PlatformDTC
EnterprisePricingAbout UsAnswersBlogDocs

Data Processing Addendum

Last Updated: September 11, 2026 Effective Date: September 11, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service and, where it applies, the Brand Owner Agreement (together, the "Agreement") between Legalize Freedom LLC, a Delaware limited liability company doing business as "PlatformDTC" ("PlatformDTC"), and the merchant that has accepted the Agreement ("Merchant"). It applies automatically to every Merchant that accepts the Agreement; no separate signature is required.

This DPA sets out the terms on which PlatformDTC processes personal data on Merchant's behalf in providing the Service. Capitalized terms not defined in this DPA have the meaning given in the Agreement.


1. Definitions

  • "Applicable Data Protection Law" means all laws relating to the processing of personal data that apply to a party's processing under the Agreement, including, where applicable, the EU GDPR, the UK GDPR, the Swiss FADP and US State Privacy Laws.
  • "Customer Personal Data" means the personal data described in Annex I that PlatformDTC processes on behalf of Merchant in providing the Service, including personal data of Merchant's Customers.
  • "EU GDPR" means Regulation (EU) 2016/679.
  • "UK GDPR" means the EU GDPR as it forms part of the law of the United Kingdom, together with the UK Data Protection Act 2018.
  • "Swiss FADP" means the Swiss Federal Act on Data Protection of 25 September 2020 and its ordinances.
  • "US State Privacy Laws" means the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations ("CCPA"), and any other US state law governing the processing of personal data that applies to the processing under this DPA.
  • "EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by PlatformDTC or its Subprocessors.
  • "Subprocessor" means a third party engaged by PlatformDTC that processes Customer Personal Data.
  • "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in Applicable Data Protection Law; "business", "service provider", "contractor", "sell" and "share" have the meanings given in the CCPA.

2. Scope and Roles of the Parties

2.1 Merchant as controller. For Customer Personal Data, Merchant is the controller (or, where Merchant processes the data on behalf of a third party, a processor acting for that controller), and PlatformDTC is Merchant's processor (or subprocessor). Under the CCPA, Merchant is the business and PlatformDTC is its service provider.

2.2 PlatformDTC as controller. PlatformDTC processes some personal data as an independent controller and not under this DPA: personal data about Merchant and Merchant's own personnel who use the Service (account, billing and support data), and personal data PlatformDTC processes to prevent fraud and abuse, to secure the Service, to meet anti-money laundering, sanctions and tax obligations, and to comply with law. That processing is described in our Privacy Policy.

2.3 Payment processing. Payments are processed by the payment providers Merchant uses through the Service — Stripe for PlatformDTC Payments, as described in Section 5.2 of the Terms of Service, and any other provider Merchant connects — under Merchant's own agreements with those providers. A payment provider's own processing of payment data under those agreements is governed by that provider's terms and not by this DPA.

2.4 Details of processing. The subject matter, nature, purpose and duration of the processing, and the categories of personal data and data subjects, are set out in Annex I.


3. Merchant's Obligations

Merchant will:

  • (a) comply with Applicable Data Protection Law in its use of the Service, including in the instructions it gives PlatformDTC;
  • (b) have a lawful basis, and give every notice and obtain every consent Applicable Data Protection Law requires, for PlatformDTC to process Customer Personal Data under the Agreement — including a privacy notice on its storefront that describes that processing, and consent for cookies and similar technologies where the law requires it;
  • (c) not instruct PlatformDTC to process special categories of personal data, or personal data of children, except where Applicable Data Protection Law permits it and Merchant has met every requirement for that processing; and
  • (d) be responsible for the accuracy and lawfulness of the Customer Personal Data it provides and of the means by which it acquired that data.

4. Processing on Documented Instructions

4.1 Instructions. PlatformDTC will process Customer Personal Data only on Merchant's documented instructions, including with regard to transfers, unless required to do otherwise by law, in which case PlatformDTC will inform Merchant of that legal requirement before processing unless the law prohibits it. The Agreement, this DPA, and Merchant's configuration and use of the Service are Merchant's complete documented instructions. Additional instructions require the written agreement of both parties.

4.2 Unlawful instructions. PlatformDTC will inform Merchant without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law. PlatformDTC is not required to monitor or provide legal advice on Merchant's compliance.

4.3 Limited use. PlatformDTC will not process Customer Personal Data for any purpose other than providing the Service and performing the Agreement, except that PlatformDTC may create aggregated or de-identified data that no longer identifies any individual, as permitted by Section 7.3 of the Terms of Service and by Applicable Data Protection Law.


