Data Processing Addendum
Version 1.0 · Effective October 20, 2026 for existing customers; effective upon acceptance for customers who accept the Terms on or after October 20, 2026.
This Data Processing Addendum (the "DPA") is entered into by Ad Badger Inc., a Delaware corporation that offers the Service under the Buy Box Checker name ("Processor"), and the customer that accepts the Terms of Service ("Customer"). This DPA is incorporated into and forms part of the Terms of Service available at https://www.buyboxchecker.com/terms (the "Terms"). The Terms, any applicable order, and this DPA are together the "Agreement." This DPA takes effect, without a separate signature, when Customer accepts the Terms, to the extent Processor processes Customer Personal Data subject to Applicable Data Protection Law. Capitalized terms not defined in this DPA have the meanings given in the Terms.
1. Definitions
1.1 Applicable Data Protection Law means the GDPR, UK Data Protection Law, and any other data-protection law that the parties expressly identify in an applicable order as governing Processor's processing of Customer Personal Data.
1.2 Controller, Data Subject, Personal Data, Personal Data Breach, processing, and Processor have the meanings given in Applicable Data Protection Law.
1.3 Customer Personal Data means Personal Data that Processor processes on Customer's behalf in providing the Service. It excludes Personal Data that Processor processes as an independent Controller under Section 2.3.
1.4 EU SCCs means the standard contractual clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
1.5 GDPR means Regulation (EU) 2016/679.
1.6 Restricted Transfer means a transfer of Personal Data that requires a safeguard under Chapter V of the GDPR or UK Data Protection Law.
1.7 Service has the meaning given in the Terms.
1.8 Subprocessor means a third party appointed by Processor to process Customer Personal Data on Customer's behalf. A customer-selected recipient described in Section 8.4 is not a Subprocessor.
1.9 UK Addendum means the International Data Transfer Addendum to the EU SCCs, template Addendum B.1.0 issued by the UK Information Commissioner and laid before Parliament on February 2, 2022, as revised under Section 18 of its mandatory clauses.
1.10 UK Data Protection Law means the UK GDPR, the Data Protection Act 2018, and binding regulations made under either, in each case as amended.
1.11 UK GDPR has the meaning given in Section 3(10), as supplemented by Section 205(4), of the Data Protection Act 2018.
2. Scope and Roles
2.1 This DPA applies only to Processor's processing of Customer Personal Data subject to Applicable Data Protection Law. The processing details are in Schedule 1.
2.2 For Customer Personal Data, Customer is a Controller and Processor is a Processor, unless Customer acts as a Processor for another Controller, in which case Processor is Customer's Subprocessor. Customer is responsible for the lawfulness of its instructions, the accuracy and quality of Customer Personal Data it provides, and any notices, legal bases, consents, and authorizations required for that processing.
2.3 Processor acts as an independent Controller for business-contact, account-administration, billing, fraud-prevention, security, legal-compliance, and service-analytics processing for which Processor determines the purposes and essential means. Processor may also act as an independent Controller to the extent it determines the purposes and essential means of collecting, normalizing, inferring, securing, retaining, or aggregating publicly available third-party seller information. This DPA does not govern that independent-Controller processing, which must be described in Processor's Privacy Policy. To the extent Customer submits third-party seller information or instructs Processor to process it solely for Customer-specific monitoring, Section 2.2 applies.
2.4 Each party will comply with Applicable Data Protection Law in performing its obligations under this DPA.
3. Documented Instructions
3.1 Processor will process Customer Personal Data only on Customer's documented instructions, including the Terms, Customer's configuration and use of the Service, an applicable order, and this DPA. Processor may process Customer Personal Data as required by law, but will notify Customer before doing so unless law prohibits notice.
3.2 Processor will promptly inform Customer if, in Processor's reasonable opinion, an instruction infringes Applicable Data Protection Law. Processor may suspend the affected processing while the parties address the issue.
