Last Updated : August 8 , 2026
This Data Processing Agreement ("DPA") is incorporated by reference into CWILL's Terms of Service available at https://www.cwill.com/terms-of-service/ or other agreement governing the use of CWILL's Services ("Agreement") entered by and between you, the Client (as defined in the Agreement) (collectively, "you", "your", "Client"), and CWILL INC, a Delaware corporation, or its applicable Affiliate(s) ("CWILL", "us", "we", "our") to reflect the Parties' agreement with regard to the Processing of Personal Data by CWILL on behalf of the Client and, to the limited extent described in Section 2.1(b), as an independent Controller. Both parties shall be referred to as the "Parties" and each, a "Party".
Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.
Each Party represents and warrants that the individual executing or accepting this DPA on its behalf is duly authorized to do so. If there is any conflict or inconsistency between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA shall prevail. If there is any conflict or inconsistency between this DPA and any Standard Contractual Clauses or other data transfer mechanisms incorporated herein, the Standard Contractual Clauses or applicable transfer mechanism shall prevail solely to the extent required by applicable Data Protection Laws.
(a) "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. "Control", for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
(b) "Authorized Affiliate" means any of Client's Affiliate(s) which is explicitly permitted to use the Service pursuant to the Agreement between Client and CWILL INC but has not signed its own agreement with CWILL and is not a "Client" as defined under the Agreement.
(c) "CCPA" means the California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100 et. seq, and its implementing regulations, including as amended by the California Privacy Rights Act.
(d) "Confidential Information" means all non-public information disclosed by one Party to the other Party in connection with this DPA, designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure, including Personal Data, Security Measures, audit reports, and the terms of this DPA.
(e) "Controller" means the entity that determines the purposes and means of the Processing of Personal Data.
(f) "Data Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by Processor on behalf of Client. A Data Incident does not include unsuccessful security incidents that do not result in unauthorized access to Personal Data, such as pings, port scans, denial-of-service attacks, or unsuccessful log-in attempts.
(g) "Data Protection Laws" means all applicable data privacy and data protection laws and regulations, including (without limitation) the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the United Kingdom General Data Protection Regulation ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), and similar privacy laws.
(h) "Data Subject" means the identified or identifiable person to whom the Personal Data relates.
(i) "International Data Transfer" means any transfer of Personal Data from within the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland to a country outside those territories that has not been recognized as providing an adequate level of data protection by the competent authority in the originating jurisdiction.
(j) "Personal Data or Personal Information" means any information that identifies or could reasonably be linked, directly or indirectly, to an identified or identifiable natural person or Consumer, to the extent such information is processed by CWILL on behalf of Client, under this DPA and the Agreement. "Personal Data" does not include any information that CWILL receives about Data Subjects (i) for purposes of CWILL providing products or services directly to the Data Subject and/or (ii) as a result of the Data Subject's instructions to, or direct relationship or intentional interaction with, CWILL.
(k) "Personnel" means any natural person acting under the authority of Processor or a Sub-processor who is authorized to Process Personal Data.
(l) "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, storage, use, disclosure, or deletion.
(m) "Processor" means the entity that Processes Personal Data on behalf of the Controller.
(n) "Security Measures" means the security measures applicable to the Services purchased by Client.
(o) "Sell" has the meaning given to it in Cal. Civ. Code § 1798.140(ad), and means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating a consumer's personal information to a third party for monetary or other valuable consideration.
(p) "Sensitive Data" means Personal Data that is classified as "sensitive personal information" or "sensitive data" under applicable Data Protection Laws, including, government-issued identifiers (such as social security numbers or driver's license numbers), financial account information, precise geolocation data, the contents of private communications, and login credentials.
(q) "Services" means the services provided to Client by CWILL INC in accordance with the Agreement.
(r) "Share" has the meaning given to it in Cal. Civ. Code § 1798.140(ah).
(s) "Special Categories of Data" means Personal Data that is classified as a "special category of personal data" or other materially similar terms under applicable Data Protection Laws, including, by way of example, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a person's sex life or sexual orientation.
