CWILL Main Logo
Products
Solutions
Case studies
Resources
Pricing
  • Post-Purchase
    Post-Purchase
    Product Suite
    Order Tracking
    Deliver an unmatched tracking experience
    Returns & Exchanges
    Simplify management and recover lost sales
    Shipping Protection
    Ensure peace of mind with every delivery
    Customer Retention
    Menu Item Loyalty And Referrals Solution
    Product Suite
    Product Reviews
    Turn satisfied shoppers into your vocal fans
    Loyalty & Referrals
    From ‘Like it’ to ‘Love it’ with complete loyalty & referrals solution
    SEO & SpeedAll CWILL Apps
    AI Chat
    Menu Item AI Chatbot App
    Pop-Up & Email Marketing
    Menu Item Email Marketing App
  • By customer journey
    Solutions Pps
    Post-Purchase
    Elevate your post-purchase experience with order tracking, returns & exchanges and shipping protection.
    By customer journey
    Solutions CR
    Customer Retention
    Grow retention and LTV with high-impact reviews, loyalty, and referrals.
      By use case
    • Drive retention & sales growth
    • Convert post-delivery joy into reviews
    • Streamline returns management
  • Case studies
    • Company
    • About CWILL
    • Careers
    • Become a partner
    • Agency partners
    • Contact us
    • Resources
    • Case studies
    • Blog
    • Best Shopify apps
    • APIs and webhooks
    • Help center
    Discover more
    depology
    Depology’s Success Story
    See how Depology lowered support tickets and shaved a day off shipping.
    Learn More
    Arrow RightArrow Right Blue
    Post Purchase Ebook Menu Item
    The Ultimate Post-Purchase eBook
    Don’t let buyer’s remorse put revenue at risk. Act now for more repeat sales!
    Download Now
    Arrow RightArrow Right Blue
  • Pricing
Try freeBook a demo
menu iconmenu icon
Try freeBook a demo

Data Processing Agreement

Last Updated : August 8 , 2026

This Data Processing Agreement ("DPA") is incorporated by reference into CWILL's Terms of Service available at https://www.cwill.com/terms-of-service/ or other agreement governing the use of CWILL's Services ("Agreement") entered by and between you, the Client (as defined in the Agreement) (collectively, "you", "your", "Client"), and CWILL INC, a Delaware corporation, or its applicable Affiliate(s) ("CWILL", "us", "we", "our") to reflect the Parties' agreement with regard to the Processing of Personal Data by CWILL on behalf of the Client and, to the limited extent described in Section 2.1(b), as an independent Controller. Both parties shall be referred to as the "Parties" and each, a "Party".

Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.

Each Party represents and warrants that the individual executing or accepting this DPA on its behalf is duly authorized to do so. If there is any conflict or inconsistency between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA shall prevail. If there is any conflict or inconsistency between this DPA and any Standard Contractual Clauses or other data transfer mechanisms incorporated herein, the Standard Contractual Clauses or applicable transfer mechanism shall prevail solely to the extent required by applicable Data Protection Laws.

1. DEFINITIONS

(a) "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. "Control", for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.

(b) "Authorized Affiliate" means any of Client's Affiliate(s) which is explicitly permitted to use the Service pursuant to the Agreement between Client and CWILL INC but has not signed its own agreement with CWILL and is not a "Client" as defined under the Agreement.

(c) "CCPA" means the California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100 et. seq, and its implementing regulations, including as amended by the California Privacy Rights Act.

(d) "Confidential Information" means all non-public information disclosed by one Party to the other Party in connection with this DPA, designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure, including Personal Data, Security Measures, audit reports, and the terms of this DPA.

(e) "Controller" means the entity that determines the purposes and means of the Processing of Personal Data.

(f) "Data Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by Processor on behalf of Client. A Data Incident does not include unsuccessful security incidents that do not result in unauthorized access to Personal Data, such as pings, port scans, denial-of-service attacks, or unsuccessful log-in attempts.

(g) "Data Protection Laws" means all applicable data privacy and data protection laws and regulations, including (without limitation) the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the United Kingdom General Data Protection Regulation ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), and similar privacy laws.

(h) "Data Subject" means the identified or identifiable person to whom the Personal Data relates.

(i) "International Data Transfer" means any transfer of Personal Data from within the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland to a country outside those territories that has not been recognized as providing an adequate level of data protection by the competent authority in the originating jurisdiction.

(j) "Personal Data or Personal Information" means any information that identifies or could reasonably be linked, directly or indirectly, to an identified or identifiable natural person or Consumer, to the extent such information is processed by CWILL on behalf of Client, under this DPA and the Agreement. "Personal Data" does not include any information that CWILL receives about Data Subjects (i) for purposes of CWILL providing products or services directly to the Data Subject and/or (ii) as a result of the Data Subject's instructions to, or direct relationship or intentional interaction with, CWILL.

