This Data Processing Addendum, including its Annexes ("DPA"), forms part of the agreement between the customer ("Merchant," "Controller," or "you") and Heem Megacorp LLC, a company organized under the laws of the State of Texas, USA with its registered office at 8500 Blazyk Drive, Austin, Texas 78737 ("HundredFold," "Processor," or "we") governing HundredFold's processing of Personal Data on the Merchant's behalf in connection with the HundredFold service available at gohundredfold.com and app.gohundredfold.com (the "Service").
This DPA reflects the parties' agreement on the processing of Personal Data in accordance with the requirements of Data Protection Laws. Where there is a conflict between this DPA and the underlying agreement between the parties (the "Agreement") on the subject of data protection, this DPA controls.
1. Definitions
For the purposes of this DPA, the following terms have the meanings set out below. Capitalized terms not defined here have the meaning given in the Agreement.
- "Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). The scope of laws that apply is set out in Section 11.
- "Controller" means the entity that, alone or jointly with others, determines the purposes and means of the processing of Personal Data. With respect to End-Customer Data, the Controller is the Merchant.
- "Processor" means the entity that processes Personal Data on behalf of the Controller. With respect to End-Customer Data, the Processor is HundredFold.
- "Sub-processor" means any third party engaged by HundredFold to process Personal Data on the Merchant's behalf in the course of providing the Service.
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by HundredFold on the Merchant's behalf under this DPA. The specific categories are set out in Annex I.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
- "End-Customer Data" means Personal Data relating to the Merchant's own customers that flows into the Service from the Merchant's connected platforms (e.g., a connected Shopify store), as described in Annex I.
- "Account Data" means Personal Data relating to the Merchant's authorized users (the people who log in to the Service), as described in Section 2.3.
- "Processing" (and "process") means any operation performed on Personal Data, whether or not by automated means, such as collection, recording, storage, use, disclosure, transmission, or erasure.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed under this DPA.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission (Commission Implementing Decision (EU) 2021/914); "UK IDTA" means the UK International Data Transfer Agreement (or the UK Addendum to the SCCs) issued by the UK Information Commissioner.
2. Subject Matter, Roles, and Scope
2.1 Subject matter and duration
The subject matter of the processing is the provision of the Service: a multi-tenant business-intelligence and action platform for direct-to-consumer ecommerce brands that connects a Merchant's store, advertising, email, and inventory data sources, surfaces AI-prioritized insights, and lets the Merchant act on them. This DPA applies for the duration of the Agreement (the "Term") and until all Personal Data is deleted or returned in accordance with Section 9.
2.2 Roles for End-Customer Data (HundredFold as Processor)
With respect to End-Customer Data that flows into the Service from the Merchant's connected platforms, the Merchant is the Controller and HundredFold is the Processor. HundredFold processes End-Customer Data only to provide the Service to that Merchant, on the Merchant's documented instructions, as set out in this DPA.
2.3 Roles for Account Data (HundredFold as Controller)
With respect to Account Data — the Personal Data of the Merchant's authorized users who log in to the Service — HundredFold acts as an independent Controller. Account Data consists of: the user's work email address, the user's role (owner, admin, member, or viewer), and an internal Supabase user identifier. Access is invite-only via an owner-managed allowlist; there is no public self-serve signup. Authentication is passwordless (a magic link sent to the work email, or Google sign-in, via Supabase Auth). HundredFold does not store user passwords, phone numbers, postal addresses, or payment data. HundredFold's processing of Account Data as a Controller is governed by the HundredFold Privacy Policy rather than by the Processor obligations in this DPA.
2.4 Details of processing
The categories of Data Subjects, categories of Personal Data, and the nature, purpose, and duration of the processing are described in Annex I.
3. Processor Obligations
HundredFold, as Processor of End-Customer Data, will:
3.1 Process only on documented instructions
Process End-Customer Data only on the Merchant's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case HundredFold will, where legally permitted, inform the Merchant of that legal requirement before processing). The Agreement, this DPA, and the Merchant's configuration and use of the Service constitute the Merchant's complete and final documented instructions. HundredFold will inform the Merchant if, in its opinion, an instruction infringes Data Protection Laws.
