Legal
Data processing addendum
Last updated 6 October 2026
This addendum forms part of the VendorDue Terms of Service and sets out the terms on which VendorDue processes personal data on behalf of merchants.
On this page
- 1. Scope
- 2. Definitions
- 3. Roles of the parties
- 4. The Merchant's obligations
- 5. Processing on instructions
- 6. Confidentiality
- 7. Security
- 8. Subprocessors
- 9. Data subject requests
- 10. Security incidents
- 11. Assistance
- 12. Return and deletion
- 13. Audits
- 14. International transfers
- 15. United States privacy laws
- 16. Liability
- 17. Changes to this DPA
- Schedule 1. Details of the processing
- Schedule 2. Technical and organisational measures
1. Scope
This Data Processing Addendum ("DPA") supplements and forms part of the VendorDue Terms of Service (the "Terms") between VendorDue ("VendorDue", "we" or "us") and the merchant that uses the Services (the "Merchant" or "you"). It applies where VendorDue processes Store Personal Data on the Merchant's behalf in providing the Services. By agreeing to the Terms, the Merchant agrees to this DPA, and no separate signature is required.
If this DPA conflicts with the Terms regarding the processing of Store Personal Data, this DPA prevails. If this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
2. Definitions
Capitalised terms not defined in this DPA have the meanings given in the Terms. In this DPA:
- "Data Protection Laws" means all laws relating to the processing of personal data that apply to a party's processing of Store Personal Data under the Terms, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act and India's Digital Personal Data Protection Act, 2023, each as amended or replaced from time to time.
- "GDPR" means Regulation (EU) 2016/679, and "UK GDPR" means the GDPR as it forms part of the law of the United Kingdom.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, Store Personal Data.
- "Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
- "Store Personal Data" means personal data in the records that the Merchant and its users submit to the Services, or that VendorDue receives from Shopify for the Merchant, in connection with the Services.
- "Subprocessor" means a third party engaged by VendorDue to process Store Personal Data.
"Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. "Service provider", "sell" and "share" have the meanings given in the California Consumer Privacy Act.
3. Roles of the parties
For Store Personal Data, the Merchant is the controller and VendorDue is the processor. Where the Merchant processes Store Personal Data on behalf of another controller, VendorDue is its subprocessor, and the Merchant is responsible for obtaining any authorisation that controller requires. VendorDue is a controller of the personal data it processes for its own purposes, such as account, billing, security and usage information, as described in its Privacy Policy. This DPA does not apply to that data.
4. The Merchant's obligations
The Merchant is responsible for the lawfulness of the Store Personal Data it provides and of its instructions to VendorDue. The Merchant represents that it has given all notices and obtained all consents and rights that Data Protection Laws require for VendorDue to process Store Personal Data as described in the Terms and this DPA. The Merchant will not submit special categories of personal data to the Services.
5. Processing on instructions
VendorDue will process Store Personal Data only on the Merchant's documented instructions, unless applicable law requires otherwise, in which case VendorDue will inform the Merchant of that requirement before processing unless the law prohibits it. The Merchant instructs VendorDue to process Store Personal Data to provide the Services in accordance with the Terms, this DPA and the Merchant's use and configuration of the Services. Further instructions require VendorDue's written agreement. VendorDue will inform the Merchant if, in its opinion, an instruction infringes Data Protection Laws.
The subject matter, nature, purpose and duration of the processing, and the types of personal data and categories of data subjects, are set out in Schedule 1.
6. Confidentiality
VendorDue will ensure that every person it authorises to process Store Personal Data is bound by an obligation of confidentiality, and that access is limited to what is necessary to provide, maintain and support the Services.
7. Security
VendorDue will implement and maintain appropriate technical and organisational measures to protect Store Personal Data, including those described in Schedule 2. VendorDue may update these measures from time to time, provided that an update does not materially reduce the overall level of protection.
8. Subprocessors
The Merchant gives VendorDue general authorisation to engage Subprocessors. VendorDue maintains a current list of its Subprocessors, which it will provide to the Merchant on request at support@vendordue.com.
VendorDue will impose on each Subprocessor, by written contract, data protection obligations that give at least the same level of protection as this DPA, and remains liable to the Merchant for each Subprocessor's performance of those obligations.
VendorDue will notify the Merchant by email at least 14 days before a new Subprocessor begins to process Store Personal Data. Within that period the Merchant may object on reasonable grounds relating to data protection. If the parties cannot resolve the objection, the Merchant may stop using the Services, and VendorDue will refund any fees paid in advance for the period after that.
9. Data subject requests
If VendorDue receives a request from a data subject about Store Personal Data, it will refer the data subject to the Merchant and will not respond to the request itself unless the Merchant instructs it to or the law requires it. Taking into account the nature of the processing, VendorDue will assist the Merchant, by appropriate technical and organisational measures and insofar as possible, in responding to such requests. The Services allow the Merchant to access, correct, export and delete Store Personal Data.
10. Security incidents
VendorDue will notify the Merchant without undue delay, and in any event within 72 hours, after confirming a Security Incident. The notice will be sent to the store owner's email address and will describe, as far as is then known, the nature of the Security Incident, the categories and approximate number of data subjects and records concerned, its likely consequences, and the measures taken or proposed to address it. Information not available at the time of the first notice will follow as it becomes available. VendorDue will take reasonable steps to contain and remedy the Security Incident. A notification is not an acknowledgement of fault or liability.
