1 Definitions
- "Applicable Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA").
- "Personal Data" means any information relating to an identified or identifiable natural person contained in Client Data that Sartori Processes on Client's behalf.
- "Process" / "Processing" has the meaning given under Applicable Data Protection Laws.
- "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given under the GDPR (and equivalent terms such as "Business" and "Service Provider" under the CCPA/CPRA apply correspondingly).
- "Sub-processor" means any third party engaged by Sartori to Process Personal Data in connection with the Services.
- "Standard Contractual Clauses" ("SCCs") means the clauses approved by the European Commission and/or the UK International Data Transfer Agreement/Addendum, as applicable, for lawful cross-border transfers.
2 Roles & Scope
As between the Parties, Client is the Controller (or Business) and Sartori is the Processor (or Service Provider) with respect to Personal Data. Where Client acts as a processor for a third-party controller, Client is deemed the Controller for purposes of this DPA and represents it has authority to instruct Sartori accordingly.
Sartori will Process Personal Data only to provide, secure, and support the Services and as further described in Annex A. This DPA applies for as long as Sartori Processes Personal Data on Client's behalf.
3 Processing Instructions
Sartori will Process Personal Data only on Client's documented instructions, including as set out in the Agreement, this DPA, and any Order Form, unless required to do otherwise by law (in which case Sartori will, where legally permitted, inform Client). Sartori will promptly notify Client if, in its opinion, an instruction infringes Applicable Data Protection Laws. Client is responsible for ensuring its instructions and the Personal Data it provides comply with Applicable Data Protection Laws and that it has a lawful basis for the Processing.
4 Confidentiality
Sartori will ensure that persons authorized to Process Personal Data are bound by appropriate confidentiality obligations and Process Personal Data only as instructed, on a need-to-know basis.
5 Security
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing, Sartori will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, including the measures described in Annex B. Sartori may update these measures provided the overall level of protection is not materially diminished.
6 Sub-processors
Client provides general authorization for Sartori to engage Sub-processors to support the Services. The current Sub-processors are listed in Annex C. Sartori will impose data protection obligations on each Sub-processor no less protective than those in this DPA and remains responsible for its Sub-processors' performance.
Sartori will give Client reasonable prior notice of any intended addition or replacement of a Sub-processor (including by updating Annex C or a subscribed list). If Client reasonably objects on data protection grounds, the Parties will work in good faith to resolve the concern; if they cannot, Client may terminate the affected Services.
7 Data Subject Requests
Taking into account the nature of the Processing, Sartori will provide reasonable assistance (by appropriate technical and organizational measures, insofar as possible) to enable Client to respond to requests from Data Subjects exercising their rights. If Sartori receives a request directly from a Data Subject regarding Client's Personal Data, it will not respond except to acknowledge and direct the Data Subject to Client, and will promptly forward the request to Client.
8 Assistance
Taking into account the nature of Processing and the information available to it, Sartori will provide reasonable assistance to Client in ensuring compliance with its obligations regarding security of Processing, Personal Data Breach notification, data protection impact assessments, and prior consultations with supervisory authorities (Articles 32–36 GDPR or equivalents). Sartori may charge a reasonable fee for assistance exceeding what is required by law or the Services.
9 Personal Data Breach
Sartori will notify Client without undue delay after becoming aware of a Personal Data Breach affecting Client's Personal Data, and will provide Client with information reasonably available to it to enable Client to meet its own notification obligations, and will take reasonable steps to mitigate and remediate the breach. Sartori's notification is not an acknowledgment of fault or liability.
10 Return or Deletion
Upon expiry or termination of the Services, Sartori will, at Client's choice, delete or return Personal Data and delete existing copies, unless retention is required by law. Copies contained in routine backups will be deleted in the ordinary course of Sartori's backup rotation. Aggregated and de-identified data that is no longer Personal Data is not subject to this Section. This Section is consistent with the retention terms of the Agreement.
11 Audits & Information
Sartori will make available to Client information reasonably necessary to demonstrate compliance with this DPA. Where required by Applicable Data Protection Laws, Sartori will allow for and contribute to audits, including inspections, conducted by Client or an auditor it mandates — no more than once per year (except where required by a supervisory authority or following a Personal Data Breach), on reasonable prior written notice, during business hours, subject to confidentiality, and in a manner that does not disrupt Sartori's operations or compromise other customers' data. Sartori may satisfy audit requests by providing relevant third-party certifications or reports where available.
12 International Transfers
Client authorizes Sartori and its Sub-processors to transfer Personal Data across borders as necessary to provide the Services. Where such transfer is from the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, the Parties agree that the applicable Standard Contractual Clauses are incorporated into this DPA by reference and apply to the transfer, with Client as data exporter and Sartori as data importer, completed with the details in the Annexes. If the SCCs conflict with this DPA on transfer matters, the SCCs prevail.
13 CCPA / CPRA Service-Provider Terms
Where the CCPA/CPRA applies, Sartori acts as a "Service Provider" and: (a) will Process Personal Information (as defined by the CCPA/CPRA) only to perform the Services and business purposes specified in the Agreement, and not for any other purpose; (b) will not "sell" or "share" Personal Information; (c) will not retain, use, or disclose Personal Information outside the direct business relationship or as otherwise prohibited; (d) will not combine Personal Information with data from other sources except as permitted by the CCPA/CPRA; and (e) certifies that it understands and will comply with these restrictions. Sartori will notify Client if it determines it can no longer meet these obligations.
14 Liability & Precedence
Each Party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Agreement. In the event of a conflict, this DPA prevails over the Agreement with respect to data protection matters, and any applicable SCCs prevail over this DPA with respect to cross-border transfers. In all other respects the Agreement remains in full force.
Annex A — Details of Processing
| Subject matter | Provision of Sartori's enterprise Services (analysis of Client's historical commerce and returns data to identify return drivers and recommendations). |
|---|---|
| Duration | For the term of the Services and the retention period stated in the Agreement. |
| Nature & purpose | Storage, organization, analysis, and modeling of Client Data to produce the Deliverables; hosting, security, and support. |
| Categories of Data Subjects | Client's end customers whose transactions appear in the data provided (to the extent any identifiers are included). |
| Types of Personal Data | Order/transaction identifiers and attributes, product and returns data, and, only to the extent Client chooses to include it, limited customer identifiers (e.g., hashed or account IDs, region/postal area). Clients are instructed to de-identify or pseudonymize wherever practicable. |
| Special-category data | None, unless expressly agreed in writing with appropriate safeguards. |
Annex B — Technical & Organizational Measures
- Encryption: Personal Data encrypted in transit (TLS) and at rest.
- Access control: role-based, least-privilege access; unique credentials; multi-factor authentication for administrative access; prompt revocation on personnel changes.
- Network & infrastructure security: hosting with reputable cloud providers offering physical security and environmental controls; segmentation and firewalling of production systems.
- Logging & monitoring: audit logging of access to production systems and monitoring for anomalous activity.
- Data minimization: Clients instructed to provide de-identified/pseudonymized data; Personal Data limited to what is necessary for the Services.
- Resilience: backups and documented restoration procedures.
- Vulnerability management: patching and periodic review of security controls.
- Personnel: confidentiality obligations and security-awareness practices.
- Incident response: a documented process for detecting, responding to, and notifying Personal Data Breaches.
Annex C — Approved Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (Google LLC) | Cloud hosting, storage, and compute | United States |
Sartori maintains the current list of Sub-processors here and will provide notice of changes as described in Section 6.
