DATA PROCESSING ADDENDUM
SellingPilot — Multi-Channel E-Commerce Hub Platform
Effective Date: June 1, 2026 | Governed by: GDPR, CCPA/CPRA, and applicable data protection law
This Data Processing Addendum ("DPA") is entered into between Alkers Solutions Inc. d/b/a SellingPilot ("SellingPilot" or "Processor") and the Seller or Customer identified in the applicable Terms of Use, SaaS Subscription Agreement, or Order Form ("Controller"). This DPA is incorporated by reference into and forms part of those agreements (the "Principal Agreement"). In the event of a conflict between this DPA and the Principal Agreement, this DPA shall control with respect to data protection matters.
This DPA applies to the extent SellingPilot processes Personal Data on behalf of the Controller in connection with the provision of the Platform's services.
SECTION 1 — DEFINITIONS
| Term | Definition |
|---|---|
| "Controller" | The natural or legal person, public authority, agency, or other body that determines the purposes and means of processing Personal Data. In the context of this DPA, the Controller is the Seller or Customer, who determines how their customers' Personal Data and Account Data are processed. |
| "Data Subject" | An identified or identifiable natural person to whom Personal Data relates. |
| "EEA" | The European Economic Area. |
| "GDPR" | Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation), as supplemented by applicable Member State law, and including the UK GDPR where applicable. |
| "Personal Data" | Any information relating to an identified or identifiable natural person. In the context of this DPA, Personal Data primarily includes information about the Controller's own customers (end consumers) that is processed by SellingPilot through the Platform. |
| "Personal Data Breach" | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed. |
| "Processing" / "Process" | Any operation or set of operations performed on Personal Data, whether or not by automated means (collecting, recording, organizing, structuring, storing, adapting, retrieving, consulting, using, disclosing, disseminating, restricting, erasing, or destroying). |
| "Processor" | A natural or legal person that processes Personal Data on behalf of the Controller. In the context of this DPA, SellingPilot is the Processor. |
| "Restricted Transfer" | A transfer of Personal Data from the EEA, UK, or Switzerland to a third country not benefiting from an adequacy decision. |
| "SCCs" | Standard Contractual Clauses for the transfer of personal data to third countries, as adopted by the European Commission (Decision 2021/914) and the equivalent UK mechanism. |
| "Sub-Processor" | Any Processor engaged by SellingPilot to carry out specific processing activities with respect to Personal Data on behalf of the Controller. |
| "Supervisory Authority" | The competent data protection authority having jurisdiction over the Controller or Processor under applicable data protection law. |
SECTION 2 — SCOPE AND NATURE OF PROCESSING
2.1 Processor Role
SellingPilot acts as a Processor with respect to Personal Data that the Controller (Seller) causes to be processed through the Platform in connection with the services described in the Principal Agreement. SellingPilot processes such Personal Data solely on behalf of and under the documented instructions of the Controller.
2.2 Controller's Independent Responsibilities
The Controller is solely responsible for: (a) determining the lawful basis for collecting and processing its customers' Personal Data; (b) providing appropriate privacy notices to Data Subjects; (c) responding to Data Subject rights requests from its own customers; and (d) ensuring that the personal data it inputs into or connects to the Platform has been lawfully obtained and may lawfully be processed by SellingPilot as Processor.
2.3 Processing Details
The nature, purpose, categories of Personal Data, categories of Data Subjects, and retention periods applicable to the processing under this DPA are set out in Schedule 1 (Processing Details) attached to this DPA. SellingPilot may process Personal Data only for the purposes and in the manner described in Schedule 1 and as otherwise directed by the Controller in writing.
SECTION 3 — PROCESSOR OBLIGATIONS
3.1 Processing on Instructions Only
SellingPilot shall process Personal Data only on documented instructions from the Controller, including as set out in this DPA and the Principal Agreement, unless required to do so by applicable law. If SellingPilot is required by law to process Personal Data other than as instructed, it shall notify the Controller of that legal requirement before processing (unless prohibited from doing so by applicable law on grounds of public interest). SellingPilot shall promptly inform the Controller if it believes any instruction violates applicable data protection law.
3.2 Confidentiality of Processing
SellingPilot shall ensure that persons authorized to process Personal Data under this DPA are subject to binding confidentiality obligations with respect to that Personal Data and are informed of the applicable data protection requirements.
3.3 Security Measures
SellingPilot shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, taking into account the nature, scope, context, and purposes of processing and the risk to the rights and freedoms of natural persons. These measures include, at minimum:
- pseudonymization and encryption of Personal Data in transit and at rest;
- ongoing confidentiality, integrity, availability, and resilience of processing systems;
- ability to restore availability and access to Personal Data in the event of a physical or technical incident;
- regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures.