3.2 No sale or unauthorized use
Not sell End-Customer Data, not retain, use, or disclose it for any purpose other than providing the Service (or as otherwise permitted by Data Protection Laws), and not combine it with Personal Data from other sources except as necessary to provide the Service to the Merchant. HundredFold certifies that it understands and will comply with these restrictions, including the CCPA/CPRA restrictions on "service providers."
3.3 Confidentiality of personnel
Ensure that persons authorized to process End-Customer Data are bound by an appropriate duty of confidentiality and process the data only as necessary to perform their duties.
3.4 Security measures
Implement and maintain the appropriate technical and organizational measures set out in Annex II to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects.
3.5 Sub-processors
Engage Sub-processors only in accordance with Section 4.
3.6 Assistance with Data Subject requests
Taking into account the nature of the processing, assist the Merchant by appropriate technical and organizational measures, insofar as possible, in fulfilling the Merchant's obligation to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection), as further described in Section 5.
3.7 Assistance with security, breach, and DPIA obligations
Assist the Merchant in ensuring compliance with its obligations regarding security of processing, notification of Personal Data Breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to HundredFold.
3.8 Personal Data Breach notification
Notify the Merchant without undue delay after becoming aware of a Personal Data Breach affecting End-Customer Data, as further described in Section 6.
3.9 Deletion or return on termination
Delete or return End-Customer Data at the end of the Term, as further described in Section 9.
3.10 Audit information
Make available to the Merchant the information necessary to demonstrate compliance with the obligations in Article 28 GDPR and allow for and contribute to audits, as further described in Section 7.
4. Sub-processors
4.1 General authorization
The Merchant provides general authorization for HundredFold to engage Sub-processors to process End-Customer Data in connection with the Service. The Sub-processors engaged as of the effective date are listed in Annex III and on HundredFold's Sub-processors page.
4.2 Flow-down obligations
Where HundredFold engages a Sub-processor, it will do so under a written contract that imposes data protection obligations no less protective than those in this DPA, in particular providing appropriate technical and organizational security measures. HundredFold remains fully liable to the Merchant for the performance of each Sub-processor's obligations.
4.3 Change notice and objection
HundredFold will notify the Merchant of any intended addition or replacement of a Sub-processor in advance (via the Sub-processors page and/or email to the Merchant's owner account), giving the Merchant the opportunity to object on reasonable data protection grounds within 30 days. If the Merchant reasonably objects and the parties cannot resolve the objection, the Merchant may, as its sole remedy, terminate the affected portion of the Service in accordance with the Agreement.
4.4 Merchant-connected platforms are not HundredFold Sub-processors
The platforms a Merchant authorizes as data sources — Shopify, Meta, Google, and Amazon — are not HundredFold Sub-processors. They are independent services chosen and connected by the Merchant and governed by the Merchant's own agreements with those providers. HundredFold reads data from (and, where authorized, writes drafts to) these platforms on the Merchant's behalf, but does not provide them as part of HundredFold's own infrastructure.
5. Assistance with Data Subject Requests
5.1 Routing of requests
If HundredFold receives a request directly from a Data Subject concerning End-Customer Data, HundredFold will not respond to the request itself (except to confirm receipt where required) and will, without undue delay, forward the request to the relevant Merchant.
5.2 Means of assistance
HundredFold will provide reasonable assistance — through the Service's functionality and, where necessary, through manual support — to enable the Merchant to respond to Data Subject requests for access, rectification, erasure, restriction, portability, and objection. Because the End-Customer Data HundredFold stores is minimal (see Annex I), most requests can be satisfied by locating, exporting, or deleting records keyed to a customer email address.
