Legal

Data Processing Addendum

Effective date: June 20, 2026

This Data Processing Addendum, including its Annexes ("DPA"), forms part of the agreement between the customer ("Merchant," "Controller," or "you") and Heem Megacorp LLC, a company organized under the laws of the State of Texas, USA with its registered office at 8500 Blazyk Drive, Austin, Texas 78737 ("HundredFold," "Processor," or "we") governing HundredFold's processing of Personal Data on the Merchant's behalf in connection with the HundredFold service available at gohundredfold.com and app.gohundredfold.com (the "Service").

This DPA reflects the parties' agreement on the processing of Personal Data in accordance with the requirements of Data Protection Laws. Where there is a conflict between this DPA and the underlying agreement between the parties (the "Agreement") on the subject of data protection, this DPA controls.

1. Definitions

For the purposes of this DPA, the following terms have the meanings set out below. Capitalized terms not defined here have the meaning given in the Agreement.

2. Subject Matter, Roles, and Scope

2.1 Subject matter and duration

The subject matter of the processing is the provision of the Service: a multi-tenant business-intelligence and action platform for direct-to-consumer ecommerce brands that connects a Merchant's store, advertising, email, and inventory data sources, surfaces AI-prioritized insights, and lets the Merchant act on them. This DPA applies for the duration of the Agreement (the "Term") and until all Personal Data is deleted or returned in accordance with Section 9.

2.2 Roles for End-Customer Data (HundredFold as Processor)

With respect to End-Customer Data that flows into the Service from the Merchant's connected platforms, the Merchant is the Controller and HundredFold is the Processor. HundredFold processes End-Customer Data only to provide the Service to that Merchant, on the Merchant's documented instructions, as set out in this DPA.

2.3 Roles for Account Data (HundredFold as Controller)

With respect to Account Data — the Personal Data of the Merchant's authorized users who log in to the Service — HundredFold acts as an independent Controller. Account Data consists of: the user's work email address, the user's role (owner, admin, member, or viewer), and an internal Supabase user identifier. Access is invite-only via an owner-managed allowlist; there is no public self-serve signup. Authentication is passwordless (a magic link sent to the work email, or Google sign-in, via Supabase Auth). HundredFold does not store user passwords, phone numbers, postal addresses, or payment data. HundredFold's processing of Account Data as a Controller is governed by the HundredFold Privacy Policy rather than by the Processor obligations in this DPA.

2.4 Details of processing

The categories of Data Subjects, categories of Personal Data, and the nature, purpose, and duration of the processing are described in Annex I.

3. Processor Obligations

HundredFold, as Processor of End-Customer Data, will:

3.1 Process only on documented instructions

Process End-Customer Data only on the Merchant's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case HundredFold will, where legally permitted, inform the Merchant of that legal requirement before processing). The Agreement, this DPA, and the Merchant's configuration and use of the Service constitute the Merchant's complete and final documented instructions. HundredFold will inform the Merchant if, in its opinion, an instruction infringes Data Protection Laws.

3.2 No sale or unauthorized use

Not sell End-Customer Data, not retain, use, or disclose it for any purpose other than providing the Service (or as otherwise permitted by Data Protection Laws), and not combine it with Personal Data from other sources except as necessary to provide the Service to the Merchant. HundredFold certifies that it understands and will comply with these restrictions, including the CCPA/CPRA restrictions on "service providers."

3.3 Confidentiality of personnel

Ensure that persons authorized to process End-Customer Data are bound by an appropriate duty of confidentiality and process the data only as necessary to perform their duties.

3.4 Security measures

Implement and maintain the appropriate technical and organizational measures set out in Annex II to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects.

3.5 Sub-processors

Engage Sub-processors only in accordance with Section 4.

3.6 Assistance with Data Subject requests

Taking into account the nature of the processing, assist the Merchant by appropriate technical and organizational measures, insofar as possible, in fulfilling the Merchant's obligation to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection), as further described in Section 5.

