Effective Date: September 28, 2025
1. Introduction and Scope
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement (“Agreement”) between Pocketsflow (“Company,” “Data Processor”) and the customer (“Customer,” “Data Controller”) and applies to the processing of Personal Data by Company on behalf of Customer in connection with the Pocketsflow services.
2. Definitions
For the purposes of this DPA:
- “Data Protection Laws” means applicable data protection and privacy laws, including GDPR, CCPA, and other relevant regulations
- “Personal Data” means any information relating to an identified or identifiable natural person
- “Processing” has the meaning given in applicable Data Protection Laws
- “Data Subject” means the identified or identifiable natural person to whom Personal Data relates
- “Subprocessor” means any processor engaged by Company to assist in fulfilling its obligations
3. Data Processing Details
3.1 Subject Matter and Duration
Company will process Personal Data to provide the Pocketsflow marketplace services as described in the Agreement, for the duration of the Agreement and as required for legal compliance thereafter.
3.2 Nature and Purpose of Processing
- Marketplace platform operation and maintenance
- Payment processing and financial transactions
- Customer support and communication
- Analytics and platform improvement
- Legal compliance and fraud prevention
3.3 Categories of Personal Data
- Identity Data: Name, username, email address
- Contact Data: Billing address, phone number
- Financial Data: Payment method information, transaction history
- Technical Data: IP address, browser type, device information
- Usage Data: Platform interaction, preferences, analytics
- Content Data: Product listings, messages, reviews
3.4 Categories of Data Subjects
- Marketplace users (buyers and sellers)
- Customer support contacts
- Website visitors
- Marketing contacts
4. Company Obligations
4.1 Processing Instructions
Company shall process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to third countries, unless required by applicable law.
4.2 Confidentiality
Company ensures that persons authorized to process Personal Data have committed themselves to confidentiality or are under appropriate statutory obligations of confidentiality.
4.3 Security Measures
Company implements appropriate technical and organizational measures including:
- Encryption of Personal Data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Employee training and background checks
- Incident response and breach notification procedures
- Regular backup and disaster recovery testing
5. Subprocessing
5.1 General Authorization
Customer provides general authorization for Company to engage subprocessors, subject to the conditions set forth in this DPA.
5.2 Current Subprocessors
- Payment Service Providers - Payment processing and financial services
- Cloud Infrastructure Providers - Cloud hosting and storage
- Analytics Services - Analytics and advertising services
- Customer Support Platforms - Customer support and communication
- Email Service Providers - Email delivery services
5.3 Subprocessor Requirements
Company ensures that subprocessors:
- Provide sufficient guarantees regarding security measures
- Are bound by data protection obligations equivalent to this DPA
- Process Personal Data only for authorized purposes
- Implement appropriate technical and organizational measures
6. Data Subject Rights
6.1 Assistance with Data Subject Requests
Company will assist Customer in responding to Data Subject requests by:
- Providing technical and organizational measures to facilitate responses
- Implementing appropriate access controls and data retrieval systems
- Cooperating with reasonable requests for assistance
- Promptly forwarding Data Subject requests to Customer
6.2 Data Subject Rights Support
Company will support Customer in fulfilling Data Subject rights including:
- Right of access to Personal Data
- Right to rectification of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object to processing
7. Data Transfers
7.1 International Transfers
Personal Data may be transferred to and processed in countries outside the European Economic Area. Such transfers will be subject to appropriate safeguards including:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules where applicable
- Certification schemes and codes of conduct
7.2 Transfer Impact Assessments
Company conducts Transfer Impact Assessments (TIAs) for transfers to countries without adequacy decisions to ensure appropriate protection levels.
8. Data Breach Notification
8.1 Incident Response
Company maintains a comprehensive incident response plan and will notify Customer without undue delay after becoming aware of a personal data breach.
8.2 Breach Notification Content
Breach notifications will include:
- Description of the nature of the breach
- Categories and approximate number of Data Subjects affected
- Categories and approximate number of Personal Data records affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
9. Data Protection Impact Assessments
Company will assist Customer with Data Protection Impact Assessments (DPIAs) where required, including providing information about processing operations, security measures, and risk assessments.
10. Data Retention and Deletion
10.1 Retention Periods
Personal Data will be retained according to the following schedules:
- Active User Data: Duration of service provision
- Transactional Data: 7 years for compliance purposes
- Marketing Data: Until consent withdrawal
- Support Data: 3 years after case closure
10.2 Data Deletion
At the end of the provision of services, Company will, at Customer’s choice, delete or return all Personal Data and delete existing copies unless retention is required by applicable law.
11. Audits and Compliance
11.1 Audit Rights
Customer may conduct audits of Company’s data processing activities, subject to reasonable notice and confidentiality requirements.
11.2 Compliance Documentation
Company will provide:
- Annual compliance reports
- Security certification documents
- Third party audit results
- Policy and procedure documentation
12. Liability and Indemnification
Each party’s liability under this DPA is subject to the limitation of liability provisions in the Agreement. Company will indemnify Customer against claims arising from Company’s breach of this DPA.
13. Term and Termination
This DPA will remain in effect for the duration of the Agreement and any period during which Company processes Personal Data on behalf of Customer.
14. Governing Law
This DPA is governed by the same law as the Agreement. For EU customers, data protection matters are governed by applicable EU Data Protection Laws.
15. Contact Information and Data Protection
For DPA related questions or Data Subject requests:
- Data Protection Officer: chain@pocketsflow.com
- Business Entity: Pocketsflow, Inc.
- Registration: Delaware, USA
- Jurisdiction: Delaware, USA
- Data Subject Requests: GDPR requests processed within 30 days
- DPA Inquiries: Technical questions answered within 48 hours
- Breach Notifications: Immediate reporting within 72 hours as required by law