5. Confidentiality of Personnel

PlatformDTC will ensure that every person it authorizes to process Customer Personal Data — including employees and contractors — is subject to a duty of confidentiality, whether contractual or statutory, and accesses Customer Personal Data only as needed to provide the Service, maintain and secure it, or comply with law.


6. Security

6.1 Measures. PlatformDTC will implement and maintain the technical and organizational measures described in Annex II, which are designed to protect Customer Personal Data against Personal Data Breaches and to provide a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.

6.2 Updates. PlatformDTC may update the measures in Annex II from time to time, provided that an update does not materially reduce the overall protection of Customer Personal Data.

6.3 Merchant's responsibilities. Merchant is responsible for the security of its own accounts, credentials, API keys and devices, for the permissions it grants its staff and agents in the Service, and for protecting Customer Personal Data it exports from the Service.


7. Subprocessors

7.1 General authorization. Merchant gives PlatformDTC general written authorization to engage Subprocessors to process Customer Personal Data. The Subprocessors in use are listed, with each one's purpose, the data it processes and its processing location, at /legal/subprocessors (the "Subprocessor List"), which Merchant authorizes as of the date it accepts the Agreement.

7.2 Flow-down and responsibility. PlatformDTC will engage each Subprocessor under a written contract that imposes data protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the service the Subprocessor provides. PlatformDTC remains responsible to Merchant for its Subprocessors' performance of those obligations.

7.3 Notice of new Subprocessors. PlatformDTC will add any new Subprocessor to the Subprocessor List, and publish a dated entry in its change log and its Atom feed, at least 30 days before that Subprocessor begins processing Customer Personal Data. Merchant is responsible for subscribing to the feed or checking the Subprocessor List. Where a Subprocessor must be replaced urgently to keep the Service secure or available, PlatformDTC will give notice as soon as reasonably practicable, and Merchant's objection right under Section 7.4 applies from that notice.

7.4 Right to object. Merchant may object to a new Subprocessor on reasonable data protection grounds by emailing privacy@platformdtc.com within that 30-day notice period. The parties will discuss the objection in good faith. If PlatformDTC cannot address the objection — for example by offering a way to use the Service that does not involve the Subprocessor — within 30 days of receiving it, Merchant may terminate the affected part of the Service by written notice, and PlatformDTC will refund any fees Merchant has prepaid for the terminated part of the Service covering the period after termination.


8. Assistance with Data Subject Requests

8.1 Requests to PlatformDTC. If PlatformDTC receives a request from a data subject to exercise a right under Applicable Data Protection Law with respect to Customer Personal Data, and the request identifies Merchant, PlatformDTC will direct the data subject to Merchant and will not otherwise respond to the request unless Merchant authorizes it or the law requires it.

8.2 Assistance. Taking into account the nature of the processing, PlatformDTC will assist Merchant by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Merchant's obligation to respond to data subject requests — through functionality of the Service where it is available, and otherwise by responding to Merchant's written request to privacy@platformdtc.com.


9. Personal Data Breach Notification

9.1 Notice. PlatformDTC will notify Merchant of a Personal Data Breach without undue delay, and in any event no later than 72 hours after becoming aware of it. Notice will be sent to the email address of Merchant's account owner.

9.2 Content. The notice will describe, to the extent the information is then available: the nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for more information. Where not all of this information is available at once, PlatformDTC will provide it in phases as it becomes available.

9.3 Response. PlatformDTC will take reasonable steps to contain, investigate and mitigate the effects of a Personal Data Breach, and will provide reasonable cooperation to help Merchant meet its own obligations to notify supervisory authorities and data subjects.

9.4 No admission. PlatformDTC's notification of or response to a Personal Data Breach is not an acknowledgment of fault or liability.


10. Data Protection Impact Assessments and Consultation

Taking into account the nature of the processing and the information available to it, PlatformDTC will provide reasonable assistance to Merchant, on written request, with any data protection impact assessment and any prior consultation with a supervisory authority that Applicable Data Protection Law requires of Merchant in relation to the Service. PlatformDTC will provide this assistance primarily by making available the documentation described in Section 12.


11. Return and Deletion

11.1 During the term. Merchant may retrieve or delete Customer Personal Data through the Service where the Service provides that functionality, or by written request to privacy@platformdtc.com.

11.2 At termination. Merchant may request a copy of Customer Personal Data by written request to privacy@platformdtc.com within 30 days after termination of the Agreement. After that period, PlatformDTC will delete Customer Personal Data within 90 days, except where PlatformDTC is required by law to retain it.