3.7 Assistance with security, breach, and DPIA obligations

Assist the Merchant in ensuring compliance with its obligations regarding security of processing, notification of Personal Data Breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to HundredFold.

3.8 Personal Data Breach notification

Notify the Merchant without undue delay after becoming aware of a Personal Data Breach affecting End-Customer Data, as further described in Section 6.

3.9 Deletion or return on termination

Delete or return End-Customer Data at the end of the Term, as further described in Section 9.

3.10 Audit information

Make available to the Merchant the information necessary to demonstrate compliance with the obligations in Article 28 GDPR and allow for and contribute to audits, as further described in Section 7.

4. Sub-processors

4.1 General authorization

The Merchant provides general authorization for HundredFold to engage Sub-processors to process End-Customer Data in connection with the Service. The Sub-processors engaged as of the effective date are listed in Annex III and on HundredFold's Sub-processors page.

4.2 Flow-down obligations

Where HundredFold engages a Sub-processor, it will do so under a written contract that imposes data protection obligations no less protective than those in this DPA, in particular providing appropriate technical and organizational security measures. HundredFold remains fully liable to the Merchant for the performance of each Sub-processor's obligations.

4.3 Change notice and objection

HundredFold will notify the Merchant of any intended addition or replacement of a Sub-processor in advance (via the Sub-processors page and/or email to the Merchant's owner account), giving the Merchant the opportunity to object on reasonable data protection grounds within 30 days. If the Merchant reasonably objects and the parties cannot resolve the objection, the Merchant may, as its sole remedy, terminate the affected portion of the Service in accordance with the Agreement.

4.4 Merchant-connected platforms are not HundredFold Sub-processors

The platforms a Merchant authorizes as data sources — Shopify, Meta, Google, and Amazon — are not HundredFold Sub-processors. They are independent services chosen and connected by the Merchant and governed by the Merchant's own agreements with those providers. HundredFold reads data from (and, where authorized, writes drafts to) these platforms on the Merchant's behalf, but does not provide them as part of HundredFold's own infrastructure.

5. Assistance with Data Subject Requests

5.1 Routing of requests

If HundredFold receives a request directly from a Data Subject concerning End-Customer Data, HundredFold will not respond to the request itself (except to confirm receipt where required) and will, without undue delay, forward the request to the relevant Merchant.

5.2 Means of assistance

HundredFold will provide reasonable assistance — through the Service's functionality and, where necessary, through manual support — to enable the Merchant to respond to Data Subject requests for access, rectification, erasure, restriction, portability, and objection. Because the End-Customer Data HundredFold stores is minimal (see Annex I), most requests can be satisfied by locating, exporting, or deleting records keyed to a customer email address.

5.3 Erasure and Shopify mandatory webhooks

HundredFold is building an automated end-customer erasure path. When complete, it will honor (a) Shopify's mandatory compliance webhooks — customers/redact, shop/redact, and customers/data_request — and (b) erasure/access requests the Merchant forwards from GDPR/CCPA Data Subjects. Until that automated path is live, HundredFold will action such requests manually upon the Merchant's instruction. HundredFold targets completion of each erasure request within 30 days of receipt, consistent with Data Protection Laws and Shopify's webhook requirements. See our Data Deletion page.

5.4 Portability/export

HundredFold is building a data-export capability to support the right to data portability (GDPR Art. 20). Until it is available in the Service, the Merchant may request an export of the End-Customer Data associated with a given Data Subject by contacting admin@gohundredfold.com, and HundredFold will provide the relevant data in a structured, commonly used, machine-readable format.

6. Personal Data Breach Notification

6.1 Notification without undue delay

HundredFold will notify the Merchant without undue delay, and in any event within 72 hours after becoming aware of a Personal Data Breach affecting End-Customer Data processed under this DPA.

6.2 Contents of notification

The notification will, to the extent known and as it becomes available, describe: the nature of the breach (including, where possible, the categories and approximate number of Data Subjects and records concerned); the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information. HundredFold will provide updates as more information becomes available.

