This Data Processing Addendum ("DPA") applies where STORESWIKI LLC ("Processor", "we") processes personal data on behalf of a customer ("Controller", "you") in the course of providing AutoGineer. It supplements our Terms of Service and takes effect automatically when you use the Platform in that capacity.
It is relevant if you are a business that puts personal data belonging to your own staff, customers or end users into a Project — in requirements, files, deliverables or messages. It does not apply to the data we process as a controller in our own right, such as your account, profile and payments; that is covered by our Privacy Policy.
If your procurement process requires a countersigned copy, contact [email protected] and we will provide one. Terms in this DPA have the meaning given in the GDPR unless stated otherwise, and it is intended to satisfy Article 28.
1.Roles and scope
You are the controller of Customer Personal Data — personal data you or your users upload to or generate within the Platform where you determine the purpose and means of its processing. We are your processor for it.
We are an independent controller for data we need in our own right: account and profile data, authentication, payment and payout records, identity-verification outcomes, moderation and dispute records, security logs, and aggregated usage analysis. Our Privacy Policy governs that processing, and nothing in this DPA makes us your processor for it.
2.Processing instructions
We process Customer Personal Data only to provide, secure and support the Platform in accordance with your instructions, which are given by your configuration and use of the Platform, by these documents, and by any separate written agreement.
- •Subject matter: providing the Platform.
- •Duration: while your account is active, plus the retention periods described in section 8.
- •Nature and purpose: hosting, storage, transmission, display to the counterparties in an engagement, backup, support and security.
- •Categories of data subject: your personnel, your customers and end users, and counterparties in your engagements — whoever you choose to include.
- •Categories of personal data: whatever you upload. Typically names, contact details and business information. Special-category data should not be uploaded.
We will tell you if we believe an instruction breaches applicable data protection law, and we may suspend processing of that instruction until it is resolved. If we are legally required to process for another purpose, we will tell you unless prohibited by law.
3.Confidentiality and personnel
- •Access is limited to personnel and partners who need it for their role, on a least-privilege basis.
- •Everyone with access is bound by confidentiality obligations that survive the end of their engagement.
- •Administrative actions on accounts are recorded in an audit trail.
4.Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- •encryption of data in transit, with HSTS enforced;
- •passwords stored only as salted hashes;
- •optional two-factor authentication for accounts;
- •card data and identity documents excluded from our systems entirely and handled by the payment processor;
- •role-based access control with an administrative audit trail;
- •rate limiting, input validation and automated screening of uploaded files;
- •segregation of production environments, and backups; and
- •logging and monitoring for security events.
We may update these measures, provided we do not materially reduce the level of protection.
5.Sub-processors
You authorise us to engage the sub-processors below. Each is bound by written terms imposing data protection obligations no less protective than this DPA, and we remain responsible to you for their performance.
- Amazon Web Services, Inc. — United States and regional data centres
- Hosting, storage, backup and transactional email delivery.
- Stripe, Inc. and affiliates — United States, Ireland
- Payment processing, holding of funded amounts, identity verification and expert payouts.
- Intercom, Inc. — United States
- In-product support messaging and help content.
- OpenAI, L.L.C. / OpenRouter, Inc. — United States
- AI drafting and automated content moderation. Receives the listing, profile or content text being processed; instructed not to train on it.
- Expo (650 Industries, Inc.) — United States
- Push notification delivery for the mobile app, together with Apple and Google platform push services.
- MongoDB Atlas — cloud regions in use
- Managed database hosting.
- QURB LLC FZ — United Arab Emirates
- Group service provider: regional delivery, operations and support for the Middle East. Access limited to what that role requires.
- AGILE CONSULTANCY SERVICES AB — Sweden
- Group service provider: engineering, delivery and operations support for Europe. Access limited to what that role requires.
We will give notice through the Platform or by email before adding or replacing a sub-processor in a way that materially affects Customer Personal Data. You may object on reasonable data protection grounds within 30 days; if we cannot accommodate the objection, you may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused period.
6.International transfers
We are established in the United States and operate with partners in the United Arab Emirates and Sweden, so Customer Personal Data may be transferred internationally.
Where personal data is transferred out of the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses, with the UK Addendum or IDTA where applicable, incorporated into this DPA by reference. Module Two (controller to processor) applies between you and us, and Module Three (processor to processor) applies onward to sub-processors. Where a choice is required, the governing law and forum are those of Ireland unless your establishment requires otherwise, and the technical and organisational measures in section 4 are the agreed measures.
7.Assistance with data subject rights
The Platform lets you access, export, correct and delete Customer Personal Data directly, which is normally the fastest way to answer a data subject.
- •If a data subject contacts us directly about data you control, we will not respond substantively; we will refer them to you where we can identify you.
- •Where you cannot fulfil a request through the Platform, we will provide reasonable assistance, at your cost where the effort is substantial.
- •We will assist with data protection impact assessments and prior consultations to the extent the information is within our knowledge.
8.Personal data breach
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting Customer Personal Data. The notice will describe what we know: the nature of the breach, the categories and approximate volume affected, the likely consequences, and the measures taken or proposed.
We will cooperate with you and take reasonable steps to mitigate. Our notification is not an acknowledgement of fault. Notifying supervisory authorities and affected data subjects about Customer Personal Data is your responsibility as controller.
9.Return and deletion
On termination, or on your written request, we will delete or return Customer Personal Data, except where we are required to retain it by law — in particular transaction and tax records, and records needed for an open dispute, chargeback or legal claim.
- •Deletion from live systems follows the request; backups age out on their normal cycle.
- •Retained records are held only for the required purpose and remain protected by this DPA until deleted.
- •Aggregated or de-identified data that can no longer identify a person is not Customer Personal Data and may be retained.
10.Audits and information
On reasonable written request, and not more than once in a twelve-month period unless required by a supervisory authority or following a breach, we will provide the information reasonably necessary to demonstrate compliance with this DPA.
Where an on-site audit is legally required, it must be at your cost, on at least 30 days' notice, during business hours, under confidentiality, and conducted so as not to disrupt our operations or compromise the confidentiality of other customers' data.
11.General
- •Where this DPA conflicts with the Terms of Service on the processing of Customer Personal Data, this DPA prevails.
- •Where this DPA conflicts with the Standard Contractual Clauses, the Clauses prevail.
- •Liability under this DPA is subject to the limitations in our Terms of Service, except where applicable law does not permit that.
- •This DPA is governed by the same law as the Terms of Service, except where the Clauses or mandatory local law require otherwise.
Questions, countersignature requests and sub-processor objections: [email protected]. STORESWIKI LLC, Lewes, Delaware, United States of America.
This DPA is drafted to reflect how the Platform actually operates and to satisfy the usual Article 28 requirements. It is not legal advice. If you are placing significant volumes of personal data on the Platform, have your own counsel review it against your obligations.