3.3 Processor will not process Customer Personal Data for Processor's own commercial purposes, for advertising, or for any purpose other than providing the Service under Customer's documented instructions, except as Applicable Data Protection Law permits or requires.
3.4 Processor will not use Customer Personal Data to train, fine-tune, or improve a machine-learning model, except a model used solely to provide the Service to Customer within Customer's documented instructions. Processor will contractually require the same restriction of any Subprocessor providing artificial-intelligence functionality.
4. Confidentiality
Processor will ensure that each person authorized to process Customer Personal Data is subject to an appropriate duty of confidentiality and receives access only as needed to perform that person's responsibilities.
5. Security
5.1 Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects, Processor will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
5.2 The measures in Schedule 2 form part of this DPA. Processor may update them if the update does not materially reduce the overall security of the Service.
5.3 Customer is responsible for securely configuring its account, managing user access and credentials, securing systems under its control, and using the Service consistently with its risk profile.
6. Personal Data Breach
6.1 Processor will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
6.2 As information becomes reasonably available, the notice will describe the nature of the breach, the categories and approximate number of affected Data Subjects and records, likely consequences, measures taken or proposed, and a contact for further information. Processor may provide information in phases.
6.3 Processor will take reasonable steps to contain, investigate, and mitigate the Personal Data Breach. Customer is responsible for determining whether to notify a supervisory authority or Data Subject, and Processor will provide reasonable assistance required by Applicable Data Protection Law.
6.4 Processor's notice or response is not an admission of fault or liability.
7. Assistance
7.1 Taking into account the nature of processing, Processor will provide appropriate technical and organizational assistance for Customer to respond to requests by Data Subjects. If a Data Subject contacts Processor directly about Customer Personal Data, Processor will direct the request to Customer and will not respond except on Customer's documented instructions or as required by law.
7.2 Taking into account the nature of processing and information available to Processor, Processor will provide reasonable assistance with Customer's obligations concerning security, breach notifications, data-protection impact assessments, and prior consultations.
7.3 Processor may charge Customer its reasonable costs for assistance materially beyond the ordinary functionality or support included in the Service, unless the assistance is required because Processor breached this DPA.
8. Subprocessors
8.1 Customer generally authorizes Processor to appoint the Subprocessors identified on the current list at https://www.buyboxchecker.com/sub-processors. That online list controls only as to which providers are current and the general function each performs if it differs from Schedule 3. It does not amend or limit the parties' roles, the categories of Personal Data described in this DPA, or Section 8.3, including Processor's automatic notice obligation and Customer's objection and termination rights. Schedule 3 records the list as of the date of this DPA.
8.2 Processor will enter into a written agreement with each Subprocessor that imposes data-protection obligations materially equivalent to those required by Applicable Data Protection Law for the services the Subprocessor performs. Processor remains responsible for a Subprocessor's performance of those obligations to the extent required by Applicable Data Protection Law.
8.3 Processor will automatically give at least 30 days' prior notice by email to the privacy contact in Customer's account before a new Subprocessor begins processing Customer Personal Data. Customer need not subscribe to or request that notice. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith to resolve the objection. If they cannot, Processor may avoid the Subprocessor or provide a commercially reasonable alternative. If neither is reasonably available, Customer may terminate the affected portion of the Service by written notice and receive a prorated refund of prepaid fees for the unused terminated period. That refund is Customer's sole monetary remedy for an unresolved Subprocessor objection, subject to liability that cannot be limited by law.
8.4 A third-party service, integration, or artificial-intelligence assistant that Customer connects to the Service is not a Subprocessor. Customer is the Controller of Customer Personal Data disclosed to that recipient and is responsible for the lawfulness of the disclosure and for any required transfer mechanism.
9. Return and Deletion
9.1 During the term, Customer may export Customer Personal Data using available Service functions.
9.2 After termination or Customer's valid written request, Processor will delete or return Customer Personal Data within 30 days, at Customer's choice, unless applicable law requires retention. Data retained in backups will remain protected, will not be restored except for disaster recovery or legal necessity, and will be deleted under Processor's ordinary backup cycle. If backup data is restored, Processor will reapply the applicable deletion request or restriction as soon as reasonably practicable.