11.3 Retained data. Customer Personal Data retained because the law requires it, and residual copies in backups (which are overwritten in the ordinary course within 90 days, as stated in our Privacy Policy), will remain subject to this DPA and will be processed only for the purpose for which it is retained.


12. Audits and Information

12.1 Documentation. On Merchant's written request, not more than once in any 12-month period (unless required by a supervisory authority or following a Personal Data Breach), PlatformDTC will make available the information reasonably necessary to demonstrate its compliance with this DPA, in the form of written documentation of its security measures and written responses to a reasonable security and privacy questionnaire.

12.2 On-site audits. Where, and only to the extent that, Applicable Data Protection Law or a supervisory authority requires an audit or inspection beyond Section 12.1, Merchant (or an independent auditor it appoints who is bound by confidentiality and is not a competitor of PlatformDTC) may conduct one, subject to: at least 30 days' written notice; an agreed scope, date and duration; conduct during normal business hours in a way that does not disrupt the Service or give access to other customers' data; and Merchant bearing its own costs and PlatformDTC's reasonable costs of supporting the audit.

12.3 Confidentiality. Information disclosed under this Section 12 is PlatformDTC's confidential information and may be used by Merchant only to assess compliance with this DPA.


13. International Transfers

13.1 Location of processing. PlatformDTC is established in the United States. Merchant acknowledges that Customer Personal Data will be processed in the United States and in the other locations shown in the Subprocessor List.

13.2 EEA transfers. To the extent PlatformDTC processes Customer Personal Data subject to the EU GDPR in a country that has not been recognized as providing an adequate level of protection, the EU SCCs are incorporated into this DPA by reference and apply as follows:

  • (a) Module Two (controller to processor) applies where Merchant is a controller, and Module Three (processor to processor) applies where Merchant is a processor; Merchant is the data exporter and PlatformDTC is the data importer;
  • (b) the optional docking clause in Clause 7 applies;
  • (c) for Clause 9(a), Option 2 (general written authorization) applies, and the time period for notice of changes to Subprocessors is 30 days, given as described in Section 7.3;
  • (d) the optional language in Clause 11(a) does not apply;
  • (e) for Clause 13, the competent supervisory authority is the one determined in Annex I.C;
  • (f) for Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland;
  • (g) for Clause 18(b), disputes are resolved by the courts of Ireland; and
  • (h) Annexes I, II and III of the EU SCCs are completed by Annex I, Annex II and the Subprocessor List of this DPA respectively.

13.3 UK transfers. To the extent PlatformDTC processes Customer Personal Data subject to the UK GDPR in a country that has not been recognized as providing an adequate level of protection, the UK Addendum is incorporated into this DPA by reference and completed as follows: Table 1 is completed with the parties' details in Annex I.A; Table 2 is completed by the EU SCCs as selected in Section 13.2; Table 3 is completed by Annex I, Annex II and the Subprocessor List; and for Table 4, both the Importer and the Exporter may end the UK Addendum as set out in its Section 19. The Mandatory Clauses of the UK Addendum apply.

13.4 Swiss transfers. To the extent PlatformDTC processes Customer Personal Data subject to the Swiss FADP in a country that has not been recognized as providing an adequate level of protection, the EU SCCs as selected in Section 13.2 apply with the following changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by the Swiss FADP; references to the EU GDPR are to be read as references to the Swiss FADP to the extent the transfer is governed by it; where a transfer is governed exclusively by the Swiss FADP, the EU SCCs are governed by Swiss law and disputes are resolved by the courts of Switzerland; and the term "Member State" is not to be interpreted so as to exclude data subjects in Switzerland from bringing claims in their place of habitual residence under Clause 18(c).

13.5 Government access requests. If PlatformDTC receives a legally binding request from a public authority for disclosure of Customer Personal Data, it will notify Merchant promptly unless the law prohibits notification, will review the legality of the request and challenge it where, after careful assessment, it concludes there are reasonable grounds to do so, and will disclose only the minimum information the request requires.

13.6 Alternative mechanisms. If a transfer mechanism in this Section 13 is replaced, amended or invalidated, the parties will rely on its replacement or on another lawful transfer mechanism, and PlatformDTC may update this Section 13 accordingly.


