Data Processing Addendum

Lawyer-review draft — last updated 28 August 2026.

This Addendum forms part of the Merchant Terms between Marvello Pty Ltd (“Marvello”) and the merchant and applies where Marvello processes Customer Personal Data for that merchant.

1. Definitions and priority

“Data Protection Law” means the Australian Privacy Act 1988 and APPs and, where applicable to the processing, the EU GDPR, UK GDPR and implementing laws. “Customer Personal Data” means personal data processed by Marvello on the merchant's behalf through Upsell Me. “Controller”, “processor”, “process” and “personal data” have the meanings given by applicable Data Protection Law. If this Addendum conflicts with the Merchant Terms on Customer Personal Data, this Addendum prevails.

2. Roles and instructions

The merchant is normally controller and Marvello processor for Customer Personal Data; each party remains responsible for any processing for which law makes it an independent controller. Marvello will process Customer Personal Data only on documented instructions in the Merchant Terms, this Addendum, the merchant's saved configuration and lawful support requests, including for transfers, unless law requires otherwise. Marvello will inform the merchant before legally required processing unless prohibited, and will promptly tell the merchant if an instruction appears to infringe Data Protection Law.

3. Processing details

4. Confidentiality and security

Marvello will ensure authorised personnel are bound by confidentiality and will maintain measures appropriate to risk, including tenant separation, least privilege, encryption in transit and at rest, managed secrets, authenticated Shopify requests and webhooks, shop-bound identifiers, minimised logs, replay and duplicate controls, deletion controls, change review and incident response. No measure eliminates all risk.

5. Subprocessors

The merchant gives general written authorisation for the subprocessors on the Subprocessor List. Marvello will impose materially equivalent data-protection obligations, remain responsible for its processor obligations, and give reasonable advance notice of a new subprocessor where practicable. A merchant may object on reasonable data-protection grounds within 14 days; the parties will seek a practical alternative, failing which either may terminate the affected service.

6. Individual rights and merchant assistance

Taking account of the nature of processing, Marvello will provide reasonable assistance for verified access, correction, deletion, restriction, portability, objection and other rights requests. If Marvello receives a request about Customer Personal Data, it may direct the person to the merchant unless law requires Marvello to respond. The merchant remains responsible for identity verification, legal assessment and its response.

7. Incidents, assessments and regulators

Marvello will notify the merchant without undue delay after becoming aware of a confirmed personal-data breach affecting its Customer Personal Data and provide available information reasonably needed for the merchant's assessment and notices. Notification is not an admission of fault. Taking account of the processing and information available, Marvello will reasonably assist with security obligations, data-protection impact assessments and regulator consultation. Each party bears its own internal costs; extraordinary merchant-specific assistance may be charged at a reasonable agreed rate unless the need was caused by Marvello's breach.

8. Return and deletion

After uninstall, termination or a valid Shopify redaction instruction, Marvello will delete or de-identify Customer Personal Data within the periods described in the Privacy Policy unless law requires limited retention. Backups are isolated from ordinary use and expire through the backup cycle. On request, Marvello will confirm completion. Shopify remains the merchant's authoritative system of record; Upsell Me is not an archival service.

9. Demonstrating compliance and audits

Marvello will make reasonably necessary compliance information available. No more than once annually, or after a material incident or regulator request, the merchant may request an audit by an independent qualified auditor bound by confidentiality. Audits must first use available documentation, occur on reasonable notice during business hours, avoid access to other tenants or security-sensitive material, and not disrupt the service. The merchant pays its costs unless the audit identifies a material Marvello breach.

10. International transfers

Processing may occur outside the merchant's country through the providers listed on the Subprocessor List. Each party will comply with transfer rules that apply to it. For restricted EEA transfers for which Marvello is the data importer, the then-current EU controller-to-processor Standard Contractual Clauses are incorporated by reference with the merchant as exporter and Marvello as importer; the processing details and safeguards in this Addendum complete the relevant annexes. For restricted UK transfers, the then-current UK Addendum applies. These mechanisms apply only to the extent legally required and counsel must confirm the execution details before public merchant release.

11. Liability and termination

The liability provisions and mandatory-law carve-outs in the Merchant Terms apply to this Addendum to the extent lawful. A material uncured breach of this Addendum is a material breach of the Merchant Terms.

12. Contact

Data-processing requests: matthew@marvellogroup.co.uk.