Details of SellingPilot's current technical and organizational measures are set out in Schedule 3 (Technical and Organizational Measures) to this DPA.
3.4 Sub-Processors
3.4.1 Authorization
The Controller grants SellingPilot general authorization to engage Sub-Processors for the provision of the Platform services, subject to the requirements of this Section 3.4. SellingPilot's current list of approved Sub-Processors is set out in Schedule 2 to this DPA and is available at on request at support@sellingpilot.com
3.4.2 Notice of Changes
SellingPilot shall provide the Controller with not less than thirty (30) days' prior written notice (via email to the Controller's registered account address or via notice on the Platform) of any intended additions to or replacements of Sub-Processors. If the Controller objects to a new Sub-Processor on reasonable data protection grounds, the Controller must notify SellingPilot in writing within ten (10) days of the notice. The parties shall work in good faith to resolve the objection. If it cannot be resolved, either party may terminate the Principal Agreement on thirty (30) days' written notice.
3.4.3 Sub-Processor Obligations
SellingPilot shall impose on each Sub-Processor data protection obligations that are no less protective than those imposed on SellingPilot under this DPA. SellingPilot shall remain liable to the Controller for the performance of each Sub-Processor's obligations to the extent provided for under applicable law.
3.5 Data Subject Rights Assistance
Taking into account the nature of the processing and the information available to it, SellingPilot shall provide reasonable assistance to the Controller in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection law (including rights of access, rectification, erasure, restriction, portability, and objection). SellingPilot shall notify the Controller promptly — within five (5) business days — if it receives a Data Subject request that relates to the Controller's Personal Data, and shall not respond to such requests directly without the Controller's authorization.
3.6 Cooperation and Compliance Assistance
SellingPilot shall, taking into account the nature of the processing and the information available to it, provide the Controller with reasonable assistance in ensuring compliance with: (a) security obligations under Article 32 GDPR; (b) obligations to notify Personal Data Breaches to supervisory authorities and Data Subjects; (c) data protection impact assessments (DPIAs); and (d) prior consultations with supervisory authorities. Such assistance may be subject to SellingPilot's standard professional services fees, where the scope of assistance goes beyond what is ordinarily included in the Platform services.
3.7 Audit Rights
SellingPilot shall make available to the Controller all information necessary to demonstrate compliance with the obligations of this DPA and, upon the Controller's reasonable written request (given no less than thirty (30) days' notice), shall allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller. Such audits shall be conducted: (a) at the Controller's expense; (b) no more than once per calendar year (unless required by a supervisory authority); (c) during business hours with minimum disruption; and (d) subject to SellingPilot's reasonable confidentiality and security requirements. SellingPilot may, at its election, substitute an audit with a third-party certification or audit report (e.g., SOC 2 Type II, ISO 27001) where it covers the relevant processing activities.
SECTION 4 — PERSONAL DATA BREACHES
4.1 Notification to Controller
SellingPilot shall notify the Controller without undue delay — and in any event within forty-eight (48) hours of becoming aware — of a Personal Data Breach affecting Personal Data processed under this DPA. The notification shall, to the extent available at the time:
- describe the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected;
- provide the name and contact details of the Data Protection contact at SellingPilot;
- describe the likely consequences of the Personal Data Breach;
- describe the measures taken or proposed to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
Where it is not possible to provide all information simultaneously, SellingPilot may provide the information in phases, as it becomes available.
4.2 Cooperation
SellingPilot shall cooperate with the Controller and take reasonable steps to mitigate the effects of and to remediate the Personal Data Breach. The Controller is responsible for determining whether the breach requires notification to a Supervisory Authority or to affected Data Subjects under applicable law, and for making any such notifications. SellingPilot shall provide reasonable assistance with such notifications upon request.
SECTION 5 — INTERNATIONAL DATA TRANSFERS
5.1 Restricted Transfers
To the extent SellingPilot transfers Personal Data originating in the EEA, UK, or Switzerland to a third country that does not benefit from an adequacy decision, the parties agree that such transfers are subject to appropriate safeguards as described in this Section 5.
5.2 Standard Contractual Clauses
For Restricted Transfers, the parties hereby incorporate the SCCs (Module Two: Controller to Processor) as adopted by the European Commission in Decision 2021/914, or the equivalent UK International Data Transfer Addendum (UK IDTA), as applicable. The SCCs and UK IDTA are incorporated by reference into this DPA and take effect as between SellingPilot and the Controller with the following parameterization:
- Clause 7 (Docking Clause): the optional docking clause is included;
- Clause 9 (Use of Sub-Processors): Option 2 (general written authorization) is selected, with a thirty (30)-day notice period for changes;
- Clause 11 (Redress): the optional independent redress mechanism is not included;
- Clause 17 (Governing Law): the SCCs are governed by the law of Ireland (or, for UK transfers, the laws of England and Wales);
- Clause 18 (Choice of Forum and Jurisdiction): disputes are submitted to the courts of Ireland (or England and Wales for UK transfers);
- Annex I (List of Parties): the parties are identified as set out in Schedule 1 to this DPA;
- Annex II (Technical and Organizational Measures): as set out in Schedule 3 to this DPA;
- Annex III (Sub-Processors): as set out in Schedule 2 to this DPA.