14. US State Privacy Laws

To the extent the processing of Customer Personal Data is subject to US State Privacy Laws, PlatformDTC:

  • (a) will process Customer Personal Data only for the limited and specified business purposes of providing the Service and performing the Agreement, as described in Annex I;
  • (b) will not sell or share Customer Personal Data;
  • (c) will not retain, use or disclose Customer Personal Data outside the direct business relationship between PlatformDTC and Merchant, or for any purpose other than those business purposes, except as US State Privacy Laws permit;
  • (d) will not combine Customer Personal Data with personal data it receives from or on behalf of another person, or collects from its own interactions with a consumer, except as US State Privacy Laws permit;
  • (e) will comply with its obligations under US State Privacy Laws and provide the same level of privacy protection they require of Merchant;
  • (f) will notify Merchant if it determines it can no longer meet its obligations under US State Privacy Laws;
  • (g) grants Merchant the right, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data, and to take reasonable and appropriate steps to ensure PlatformDTC uses Customer Personal Data consistently with Merchant's obligations, including through Section 12;
  • (h) will assist Merchant in responding to consumer requests as described in Section 8;
  • (i) will engage Subprocessors only under a written contract that meets the requirements of US State Privacy Laws, with notice and an opportunity to object as described in Section 7; and
  • (j) certifies that it understands and will comply with the restrictions in this Section 14.

Where a US State Privacy Law requires it, PlatformDTC will allow reasonable assessments of its compliance by Merchant or Merchant's designated assessor as described in Section 12, or provide a report of an independent assessment instead.


15. Liability

Each party's liability arising out of or relating to this DPA, however arising, is subject to the limitations and exclusions of liability in Section 14 of the Terms of Service, and any reference in those limitations to a party's liability means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this Section 15 limits either party's liability to data subjects under Clause 12 of the EU SCCs, or any liability that cannot be limited under applicable law.


16. Term, Precedence and Changes

16.1 Term. This DPA takes effect when Merchant accepts the Agreement and continues for as long as PlatformDTC processes Customer Personal Data, including after the Agreement ends.

16.2 Order of precedence. If there is a conflict: the EU SCCs, the UK Addendum and the Swiss adjustments in Section 13 prevail over this DPA; this DPA prevails over the rest of the Agreement with respect to the processing of Customer Personal Data; and Section 14 prevails over the rest of this DPA with respect to processing subject to US State Privacy Laws.

16.3 Changes. PlatformDTC may update this DPA to reflect changes in Applicable Data Protection Law, a transfer mechanism, or the Service. Material changes will be notified at least 14 days in advance by email or in-platform notice, consistent with Section 17 of the Terms of Service. No change will materially reduce the protection of Customer Personal Data unless the change is required by law.

16.4 Governing law. Except as Section 13 provides for the EU SCCs, the UK Addendum and Swiss transfers, this DPA is governed by the law that governs the Agreement.


Annex I — Details of Processing

A. List of parties

Data exporter: Merchant — the name, address and contact details of the account owner are those held in Merchant's PlatformDTC account. Role: controller (Module Two) or processor (Module Three). Activities: use of the Service to operate Merchant's online store and related business.

Data importer: Legalize Freedom LLC (dba PlatformDTC)
16192 Coastal Highway, Lewes, Delaware 19958, United States
Contact: privacy@platformdtc.com
Role: processor. Activities: providing the Service under the Agreement.

Each party's acceptance of the Agreement constitutes its signature of this Annex.

B. Description of processing

Categories of data subjects

  • Merchant's Customers and prospective customers, including shoppers, subscribers, visitors to Merchant's storefront and checkout, and people who start a checkout without completing it
  • Recipients of gifts, and people whose contact details a Customer provides for delivery
  • People who write product reviews, contact Merchant's support, or exchange messages with Merchant through the Service
  • Any other individuals whose personal data Merchant submits to the Service

Categories of personal data

  • Identity and contact data: name, email address, phone number, date of birth where the Merchant collects it
  • Billing and shipping addresses
  • Order, transaction and subscription data: items, amounts, discounts, refunds, subscription plans and renewal history, gift messages and recipient details, and payment references returned by payment providers (PlatformDTC does not store full card numbers or card security codes; for stores that connect Authorize.net, card details pass through PlatformDTC's checkout API in transit to Authorize.net without being stored)
  • Customer account data for shoppers who create an account with Merchant's store
  • Marketing preferences and consent records, including the time, IP address and user agent recorded when consent is given
  • Email, SMS and push engagement data: messages sent, delivery, opens and clicks
  • Device, session and attribution data: IP address, user agent, session and event data, and advertising click and browser identifiers (such as Meta's fbc and fbp values)
  • Communications content: support messages, order notes and comments, SMS conversations, and product reviews
  • Any other personal data Merchant or its Customers submit to the Service

Sensitive data None is intended to be processed. Merchant must not submit special categories of personal data except as Section 3(c) permits.