(t) "Standard Contractual Clauses" shall mean (i) the standard contractual clauses set out in the Annex of Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs"); or (ii) where the UK GDPR applies, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner's Office in the UK.
(u) "Sub-processor (s)" means any third party (including CWILL Affiliates and third-party artificial intelligence service providers) engaged by CWILL to Process Personal Data on behalf of Client.
(v) "UK GDPR" means the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419).
(w) The terms "Member State" and "Supervisory Authority" shall have the same meaning as in the GDPR. The terms "Business", "Business Purpose", "Consumer" and "Service Provider" shall have the same meaning as in the CCPA.
For purposes of clarity, where the CCPA applies, "Controller" also means "Business," "Processor" also means "Service Provider" or "Contractor" (as applicable), and "Data Subject" also means "Consumer." Sub-processors engaged by Processor shall be subject to the same data protection obligations as apply to Processor acting as a Service Provider or Contractor under the CCPA.
2.1 Roles of the Parties. The Parties acknowledge and agree that: (a) with regard to the Processing of Personal Data performed on behalf of Client in connection with the provision of the Services, Client is the Controller of such Personal Data, and CWILL is the Processor; and (b) CWILL is an independent Controller with respect to Personal Data that CWILL Processes for its own legitimate business purposes, including merchant account administration, billing, payment processing, security, fraud prevention, legal compliance, customer relationship management, and the creation of anonymized and aggregated analytics, reports, and insights (collectively, "CWILL Controller Activities"). Where CWILL acts as an independent Controller, CWILL shall Process such Personal Data in accordance with the CWILL Privacy Policy and applicable Data Protection Laws. This DPA does not limit or prohibit CWILL from acting in that capacity. The terms "Controller" and "Processor" as used elsewhere in this DPA refer to Client and CWILL, respectively, except where expressly stated otherwise or where Section 2.1(b) applies.
2.2 Client's Processing of Personal Data. Client, in its use of the Service, and Client's instructions to the Processor, shall comply with Data Protection Laws. Client shall establish and have any and all required legal bases in order to collect, Process and transfer to Processor the Personal Data, and to authorize the Processing by Processor, and for Processor's Processing activities on Client's behalf, including the pursuit of 'business purposes' as defined under the CCPA.
2.3 Processor's Processing of Personal Data. When Processing on Client's behalf under the Agreement, Processor shall Process Personal Data for the following purposes: (i) Processing in accordance with the Agreement and this DPA; (ii) Processing for Client as part of its provision of the Services; (iii) Processing as required under the laws applicable to Processor, and/or as required by a court of competent jurisdiction or other competent governmental authority.
Processor shall inform Client without undue delay if, in Processor's opinion, an instruction for the Processing of Personal Data given by Client infringes applicable Data Protection Laws. To the extent that Processor cannot comply with an instruction from Client, Processor (i) shall inform Client, providing relevant details of the issue, and (ii) may, without liability to Client, temporarily cease all Processing of the affected Personal Data (other than securely storing such data) and/or suspend Client's access to the Services. If the Parties do not agree on a resolution within thirty (30) days, Client may, as its sole remedy with respect to the instruction at issue, terminate the Agreement and this DPA with respect to the affected Processing, and Client shall pay to Processor all amounts owed to Processor for Services rendered through the date of termination. Such termination shall not entitle Client to a refund of fees previously paid for Services already rendered, provided that nothing in this paragraph shall limit or exclude either Party's rights or remedies arising from a breach of this DPA or applicable Data Protection Laws.
2.4 Details of the Processing. The subject-matter of Processing of Personal Data by Processor is the performance of the Services pursuant to the Agreement. The duration of the Processing, the nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects Processed under this DPA are further specified in Annex I to this DPA.
2.5 Sensitive Data. The Parties agree that the Services are not designed for the Processing of Sensitive Data or Special Categories of Data. Client shall not submit Sensitive Data or Special Categories of Data to the Services without Processor's prior written consent. If Client submits such data without obtaining prior written consent, Processor shall have no liability for any claims arising from the Processing of such data, and Client shall indemnify Processor against any losses arising therefrom.