11. Assistance
Taking into account the nature of the processing and the information available to it, VendorDue will give the Merchant reasonable assistance with its obligations under Data Protection Laws relating to security, data protection impact assessments and prior consultation with supervisory authorities.
12. Return and deletion
The Merchant may export Store Personal Data at any time using the export feature in the Services. Vendors' payout addresses are left out of that export for their protection and will be provided to an administrator of the store on request. When the Merchant uninstalls VendorDue or deletes its workspace, VendorDue will delete Store Personal Data after a 48-hour period in which the decision can be reversed, and it will leave VendorDue's backups within seven days after that, unless applicable law requires it to be kept. Any Store Personal Data kept under such a requirement remains subject to this DPA until it is deleted.
13. Audits
VendorDue will make available to the Merchant, on request, the information reasonably necessary to demonstrate compliance with this DPA, including written answers to reasonable security questionnaires. Where Data Protection Laws require it, the Merchant may, no more than once in any 12-month period, on at least 30 days' written notice and at its own cost, have an independent auditor bound by confidentiality audit VendorDue's compliance. An audit must take place during normal business hours, must not unreasonably interfere with VendorDue's operations, and must not give access to the data of other merchants.
14. International transfers
VendorDue stores Store Personal Data in the United States and operates the Services from India. The Merchant authorises VendorDue and its Subprocessors to transfer Store Personal Data to, and process it in, countries other than the one in which it was collected, subject to this section.
Where Store Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses are incorporated into this DPA as follows: (a) Module Two applies where the Merchant is a controller, and Module Three where the Merchant is a processor; (b) Clause 7 applies; (c) in Clause 9, Option 2 applies, with the notice period in section 8 of this DPA; (d) the optional wording in Clause 11 does not apply; (e) in Clauses 17 and 18, the governing law and the courts are those of Ireland; and (f) Annexes I and II are completed by Schedules 1 and 2 of this DPA, and the competent supervisory authority is determined in accordance with Clause 13.
Where Store Personal Data subject to the UK GDPR is transferred, the International Data Transfer Addendum to the Standard Contractual Clauses issued by the United Kingdom's Information Commissioner applies, completed with the information in this DPA. Where Store Personal Data subject to the Swiss Federal Act on Data Protection is transferred, the Standard Contractual Clauses apply with references to the GDPR read as references to that Act, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
15. United States privacy laws
Where the California Consumer Privacy Act or a similar United States state law applies, VendorDue acts as the Merchant's service provider or processor for Store Personal Data and will not: (a) sell or share Store Personal Data; (b) retain, use or disclose Store Personal Data for any purpose other than providing the Services, or outside the direct business relationship between VendorDue and the Merchant; or (c) combine Store Personal Data with personal information it receives from other sources, except as the law permits. VendorDue will provide the level of privacy protection those laws require, will tell the Merchant if it can no longer meet its obligations under them, and allows the Merchant to take reasonable and appropriate steps to stop and remedy any unauthorised use. VendorDue certifies that it understands these restrictions and will comply with them.
16. Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Terms, to the extent Data Protection Laws permit. Nothing in this DPA limits the rights of data subjects under the Standard Contractual Clauses.
17. Changes to this DPA
VendorDue may update this DPA from time to time. VendorDue will notify store owners of a material change by email or in the Services at least 14 days before it takes effect. A change required by law may take effect sooner.
Schedule 1. Details of the processing
Parties. The data exporter is the Merchant, which may be contacted at the store owner's email address held in the Services. The data importer is VendorDue, which may be contacted at support@vendordue.com.
Categories of data subjects. The Merchant's staff and collaborators who use the Services; the Merchant's vendors and their contacts; and any other person named in records, messages or files submitted to the Services.
Categories of personal data. Names and contact details; payout addresses; details of orders relevant to vendor earnings, which do not include customers' names, contact details or addresses; consignor rates, payouts and payment records; messages and files; and sign-in and account records.
Special categories of personal data. None.
Nature and purpose of the processing. Collecting, storing, organising, calculating, displaying, transmitting, exporting and deleting Store Personal Data in order to provide the Services, including calculating vendor earnings, publishing payouts, recording payments, delivering messages and files between the Merchant and its vendors, and providing support.
Frequency. Continuous for the term of the Terms.
Duration. For the term of the Terms, and until deletion in accordance with section 12.
Schedule 2. Technical and organisational measures
VendorDue maintains the following measures.
- Encryption. Store Personal Data is encrypted in transit and at rest. Contact details, payout details, credentials, messages, notes and files are also encrypted with a key specific to each Merchant, which is itself protected by a key held outside the database.
- Separation. Each Merchant's data is logically separated, and database access is restricted so that a request made for one Merchant cannot read another Merchant's data.
- Access control. Access to Store Personal Data is limited to authorised personnel who need it, and access through VendorDue's administrative tools is recorded.
- Authentication. The Services support passkeys, authenticator apps and one-time codes, check passwords against known breaches, and ask for fresh verification before sensitive actions such as sending a payment or deleting a workspace.
- Minimal access to Shopify. The Services request read-only access to only the Shopify data they need.
- Application security. Rate limits, bot protection on public forms, protection against cross-site request forgery, and a restrictive content security policy.
- Resilience. Daily backups, each kept for seven days.
- Incident response. Procedures to detect, investigate, contain and report Security Incidents, and a published channel for reporting vulnerabilities.
- Deletion. Documented procedures for deleting a Merchant's data, including its files and encryption key.
Questions about this page: support@vendordue.com.