(k) "Personnel" means any natural person acting under the authority of Processor or a Sub-processor who is authorized to Process Personal Data.

(l) "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, storage, use, disclosure, or deletion.

(m) "Processor" means the entity that Processes Personal Data on behalf of the Controller.

(n) "Security Measures" means the security measures applicable to the Services purchased by Client.

(o) "Sell" has the meaning given to it in Cal. Civ. Code § 1798.140(ad), and means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating a consumer's personal information to a third party for monetary or other valuable consideration.

(p) "Sensitive Data" means Personal Data that is classified as "sensitive personal information" or "sensitive data" under applicable Data Protection Laws, including, government-issued identifiers (such as social security numbers or driver's license numbers), financial account information, precise geolocation data, the contents of private communications, and login credentials.

(q) "Services" means the services provided to Client by CWILL INC in accordance with the Agreement.

(r) "Share" has the meaning given to it in Cal. Civ. Code § 1798.140(ah).

(s) "Special Categories of Data" means Personal Data that is classified as a "special category of personal data" or other materially similar terms under applicable Data Protection Laws, including, by way of example, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a person's sex life or sexual orientation.

(t) "Standard Contractual Clauses" shall mean (i) the standard contractual clauses set out in the Annex of Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs"); or (ii) where the UK GDPR applies, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner's Office in the UK.

(u) "Sub-processor (s)" means any third party (including CWILL Affiliates and third-party artificial intelligence service providers) engaged by CWILL to Process Personal Data on behalf of Client.

(v) "UK GDPR" means the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419).

(w) The terms "Member State" and "Supervisory Authority" shall have the same meaning as in the GDPR. The terms "Business", "Business Purpose", "Consumer" and "Service Provider" shall have the same meaning as in the CCPA.

For purposes of clarity, where the CCPA applies, "Controller" also means "Business," "Processor" also means "Service Provider" or "Contractor" (as applicable), and "Data Subject" also means "Consumer." Sub-processors engaged by Processor shall be subject to the same data protection obligations as apply to Processor acting as a Service Provider or Contractor under the CCPA.

2. PROCESSING OF PERSONAL DATA

2.1 Roles of the Parties. The Parties acknowledge and agree that: (a) with regard to the Processing of Personal Data performed on behalf of Client in connection with the provision of the Services, Client is the Controller of such Personal Data, and CWILL is the Processor; and (b) CWILL is an independent Controller with respect to Personal Data that CWILL Processes for its own legitimate business purposes, including merchant account administration, billing, payment processing, security, fraud prevention, legal compliance, customer relationship management, and the creation of anonymized and aggregated analytics, reports, and insights (collectively, "CWILL Controller Activities"). Where CWILL acts as an independent Controller, CWILL shall Process such Personal Data in accordance with the CWILL Privacy Policy and applicable Data Protection Laws. This DPA does not limit or prohibit CWILL from acting in that capacity. The terms "Controller" and "Processor" as used elsewhere in this DPA refer to Client and CWILL, respectively, except where expressly stated otherwise or where Section 2.1(b) applies.

2.2 Client's Processing of Personal Data. Client, in its use of the Service, and Client's instructions to the Processor, shall comply with Data Protection Laws. Client shall establish and have any and all required legal bases in order to collect, Process and transfer to Processor the Personal Data, and to authorize the Processing by Processor, and for Processor's Processing activities on Client's behalf, including the pursuit of 'business purposes' as defined under the CCPA.

2.3 Processor's Processing of Personal Data. When Processing on Client's behalf under the Agreement, Processor shall Process Personal Data for the following purposes: (i) Processing in accordance with the Agreement and this DPA; (ii) Processing for Client as part of its provision of the Services; (iii) Processing as required under the laws applicable to Processor, and/or as required by a court of competent jurisdiction or other competent governmental authority.

Processor shall inform Client without undue delay if, in Processor's opinion, an instruction for the Processing of Personal Data given by Client infringes applicable Data Protection Laws. To the extent that Processor cannot comply with an instruction from Client, Processor (i) shall inform Client, providing relevant details of the issue, and (ii) may, without liability to Client, temporarily cease all Processing of the affected Personal Data (other than securely storing such data) and/or suspend Client's access to the Services. If the Parties do not agree on a resolution within thirty (30) days, Client may, as its sole remedy with respect to the instruction at issue, terminate the Agreement and this DPA with respect to the affected Processing, and Client shall pay to Processor all amounts owed to Processor for Services rendered through the date of termination. Such termination shall not entitle Client to a refund of fees previously paid for Services already rendered, provided that nothing in this paragraph shall limit or exclude either Party's rights or remedies arising from a breach of this DPA or applicable Data Protection Laws.