2.6 Records of Processing Activities. To the extent required under applicable Data Protection Laws, Processor shall maintain records of Processing activities carried out on behalf of Client and make such records available to a competent Supervisory Authority upon request.
2.7 US State Privacy Laws
2.7.1 To the extent Client Personal Data includes Personal Information as is defined under US State Privacy Laws, that Processor Processes as a Service Provider or Processor on behalf of Client, Processor will Process such Personal Data in accordance with applicable US State Privacy Laws and in accordance with Client's documented instructions, as necessary for the limited and specified purposes identified in this DPA and the Agreement. Processor will not: (a) retain, use, disclose or otherwise Process such Personal Data for a commercial purpose other than for the limited and specified purposes identified in this DPA and the Agreement, or as otherwise permitted under US State Privacy Laws; (b) "sell" or "share" such Personal Data within the meaning of the US State Privacy Laws; (c) retain, use, disclose or otherwise Process such Personal Data outside the direct business relationship with Client; or (d) combine such Personal Data with personal information that it receives from other sources, except as permitted under US State Privacy Laws. Processor will notify Client if Processor determines that it can no longer meet its obligations under the US State Privacy Laws.
2.8.2 De-Identified and Aggregated Data. In accordance with Client's use of the Services, Processor may de-identify and aggregate Personal Data and use such de-identified and aggregated data to improve the Services, generate industry benchmarks, and create analytics reports, provided that such data cannot reasonably be used to identify any individual Data Subject. Processor will: (a) adopt reasonable measures to prevent such de-identified data from being re-identified; (b) not attempt to re-identify such data, except solely to verify that the de-identification process is effective; and (c) before sharing de-identified data with any other party, contractually obligate such party to comply with the requirements of this Section 2.8.2.
2.8.3 Processor shall not retain, use, or disclose Personal Data for cross-context behavioral advertising as that term is understood under the CCPA/CPRA.
3.1 Processor shall without undue delay, notify Client or refer Data Subject or Consumer to Client, if Processor receives a request from a Data Subject or Consumer to exercise their rights (to the extent available to them under applicable Data Protection Laws) ("Data Subject Request"). Processor shall reasonably assist Client by implementing appropriate technical and organizational measures for the fulfilment of Client's obligation to respond to a Data Subject Request under Data Protection Laws. Processor may advise Data Subjects on available features for self-exercising their Data Subject Requests through the Services (where appropriate), and/or refer Data Subject Requests received, and the Data Subjects making them, directly to the Client for its treatment of such requests.
4.1 Processor shall ensure that Personnel who access Personal Data are bound by confidentiality obligations and access Personal Data only as necessary to perform the Services. These obligations survive termination of this DPA. Each Party shall keep the other Party's Confidential Information, except where disclosure is required by law or the information is already public through no fault of the receiving Party.
6.1 Controls for the Protection of Personal Data. Processor shall maintain appropriate technical and organizational measures, as described in Schedule B, for the protection of Personal Data Processed hereunder, including protection against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data. Processor shall maintain a documented information security program consistent with a recognized security framework. Processor may update or modify the Security Measures from time to time, provided that such updates and modifications do not materially decrease the overall security of the Services. Upon Client's reasonable request, Processor will provide reasonable assistance to Client, ensuring compliance with the obligations pursuant to applicable data protection laws, taking into account the nature of the Processing and the information available to Processor.
6.2 Audits and Inspections. Upon Client's thirty (30) days' prior written request at, and in no event, no more than once every twelve (12) months, and subject to strict confidentiality undertakings by Client, Processor shall make available to Client information necessary to demonstrate compliance with this DPA, and allow for audits, including inspections, conducted by Client. Such information shall not be used for any other purpose or disclosed to any third party without Processor's prior written approval.
6.3 In the event of an audit or inspections as set forth above, Client shall ensure that it (and each of its mandated auditors) will not cause (or, if it cannot avoid, minimize) any damage, injury or disruption to Processor's premises, equipment, personnel and business while conducting such audit or inspection.
