Commercive

Last updated: May 27, 2026

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between Commercive LLC (the "Processor") and the merchant using the Commercive Shopify application (the "Controller"). It governs the processing of personal data carried out by Commercive on the Controller's behalf and is designed to satisfy Article 28 of the EU General Data Protection Regulation ("GDPR") and the UK equivalent.

1. Roles of the parties

The Controller determines the purposes and means of processing personal data relating to its end customers, staff, and operations. Commercive acts solely as a Processor, handling personal data only on documented instructions from the Controller, including those set out in the main service agreement, the Commercive dashboard configuration, and this DPA.

2. Subject matter and duration

The subject matter of the processing is the provision of fulfillment, inventory, and logistics services through the Commercive platform. Processing continues for the duration of the service agreement and any wind-down period defined in Section 9.

3. Categories of data and data subjects

Personal data processed under this DPA typically includes: end-customer names, shipping and billing addresses, email addresses, telephone numbers, order details, and payment status references (no full card numbers). Data subjects include the Controller's end customers and the Controller's authorized users of the Commercive dashboard.

4. Processor obligations

Commercive will: (a) process personal data only on the Controller's documented instructions; (b) ensure persons authorized to process the data are bound by confidentiality; (c) implement appropriate technical and organizational measures (see Section 6); (d) assist the Controller in responding to data-subject requests; (e) assist with data-protection impact assessments and consultations with supervisory authorities where required; and (f) make available all information necessary to demonstrate compliance with Article 28 GDPR.

5. Sub-processors

The Controller provides general authorization for Commercive to engage sub-processors to deliver the service, including shipping carriers, cloud hosting providers, database and object-storage providers, transactional email providers, error-monitoring services, and payment processors (for the Controller's subscription billing only). A current list is available on request. Commercive will notify the Controller of any intended changes with at least thirty (30) days' notice, during which the Controller may object on reasonable data-protection grounds. Commercive imposes data-protection obligations on every sub-processor that are no less protective than this DPA.

6. Security measures

Commercive maintains, at a minimum: TLS 1.2+ in transit and AES-256 at rest; role-based access control with single sign-on and multi-factor authentication for production systems; bcrypt password hashing; least-privilege database credentials; isolated environments for development, staging, and production; logging of administrative actions; secret-management tooling separate from source code; vulnerability scanning of dependencies; and a documented incident-response procedure.

7. Personal data breaches

Commercive will notify the Controller without undue delay, and in any event within seventy-two (72) hours of confirmed discovery of a personal data breach affecting the Controller's data. Notification will be delivered by email to the merchant's primary admin contact on file. The notification will describe, to the extent then known, the nature of the breach, categories and approximate volume of data and data subjects, likely consequences, and measures taken or proposed to address the breach and mitigate its effects.

8. International transfers

Where the processing of personal data of EU, UK, or Swiss data subjects involves transfer to a country without an adequacy decision, the parties agree that the EU Standard Contractual Clauses (Module Two, Controller-to-Processor) and the UK International Data Transfer Addendum are incorporated by reference and apply to such transfers.

9. Return and deletion of data

Upon termination of the service, the Controller may, within thirty (30) days, request export of its data via the dashboard or by emailing support@commercive.co. After this period, Commercive will delete operational personal data from production systems within sixty (60) further days, except where retention is required by applicable law (for example, financial records retained for tax purposes). Backups are aged out per the schedule in our Privacy Policy.

10. Audit

Commercive will make available to the Controller, on reasonable written request and subject to confidentiality undertakings, the information necessary to demonstrate compliance with this DPA, including current security documentation and third-party attestations where available. On-site audits, where strictly required by law, will be scheduled with reasonable notice, conducted during business hours, and limited in scope to relevant systems.

11. Liability and order of precedence

Each party's liability under this DPA is subject to the limitations of liability set out in the main service agreement. In case of conflict between this DPA and the main agreement, this DPA prevails for matters relating to the processing of personal data.

12. Governing law

This DPA is governed by the laws of the State of New York, United States of America, without regard to its conflict-of-laws principles. The contracting entity is Commercive LLC, a New York limited liability company with its principal place of business at 595 West Broadway, Cedarhurst, NY 11516. The parties submit to the exclusive jurisdiction of the state and federal courts located in the State of New York for any disputes arising out of or relating to this DPA.

13. Contact

DPA-related notices and queries should be sent to support@commercive.co with the subject line "DPA for <your shop domain>".