5.3 Erasure and Shopify mandatory webhooks
HundredFold is building an automated end-customer erasure path. When complete, it will honor (a) Shopify's mandatory compliance webhooks — customers/redact, shop/redact, and customers/data_request — and (b) erasure/access requests the Merchant forwards from GDPR/CCPA Data Subjects. Until that automated path is live, HundredFold will action such requests manually upon the Merchant's instruction. HundredFold targets completion of each erasure request within 30 days of receipt, consistent with Data Protection Laws and Shopify's webhook requirements. See our Data Deletion page.
5.4 Portability/export
HundredFold is building a data-export capability to support the right to data portability (GDPR Art. 20). Until it is available in the Service, the Merchant may request an export of the End-Customer Data associated with a given Data Subject by contacting admin@gohundredfold.com, and HundredFold will provide the relevant data in a structured, commonly used, machine-readable format.
6. Personal Data Breach Notification
6.1 Notification without undue delay
HundredFold will notify the Merchant without undue delay, and in any event within 72 hours after becoming aware of a Personal Data Breach affecting End-Customer Data processed under this DPA.
6.2 Contents of notification
The notification will, to the extent known and as it becomes available, describe: the nature of the breach (including, where possible, the categories and approximate number of Data Subjects and records concerned); the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information. HundredFold will provide updates as more information becomes available.
6.3 Cooperation
HundredFold will cooperate with the Merchant and take reasonable steps as directed by the Merchant to assist in the investigation, mitigation, and remediation of the breach, including supporting the Merchant's own notification obligations to supervisory authorities and affected Data Subjects. A notification under this Section is not an acknowledgment of fault or liability.
7. Audit and Compliance Information
7.1 Documentation
HundredFold will make available to the Merchant, on reasonable request, the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, including the relevant compliance reports of its infrastructure Sub-processors. Both Supabase and Vercel maintain SOC 2 Type II reports; HundredFold's controls are designed to align with the SOC 2 Trust Services Criteria, and a HundredFold SOC 2 program is planned. HundredFold does not itself currently hold a SOC 2 report.
7.2 Audits
Where the information made available under Section 7.1 is not sufficient to demonstrate compliance, HundredFold will allow for and contribute to audits, including inspections, conducted by the Merchant or an independent auditor mandated by the Merchant. Audits will be conducted on reasonable prior written notice (no less than 30 days, except where Data Protection Laws or a supervisory authority require otherwise), no more than once per twelve-month period (unless required following a Personal Data Breach or by a supervisory authority), during normal business hours, subject to confidentiality obligations, and in a manner that does not disrupt HundredFold's operations or compromise the security of other customers' data.
8. International Transfers
8.1 Transfer mechanism
To the extent HundredFold's processing of End-Customer Data involves a transfer of Personal Data out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, the parties agree that such transfers will be governed by an appropriate transfer mechanism, specifically: the EU Standard Contractual Clauses (Module Two: Controller-to-Processor) for EEA transfers, the UK IDTA (or UK Addendum to the SCCs) for UK transfers, and the relevant addendum for Swiss transfers.
8.2 Incorporation
Where the SCCs apply, they are incorporated into this DPA by reference and completed using the information in Annex I (description of transfer), Annex II (technical and organizational measures), and Annex III (Sub-processors). In the event of a conflict between the SCCs and this DPA, the SCCs prevail with respect to the transfer they govern.
9. Deletion or Return on Termination
9.1 On termination
Upon expiry or termination of the Agreement, HundredFold will, at the Merchant's choice, delete or return all End-Customer Data, and delete existing copies, unless retention is required by applicable law. The Merchant may make this election within 30 days of termination; absent an election, HundredFold will delete the End-Customer Data following that period.
9.2 Retention during the Term
HundredFold currently retains data for the duration of the Term and does not yet perform automated, age-based deletion of End-Customer Data; data is retained for as long as the account is active. HundredFold is building automated retention controls; until they are live, deletion occurs on request or on termination as described in this Section and Section 5.3.
9.3 Backups
Residual copies of End-Customer Data may persist in routine, secured backups for a limited period after deletion from the live environment; such copies are protected by the measures in Annex II and are deleted in the ordinary course of backup rotation.
10. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together.