2.4 Details of the Processing. The subject-matter of Processing of Personal Data by Processor is the performance of the Services pursuant to the Agreement. The duration of the Processing, the nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects Processed under this DPA are further specified in Annex I to this DPA.

2.5 Sensitive Data. The Parties agree that the Services are not designed for the Processing of Sensitive Data or Special Categories of Data. Client shall not submit Sensitive Data or Special Categories of Data to the Services without Processor's prior written consent. If Client submits such data without obtaining prior written consent, Processor shall have no liability for any claims arising from the Processing of such data, and Client shall indemnify Processor against any losses arising therefrom.

2.6 Records of Processing Activities. To the extent required under applicable Data Protection Laws, Processor shall maintain records of Processing activities carried out on behalf of Client and make such records available to a competent Supervisory Authority upon request.

2.7 US State Privacy Laws

2.7.1 To the extent Client Personal Data includes Personal Information as is defined under US State Privacy Laws, that Processor Processes as a Service Provider or Processor on behalf of Client, Processor will Process such Personal Data in accordance with applicable US State Privacy Laws and in accordance with Client's documented instructions, as necessary for the limited and specified purposes identified in this DPA and the Agreement. Processor will not: (a) retain, use, disclose or otherwise Process such Personal Data for a commercial purpose other than for the limited and specified purposes identified in this DPA and the Agreement, or as otherwise permitted under US State Privacy Laws; (b) "sell" or "share" such Personal Data within the meaning of the US State Privacy Laws; (c) retain, use, disclose or otherwise Process such Personal Data outside the direct business relationship with Client; or (d) combine such Personal Data with personal information that it receives from other sources, except as permitted under US State Privacy Laws. Processor will notify Client if Processor determines that it can no longer meet its obligations under the US State Privacy Laws.

2.8.2 De-Identified and Aggregated Data. In accordance with Client's use of the Services, Processor may de-identify and aggregate Personal Data and use such de-identified and aggregated data to improve the Services, generate industry benchmarks, and create analytics reports, provided that such data cannot reasonably be used to identify any individual Data Subject. Processor will: (a) adopt reasonable measures to prevent such de-identified data from being re-identified; (b) not attempt to re-identify such data, except solely to verify that the de-identification process is effective; and (c) before sharing de-identified data with any other party, contractually obligate such party to comply with the requirements of this Section 2.8.2.

2.8.3 Processor shall not retain, use, or disclose Personal Data for cross-context behavioral advertising as that term is understood under the CCPA/CPRA.

3. DATA SUBJECT REQUESTS

3.1 Processor shall without undue delay, notify Client or refer Data Subject or Consumer to Client, if Processor receives a request from a Data Subject or Consumer to exercise their rights (to the extent available to them under applicable Data Protection Laws) ("Data Subject Request"). Processor shall reasonably assist Client by implementing appropriate technical and organizational measures for the fulfilment of Client's obligation to respond to a Data Subject Request under Data Protection Laws. Processor may advise Data Subjects on available features for self-exercising their Data Subject Requests through the Services (where appropriate), and/or refer Data Subject Requests received, and the Data Subjects making them, directly to the Client for its treatment of such requests.

4. CONFIDENTIALITY

4.1 Processor shall ensure that Personnel who access Personal Data are bound by confidentiality obligations and access Personal Data only as necessary to perform the Services. These obligations survive termination of this DPA. Each Party shall keep the other Party's Confidential Information, except where disclosure is required by law or the information is already public through no fault of the receiving Party.

5. AUTHORIZED SUB-PROCESSORS

5.1 Appointment of Sub-processors. Client acknowledges and agrees that (a) Processor's Affiliates may be engaged as Sub-processors; and (b) Processor and Processor's Affiliates on behalf of Processor may each engage third-party Sub-processors in connection with the provision of the Service.

5.2 List of Current Sub-processors and Notification of New Sub-processors.

5.2.1 Client provides general written authorization for Processor to engage Sub-processors to Process Personal Data on behalf of Client. Processor shall make available to Client the current list of Sub-processors engaged by Processor to process Personal Data, which list is accessible at https://trust.cwill.com/subprocessors/ (the "Sub-Processor List"). By commencing use of the Services, Client acknowledges, accepts, and authorizes the Sub-processors set forth on the Sub-Processor List and such authorization shall constitute Client's engagement of those Sub-processors for the purposes of this DPA.