6.3 Cooperation

HundredFold will cooperate with the Merchant and take reasonable steps as directed by the Merchant to assist in the investigation, mitigation, and remediation of the breach, including supporting the Merchant's own notification obligations to supervisory authorities and affected Data Subjects. A notification under this Section is not an acknowledgment of fault or liability.

7. Audit and Compliance Information

7.1 Documentation

HundredFold will make available to the Merchant, on reasonable request, the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, including the relevant compliance reports of its infrastructure Sub-processors. Both Supabase and Vercel maintain SOC 2 Type II reports; HundredFold's controls are designed to align with the SOC 2 Trust Services Criteria, and a HundredFold SOC 2 program is planned. HundredFold does not itself currently hold a SOC 2 report.

7.2 Audits

Where the information made available under Section 7.1 is not sufficient to demonstrate compliance, HundredFold will allow for and contribute to audits, including inspections, conducted by the Merchant or an independent auditor mandated by the Merchant. Audits will be conducted on reasonable prior written notice (no less than 30 days, except where Data Protection Laws or a supervisory authority require otherwise), no more than once per twelve-month period (unless required following a Personal Data Breach or by a supervisory authority), during normal business hours, subject to confidentiality obligations, and in a manner that does not disrupt HundredFold's operations or compromise the security of other customers' data.

8. International Transfers

8.1 Transfer mechanism

To the extent HundredFold's processing of End-Customer Data involves a transfer of Personal Data out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, the parties agree that such transfers will be governed by an appropriate transfer mechanism, specifically: the EU Standard Contractual Clauses (Module Two: Controller-to-Processor) for EEA transfers, the UK IDTA (or UK Addendum to the SCCs) for UK transfers, and the relevant addendum for Swiss transfers.

8.2 Incorporation

Where the SCCs apply, they are incorporated into this DPA by reference and completed using the information in Annex I (description of transfer), Annex II (technical and organizational measures), and Annex III (Sub-processors). In the event of a conflict between the SCCs and this DPA, the SCCs prevail with respect to the transfer they govern.

9. Deletion or Return on Termination

9.1 On termination

Upon expiry or termination of the Agreement, HundredFold will, at the Merchant's choice, delete or return all End-Customer Data, and delete existing copies, unless retention is required by applicable law. The Merchant may make this election within 30 days of termination; absent an election, HundredFold will delete the End-Customer Data following that period.

9.2 Retention during the Term

HundredFold currently retains data for the duration of the Term and does not yet perform automated, age-based deletion of End-Customer Data; data is retained for as long as the account is active. HundredFold is building automated retention controls; until they are live, deletion occurs on request or on termination as described in this Section and Section 5.3.

9.3 Backups

Residual copies of End-Customer Data may persist in routine, secured backups for a limited period after deletion from the live environment; such copies are protected by the measures in Annex II and are deleted in the ordinary course of backup rotation.

10. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together.

11. Scope of Data Protection Laws, Governing Law, and General

11.1 Audience and scope

The parties confirm that the following Data Protection Laws are in scope for this DPA: the EU GDPR and UK GDPR, and the California CCPA/CPRA. The rights-and-assistance provisions of this DPA apply to the extent the corresponding law applies to the relevant processing.

11.2 Governing law

This DPA is governed by the law and subject to the jurisdiction stated in the Agreement, except where Data Protection Laws (or the SCCs) require otherwise: the State of Texas, USA.

11.3 Order of precedence

In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails. The Annexes form an integral part of this DPA.

11.4 Changes

HundredFold may update this DPA from time to time to reflect changes in Data Protection Laws, Sub-processors, or the Service, provided that no update will materially reduce the protections for End-Customer Data without the Merchant's consent where required by Data Protection Laws.

11.5 Contact

Data protection and security inquiries may be directed to admin@gohundredfold.com.

