Data Processing Addendum

Last updated: April 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Maker Labs (“processor”) and the merchant (“controller”) for any personal data processed by Maker on the merchant's behalf under GDPR, UK GDPR, and equivalent data protection laws.

1. Roles and scope

The merchant is the controller of personal data about their customers. Maker is a processor acting on the merchant's documented instructions, which are the Terms of Service, the Admin configuration, and the APIs the merchant invokes.

2. Subject matter and duration

Subject matter: operating the merchant's store (storefront, checkout, email, order management). Duration: for the life of the merchant's subscription plus the retention windows in the Privacy Policy.

3. Categories of data subjects and data

  • Customers of the merchant's store (end-shoppers).
  • Staff members the merchant invites to their store.
  • Identification data, contact data, order data, payment metadata, device and usage data.

4. Security measures

TLS in transit, encrypted backups, modern password hashing, role-based access with audit logging, continuous monitoring, vendor hardening, and least-privilege access for Maker staff. Details in the Privacy Policy.

5. Subprocessors

The merchant authorises Maker to engage the subprocessors listed at /legal/subprocessors. Maker will notify merchants of new subprocessors at least 14 days before engaging them, giving the merchant a chance to object.

6. International transfers

Where personal data is transferred out of the EEA, UK, or Switzerland, Maker relies on the current Standard Contractual Clauses and additional safeguards as required.

7. Data subject rights

If Maker receives a data-subject request directly, we'll route it to the merchant without responding on the merchant's behalf. Maker will, taking into account the nature of the processing, assist the merchant in responding (e.g. export and deletion tooling in the Admin).

8. Breach notification

Maker will notify the merchant of a confirmed personal data breach without undue delay, and in any case within 48 hours of Maker becoming aware, so the merchant can meet its own notification obligations.

9. Return and deletion

On termination, Maker will delete or return personal data at the merchant's option, subject to the 30-day reactivation window and any legal retention requirements (e.g. tax records).

10. Audit

Maker makes available information necessary to demonstrate compliance, including our security documentation and third-party attestations. Additional audits may be arranged on reasonable notice.

11. Contact

Data protection questions go to [email protected].