Data Processing Addendum
Lawyer-review draft — last updated 28 August 2026.
This Addendum forms part of the Merchant Terms between Marvello Pty Ltd (“Marvello”) and the merchant and applies where Marvello processes Customer Personal Data for that merchant.
1. Definitions and priority
“Data Protection Law” means the Australian Privacy Act 1988 and APPs and, where applicable to the processing, the EU GDPR, UK GDPR and implementing laws. “Customer Personal Data” means personal data processed by Marvello on the merchant's behalf through Upsell Me. “Controller”, “processor”, “process” and “personal data” have the meanings given by applicable Data Protection Law. If this Addendum conflicts with the Merchant Terms on Customer Personal Data, this Addendum prevails.
2. Roles and instructions
The merchant is normally controller and Marvello processor for Customer Personal Data; each party remains responsible for any processing for which law makes it an independent controller. Marvello will process Customer Personal Data only on documented instructions in the Merchant Terms, this Addendum, the merchant's saved configuration and lawful support requests, including for transfers, unless law requires otherwise. Marvello will inform the merchant before legally required processing unless prohibited, and will promptly tell the merchant if an instruction appears to infringe Data Protection Law.
3. Processing details
- Subject and duration: operating, securing and supporting Upsell Me while authorised, plus the limited deletion, dispute and legal periods in the Privacy Policy.
- Nature and purposes: authentication; offer selection and display; checkout and order safety; duplicate and replay prevention; paid-upsell attribution; analytics; Add Items and Address Changes; support; security; compliance; and billing evidence where enabled.
- People: merchant staff, Shopify customers, recipients and other people whose delivery details a customer supplies.
- Data: Shopify store and user identifiers; product, checkout, order, line-item, payment-status, fulfilment-status, market and currency facts; offer interactions; pseudonymous fingerprints; and, only for Address Changes, selected name, phone and delivery-address fields. Upsell Me does not process card data.
4. Confidentiality and security
Marvello will ensure authorised personnel are bound by confidentiality and will maintain measures appropriate to risk, including tenant separation, least privilege, encryption in transit and at rest, managed secrets, authenticated Shopify requests and webhooks, shop-bound identifiers, minimised logs, replay and duplicate controls, deletion controls, change review and incident response. No measure eliminates all risk.
5. Subprocessors
The merchant gives general written authorisation for the subprocessors on the Subprocessor List. Marvello will impose materially equivalent data-protection obligations, remain responsible for its processor obligations, and give reasonable advance notice of a new subprocessor where practicable. A merchant may object on reasonable data-protection grounds within 14 days; the parties will seek a practical alternative, failing which either may terminate the affected service.
6. Individual rights and merchant assistance
Taking account of the nature of processing, Marvello will provide reasonable assistance for verified access, correction, deletion, restriction, portability, objection and other rights requests. If Marvello receives a request about Customer Personal Data, it may direct the person to the merchant unless law requires Marvello to respond. The merchant remains responsible for identity verification, legal assessment and its response.
7. Incidents, assessments and regulators
Marvello will notify the merchant without undue delay after becoming aware of a confirmed personal-data breach affecting its Customer Personal Data and provide available information reasonably needed for the merchant's assessment and notices. Notification is not an admission of fault. Taking account of the processing and information available, Marvello will reasonably assist with security obligations, data-protection impact assessments and regulator consultation. Each party bears its own internal costs; extraordinary merchant-specific assistance may be charged at a reasonable agreed rate unless the need was caused by Marvello's breach.
8. Return and deletion
After uninstall, termination or a valid Shopify redaction instruction, Marvello will delete or de-identify Customer Personal Data within the periods described in the Privacy Policy unless law requires limited retention. Backups are isolated from ordinary use and expire through the backup cycle. On request, Marvello will confirm completion. Shopify remains the merchant's authoritative system of record; Upsell Me is not an archival service.
9. Demonstrating compliance and audits
Marvello will make reasonably necessary compliance information available. No more than once annually, or after a material incident or regulator request, the merchant may request an audit by an independent qualified auditor bound by confidentiality. Audits must first use available documentation, occur on reasonable notice during business hours, avoid access to other tenants or security-sensitive material, and not disrupt the service. The merchant pays its costs unless the audit identifies a material Marvello breach.
10. International transfers
Processing may occur outside the merchant's country through the providers listed on the Subprocessor List. Each party will comply with transfer rules that apply to it. For restricted EEA transfers for which Marvello is the data importer, the then-current EU controller-to-processor Standard Contractual Clauses are incorporated by reference with the merchant as exporter and Marvello as importer; the processing details and safeguards in this Addendum complete the relevant annexes. For restricted UK transfers, the then-current UK Addendum applies. These mechanisms apply only to the extent legally required and counsel must confirm the execution details before public merchant release.
11. Liability and termination
The liability provisions and mandatory-law carve-outs in the Merchant Terms apply to this Addendum to the extent lawful. A material uncured breach of this Addendum is a material breach of the Merchant Terms.
12. Contact
Data-processing requests: matthew@marvellogroup.co.uk.