5.2.2 Objection to New Sub-processors. Processor shall update the Sub-Processor List prior to engaging any new Sub-processor. Client may reasonably object to Processor's use of a new Sub-processor by notifying Processor in writing within fourteen (14) days after the updated Sub-Processor List is published. Such written objection shall include the specific reasons for objecting, which must relate to the protection of Personal Data. Failure to object in writing within fourteen (14) days following publication of the updated Sub-Processor List shall be deemed acceptance of the new Sub-processor. In the event Client reasonably objects, Processor will use reasonable efforts to make available to Client a change in the Service or recommend a commercially reasonable change to Client's configuration or use of the Service to avoid Processing of Personal Data by the objected-to new Sub-processor. If Processor is unable to make available such change within thirty (30) days, either Party may terminate the affected Services by providing written notice to the other Party. All amounts due under the Agreement before the termination date with respect to the Processing at issue shall be duly paid to Processor. Such termination shall not entitle Client to a refund of fees previously paid for Services already rendered.

5.3 Agreements with Sub-processors. Where Processor engages a Sub-processor for carrying out specific Processing activities on behalf of the Client, the same or materially similar data protection obligations as set out in this DPA shall be imposed on such new Sub-processor by way of a contract. Where a Sub-processor fails to fulfil its data protection obligations concerning its processing of Personal Data, Processor shall remain responsible for the performance of the Sub-processor's obligations.

6. SECURITY & AUDITS

6.1 Controls for the Protection of Personal Data. Processor shall maintain appropriate technical and organizational measures, as described in Schedule B, for the protection of Personal Data Processed hereunder, including protection against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data. Processor shall maintain a documented information security program consistent with a recognized security framework. Processor may update or modify the Security Measures from time to time, provided that such updates and modifications do not materially decrease the overall security of the Services. Upon Client's reasonable request, Processor will provide reasonable assistance to Client, ensuring compliance with the obligations pursuant to applicable data protection laws, taking into account the nature of the Processing and the information available to Processor.

6.2 Audits and Inspections. Upon Client's thirty (30) days' prior written request at, and in no event, no more than once every twelve (12) months, and subject to strict confidentiality undertakings by Client, Processor shall make available to Client information necessary to demonstrate compliance with this DPA, and allow for audits, including inspections, conducted by Client. Such information shall not be used for any other purpose or disclosed to any third party without Processor's prior written approval.

6.3 In the event of an audit or inspections as set forth above, Client shall ensure that it (and each of its mandated auditors) will not cause (or, if it cannot avoid, minimize) any damage, injury or disruption to Processor's premises, equipment, personnel and business while conducting such audit or inspection.

6A. CROSS-BORDER DATA ACCESS CONTROLS

6A.1 In the event that Processor receives a legally binding request from a governmental authority in any jurisdiction for access to Personal Data Processed on behalf of Client, Processor shall (to the extent legally permitted): (a) promptly notify Client of such request, (b) challenge the request where Processor has reasonable grounds to consider it unlawful, (c) provide the minimum amount of information permissible when responding to the request, and (d) provide Client with copies of all relevant correspondence. Processor shall not voluntarily provide any governmental authority with direct access to Personal Data Processed on behalf of Client.

7. DATA INCIDENT MANAGEMENT AND NOTIFICATION

7.1 Processor shall notify Client without undue delay after becoming aware of a Data Incident. Processor shall make reasonable efforts to identify and take those steps as Processor deems necessary and reasonable to remediate and/or mitigate the cause of such Data Incident to the extent the remediation and/or mitigation is within Processor's reasonable control. The obligations herein shall not apply to incidents that are caused by Client or anyone who uses the Services on Client's behalf. Client will not make, disclose, release or publish any finding, admission of liability, communication, notice, press release or report concerning any Data Incident which directly or indirectly identifies Processor (including in any legal proceeding or in any notification to regulatory or supervisory authorities or affected individuals) without Processor's prior written approval, unless, and solely to the extent that, Client is compelled to do so pursuant to applicable Data Protection Laws. In the latter case, unless prohibited by such laws, Client shall provide Processor with reasonable prior written notice to provide Processor with the opportunity to object to such disclosure and in any case, Client will limit the disclosure to the minimum scope required.

8. RETURN AND DELETION OF PERSONAL DATA

8.1 Following expiration or termination of the Agreement and subject thereto, Processor shall in accordance with the Agreement delete or return to Client all Personal Data it Processes on behalf of Client, and Processor shall delete existing copies of such Personal Data unless Data Protection Laws require otherwise. To the extent authorized or required by applicable law, Processor may also retain the Personal Data for the establishment, exercise or defense of legal claims and/or for compliance with legal obligations.