6A.1 In the event that Processor receives a legally binding request from a governmental authority in any jurisdiction for access to Personal Data Processed on behalf of Client, Processor shall (to the extent legally permitted): (a) promptly notify Client of such request, (b) challenge the request where Processor has reasonable grounds to consider it unlawful, (c) provide the minimum amount of information permissible when responding to the request, and (d) provide Client with copies of all relevant correspondence. Processor shall not voluntarily provide any governmental authority with direct access to Personal Data Processed on behalf of Client.
7.1 Processor shall notify Client without undue delay after becoming aware of a Data Incident. Processor shall make reasonable efforts to identify and take those steps as Processor deems necessary and reasonable to remediate and/or mitigate the cause of such Data Incident to the extent the remediation and/or mitigation is within Processor's reasonable control. The obligations herein shall not apply to incidents that are caused by Client or anyone who uses the Services on Client's behalf. Client will not make, disclose, release or publish any finding, admission of liability, communication, notice, press release or report concerning any Data Incident which directly or indirectly identifies Processor (including in any legal proceeding or in any notification to regulatory or supervisory authorities or affected individuals) without Processor's prior written approval, unless, and solely to the extent that, Client is compelled to do so pursuant to applicable Data Protection Laws. In the latter case, unless prohibited by such laws, Client shall provide Processor with reasonable prior written notice to provide Processor with the opportunity to object to such disclosure and in any case, Client will limit the disclosure to the minimum scope required.
8.1 Following expiration or termination of the Agreement and subject thereto, Processor shall in accordance with the Agreement delete or return to Client all Personal Data it Processes on behalf of Client, and Processor shall delete existing copies of such Personal Data unless Data Protection Laws require otherwise. To the extent authorized or required by applicable law, Processor may also retain the Personal Data for the establishment, exercise or defense of legal claims and/or for compliance with legal obligations.
9.1 Restricted Transfers outside the EEA and Switzerland. Where Personal Data protected by the GDPR or the FADP is transferred, either directly or via onward transfer, to a country outside the EEA or Switzerland that has not been recognized as providing an adequate level of data protection, the following transfer mechanism shall apply:
9.2 Restricted Transfers outside the United Kingdom. Where Personal Data protected by the UK GDPR is transferred, either directly or via onward transfer, to a country outside of the United Kingdom that is not subject to an adequacy decision, the following applies:
9.3 Restricted Transfers to Other Jurisdictions. Where Personal Data originating from a jurisdiction not covered by Sections 9.1 or Section 9.2 is transferred to a country without an adequate level of data protection, Processor shall implement an appropriate transfer mechanism prior to making such transfer under the applicable Data Protection Laws. Processor shall provide Client, upon reasonable request, with information regarding the mechanism relied upon and confirms that it will comply with the applicable Data Protection Laws governing each such transfer, including any supplementary measures necessary to ensure the level of protection is not undermined.
11.1 Data Protection Impact Assessment and Prior Consultation. Upon Client's reasonable request, Processor shall provide Client, with reasonable cooperation and assistance needed to fulfil Client's obligations under applicable Data Protection Laws to carry out a data protection impact assessment related to Client's use of the Service, to the extent Client does not otherwise have access to the relevant information, and to the extent such information is available to Processor. Processor shall provide reasonable assistance to Client in the cooperation or prior consultation with the relevant Supervisory Authority in the performance of its tasks relating to this Section 11.1, to the extent required under applicable Data Protection Laws.
11.2 Modifications. Each Party may by at least forty-five (45) calendar days' prior written notice to the other Party, request in writing any variations to this DPA if they are required as a result of any change in, or decision of a competent authority under, any Data Protection Laws, to allow Processing of Client Personal Data to be made (or continue to be made) without breach of those Data Protection Laws. Pursuant to such notice: (a) The Parties shall make commercially reasonable efforts to accommodate such modification requested by Client or that Processor believes is necessary; and (b) Client shall not unreasonably withhold or delay agreement to any consequential variations to this DPA proposed by Processor to protect the Processor against additional risks, or to indemnify and compensate Processor for any further steps and costs associated with the variations made herein at Client's request. The Parties shall promptly negotiate in good faith with a view to implementing those or alternative variations designed to address the requirements identified in Client's or Processor's notice as soon as is reasonably practicable. In the event that the Parties are unable to reach such an agreement within thirty (30) days of such notice, then Client or Processor may, by written notice to the other Party, with immediate effect, terminate the Agreement to the extent that it relates to the Services which are affected by the proposed variations (or lack thereof). Such termination shall not entitle Client to a refund of fees previously paid for Services already rendered, provided that nothing in this Section shall limit or exclude either Party's rights or remedies arising from a breach of this DPA or applicable Data Protection Laws.