9.3 On written request, Processor will confirm completion of deletion. Processor may retain records necessary to demonstrate compliance, resolve disputes, prevent fraud, and meet legal, tax, and accounting duties, provided those records remain protected and are not used for another purpose.
10. Information and Audits
10.1 Processor will make available information reasonably necessary to demonstrate compliance with Article 28 of the GDPR or the equivalent UK GDPR obligation. Processor may satisfy this duty first through current third-party reports, certifications, security summaries, and written responses.
10.2 If that information is not reasonably sufficient, Customer may conduct one audit in a 12-month period through an independent auditor that is not Processor's competitor and is bound by confidentiality. Customer must give at least 30 days' prior notice, conduct the audit during normal business hours, avoid disruption and access to another customer's data, and bear its costs. Processor will bear reasonable audit costs only if the audit identifies a material breach of this DPA by Processor.
10.3 The frequency and notice limits do not apply after a material Personal Data Breach affecting Customer Personal Data, when Customer has reasonable documented grounds to suspect material noncompliance, or when a supervisory authority requires an audit. Processor may require reasonable scope, security, and confidentiality safeguards.
10.4 Processor will maintain the records of processing required of a Processor by Applicable Data Protection Law and will make them available to a competent supervisory authority as legally required.
11. Regulatory Cooperation
Processor will cooperate with a competent supervisory authority as required by Applicable Data Protection Law. Processor will notify Customer of a legally binding demand for Customer Personal Data unless law prohibits notice. Where legally permitted and reasonably appropriate, Processor will challenge a demand that conflicts with this DPA or Applicable Data Protection Law.
12. International Transfers
12.1 Processor will not make a Restricted Transfer unless the transfer is covered by an adequacy decision, the EU SCCs, the UK Addendum, or another lawful transfer mechanism.
12.2 For an EEA Restricted Transfer from Customer to Processor, the EU SCCs are incorporated into this DPA in their unmodified form, completed as stated in Schedule 4. Module Two applies where Customer is a Controller. Module Three applies where Customer is a Processor.
12.3 For a UK Restricted Transfer from Customer to Processor, the UK Addendum applies to the EU SCCs as completed in Schedule 5.
12.4 Before a UK Restricted Transfer relies on an Article 46 safeguard, the party responsible for initiating the transfer will, acting reasonably and proportionately, document whether the data protection test in Article 46(6) to (8) of the UK GDPR is met. The test must consider whether the protection provided after transfer, viewed as a whole, would be materially lower than the protection under the UK GDPR and relevant parts of the Data Protection Act 2018. Each party will provide information and cooperation reasonably necessary for that assessment and will implement any supplementary measures identified as necessary.
12.5 If a party determines that a selected safeguard no longer provides the required protection or that the data protection test is not met, the parties will work in good faith to implement supplementary measures or another lawful mechanism. Processor may suspend the affected transfer if no lawful mechanism is reasonably available.
12.6 The transfer mechanisms in this DPA address transfers of Customer Personal Data from Customer to Processor. They do not, by themselves, govern a transfer from an upstream data collector to Processor when Customer is not the exporter.
13. Liability
The liability of each party arising out of or relating to this DPA is subject to the exclusions and limitations in the Agreement, except to the extent the EU SCCs, UK Addendum, or Applicable Data Protection Law prohibits that limitation. Nothing in this DPA limits a Data Subject's rights under the EU SCCs or UK Addendum.
14. Order of Precedence
If documents conflict concerning Customer Personal Data, the following order controls: (a) the EU SCCs or UK Addendum for the Restricted Transfer they govern; (b) this DPA; and (c) the remainder of the Agreement. This DPA does not vary the EU SCCs or the mandatory clauses of the UK Addendum.
15. Term and General Terms
15.1 This DPA continues while Processor processes Customer Personal Data. Duties that by their nature continue, including confidentiality, deletion, audit, transfer, and liability provisions, survive termination.