11. Scope of Data Protection Laws, Governing Law, and General
11.1 Audience and scope
The parties confirm that the following Data Protection Laws are in scope for this DPA: the EU GDPR and UK GDPR, and the California CCPA/CPRA. The rights-and-assistance provisions of this DPA apply to the extent the corresponding law applies to the relevant processing.
11.2 Governing law
This DPA is governed by the law and subject to the jurisdiction stated in the Agreement, except where Data Protection Laws (or the SCCs) require otherwise: the State of Texas, USA.
11.3 Order of precedence
In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails. The Annexes form an integral part of this DPA.
11.4 Changes
HundredFold may update this DPA from time to time to reflect changes in Data Protection Laws, Sub-processors, or the Service, provided that no update will materially reduce the protections for End-Customer Data without the Merchant's consent where required by Data Protection Laws.
11.5 Contact
Data protection and security inquiries may be directed to admin@gohundredfold.com.
Signatures
| Merchant (Controller) | HundredFold (Processor) |
|---|---|
| Entity: ____________________ | Entity: Heem Megacorp LLC |
| Signature: ____________________ | Signature: ____________________ |
| Name: ____________________ | Name: ____________________ |
| Title: ____________________ | Title: ____________________ |
| Date: ____________________ | Date: ____________________ |
This DPA may be accepted by the Merchant's acceptance of the Agreement that incorporates it, in which case a physical signature is not required for it to be binding.
Annex I — Description of Processing
A. Parties
- Controller / data exporter: the Merchant (the ecommerce brand using the Service).
- Processor / data importer: Heem Megacorp LLC
B. Categories of Data Subjects
- The Merchant's customers (end customers who place orders on the Merchant's connected store).
- The Merchant's authorized users (team members who log in to the Service). Note: with respect to authorized users' Account Data, HundredFold acts as an independent Controller per Section 2.3; this row is included for completeness of the data inventory.
C. Categories of Personal Data
| Data Subject category | Personal Data processed | Source |
|---|---|---|
| Merchant's customers (End-Customer Data) | Customer email address; shipping city, state/province, and country. No customer names, street addresses, phone numbers, payment/card data, or customer profiles are collected or stored. | The Merchant's connected Shopify store (orders) |
| Merchant's authorized users (Account Data) | Work email address; role (owner / admin / member / viewer); internal Supabase user id. No passwords, phone numbers, addresses, or payment data. | Provided at invitation / sign-in via Supabase Auth |
D. Special categories of Personal Data
None. HundredFold does not process special-category (sensitive) Personal Data under this DPA.
E. Nature and purpose of processing
Storage, organization, analysis, and presentation of the Personal Data above for the purpose of providing the Service — a business-intelligence and action platform — including: syncing and storing connected-store data; computing aggregate analytics and insights; and, on the Merchant's instruction, exporting customer email addresses (derived from orders) to the Merchant's own Klaviyo account to build win-back marketing audiences. The customer email address is the only End-Customer Personal Data used for the win-back export.
F. AI processing limitation
HundredFold's AI analyst and daily briefing (powered by Anthropic Claude) receive business aggregates only (e.g., revenue/ROAS/AOV KPIs, inventory summaries, top-ad metrics, customer-health rates such as repeat and refund percentages, email metrics, replenishment plans) and the Merchant's own written business-context notes. The AI never receives customer names, emails, or addresses, nor any API keys, tokens, or secrets.
G. Frequency of processing
Continuous / on a recurring scheduled basis (automated syncs and scheduled jobs) for the duration of the Term.
H. Duration / retention
For the duration of the Term, then deleted or returned in accordance with Section 9. Retention approach: data is retained for as long as the account is active; automated, age-based deletion is being implemented.
I. Transfer details (where SCCs apply)
- Frequency of transfer: continuous, as part of providing the Service.
- Nature of transfer: storage and processing by Sub-processors listed in Annex III.
- Subject matter, nature, and duration: as set out above.
- Sub-processor hosting region: United States (confirm and complete the SCC transfer table before publication).