9. INTERNATIONAL DATA TRANSFERS

9.1 Restricted Transfers outside the EEA and Switzerland. Where Personal Data protected by the GDPR or the FADP is transferred, either directly or via onward transfer, to a country outside the EEA or Switzerland that has not been recognized as providing an adequate level of data protection, the following transfer mechanism shall apply:

  1. Where Client is a Controller of Personal Data protected by the GDPR, Module 2 (Controller to Processor) of the EU SCCs applies between Client as "data exporter" and CWILL as "data importer" on the following basis: (i) in Clause 7, the optional docking clause will not apply; (ii) in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in Section 5 of this DPA; (iii) in Clause 11, the optional language shall not apply; (iv) in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Belgian law; (v) in Clause 18(b), disputes shall be resolved before the courts of Brussels; (vi) for Annex I, the Parties' details are as described in this DPA; the appointed contact person for the Processor is described in Annex I; the description of the transfer is set forth in Annex I and Annex II; the competent supervisory authority shall be defined in accordance with Clause 13 of the EU SCCs; (vii) Annex II to the EU SCCs will be deemed to incorporate Schedule B to this DPA; and (viii) Annex III to the EU SCCs will be the Authorized Sub-processors. Where Client is a Controller of Personal Data protected by the FADP, Module 2 of the EU SCCs applies between Client as "data exporter" and CWILL as "data importer" on the preceding basis and additionally: (i) in Clause 13, the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner; (ii) the term "Member State" must not be interpreted in such a way as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence in accordance with Clause 18(c); (iii) all references to the GDPR are also deemed to refer to the FADP; and (iv) the EU SCCs also protect the Personal Data of legal entities until the revised FADP no longer so provides.

9.2 Restricted Transfers outside the United Kingdom. Where Personal Data protected by the UK GDPR is transferred, either directly or via onward transfer, to a country outside of the United Kingdom that is not subject to an adequacy decision, the following applies:

  1. In respect of Personal Data subject to the UK GDPR, the Parties agree: (i) to rely on the EU SCCs as completed in Section 9.1 and as amended by the UK Addendum (as defined in Section 1(o)); (ii) the UK Addendum shall be incorporated by this reference and form an integral part of this DPA; and (iii) Client shall be "data exporter" and CWILL shall be "data importer".
  2. The UK Addendum tables shall be completed as follows: (i) Table 1: Start date: as set forth in the Agreement; Parties' details: as set forth in this DPA and the Agreement; Key Contact: as set forth in Annex I; (ii) Table 2: the "Addendum EU SCCs" refers to the EU SCCs as defined in this DPA, with applicable modules and clauses as described in Section 9.1; (iii) Table 3: Annex 1A (List of Parties): as set forth in this DPA; Annex 1B (Description of Transfer): as set forth in this DPA; Annex II (Technical and Organisational Measures): as set forth in this DPA; Annex III (List of Sub-processors): as set forth at the Sub-Processor List URL in Section 5.2.1; and (iv) Table 4: either Party may end the UK Addendum in accordance with its terms.
  3. Mandatory Clauses: the Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of UK GDPR on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.

9.3 Restricted Transfers to Other Jurisdictions. Where Personal Data originating from a jurisdiction not covered by Sections 9.1 or Section 9.2 is transferred to a country without an adequate level of data protection, Processor shall implement an appropriate transfer mechanism prior to making such transfer under the applicable Data Protection Laws. Processor shall provide Client, upon reasonable request, with information regarding the mechanism relied upon and confirms that it will comply with the applicable Data Protection Laws governing each such transfer, including any supplementary measures necessary to ensure the level of protection is not undermined.

10. AUTHORIZED AFFILIATES

10.1 Contractual Relationship. By entering into this DPA, Client does so on behalf of itself and, as applicable, in the name and on behalf of its Authorized Affiliates. Each Authorized Affiliate agrees to be bound by Client's obligations under this DPA to the extent that Processor Processes Personal Data on behalf of such Authorized Affiliate. All access to and use of the Services by Authorized Affiliates must comply with the Agreement and this DPA, and any violation by an Authorized Affiliate shall be deemed a violation by Client. Only the Client that has entered the Agreement may exercise any right or seek any remedy under this DPA, and such Client must exercise such rights for itself and all Authorized Affiliates combined, rather than separately for each.

10.2 Communication. Client shall remain responsible for coordinating all communication with Processor under the Agreement and this DPA and shall be entitled to make and receive any communication in relation to this DPA on behalf of its Authorized Affiliates.

11. OTHER PROVISIONS

11.1 Data Protection Impact Assessment and Prior Consultation. Upon Client's reasonable request, Processor shall provide Client, with reasonable cooperation and assistance needed to fulfil Client's obligations under applicable Data Protection Laws to carry out a data protection impact assessment related to Client's use of the Service, to the extent Client does not otherwise have access to the relevant information, and to the extent such information is available to Processor. Processor shall provide reasonable assistance to Client in the cooperation or prior consultation with the relevant Supervisory Authority in the performance of its tasks relating to this Section 11.1, to the extent required under applicable Data Protection Laws.

