Commerce Spine Data Processing Addendum

Version 1.1, effective September 24, 2026. Version 1.1 only renames EcomBrain to Commerce Spine and updates the web addresses; nothing else changed. Questions: [email protected]

1. Parties and Incorporation

This Data Processing Addendum ("DPA") is between SellerPlex LLC, a Wyoming limited liability company at 1910 Thomes Ave, Cheyenne, WY 82001, USA ("SellerPlex", "we"), and the customer identified in the Commerce Spine account ("Customer", "you").

This DPA is part of, and incorporated into, the Commerce Spine Terms of Service (https://www.commercespine.com/terms/, the "Terms"). It applies whenever we process personal data contained in Customer Data on your behalf. Capitalized terms not defined here have the meanings in the Terms. For how we handle personal data on our own behalf (marketing site visitors, account contacts, billing), see the Privacy Policy (https://www.commercespine.com/privacy/).

2. Definitions, in Plain Language

3. Roles

For personal data within Customer Data, you are the controller (or business) and we are the processor (or service provider). You are responsible for having a lawful basis to collect and use that data and for the accuracy of your instructions. We are responsible for processing it only as this DPA and the Terms allow.

4. Scope and Purpose of Processing

We process Customer Data for one purpose: to operate the Commerce Spine warehouse and API for your Organization. Concretely, that means syncing your data from Amazon under the authorization you granted, storing it in your Organization's warehouse on Google Cloud Platform, serving it to your Tokens through the read-only API, and maintaining backups and logs needed to run the Service reliably.

We will not:

  1. Sell Customer Data or share it for cross-context behavioral advertising.
  2. Use Customer Data for SellerPlex's agency services or for any other customer or client.
  3. Train AI models on Customer Data.
  4. Combine Customer Data with personal data from other sources, except as needed to provide the Service to you.

Annex A describes the processing details (subject matter, duration, nature, categories of data and data subjects).

5. Customer Instructions

We process Customer Data only on your documented instructions. The Terms, this DPA, and your use of the Service's settings and features (for example, connecting or disconnecting an Amazon account, issuing or revoking a Token, cancelling your subscription) are your complete instructions. If a law requires us to process differently, we will tell you before we do, unless the law forbids that notice. If we believe an instruction violates data protection law, we will flag it and may pause the affected processing until it is resolved.

6. Confidentiality of Personnel

We limit access to Customer Data to personnel who need it to operate or support the Service, and we require everyone with access to be bound by confidentiality obligations, whether by contract or professional duty, before they touch it.

7. Security Measures

We protect Customer Data with appropriate technical and organizational measures. The specifics we commit to today:

  1. Encryption in transit. All data moves over TLS, both between Amazon and the warehouse and between the API and your clients.
  2. Encryption at rest. Warehouse data is encrypted at rest on Google Cloud Platform.
  3. Access controls. Access to production systems is restricted to authorized personnel, authenticated, and limited to what each role needs.
  4. Token security. API tokens are scoped per Organization, revocable at any time in the console, and stored hashed; we cannot read your token back after issuance.
  5. Isolation per Organization. Each Organization's data is logically isolated. Every API request is scoped to the Organization that owns the Token; requests cannot reach another Organization's data.
  6. Audit logging. We log administrative and API access so that access to Customer Data can be reviewed.

We will not materially weaken this overall level of protection during your subscription. We may improve or replace individual measures as the Service and threat landscape evolve.

8. Subprocessors

  1. Authorization. You authorize the subprocessors listed in Annex B. We remain responsible to you for their performance, and we bind each subprocessor to data protection obligations materially equivalent to this DPA.
  2. Changes. Before adding or replacing a subprocessor that will process Customer Data, we will notify you by email at least 30 days in advance. If you have a reasonable data protection objection, tell us within those 30 days and we will work with you in good faith on a solution (for example, a configuration change). If none is workable, you may cancel your subscription and receive a pro-rata refund of prepaid fees for the unused period; this is the sole remedy for a subprocessor objection.
  3. Amazon is a data source. Amazon provides your data to us under the authorization you granted through Amazon's own flow. It acts on its own agreements with you rather than on our instructions, so we treat it as a data source you control rather than a subprocessor. It is listed in Annex B for transparency.

9. Data Subject Requests

If a data subject sends us a request about personal data in your Customer Data (access, deletion, correction, and similar rights), we will not respond on your behalf; we will redirect the person to you where identifiable and notify you promptly. Given the nature of the data, we usually cannot identify a data subject inside your warehouse ourselves. Where you cannot fulfill a request through the console or API on your own, we will provide reasonable assistance at your written request.

10. Breach Notification

If we confirm a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data, we will notify you without undue delay, and in any case within 72 hours of confirming the breach. The notice will describe what happened, the data affected so far as known, and the steps we are taking. We will keep you updated as the investigation progresses and cooperate with your own notification obligations. Notification is not an admission of fault.

11. International Transfers

Customer Data is hosted in the United States on Google Cloud Platform. If you are subject to GDPR, UK GDPR, or similar laws that restrict transfers to the US, the EU Standard Contractual Clauses (module 2, controller to processor), with the UK Addendum where applicable, are incorporated into this DPA by reference and apply to those transfers. A countersigned copy is available on request via [email protected].

12. Deletion and Return on Termination

When your subscription ends, we delete your Organization's warehouse data within 30 days. Backups containing your data expire on a rolling basis and are purged within a further 35 days as part of the normal backup rotation. During the 30-day window you may ask us for reasonable help exporting your data. We may retain limited records where the law requires (for example, billing records), protected under this DPA for as long as we hold them.

13. Audit Rights

Given the size and stage of the Service, audits work as follows: on written request, no more than once per year, we will provide a summary of our security measures, relevant certifications or attestations from our infrastructure providers (for example, Google Cloud's SOC 2 and ISO 27001 reports), and written answers to reasonable security questionnaires. This is intended to satisfy audit and information rights. If your regulator requires more, we will discuss reasonable additional steps at your cost.

14. Liability

Liability under this DPA is subject to the limitations and carve-outs in Section 12 of the Terms. This DPA does not create a separate or higher cap.


Annex A: Processing Details

Annex B: Subprocessors and Data Sources

Current as of September 24, 2026. Changes follow the notice process in Section 8.2.

Entity Role What it processes Location
Google Cloud Platform (Google LLC) Subprocessor Warehouse hosting, storage, and backups for Customer Data United States
Stripe, Inc. Subprocessor Payment and billing data for the Customer's subscription (not warehouse data) United States
HighLevel Inc. (GoHighLevel) Subprocessor CRM for marketing-side lead and contact data (not warehouse data) United States
Amazon (Amazon.com, Inc. and affiliates) Data source, not a subprocessor (see Section 8.3) Provides Customer Data under the Customer's own authorization Per Amazon's infrastructure
SellerPlex LLC · 1910 Thomes Ave, Cheyenne, WY 82001, USA · [email protected]