15.2 The governing-law and dispute provisions of the Terms apply to this DPA, except where the EU SCCs or UK Addendum requires otherwise.
15.3 A change to this DPA must be in writing and agreed by both parties, except that Processor may update a schedule to reflect a permitted Subprocessor change, an improvement that does not materially reduce protection, or a binding change to Applicable Data Protection Law or an approved transfer mechanism.
15.4 If a provision of this DPA is unenforceable, it will be modified to the minimum extent necessary, and the remainder will remain effective.
Schedule 1: Processing Details
A. Subject matter and purpose
Processor processes Customer Personal Data to provide, secure, maintain, and support the Service according to Customer's documented instructions and the Agreement. The Service monitors public Amazon product pages for ASINs and locations selected by Customer and provides related account, analytics, notification, support, API, webhook, and artificial-intelligence-assisted functionality.
B. Duration
Processing continues for the term of the Agreement and the deletion period in Section 9, subject to legal retention and backup cycles.
C. Nature and operations
Collection, recording, organization, structuring, storage, retrieval, consultation, analysis, inference, transmission, display, support access, restriction, deletion, and anonymization, as needed for the Service.
D. Data Subjects
- Customer's account owners, administrators, users, employees, contractors, and business contacts.
- Individuals who communicate with Customer or Processor through support channels about Customer's account.
- Individual sellers or contacts whose publicly available information appears on Amazon product pages monitored at Customer's direction, only to the extent Processor processes that information solely on Customer's behalf and not as an independent Controller under Section 2.3.
- Referral participants or client contacts whose data Customer submits through the Service, if applicable.
E. Categories of Customer Personal Data
- Name, business email address, business contact information, account identifier, organization, role, and user permissions.
- Authentication and security data, excluding plaintext passwords.
- IP address, device, browser, request, login, usage, and audit-log information.
- Subscription and billing metadata, transaction history, and billing contact information. Full card details are submitted directly to Stripe and are not received by Processor.
- ASINs, brands, seller names, geographic locations or postcodes, monitoring configurations, monitoring history, alerts, competitive offers, prices, and related account analytics, to the extent those items constitute Personal Data processed on Customer's behalf.
- API, MCP, webhook, and integration identifiers, configurations, prompts, requests, responses, and logs.
- Support messages, attachments, and account troubleshooting information.
- Referral codes and attribution events, if Customer uses the referral functionality.
F. Sensitive Personal Data
The Service is not designed for special-category data under Article 9 of the GDPR, criminal-offence data under Article 10, government identifiers, financial-account credentials, health data, biometric data, or similarly sensitive data. Customer must not submit such data unless the parties first agree in writing on additional safeguards.
G. Frequency
Continuous or recurring during Customer's use of the Service, including daily monitoring and notifications where configured.
H. Retention
- Account and monitoring data: while the account is active and ordinarily deleted or anonymized within 30 days after a valid deletion request or termination.
- Billing and transaction records: only for the period required by tax, accounting, fraud-prevention, and legal obligations.
- Support communications: only while needed to provide support, administer the account, resolve a dispute, or satisfy a legal obligation, under Processor's documented retention schedule.
- Security, access, API, and audit logs: for the period established in Processor's documented security and evidentiary retention schedule.
- Session replay and product analytics: for the configured product-analytics retention period, subject to consent, minimization, and masking controls.
- Backups: until overwritten or deleted in Processor's ordinary documented backup cycle.
Schedule 2: Technical and Organizational Measures
Processor will maintain measures appropriate to the Service and risk, including:
- A written information-security program with assigned responsibility, periodic risk review, and security policies proportionate to Processor's size and processing.
- Unique user identifiers, role-based access, least-privilege access, prompt access revocation, and periodic access review.
- Multi-factor authentication for privileged access to production infrastructure, database administration, and cloud-provider consoles.
- Industry-standard encryption for Customer Personal Data in transit over public networks and encryption at rest for production databases and backups containing Customer Personal Data or documented compensating controls providing materially equivalent protection where encryption at rest is not technically available.