Annex II — Technical and Organizational Measures
HundredFold maintains the following technical and organizational measures to protect End-Customer Data. These measures are designed to align with the SOC 2 Trust Services Criteria. HundredFold may update measures over time provided the overall level of protection is not reduced.
1. Multi-tenant isolation and access control
- Every record carries the owning organization's identifier ("org id"). Every database read and write is scoped to the caller's organization in application code, with PostgreSQL Row-Level Security (RLS) enforced as a database-level backstop. One Merchant cannot access another Merchant's data. (Built and tested.)
- Passwordless authentication (magic link to a work email or Google sign-in via Supabase Auth); invite-only access via an owner-managed allowlist; role-based access control (owner / admin / member / viewer). No public self-serve signup.
2. Encryption
- In transit: HTTPS/TLS for all connections to the Service.
- At rest: encryption at rest provided by the managed database/infrastructure provider.
3. Integration token storage
- Target architecture (rollout in progress): integration tokens are stored in Supabase Vault by reference — encrypted at rest, with application tables holding only an opaque secret ID and decryption performed by
SECURITY DEFINERfunctions that are revoked from the anonymous and authenticated roles (only the server's service-role connection can call them). Token resolution reads Vault-first, with a per-provider backfill migrating remaining credentials. - Current state: this is not yet the active path for all providers; some credentials currently reside in server-side environment variables or, for some OAuth providers, in database columns pending backfill. In all cases, credentials are never exposed to the browser or the AI model, and the database enforces the PostgreSQL Row-Level Security and per-organization scoping in Annex II.1.
4. Secrets management
- Provider API keys and application secrets live in server-side environment variables, are never exposed to the browser, and are never sent to the AI model.
5. Logging and monitoring
- Application and infrastructure logging of system activity to support operations, troubleshooting, and security monitoring. Logs are configured to exclude secrets and to avoid unnecessary Personal Data.
6. Backups and recovery
- Automated database backups and point-in-time recovery provided through the managed database provider.
7. AI privacy controls
- The AI analyst/briefing receives business aggregates only and the Merchant's business-context notes. No end-customer PII and no secrets are sent to the AI model (see Annex I.F).
8. Sub-processor diligence
- Sub-processors are engaged under written contracts with data protection terms no less protective than this DPA. Both primary infrastructure Sub-processors (Supabase and Vercel) maintain SOC 2 Type II reports.
9. Infrastructure security
- Hosting and scheduled jobs run on Vercel; data and authentication run on Supabase — both SOC 2 Type II providers.
10. Cookies
- The application sets only a strictly necessary Supabase authentication/session cookie. No advertising or analytics tracking cookies are used.
11. Incident response
- HundredFold is documenting a formal incident and breach response plan covering detection, assessment, containment, notification (per Section 6), and remediation.
Annex III — Sub-processors
The current list of Sub-processors HundredFold engages to process End-Customer Data is maintained on the HundredFold Sub-processors page and reproduced below as of the effective date. Changes are governed by Section 4.3.
| Sub-processor | Purpose / processing activity | Personal Data involved | Region |
|---|---|---|---|
| Supabase | Managed PostgreSQL database and authentication; stores all application data and user emails | End-Customer Data (email, ship city/state/country) and Account Data | United States |
| Vercel | Application hosting and scheduled cron jobs | Processed in transit/at runtime; no dedicated data store of End-Customer Data | United States |
| Anthropic | AI analysis (daily briefing, strategy, copy generation) | Business aggregates only — no end-customer PII, no secrets | United States |
| Higgsfield | AI image generation for ad creative | Product images + text prompts — no customer/personal data | United States |
| Resend | Transactional email (warehouse packing lists / FBA labels to a Merchant-configured warehouse email) | No end-customer PII | United States |
| Klaviyo | Email-marketing platform; receives draft templates and customer emails for win-back lists | Customer email addresses (exported on the Merchant's instruction) | United States |
Note on data sources vs. Sub-processors: the platforms a Merchant connects as data sources — Shopify, Meta, Google, and Amazon — are merchant-authorized integrations governed by their own terms and are not HundredFold infrastructure Sub-processors (see Section 4.4).