11.2 Modifications. Each Party may by at least forty-five (45) calendar days' prior written notice to the other Party, request in writing any variations to this DPA if they are required as a result of any change in, or decision of a competent authority under, any Data Protection Laws, to allow Processing of Client Personal Data to be made (or continue to be made) without breach of those Data Protection Laws. Pursuant to such notice: (a) The Parties shall make commercially reasonable efforts to accommodate such modification requested by Client or that Processor believes is necessary; and (b) Client shall not unreasonably withhold or delay agreement to any consequential variations to this DPA proposed by Processor to protect the Processor against additional risks, or to indemnify and compensate Processor for any further steps and costs associated with the variations made herein at Client's request. The Parties shall promptly negotiate in good faith with a view to implementing those or alternative variations designed to address the requirements identified in Client's or Processor's notice as soon as is reasonably practicable. In the event that the Parties are unable to reach such an agreement within thirty (30) days of such notice, then Client or Processor may, by written notice to the other Party, with immediate effect, terminate the Agreement to the extent that it relates to the Services which are affected by the proposed variations (or lack thereof). Such termination shall not entitle Client to a refund of fees previously paid for Services already rendered, provided that nothing in this Section shall limit or exclude either Party's rights or remedies arising from a breach of this DPA or applicable Data Protection Laws.

12. LIABILITY

12.1 Limitation of Liability. Each Party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to and shall not exceed the limitations and exclusions of liability set forth in the Agreement, including any aggregate liability caps, exclusions of consequential, indirect, special, or punitive damages, and any other limitations expressly agreed upon by the Parties therein. The Parties expressly agree that the limitations and exclusions of liability contained in the Agreement shall apply to this DPA as if fully set forth herein and shall be read and construed together with this DPA as a single integrated instrument. Any reference in the Agreement to the liability of a Party shall be interpreted to mean the aggregate liability of that Party and all of its Affiliates under both the Agreement and this DPA, taken together.

13. GOVERNING LAW AND JURISDICTION

This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions set forth in the Agreement, unless a different governing law or jurisdiction is expressly required by applicable Data Protection Laws. In the event of any conflict between the governing law provisions of the Agreement and the mandatory requirements of applicable Data Protection Laws, the applicable Data Protection Laws shall prevail solely to the extent of such conflict and only with respect to the specific obligations governed by those laws.

14. ORDER OF PRECEDENCE

In the event of any conflict or inconsistency between this DPA and the Agreement with respect to the subject matter of this DPA, the terms of this DPA shall prevail. In the event of any conflict or inconsistency between the body of this DPA and any Standard Contractual Clauses or other data transfer mechanisms incorporated herein, the Standard Contractual Clauses or applicable transfer mechanism shall prevail solely to the extent required by applicable Data Protection Laws.

15. SEVERABILITY

Should any provision of this DPA be found invalid, illegal, or unenforceable by a court or regulatory authority of competent jurisdiction, the remaining provisions of this DPA shall continue in full force and effect and shall not be affected or impaired thereby. The invalid, illegal, or unenforceable provision shall be either (a) amended to the minimum extent necessary to make it valid, legal, and enforceable while preserving the original intent of the Parties as closely as possible, or if such amendment is not possible, (b) deemed severed from this DPA, with the remainder of this DPA construed as if such provision had never been included. The Parties agree to negotiate in good faith a valid replacement provision that most nearly reflects the original intent of the severed provision.

16. ENTIRE AGREEMENT

This DPA, together with the Agreement and any exhibits, schedules, or addenda attached hereto or incorporated by reference, constitutes the entire agreement between the Parties with respect to the Processing of Personal Data under the Agreement and supersedes all prior and contemporaneous understandings, representations, warranties, and agreements, whether written or oral, relating to the subject matter hereof. No modification, amendment, or waiver of any provision of this DPA shall be valid or binding unless made in writing and duly executed by authorized representatives of both Parties. Any waiver by either Party of a breach of any provision of this DPA shall not operate or be construed as a waiver of any subsequent or other breach thereof.

Annex I
A: LIST OF PARTIES

Data exporter(s)/importer(s): As determined by the particular relevant transfer.

Name: CWILL INC - 8 The Green Ste A, Dover, Kent, DE, 19901

Contact person's name, position, and contact details: Data Protection Officer, [email protected]

Activities relevant to the data transferred under these Clauses: As agreed between the Parties, in accordance with the Data Processing Agreement and the Agreement.

Signature and date: By entering into the Agreement to which the Data Processing Agreement is attached, the Party will be deemed to have signed this Annex I.

Role (controller/processor): As determined by the particular relevant transfer.

Data exporter(s)/importer(s): As determined by the particular relevant transfer.

Name: The party named in the Agreement to which the Data Processing Agreement is attached.

Address: The address in the Agreement to which the Data Processing Agreement is attached.