Signatures

Merchant (Controller)HundredFold (Processor)
Entity: ____________________Entity: Heem Megacorp LLC
Signature: ____________________Signature: ____________________
Name: ____________________Name: ____________________
Title: ____________________Title: ____________________
Date: ____________________Date: ____________________

This DPA may be accepted by the Merchant's acceptance of the Agreement that incorporates it, in which case a physical signature is not required for it to be binding.

Annex I — Description of Processing

A. Parties

B. Categories of Data Subjects

C. Categories of Personal Data

Data Subject categoryPersonal Data processedSource
Merchant's customers (End-Customer Data)Customer email address; shipping city, state/province, and country. No customer names, street addresses, phone numbers, payment/card data, or customer profiles are collected or stored.The Merchant's connected Shopify store (orders)
Merchant's authorized users (Account Data)Work email address; role (owner / admin / member / viewer); internal Supabase user id. No passwords, phone numbers, addresses, or payment data.Provided at invitation / sign-in via Supabase Auth

D. Special categories of Personal Data

None. HundredFold does not process special-category (sensitive) Personal Data under this DPA.

E. Nature and purpose of processing

Storage, organization, analysis, and presentation of the Personal Data above for the purpose of providing the Service — a business-intelligence and action platform — including: syncing and storing connected-store data; computing aggregate analytics and insights; and, on the Merchant's instruction, exporting customer email addresses (derived from orders) to the Merchant's own Klaviyo account to build win-back marketing audiences. The customer email address is the only End-Customer Personal Data used for the win-back export.

F. AI processing limitation

HundredFold's AI analyst and daily briefing (powered by Anthropic Claude) receive business aggregates only (e.g., revenue/ROAS/AOV KPIs, inventory summaries, top-ad metrics, customer-health rates such as repeat and refund percentages, email metrics, replenishment plans) and the Merchant's own written business-context notes. The AI never receives customer names, emails, or addresses, nor any API keys, tokens, or secrets.

G. Frequency of processing

Continuous / on a recurring scheduled basis (automated syncs and scheduled jobs) for the duration of the Term.

H. Duration / retention

For the duration of the Term, then deleted or returned in accordance with Section 9. Retention approach: data is retained for as long as the account is active; automated, age-based deletion is being implemented.

I. Transfer details (where SCCs apply)

Annex II — Technical and Organizational Measures

HundredFold maintains the following technical and organizational measures to protect End-Customer Data. These measures are designed to align with the SOC 2 Trust Services Criteria. HundredFold may update measures over time provided the overall level of protection is not reduced.

1. Multi-tenant isolation and access control

2. Encryption

3. Integration token storage

4. Secrets management

5. Logging and monitoring

6. Backups and recovery

7. AI privacy controls

8. Sub-processor diligence

9. Infrastructure security

10. Cookies

11. Incident response

Annex III — Sub-processors

The current list of Sub-processors HundredFold engages to process End-Customer Data is maintained on the HundredFold Sub-processors page and reproduced below as of the effective date. Changes are governed by Section 4.3.

Sub-processorPurpose / processing activityPersonal Data involvedRegion
SupabaseManaged PostgreSQL database and authentication; stores all application data and user emailsEnd-Customer Data (email, ship city/state/country) and Account DataUnited States
VercelApplication hosting and scheduled cron jobsProcessed in transit/at runtime; no dedicated data store of End-Customer DataUnited States
AnthropicAI analysis (daily briefing, strategy, copy generation)Business aggregates only — no end-customer PII, no secretsUnited States
HiggsfieldAI image generation for ad creativeProduct images + text prompts — no customer/personal dataUnited States
ResendTransactional email (warehouse packing lists / FBA labels to a Merchant-configured warehouse email)No end-customer PIIUnited States
KlaviyoEmail-marketing platform; receives draft templates and customer emails for win-back listsCustomer email addresses (exported on the Merchant's instruction)United States

Note on data sources vs. Sub-processors: the platforms a Merchant connects as data sources — Shopify, Meta, Google, and Amazon — are merchant-authorized integrations governed by their own terms and are not HundredFold infrastructure Sub-processors (see Section 4.4).