- Secure credential management, salted and cryptographically hashed user passwords, and protection of API keys and secrets.
- Logical separation of customer accounts and controls designed to prevent unauthorized cross-account access. Session-replay tools will be configured to mask passwords, payment fields, credentials, and other sensitive inputs and to exclude pages or fields that cannot be captured safely.
- Logging and monitoring of material authentication, administrative, and security events, with restricted access to logs.
- Secure-development practices, code review for material changes, dependency management, vulnerability assessment, and risk-based remediation and patching.
- Malware protection and endpoint-security measures appropriate to systems used to access production Customer Personal Data.
- Tested backup, restoration, business-continuity, and disaster-recovery procedures proportionate to the Service.
- A documented incident-response process covering identification, containment, investigation, remediation, evidence preservation, and notification.
- Personnel confidentiality obligations and periodic security and privacy awareness training for personnel with access to Customer Personal Data.
- Subprocessor diligence and contractual security and data-protection obligations appropriate to each provider's role.
- Secure deletion or anonymization procedures and controls limiting restored backup data to disaster-recovery or legal-necessity use.
- Physical security inherited from vetted hosting providers and reasonable physical safeguards for Processor-controlled workplaces and devices.
- Periodic testing or assessment of the effectiveness of material security controls.
Schedule 3: Current Subprocessors and Material Providers
The current list at https://www.buyboxchecker.com/sub-processors controls only as provided in Section 8.1. The table below records the public list as of August 13, 2026.
| Provider | Function | Data processed | Processing location |
|---|---|---|---|
| Supabase | Database and authentication | Account data, monitoring configuration, and history | United States |
| Vercel | Application hosting and content delivery | Request metadata and IP addresses | United States |
| Stripe | Payment processing and subscription billing | Billing contact and transaction data | United States |
| Amazon data collection provider identified on the public list | Collection of public Amazon product-page data | ASINs and monitored locations submitted to the collector; returned fields may include seller names, seller identifiers, offers, prices, and other page data that constitute Personal Data in context, subject to the role allocation in Section 2.3 | European Union |
| Resend | Transactional and digest email | Email address and message content | United States |
| Inngest | Background job orchestration | Account and ASIN identifiers in job payloads | United States |
| PostHog | Analytics and session replay | Usage events, identity, device and browser metadata, and dashboard sessions | United States |
| Google Analytics and Google Tag Manager | Website analytics | Pseudonymous usage and device or browser metadata | United States |
| Google Gemini API | Artificial-intelligence summaries | Seller name, ASINs, locations or postcodes, status, competing sellers, and prices | United States |
| Cloudflare | DNS and bot protection | IP address and request metadata | United States |
| Chatwoot | Self-hosted customer-support application | Name, email, and support content | United States, Oregon |
| Hetzner | Hosting for self-hosted Chatwoot | Support-system data at rest | United States, Oregon |
| FirstPromoter | Referral and affiliate attribution | Codes, events, identity, email, and account identifier | European Union |
Directly loaded third-party content identified on the public page, including Amazon's image content-delivery network, jsDelivr, and YouTube, is not listed as Subprocessor processing on Processor's behalf. Processor will describe those direct disclosures and the parties' roles in its Privacy Policy.
Schedule 4: EU Standard Contractual Clauses
1. Modules. Module Two applies when Customer is a Controller and Processor is a Processor. Module Three applies when Customer is a Processor and Processor is a Subprocessor.
2. Clause 7. The optional docking clause applies.
3. Clause 9. Option 2, general written authorization, applies. The notice period is the period in Section 8.3 of this DPA.
4. Clause 11. The optional independent dispute-resolution language does not apply.
5. Clause 13 and Annex I.C. If Customer is established in the EEA, the competent supervisory authority is the authority responsible for Customer. If Customer is not established in the EEA but must appoint an Article 27 representative, it is the authority for the representative's Member State. If neither rule identifies an authority and Customer has not notified Processor of another authority properly competent under Clause 13, the Irish Data Protection Commission is identified in Annex I.C.