Contact person's name, position, and contact details: The contact information as contained in the Agreement.

Activities relevant to the data transferred under these Clauses: As agreed between the Parties, in accordance with the Data Processing Agreement and the Agreement.

Signature and date: By entering into the Agreement to which the Data Processing Agreement is attached, the Party will be deemed to have signed this.

Annex I. Role (controller/processor): As determined by the particular relevant transfer.

B: DESCRIPTION OF TRANSFER

Nature and Purpose of Processing

Processor will Process Personal Data in order to provide the Services in accordance with the Agreement, including this DPA. The nature of the Processing includes collection, structuring, storage, transmission, retrieval, consultation, use, disclosure by transmission, and deletion of Personal Data by automated means. The specific purposes are:

  1. Providing the Service to Client;
  2. Performing the Agreement, this DPA and/or other contracts executed by the Parties;
  3. Acting upon Client's instructions, where such instructions are consistent with the terms of the Agreement;
  4. Disclosing Personal Data (i) to third parties in accordance with Client's instructions and/or pursuant to Client's use of the Services (e.g., integrations between the Services and any services provided by third parties, as configured by or on behalf of Client to facilitate the disclosure of Personal Data between the Services and such third party services);
  5. Rendering Personal Data fully anonymous, non-identifiable and non-personal in accordance with applicable standards recognized by Data Protection Laws and guidance issued thereunder;
  6. Complying with applicable laws and regulations;
  7. All tasks related to any of the above.

Categories of Data Subjects and Personal Data Processed

Categories of Data Subjects and Types of Personal Data Processed, by Service:

(a) CWILL Post-Purchase Suite (CWILL Order Tracking, CWILL Returns & Exchanges, CWILL Shipping Protection): Data Subjects: merchants, merchant employees, end-consumers, shipment recipients, tracking-page visitors, and shipping-protection claimants. Personal Data: tracking number, carrier, customer name, email address, phone number, country, shipping address, product information, order information, tracking events, delivery status, shipment metadata, and (for Shipping Protection) claim-related data shared with Seel, Inc. including order number, Cover ID, and supporting documentation.

(b) CWILL Customer Retention Suite (CWILL Product Reviews, CWILL Loyalty & Referrals): Data Subjects: merchants, merchant employees, reviewers, store visitors, loyalty-program members, and referred individuals. Personal Data: review ID, product ID, product name, review content, rating, review date, reviewer name, email, profile, purchase status, review status, replies, images, videos, helpful votes, notification preferences, submission method, engagement metrics; and for Loyalty: customer name, email, loyalty ID, date of birth (where enabled by the Merchant), IP address, account creation date, order history, points, rewards, referral activity, program participation records, and loyalty preferences.

(c) CWILL Pop-Up & Email Marketing: Data Subjects: merchants, merchant employees, email subscribers, recipients, and popup visitors. Personal Data: recipient name, email address, contact details, email template content (subject, body, images, links), delivery/open/click metrics, bounce and unsubscribe data, campaign analytics, audience segmentation tags, A/B test results, and email preference settings.

(d) CWILL AI Chat: Data Subjects: merchants, support agents, and end-consumers using chat. Personal Data: chat transcripts, message history, customer name, email, phone number, tracking number, fulfillment status, store-policy information, AI-generated responses, customer feedback, and chat engagement analytics.

(e) CWILL SEO & Speed (SEOWILL): Data Subjects: merchants and merchant employees. Personal Data: store name, store domain, product and collection information, page and blog content, keywords, rankings, traffic analytics, Google Search Console data (where authorized), redirect information, backlink information, SEO settings, and AI-generated content. SEOWILL is not intended to process identifiable end-consumer data.

(f) TrackingMore: Data Subjects: merchants, API customers, their employees, shipment recipients, and tracking-page visitors. Personal Data: order number, order value, order date, item details, tracking number, carrier name, shipping method, parcel weight, shipping dates and addresses, customer name, email, phone number, shipping address, notification preferences, delivery status, delivery location, delivery date, signer name, estimated delivery date, shipping label files, shipping rates, manifest files, return reason, return method, resolution type, return product images, refund amount, and return date.

Duration of Processing: For the term of the Agreement and for a period of up to 180 days thereafter (or such longer period as required by applicable law), subject to Section 8 and Section 8A of this DPA.

Contact for the Processor: [email protected]; DPO: [email protected].

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:

N/A

The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis):

Continuous

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: The data exporter determines the duration of processing in accordance with the terms of the Agreement but will retain the information for no longer than necessary to fulfill the purposes for which it was collected. For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:

Personal Data will be retained for the duration of the Agreement and for a reasonable period thereafter, in line with applicable Data Protection Laws and Processor's then-current data retention policies, as further described in Sections 8 and 8A of this DPA.