12.1 Limitation of Liability. Each Party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to and shall not exceed the limitations and exclusions of liability set forth in the Agreement, including any aggregate liability caps, exclusions of consequential, indirect, special, or punitive damages, and any other limitations expressly agreed upon by the Parties therein. The Parties expressly agree that the limitations and exclusions of liability contained in the Agreement shall apply to this DPA as if fully set forth herein and shall be read and construed together with this DPA as a single integrated instrument. Any reference in the Agreement to the liability of a Party shall be interpreted to mean the aggregate liability of that Party and all of its Affiliates under both the Agreement and this DPA, taken together.
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions set forth in the Agreement, unless a different governing law or jurisdiction is expressly required by applicable Data Protection Laws. In the event of any conflict between the governing law provisions of the Agreement and the mandatory requirements of applicable Data Protection Laws, the applicable Data Protection Laws shall prevail solely to the extent of such conflict and only with respect to the specific obligations governed by those laws.
In the event of any conflict or inconsistency between this DPA and the Agreement with respect to the subject matter of this DPA, the terms of this DPA shall prevail. In the event of any conflict or inconsistency between the body of this DPA and any Standard Contractual Clauses or other data transfer mechanisms incorporated herein, the Standard Contractual Clauses or applicable transfer mechanism shall prevail solely to the extent required by applicable Data Protection Laws.
Should any provision of this DPA be found invalid, illegal, or unenforceable by a court or regulatory authority of competent jurisdiction, the remaining provisions of this DPA shall continue in full force and effect and shall not be affected or impaired thereby. The invalid, illegal, or unenforceable provision shall be either (a) amended to the minimum extent necessary to make it valid, legal, and enforceable while preserving the original intent of the Parties as closely as possible, or if such amendment is not possible, (b) deemed severed from this DPA, with the remainder of this DPA construed as if such provision had never been included. The Parties agree to negotiate in good faith a valid replacement provision that most nearly reflects the original intent of the severed provision.
This DPA, together with the Agreement and any exhibits, schedules, or addenda attached hereto or incorporated by reference, constitutes the entire agreement between the Parties with respect to the Processing of Personal Data under the Agreement and supersedes all prior and contemporaneous understandings, representations, warranties, and agreements, whether written or oral, relating to the subject matter hereof. No modification, amendment, or waiver of any provision of this DPA shall be valid or binding unless made in writing and duly executed by authorized representatives of both Parties. Any waiver by either Party of a breach of any provision of this DPA shall not operate or be construed as a waiver of any subsequent or other breach thereof.
Data exporter(s)/importer(s): As determined by the particular relevant transfer.
Name: CWILL INC - 8 The Green Ste A, Dover, Kent, DE, 19901
Contact person's name, position, and contact details: Data Protection Officer, [email protected]
Activities relevant to the data transferred under these Clauses: As agreed between the Parties, in accordance with the Data Processing Agreement and the Agreement.
Signature and date: By entering into the Agreement to which the Data Processing Agreement is attached, the Party will be deemed to have signed this Annex I.
Role (controller/processor): As determined by the particular relevant transfer.
Data exporter(s)/importer(s): As determined by the particular relevant transfer.
Name: The party named in the Agreement to which the Data Processing Agreement is attached.
Address: The address in the Agreement to which the Data Processing Agreement is attached.
Contact person's name, position, and contact details: The contact information as contained in the Agreement.
