Introducing the Pocketsflow startup program: Win $100K if you are a startupWin $100K if you are a startup

LegalLast updated

Data Processing Addendum

Pocketsflow's data processing addendum for sellers.

Effective Date: September 28, 2025

1. Introduction and Scope

This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement (“Agreement”) between Pocketsflow (“Company,” “Data Processor”) and the customer (“Customer,” “Data Controller”) and applies to the processing of Personal Data by Company on behalf of Customer in connection with the Pocketsflow services.

2. Definitions

For the purposes of this DPA:

  • “Data Protection Laws” means applicable data protection and privacy laws, including GDPR, CCPA, and other relevant regulations
  • “Personal Data” means any information relating to an identified or identifiable natural person
  • “Processing” has the meaning given in applicable Data Protection Laws
  • “Data Subject” means the identified or identifiable natural person to whom Personal Data relates
  • “Subprocessor” means any processor engaged by Company to assist in fulfilling its obligations

3. Data Processing Details

3.1 Subject Matter and Duration

Company will process Personal Data to provide the Pocketsflow marketplace services as described in the Agreement, for the duration of the Agreement and as required for legal compliance thereafter.

3.2 Nature and Purpose of Processing

  • Marketplace platform operation and maintenance
  • Payment processing and financial transactions
  • Customer support and communication
  • Analytics and platform improvement
  • Legal compliance and fraud prevention

3.3 Categories of Personal Data

  • Identity Data: Name, username, email address
  • Contact Data: Billing address, phone number
  • Financial Data: Payment method information, transaction history
  • Technical Data: IP address, browser type, device information
  • Usage Data: Platform interaction, preferences, analytics
  • Content Data: Product listings, messages, reviews

3.4 Categories of Data Subjects

  • Marketplace users (buyers and sellers)
  • Customer support contacts
  • Website visitors
  • Marketing contacts

4. Company Obligations

4.1 Processing Instructions

Company shall process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to third countries, unless required by applicable law.

4.2 Confidentiality

Company ensures that persons authorized to process Personal Data have committed themselves to confidentiality or are under appropriate statutory obligations of confidentiality.

4.3 Security Measures

Company implements appropriate technical and organizational measures including:

  • Encryption of Personal Data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training and background checks
  • Incident response and breach notification procedures
  • Regular backup and disaster recovery testing

5. Subprocessing

5.1 General Authorization

Customer provides general authorization for Company to engage subprocessors, subject to the conditions set forth in this DPA.

5.2 Current Subprocessors

  • Payment Service Providers - Payment processing and financial services
  • Cloud Infrastructure Providers - Cloud hosting and storage
  • Analytics Services - Analytics and advertising services
  • Customer Support Platforms - Customer support and communication
  • Email Service Providers - Email delivery services

5.3 Subprocessor Requirements

Company ensures that subprocessors:

  • Provide sufficient guarantees regarding security measures
  • Are bound by data protection obligations equivalent to this DPA
  • Process Personal Data only for authorized purposes
  • Implement appropriate technical and organizational measures

6. Data Subject Rights

6.1 Assistance with Data Subject Requests

Company will assist Customer in responding to Data Subject requests by:

  • Providing technical and organizational measures to facilitate responses
  • Implementing appropriate access controls and data retrieval systems
  • Cooperating with reasonable requests for assistance
  • Promptly forwarding Data Subject requests to Customer

6.2 Data Subject Rights Support

Company will support Customer in fulfilling Data Subject rights including:

  • Right of access to Personal Data
  • Right to rectification of inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing

7. Data Transfers

7.1 International Transfers

Personal Data may be transferred to and processed in countries outside the European Economic Area. Such transfers will be subject to appropriate safeguards including:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules where applicable
  • Certification schemes and codes of conduct

7.2 Transfer Impact Assessments

Company conducts Transfer Impact Assessments (TIAs) for transfers to countries without adequacy decisions to ensure appropriate protection levels.

8. Data Breach Notification

8.1 Incident Response

Company maintains a comprehensive incident response plan and will notify Customer without undue delay after becoming aware of a personal data breach.

8.2 Breach Notification Content

Breach notifications will include:

  • Description of the nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Categories and approximate number of Personal Data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

9. Data Protection Impact Assessments

Company will assist Customer with Data Protection Impact Assessments (DPIAs) where required, including providing information about processing operations, security measures, and risk assessments.

10. Data Retention and Deletion

10.1 Retention Periods

Personal Data will be retained according to the following schedules:

  • Active User Data: Duration of service provision
  • Transactional Data: 7 years for compliance purposes
  • Marketing Data: Until consent withdrawal
  • Support Data: 3 years after case closure

10.2 Data Deletion

At the end of the provision of services, Company will, at Customer’s choice, delete or return all Personal Data and delete existing copies unless retention is required by applicable law.

11. Audits and Compliance

11.1 Audit Rights

Customer may conduct audits of Company’s data processing activities, subject to reasonable notice and confidentiality requirements.

11.2 Compliance Documentation

Company will provide:

  • Annual compliance reports
  • Security certification documents
  • Third party audit results
  • Policy and procedure documentation

12. Liability and Indemnification

Each party’s liability under this DPA is subject to the limitation of liability provisions in the Agreement. Company will indemnify Customer against claims arising from Company’s breach of this DPA.

13. Term and Termination

This DPA will remain in effect for the duration of the Agreement and any period during which Company processes Personal Data on behalf of Customer.

14. Governing Law

This DPA is governed by the same law as the Agreement. For EU customers, data protection matters are governed by applicable EU Data Protection Laws.

15. Contact Information and Data Protection

For DPA related questions or Data Subject requests:

  • Data Protection Officer: chain@pocketsflow.com
  • Business Entity: Pocketsflow, Inc.
  • Registration: Delaware, USA
  • Jurisdiction: Delaware, USA
  • Data Subject Requests: GDPR requests processed within 30 days
  • DPA Inquiries: Technical questions answered within 48 hours
  • Breach Notifications: Immediate reporting within 72 hours as required by law