C: COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies in accordance with Clause 13:

The data exporter's competent supervisory authority will be determined in accordance with the GDPR.

Annex II - Technical and Organizational Measures

Processor maintains appropriate organizational and technical security measures designed to protect Personal Data against unauthorized access, loss, alteration, disclosure, destruction, or other unlawful Processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risks to individuals' rights and freedoms. The following describes the categories of measures Processor has implemented. Processor may update these measures from time to time, provided that such updates do not materially decrease the overall level of protection.

Category Subcategory Relevant Security Issue CWILL Implementation
Privacy / Security Data Retention and Storage Data storage All data, including collected personal data, are stored in the cloud through the cloud services as shown in the Authorized Sub-processors' list. The location of the data centres is further described in the Authorized Sub-processors list.
Privacy / Security Data Retention and Storage Personal data retention and erasure There are defined retention periods for collected personal data. If the personal data are no longer required to be retained, they are systematically destroyed and/or anonymized.
Security Access Control Management Implemented password policies, password controls. Encryption / hashing of passwords CWILL has implemented internal password policies to specify security requirements and avoid employees using weak passwords. Passwords are hashed using industry-standard algorithms with a random salt.
Security Access Control Management Immediate removal of access rights for users leaving the organization Employee off-boarding procedures are in place to ensure employees' access rights are removed when leaving.
Security Access Control Management Least privilege and role-based access control Access to systems that process Personal Data is restricted based on role, business need, and the principle of least privilege. User permissions are granted according to job responsibilities and reviewed periodically.
Security Access Control Management Access approval and provisioning Access to production systems and Personal Data is granted through an approval-based provisioning process and limited to authorized personnel with a legitimate business need.
Security Access Control Management Periodic access review CWILL periodically reviews user access rights to systems that process Personal Data and removes or adjusts access that is no longer required.
Security Access Control Management Authentication and multi-factor authentication CWILL enforces password policies for internal accounts and requires multi-factor authentication for administrative access and access to all systems that process Personal Data.
Security Access Control Management Logging and monitoring of privileged access Administrative and privileged access to production systems is logged and monitored to detect unauthorized or inappropriate access.
Security Data Transmission and Encryption Encryption of Personal Data during transmission Personal Data transmitted over public networks is encrypted using TLS 1.2 or higher. CWILL maintains configurations designed to prevent the use of deprecated protocols and weak cipher suites.
Security Data Retention and Storage Encryption of Personal Data at rest Personal Data stored in production databases, object storage, and backups is encrypted at rest using industry-standard encryption mechanisms provided by cloud infrastructure providers or equivalent controls. Access to encryption keys is restricted to authorized systems and personnel.
Security Vulnerability Management and Security Testing Vulnerability scanning, penetration testing, and remediation CWILL conducts periodic vulnerability assessments and security testing of systems that process Personal Data, including automated vulnerability scanning and, where appropriate, penetration testing. Identified vulnerabilities are reviewed, risk-rated, and remediated within commercially reasonable timeframes based on severity. Security testing is performed in a manner designed to avoid unauthorized access to, alteration of, or disruption to Personal Data.
Security Business Continuity Management Backup policies and frequency Daily backup performed by cloud services at primary and secondary data centres
Security Business Continuity Management Disaster recovery sites in multiple / diverse geographic locations The data centres hosting the cloud services are located in different locations to reduce risks of data loss.
Privacy / Security Governance Security awareness training program currently in place: topics and frequency Security awareness training is implemented when onboarding employees and conducted at least annually thereafter. Main topics covered during the training include: general obligations under various information security policies, standards, procedures, guidelines, applicable security related laws and regulations, contractual terms and standards of ethics and acceptable behaviour.
Privacy / Security Incident Response Management Incident response procedures in place. Existence of a team with defined roles and responsibilities. Existence of communication procedures regarding security incidents such as data breaches. Notification timeframe regarding third parties Data breach response team and plan are in place (Detect, Contain, Analyze, Notify, Respond, Document, Learn). Data breach response team checklist, with defined roles and responsibilities.
Annex III - List of Sub-processors

https://trust.cwill.com/subprocessors/

CWILL

Post-Purchase and Retention Suite

AICPA SOC for Service Organizations
CWILL on LinkedInCWILL on YouTubeCWILL on X

Products

Order TrackingReturns & ExchangesShipping ProtectionProduct ReviewsLoyalty & ReferralsAI ChatPop-Up & Email MarketingSEO & Speed

Solutions

Post-PurchaseCustomer Retention

Resources

BlogCase studiesBest Shopify appsAPIs and webhooks

Company

About CWILLCareersBecome a partnerAgency partners

Support

Book a demoContact usHelp center

© 2018-2026 CWILL. All rights reserved.

Terms of service
Privacy policy
Security
Trust
Cookies