Activities relevant to the data transferred under these Clauses: As agreed between the Parties, in accordance with the Data Processing Agreement and the Agreement.
Signature and date: By entering into the Agreement to which the Data Processing Agreement is attached, the Party will be deemed to have signed this.
Annex I. Role (controller/processor): As determined by the particular relevant transfer.
Nature and Purpose of Processing
Processor will Process Personal Data in order to provide the Services in accordance with the Agreement, including this DPA. The nature of the Processing includes collection, structuring, storage, transmission, retrieval, consultation, use, disclosure by transmission, and deletion of Personal Data by automated means. The specific purposes are:
Categories of Data Subjects and Personal Data Processed
Categories of Data Subjects and Types of Personal Data Processed, by Service:
(a) CWILL Post-Purchase Suite (CWILL Order Tracking, CWILL Returns & Exchanges, CWILL Shipping Protection): Data Subjects: merchants, merchant employees, end-consumers, shipment recipients, tracking-page visitors, and shipping-protection claimants. Personal Data: tracking number, carrier, customer name, email address, phone number, country, shipping address, product information, order information, tracking events, delivery status, shipment metadata, and (for Shipping Protection) claim-related data shared with Seel, Inc. including order number, Cover ID, and supporting documentation.
(b) CWILL Customer Retention Suite (CWILL Product Reviews, CWILL Loyalty & Referrals): Data Subjects: merchants, merchant employees, reviewers, store visitors, loyalty-program members, and referred individuals. Personal Data: review ID, product ID, product name, review content, rating, review date, reviewer name, email, profile, purchase status, review status, replies, images, videos, helpful votes, notification preferences, submission method, engagement metrics; and for Loyalty: customer name, email, loyalty ID, date of birth (where enabled by the Merchant), IP address, account creation date, order history, points, rewards, referral activity, program participation records, and loyalty preferences.
(c) CWILL Pop-Up & Email Marketing: Data Subjects: merchants, merchant employees, email subscribers, recipients, and popup visitors. Personal Data: recipient name, email address, contact details, email template content (subject, body, images, links), delivery/open/click metrics, bounce and unsubscribe data, campaign analytics, audience segmentation tags, A/B test results, and email preference settings.
(d) CWILL AI Chat: Data Subjects: merchants, support agents, and end-consumers using chat. Personal Data: chat transcripts, message history, customer name, email, phone number, tracking number, fulfillment status, store-policy information, AI-generated responses, customer feedback, and chat engagement analytics.
(e) CWILL SEO & Speed (SEOWILL): Data Subjects: merchants and merchant employees. Personal Data: store name, store domain, product and collection information, page and blog content, keywords, rankings, traffic analytics, Google Search Console data (where authorized), redirect information, backlink information, SEO settings, and AI-generated content. SEOWILL is not intended to process identifiable end-consumer data.
(f) TrackingMore: Data Subjects: merchants, API customers, their employees, shipment recipients, and tracking-page visitors. Personal Data: order number, order value, order date, item details, tracking number, carrier name, shipping method, parcel weight, shipping dates and addresses, customer name, email, phone number, shipping address, notification preferences, delivery status, delivery location, delivery date, signer name, estimated delivery date, shipping label files, shipping rates, manifest files, return reason, return method, resolution type, return product images, refund amount, and return date.
Duration of Processing: For the term of the Agreement and for a period of up to 180 days thereafter (or such longer period as required by applicable law), subject to Section 8 and Section 8A of this DPA.
Contact for the Processor: [email protected]; DPO: [email protected].
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:
N/A
The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis):
Continuous
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: The data exporter determines the duration of processing in accordance with the terms of the Agreement but will retain the information for no longer than necessary to fulfill the purposes for which it was collected. For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing:
Personal Data will be retained for the duration of the Agreement and for a reasonable period thereafter, in line with applicable Data Protection Laws and Processor's then-current data retention policies, as further described in Sections 8 and 8A of this DPA.
Identify the competent supervisory authority/ies in accordance with Clause 13:
The data exporter's competent supervisory authority will be determined in accordance with the GDPR.