Frequency of the transfer Continuous, for as long as Merchant uses the Service.

Nature of the processing Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, analysis, disclosure by transmission to Subprocessors and to recipients Merchant directs (such as fulfilment providers and advertising platforms Merchant connects), restriction, erasure and destruction.

Purposes of the processing Providing the Service to Merchant in accordance with the Agreement, including: hosting and operating Merchant's storefront and checkout; processing orders, subscriptions, refunds and fulfilment; sending transactional and marketing email, SMS and push messages Merchant configures; customer support; analytics and reporting for Merchant; sending conversion events to advertising platforms Merchant connects; operating AI features and agents Merchant uses; and securing, maintaining and supporting the Service.

Duration of the processing and retention For the term of the Agreement, and afterwards until the Customer Personal Data is returned or deleted under Section 11.

Transfers to Subprocessors For the subject matter, nature and duration set out in this Annex, as described for each Subprocessor on the Subprocessor List.

C. Competent supervisory authority

Where Merchant is established in an EU Member State, the supervisory authority of that Member State. Where Merchant is not established in the EU but is subject to the EU GDPR under its Article 3(2) and has appointed a representative under Article 27(1), the supervisory authority of the Member State in which that representative is established. Where Merchant is subject to the EU GDPR under its Article 3(2) without having appointed a representative, the Data Protection Commission of Ireland. For the UK GDPR, the UK Information Commissioner. For the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner.


Annex II — Technical and Organizational Security Measures

PlatformDTC maintains the following measures. Further detail is published on our Security page.

Encryption in transit

  • PlatformDTC's public hosts accept only TLS 1.2 or TLS 1.3; TLS 1.0 and 1.1 are refused.
  • The API sends HTTP Strict Transport Security.
  • Connections to the primary database are required to use TLS.

Encryption at rest

  • The primary database that stores Customer Personal Data is encrypted at rest with a key managed in the cloud provider's key management service.
  • Files stored in object storage are encrypted at rest with AES-256, and the buckets that hold store files, checkout assets and support attachments block all public access.
  • Credentials that merchants connect for payment providers and tracking pixels are encrypted before they are stored.

Payment card data

  • PlatformDTC does not store full card numbers or card security codes. For Stripe, Checkout.com and MyFatoorah, card details are entered into the provider's hosted payment fields and do not reach PlatformDTC servers; for PayPal, the customer approves the payment in PayPal's own checkout. For stores that connect Authorize.net, card details are sent over TLS to PlatformDTC's checkout API and passed to Authorize.net, and are not written to PlatformDTC's database or logs.

Authentication and access

  • User passwords are stored only as salted bcrypt hashes (cost factor 12), never in plain text or reversible form.
  • Session tokens are held in HttpOnly, Secure cookies and stored on PlatformDTC's servers only as hashes; sign-in and verification requests are rate limited.
  • Agents act on the Service through the Agent Gateway using scoped API keys, stored only as hashes, which can be limited to specific stores and revoked individually. Every Agent Gateway call is recorded in an audit log, and a key can be set to require human approval before it dispatches spend actions.
  • The primary database accepts connections only from an allow-list of network addresses.
  • Access by PlatformDTC personnel to Customer Personal Data is limited to what is needed to provide, maintain, secure and support the Service, subject to Section 5.

Availability and recovery

  • The primary database has automated continuous backups with point-in-time restore, and deletion protection is enabled.
  • Current service status is published at status.platformdtc.com.

Vulnerability management and incident response

  • Security vulnerabilities can be reported to security@platformdtc.com under our Vulnerability Disclosure Policy.
  • Personal Data Breaches are handled and notified as set out in Section 9.

Subprocessors

  • Subprocessors are engaged under Section 7, and each is listed with its processing location on the Subprocessor List.

Contact

Questions about this DPA: privacy@platformdtc.com

Legalize Freedom LLC (dba PlatformDTC), Privacy Team
16192 Coastal Highway
Lewes, Delaware 19958
United States

PlatformDTC

One platform to run your brand. Agents included.

Resources

  • Answers
  • Glossary
  • Agent Readiness Checker
  • DTC AI Crawler Index
  • Blog
  • Pricing
  • Explore all pages

Company

  • About Us
  • Enterprise
  • Talk to Sales
  • Contact
  • Developer Docs
  • System Status
  • Community

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • All policies

© Copyright 2026 PlatformDTC. All Rights Reserved.