6. Clause 17. Option 1 applies. The EU SCCs are governed by the law of Ireland.
7. Clause 18. Any dispute arising from the EU SCCs will be resolved by the courts of Ireland.
8. Annex I.A. The data exporter is Customer, identified by the legal entity name, registered address, privacy contact, role, and other account or order details recorded when Customer accepts the Terms. The data importer is Ad Badger Inc., 2028 E Ben White Blvd, Ste 240-4800, Austin, Texas 78741, USA; privacy contact: help@buyboxchecker.com. Activities are described in Schedule 1. Processor's append-only acceptance record provides the signature and date for Annex I.A.
9. Annex I.B. The categories of Data Subjects, Personal Data, sensitive data, frequency, nature, purpose, and duration are in Schedule 1. No special-category data is intended.
10. Annex I.C. The competent authority is identified under item 5.
11. Annex II. The technical and organizational measures are in Schedule 2.
12. Annex III. Annex III does not apply because Clause 9 Option 2, general written authorization, applies. Processor's current Subprocessors are identified for purposes of Section 8.1 on the controlling online list and recorded in Schedule 3 as of the DPA date.
13. Conflicts. Nothing in the Agreement modifies the EU SCCs. If this DPA conflicts with the EU SCCs for a Restricted Transfer, the EU SCCs control.
Schedule 5: UK International Data Transfer Addendum
For a UK Restricted Transfer, the UK Addendum is incorporated and completed as follows. This Schedule 5 supplies the information required by Part 1 of the UK Addendum. By accepting the Terms, each party enters into this Schedule 5 and the UK Addendum as a legally binding contract, and Data Subjects may enforce the rights granted to them by the UK Addendum. No UK Restricted Transfer may begin until the exporter details required by Table 1 are complete in Customer's account or applicable order and in Processor's append-only acceptance record, and the information required by Tables 2 and 3 is complete in the Agreement.
Table 1: Parties and Start Date
Exporter. Customer, with the legal entity name, registered address, privacy contact, and other details recorded in its account or applicable order and in Processor's acceptance record. Customer may be a Controller or Processor as stated in Section 2.
Importer. Ad Badger Inc., 2028 E Ben White Blvd, Ste 240-4800, Austin, Texas 78741, USA; help@buyboxchecker.com. Importer is a Processor or Subprocessor.
Start date. The date Customer accepts the Terms, as recorded in Processor's append-only acceptance log.
Each party may receive notices at the contact details in the Agreement. Acceptance of the Terms constitutes signature of the UK Addendum.
Table 2: Selected SCCs, Modules, and Clauses
The Addendum EU SCCs are the EU SCCs incorporated under Schedule 4 by reference to the Annex to Commission Implementing Decision (EU) 2021/914 of June 4, 2021. A copy is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj and from Processor on request. Module Two or Module Three applies according to the parties' roles. Clause 7 applies. Clause 9 Option 2 applies with the Section 8.3 notice period. Clause 11 does not apply.
Table 3: Appendix Information
Annex I.A and I.B information appears in Schedules 1 and 4. Annex II appears in Schedule 2. Annex III does not apply because Clause 9 Option 2 applies. Processor's current Subprocessors are identified on the controlling online list described in Section 8.1 and recorded in Schedule 3 as of the DPA date.
Table 4: Ending the Addendum
Neither party may end the UK Addendum under Section 19 of its mandatory clauses solely because the Information Commissioner issues a revised approved addendum. The parties will implement a lawful replacement or amendment as required.
Mandatory Clauses
Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
The block quotation above incorporates Part 2 by reference without modification. The parties will not amend the UK Addendum except as Sections 16 and 17 of Part 2 permit and will not modify the approved EU SCCs except as Section 12 of Part 2 permits. If this DPA conflicts with the mandatory clauses for a UK Restricted Transfer, the mandatory clauses control.