In the event of a conflict between this DPA and the SCCs, the SCCs shall prevail with respect to Restricted Transfers to which they apply.
SECTION 6 — CCPA / CPRA SERVICE PROVIDER PROVISIONS
6.1 Service Provider Designation
To the extent the California Consumer Privacy Act (CCPA) as amended by the CPRA applies to the processing of Personal Data under this DPA, SellingPilot acts as a "Service Provider" as defined under the CCPA/CPRA, processing Personal Data on behalf of the Controller ("Business") pursuant to a written contract that prohibits SellingPilot from:
- selling or sharing the Personal Data (as defined under CCPA/CPRA);
- retaining, using, or disclosing the Personal Data for any purpose other than providing the services specified in the Principal Agreement or as otherwise permitted by the CCPA/CPRA;
- retaining, using, or disclosing the Personal Data outside of the direct business relationship between SellingPilot and the Controller;
- combining the Personal Data with personal information received from other sources (except as permitted by the CCPA/CPRA).
6.2 Consumer Rights Requests
Upon receipt of a verifiable consumer request that relates to Personal Data processed by SellingPilot as a Service Provider, SellingPilot shall notify the Controller within five (5) business days and cooperate with the Controller's response. SellingPilot shall not independently fulfill consumer rights requests with respect to the Controller's Personal Data without the Controller's authorization.
6.3 Compliance Certification
SellingPilot certifies that it understands the restrictions on processing set forth in Section 6.1 and will comply with them. SellingPilot shall notify the Controller promptly if it determines it can no longer meet its obligations as a Service Provider under the CCPA/CPRA.
SECTION 7 — RETURN AND DELETION OF PERSONAL DATA
Upon expiry or termination of the Principal Agreement, or upon the Controller's written request, SellingPilot shall, at the Controller's election: (a) return to the Controller all Personal Data processed under this DPA in a commercially reasonable format; or (b) securely delete all such Personal Data from its live systems. SellingPilot shall complete the return or deletion within thirty (30) days of the written request or termination date, and shall provide written confirmation of deletion upon request. SellingPilot may retain Personal Data to the extent required by applicable law (including for tax, financial, and legal compliance purposes), subject to the confidentiality and security obligations of this DPA. Backup copies of deleted Personal Data shall be overwritten in the ordinary course within ninety (90) days of deletion from live systems.
SECTION 8 — TERM AND TERMINATION
This DPA enters into force on the Effective Date and continues for the duration of the Principal Agreement. It will automatically terminate upon the termination or expiration of the Principal Agreement, subject to survival of obligations with respect to Personal Data not yet returned or deleted. Sections 3.3 (Security Measures), 4 (Personal Data Breaches), 7 (Return and Deletion), and any obligations that by their nature survive, shall survive termination of this DPA.
SECTION 9 — GENERAL PROVISIONS
9.1 Precedence
This DPA supplements and forms part of the Principal Agreement. In the event of a conflict or inconsistency between this DPA and the Principal Agreement with respect to the protection of Personal Data, this DPA shall take precedence. The terms of the Principal Agreement continue to apply to all other matters.
9.2 Governing Law
This DPA is governed by the laws of the State of California, without regard to conflict of law principles, except to the extent that the SCCs apply different governing law to Restricted Transfers, in which case the SCCs governing law applies to those transfers.
9.3 Liability
Each party's liability arising out of or related to this DPA is subject to the limitations of liability set forth in the Principal Agreement. However, SellingPilot's liability under the SCCs shall not be limited below the minimum required by the SCCs. Nothing in this DPA limits either party's liability to Data Subjects or Supervisory Authorities under applicable data protection law.
9.4 Entire Agreement on Data Protection
This DPA, together with the Schedules attached hereto and the SCCs (where applicable), constitutes the entire agreement between the parties with respect to the subject matter of data processing and supersedes all prior agreements, representations, and understandings relating to that subject matter.
