Data Processing Addendum
Last updated: April 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Maker Labs (“processor”) and the merchant (“controller”) for any personal data processed by Maker on the merchant's behalf under GDPR, UK GDPR, and equivalent data protection laws.
1. Roles and scope
The merchant is the controller of personal data about their customers. Maker is a processor acting on the merchant's documented instructions, which are the Terms of Service, the Admin configuration, and the APIs the merchant invokes.
2. Subject matter and duration
Subject matter: operating the merchant's store (storefront, checkout, email, order management). Duration: for the life of the merchant's subscription plus the retention windows in the Privacy Policy.
3. Categories of data subjects and data
- Customers of the merchant's store (end-shoppers).
- Staff members the merchant invites to their store.
- Identification data, contact data, order data, payment metadata, device and usage data.
4. Security measures
TLS in transit, encrypted backups, modern password hashing, role-based access with audit logging, continuous monitoring, vendor hardening, and least-privilege access for Maker staff. Details in the Privacy Policy.
5. Subprocessors
The merchant authorises Maker to engage the subprocessors listed at /legal/subprocessors. Maker will notify merchants of new subprocessors at least 14 days before engaging them, giving the merchant a chance to object.
6. International transfers
Where personal data is transferred out of the EEA, UK, or Switzerland, Maker relies on the current Standard Contractual Clauses and additional safeguards as required.
7. Data subject rights
If Maker receives a data-subject request directly, we'll route it to the merchant without responding on the merchant's behalf. Maker will, taking into account the nature of the processing, assist the merchant in responding (e.g. export and deletion tooling in the Admin).
8. Breach notification
Maker will notify the merchant of a confirmed personal data breach without undue delay, and in any case within 48 hours of Maker becoming aware, so the merchant can meet its own notification obligations.
9. Return and deletion
On termination, Maker will delete or return personal data at the merchant's option, subject to the 30-day reactivation window and any legal retention requirements (e.g. tax records).
10. Audit
Maker makes available information necessary to demonstrate compliance, including our security documentation and third-party attestations. Additional audits may be arranged on reasonable notice.
11. Contact
Data protection questions go to [email protected].