Processor maintains appropriate organizational and technical security measures designed to protect Personal Data against unauthorized access, loss, alteration, disclosure, destruction, or other unlawful Processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risks to individuals' rights and freedoms. The following describes the categories of measures Processor has implemented. Processor may update these measures from time to time, provided that such updates do not materially decrease the overall level of protection.
| Category | Subcategory | Relevant Security Issue | CWILL Implementation |
|---|---|---|---|
| Privacy / Security | Data Retention and Storage | Data storage | All data, including collected personal data, are stored in the cloud through the cloud services as shown in the Authorized Sub-processors' list. The location of the data centres is further described in the Authorized Sub-processors list. |
| Privacy / Security | Data Retention and Storage | Personal data retention and erasure | There are defined retention periods for collected personal data. If the personal data are no longer required to be retained, they are systematically destroyed and/or anonymized. |
| Security | Access Control Management | Implemented password policies, password controls. Encryption / hashing of passwords | CWILL has implemented internal password policies to specify security requirements and avoid employees using weak passwords. Passwords are hashed using industry-standard algorithms with a random salt. |
| Security | Access Control Management | Immediate removal of access rights for users leaving the organization | Employee off-boarding procedures are in place to ensure employees' access rights are removed when leaving. |
| Security | Access Control Management | Least privilege and role-based access control | Access to systems that process Personal Data is restricted based on role, business need, and the principle of least privilege. User permissions are granted according to job responsibilities and reviewed periodically. |
| Security | Access Control Management | Access approval and provisioning | Access to production systems and Personal Data is granted through an approval-based provisioning process and limited to authorized personnel with a legitimate business need. |
| Security | Access Control Management | Periodic access review | CWILL periodically reviews user access rights to systems that process Personal Data and removes or adjusts access that is no longer required. |
| Security | Access Control Management | Authentication and multi-factor authentication | CWILL enforces password policies for internal accounts and requires multi-factor authentication for administrative access and access to all systems that process Personal Data. |
| Security | Access Control Management | Logging and monitoring of privileged access | Administrative and privileged access to production systems is logged and monitored to detect unauthorized or inappropriate access. |
| Security | Data Transmission and Encryption | Encryption of Personal Data during transmission | Personal Data transmitted over public networks is encrypted using TLS 1.2 or higher. CWILL maintains configurations designed to prevent the use of deprecated protocols and weak cipher suites. |
| Security | Data Retention and Storage | Encryption of Personal Data at rest | Personal Data stored in production databases, object storage, and backups is encrypted at rest using industry-standard encryption mechanisms provided by cloud infrastructure providers or equivalent controls. Access to encryption keys is restricted to authorized systems and personnel. |
| Security | Vulnerability Management and Security Testing | Vulnerability scanning, penetration testing, and remediation | CWILL conducts periodic vulnerability assessments and security testing of systems that process Personal Data, including automated vulnerability scanning and, where appropriate, penetration testing. Identified vulnerabilities are reviewed, risk-rated, and remediated within commercially reasonable timeframes based on severity. Security testing is performed in a manner designed to avoid unauthorized access to, alteration of, or disruption to Personal Data. |
| Security | Business Continuity Management | Backup policies and frequency | Daily backup performed by cloud services at primary and secondary data centres |
| Security | Business Continuity Management | Disaster recovery sites in multiple / diverse geographic locations | The data centres hosting the cloud services are located in different locations to reduce risks of data loss. |
| Privacy / Security | Governance | Security awareness training program currently in place: topics and frequency | Security awareness training is implemented when onboarding employees and conducted at least annually thereafter. Main topics covered during the training include: general obligations under various information security policies, standards, procedures, guidelines, applicable security related laws and regulations, contractual terms and standards of ethics and acceptable behaviour. |
| Privacy / Security | Incident Response Management | Incident response procedures in place. Existence of a team with defined roles and responsibilities. Existence of communication procedures regarding security incidents such as data breaches. Notification timeframe regarding third parties | Data breach response team and plan are in place (Detect, Contain, Analyze, Notify, Respond, Document, Learn). Data breach response team checklist, with defined roles and responsibilities. |