controller's compliance with GDPR Arts. 33 and 34 and equivalent obligations under other applicable law.

Data Protection Impact Assessments

Taking into account the nature of the Processing and the information available to the Processor, the Processor shall provide reasonable assistance to the Controller with data protection impact assessments under GDPR Art. 35 and with prior consultations with the competent Supervisory Authority under GDPR Art. 36. This assistance is limited to information and cooperation within the Processor's reasonable control and may be subject to a reasonable fee for materially burdensome requests, agreed in advance.

International Transfers and Standard Contractual Clauses

Personal Data is Processed primarily in the European Union. Where the Processor transfers Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland to a country not covered by an adequacy decision, such transfer shall be made pursuant to appropriate safeguards under GDPR Art. 46, including the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this DPA by reference. The applicable Module is determined by the transfer scenario: Module 2 (Controller to Processor) applies to transfers where the Controller is the data exporter and the Processor (established in the United States) is the data importer; Module 3 (Processor to Processor) applies as between the Processor and its subprocessors.

For UK transfers, the International Data Transfer Addendum issued by the UK Information Commissioner's Office is incorporated. For Swiss transfers, the SCCs are read together with the adaptations notified by the Swiss Federal Data Protection and Information Commissioner. Where the Processor is certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), transfers covered by that certification may rely on it as an alternative transfer mechanism.

The Processor has assessed the law and practice of the United States as regards access by public authorities to Personal Data and has adopted supplementary measures, including encryption in transit and at rest and strict access controls, to ensure a level of protection essentially equivalent to that guaranteed in the European Union (Schrems II standard, CJEU Case C-311/18).

Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and with GDPR Art. 28, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller. To satisfy this obligation, the Processor shall, in the first instance, provide copies of current third-party audit reports and certifications (e.g., ISO/IEC 27001, SOC 2) where available, together with responses to reasonable written questionnaires.

Where those materials are not sufficient to address the Controller's reasonable concerns, the Controller may request an on-site audit at the Processor's premises (excluding data-centre premises, which are subject to the hosting provider's audit regime), no more than once per twelve (12) month period, on at least thirty (30) days' prior written notice, during normal business hours, under confidentiality, and in a manner that does not unreasonably disrupt operations or compromise the security or confidentiality of other customers' data. The Controller shall bear its own costs; reasonable costs incurred by the Processor to support the audit beyond routine cooperation may be invoiced at the Processor's then-current rates. Any material findings shall be addressed through a mutually agreed remediation plan.

Return and Deletion

Upon termination or expiry of the Principal Agreement, the Processor shall, at the choice of the Controller expressed in writing before the effective date of termination, return or delete all Personal Data Processed on the Controller's behalf. In the absence of a timely instruction, the Processor shall delete the Personal Data within ninety (90) days of the effective date of termination. Backups containing Personal Data will be overwritten in the normal rotation cycle and will remain access-restricted until expiry.

The Processor may retain Personal Data to the extent required by applicable law, or for the establishment, exercise, or defence of legal claims, for the minimum duration required, subject to continued confidentiality and security obligations under this DPA.

Liability

Each Party's liability arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under applicable law, including liability under GDPR Art. 82 toward Data Subjects, liability for death or personal injury caused by negligence, or liability for fraud or fraudulent misrepresentation.

Governing Law and Jurisdiction

This DPA is governed by the laws of the State of Texas and the federal laws of the United States, without regard to conflict-of-laws principles. The state and federal courts located in Harris County, Texas, United States shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA. Where the SCCs apply, the governing-law and forum provisions of the SCCs control to the extent they mandate a Member State law and forum. Nothing in this clause deprives a consumer resident in the European Union of the protection afforded to them by mandatory provisions of the law of the country in which they are habitually resident (see Rome I Regulation (EC) No 593/2008 Art. 6 and Brussels I bis Regulation (EU) 1215/2012 Arts. 17-19).

Annex A — Processing Details

A.1 List of Parties

Data exporter: the Controller, as identified in the Principal Agreement, acting in the role of controller for Personal Data submitted to the platform. Data importer: ArtizIQ LLC, a limited liability company organized under the laws of the State of Texas, USA, acting as processor on behalf of the Controller. Contact details for both Parties are those set out in the Principal Agreement or, for the importer, privacy@artiziq.com.

A.2 Description of Transfer

Categories of Data Subjects and Personal Data are those set out in Categories of Data Subjects and Categories of Personal Data. The frequency of the transfer is continuous (on-demand API traffic and ongoing platform operation). The nature of the Processing and the purposes of the transfer are described in Nature and Purpose of Processing. The period for which the Personal Data will be retained is described in Return and Deletion and the Privacy Policy. Transfers to (sub)processors are described in Annex C.

A.3 Competent Supervisory Authority

For Processing in the European Union, the competent Supervisory Authority is determined in accordance with GDPR Art. 55-56; where no EU establishment of the Processor exists, the supervisory authority of the Member State in which the Controller's lead establishment is located acts as the relevant authority for the Controller.

Annex B — Technical and Organizational Security Measures

The Processor implements the following categories of measures; further detail is set out at Security:

Annex C — Subprocessors

The following categories of subprocessors are engaged by the Processor. Specific vendor identities, the regions in which they Process Personal Data, and the nature of the data disclosed to each are provided to the Controller under non-disclosure and updated when changes occur.

The Processor will notify the Controller of changes to this Annex C in accordance with Subprocessors.