SCHEDULE 1 — PROCESSING DETAILS
| Item | Details |
|---|---|
| Parties | Controller: Seller / Customer (identified in Principal Agreement). Processor: Alkers Solutions Inc. d/b/a SellingPilot, 21688 Gateway Center Drive, Suite 300, Diamond Bar, CA 91765. |
| Subject Matter | Processing of Personal Data in connection with SellingPilot's provision of multi-channel e-commerce hub platform services. |
| Duration | Duration of the Principal Agreement plus any applicable retention periods. |
| Nature of Processing | Storage, retrieval, transmission, organization, and deletion of Personal Data in the course of providing channel integration, order management, inventory management, customer engagement, and analytics services. |
| Purpose of Processing | To provide the Platform services as described in the Principal Agreement and as directed by the Controller. Processing includes: (1) transmitting order and customer contact data between channels and the Platform; (2) storing order history and customer interaction records; (3) providing analytics derived from transaction and customer engagement data. |
| Categories of Personal Data | End-consumer names and contact information (email, phone, shipping address); order details and purchase history; customer communication records; payment status data (not full payment card data); customer review and feedback data; IP addresses where transmitted by channels. |
| Categories of Data Subjects | End consumers of the Controller (Seller's customers) who have transacted or interacted with the Seller through connected sales channels. |
| Special Categories | None intended. Controller must not input special category data (as defined under GDPR Article 9) into the Platform without SellingPilot's prior written consent. |
| Retention | During the Subscription Term plus thirty (30) days following expiry/termination (live systems). Up to ninety (90) days in backup systems thereafter. |
SCHEDULE 2 — APPROVED SUB-PROCESSORS
The following categories of Sub-Processors are currently authorized. A specific list of named Sub-Processors is available upon request at support@sellingpilot.com. SellingPilot will maintain an up-to-date named sub-processor list accessible to Controllers.
| Category | Processing Activity | Location(s) |
|---|---|---|
| Cloud Infrastructure Provider | Hosting, storage, and computing for the Platform and all data | United States |
| Database / Storage Services | Structured storage of order, inventory, and customer data | United States |
| Email / Notification Services | Transactional email delivery to Sellers and Team Members | United States |
| Analytics Platform | Aggregated platform usage analytics (no individual PII exposed) | United States |
| Customer Support Platform | Ticketing and support communications | United States |
| Identity Verification Service | Account verification and fraud prevention signals | United States |
| Payment Processor | Subscription billing — does not receive Consumer Personal Data | United States |
SCHEDULE 3 — TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)
SellingPilot implements and maintains the following technical and organizational measures to protect Personal Data processed under this DPA. These measures are reviewed and updated regularly as part of SellingPilot's information security program.
A. Access Controls
- Role-based access control (RBAC): access to Personal Data is restricted to personnel with a documented business need;
- Principle of least privilege enforced across all systems;
- Multi-factor authentication (MFA) required for all system administrator access;
- Privileged access management (PAM) controls for infrastructure and database access;
- Regular access reviews and prompt de-provisioning upon role change or termination.
B. Encryption
- Data in transit: TLS 1.2 or higher for all data transmitted between users and the Platform and between Platform components;
- Data at rest: AES-256 encryption for all databases and storage volumes containing Personal Data;
- Encryption key management: keys managed using industry-standard key management systems with separation of key custodians.
C. Physical Security
- Data centers operated by SellingPilot's cloud infrastructure sub-processor, which maintains SOC 2 Type II or ISO 27001 certification;
- No SellingPilot personnel physical access to production hardware in sub-processor facilities;
- Office access controls: keycard and badge access to SellingPilot office facilities.
D. System and Network Security
- Firewall and network segmentation between production environments and other network zones;
- Intrusion detection and prevention systems (IDS/IPS);
- Regular vulnerability scanning and patch management program;
- Annual penetration testing of Platform and critical infrastructure by qualified third-party security firm;
- DDoS mitigation controls.
E. Incident Response and Business Continuity
- Documented incident response plan with defined roles, responsibilities, and escalation procedures;
- Personal Data Breach notification procedure consistent with Section 4 of this DPA;
- Recovery time objective (RTO) and recovery point objective (RPO) defined and tested periodically;
- Regular backup of production data with encrypted off-site/offsite replication.
F. Organizational Measures
- Data protection training provided to all personnel who process Personal Data, at onboarding and annually thereafter;
- Security awareness program covering phishing, social engineering, and data handling best practices;
- All employees and contractors with access to Personal Data bound by confidentiality obligations;
- Vendor/sub-processor security assessment program: security and data protection due diligence before onboarding new Sub-Processors;
- Data protection policies and procedures maintained, reviewed, and updated at least annually.
SellingPilot may update its TOMs from time to time to reflect improvements in security technology and practices, provided that updates do not materially reduce the level of protection afforded to Personal Data. SellingPilot will notify the Controller of any material reduction in the security measures upon request.
© 2026 Alkers Solutions Inc. d/b/a SellingPilot. All Rights Reserved. This Data Processing Addendum was last updated on June 1, 2026.