Start free

Data Processing Addendum

Your customers' data is yours. We process it only to run your site, and here is exactly how.

Plain-English baseline. This is a clear, good-faith starting draft — not legal advice. Have your counsel review and adapt it before relying on it for your jurisdiction.
Last updated 2026

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you (the account holder) and OOXO. When your site collects personal data about your customers, members, visitors or staff ("Customer Personal Data"), you are the controller and OOXO is your processor. It applies automatically; there is nothing to sign. If you need a countersigned copy, email [email protected].

2. Processing on your instructions

We process Customer Personal Data only to provide the service — hosting your site, taking orders and bookings, sending the emails you configure, backups and security — and on your documented instructions, which are your settings in the Studio. We don't sell it, use it to advertise, or train shared AI models on it.

3. Details of the processing

  • Subjects: your site's visitors, customers, members, applicants and staff.
  • Categories: contact details, order, booking and payment references (never full card numbers), messages and form answers, account credentials (stored hashed), and technical data such as IP address.
  • Duration: for as long as you use the service, then deletion as set out below.

4. Security

We keep appropriate technical and organisational measures in place, including: each site's data in its own separate database; encryption in transit (TLS with HSTS) and of stored secrets and offsite backups at rest; hashed passwords and optional two-factor sign-in; least-privilege staff access where every support session inside an account is logged; rate limits and abuse monitoring. See Security & Trust.

5. Confidentiality

Everyone at OOXO who can access Customer Personal Data is bound by confidentiality and accesses it only where needed to support you or keep the service safe.

6. Sub-processors

We use a small set of sub-processors: our hosting and infrastructure providers, our email-delivery infrastructure, and — only when you connect them — your own payment provider (such as Stripe or PayPal), shipping, SMS and calendar providers. Payment providers you connect act under your own contract with them. We'll give notice of a new sub-processor by updating this page, and you may object by contacting us.

7. Helping you with requests and incidents

Your Studio lets you export, correct and delete a customer's data, and your shoppers can request their own export or erasure from your site (confirmed by email). We'll assist you with any other data-subject request, data-protection impact assessment or regulator enquiry about our processing. We'll notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your Customer Personal Data.

8. International transfers

Where Customer Personal Data is transferred outside the EEA, UK or Switzerland, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses (and the UK addendum), which are incorporated by reference.

9. Return and deletion

You can export your sites and data at any time. When you delete a site or your account, we delete Customer Personal Data from live systems after a short recovery grace period, and from backups as they age out of retention (typically 30 days), unless the law requires us to keep it.

10. Audits

On reasonable request we'll provide the information needed to show compliance with this DPA, including our security documentation. Questions: [email protected].

Questions?

We're happy to talk it through.

Email [email protected] →