Draft — pending legal review. This document has not yet been reviewed by a solicitor and does not constitute the final, binding version.

Data Processing Addendum

This addendum applies where Badger Commerce processes personal data on behalf of your organisation as a processor. It forms part of our agreement with you.

Last updated: 13 July 2026

Requesting a signed copy

This page sets out our standard data processing terms. If your organisation requires a countersigned Data Processing Addendum (DPA) for your records, email [email protected] and we will provide an executable copy. These online terms apply in the meantime wherever we act as your processor.

1. Definitions

Terms such as "controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given in UK Data Protection Law. "UK Data Protection Law" means the UK GDPR and the Data Protection Act 2018. "Customer Personal Data" means personal data that we process on your behalf under the Terms of Service (the "Agreement").

2. Roles of the parties

Customer Personal Data is processed by Badger Commerce Limited, which owns and operates the Badger Commerce platform and tools. Accordingly, for Customer Personal Data you are the controller and Badger Commerce Limited is the processor, and this addendum is entered into with Badger Commerce Limited (even where your commercial contract for the Services is with its authorised reseller). Where you are yourself acting as a processor for another controller, Badger Commerce Limited acts as your sub-processor, and you confirm you have the necessary authority. Each party will comply with its own obligations under UK Data Protection Law.

3. Processing on your instructions

We will process Customer Personal Data only on your documented instructions, including as set out in the Agreement and this addendum, and as needed to provide and support the Services, unless required to do otherwise by law (in which case we will tell you, unless the law prohibits it). We will inform you if, in our opinion, an instruction infringes UK Data Protection Law.

4. Subject matter and details of processing

  • Subject matter: our provision of the Services to you.
  • Duration: the term of the Agreement, plus any post-termination period described in it.
  • Nature and purpose: hosting, authentication, billing, and related processing needed to operate the platform and the tools you subscribe to.
  • Types of personal data: account and profile data, contact details, billing details, and usage and audit data of your authorised users.
  • Categories of data subject: your authorised users and personnel.

5. Confidentiality

We ensure that personnel authorised to process Customer Personal Data are subject to appropriate duties of confidentiality and only process it as necessary to perform their role.

6. Security measures

We implement appropriate technical and organisational measures to protect Customer Personal Data, taking account of the state of the art, the costs of implementation, and the risks involved. An overview of these measures is on our Security page and is incorporated into this addendum by reference.

7. Sub-processors

You give us general authorisation to engage sub-processors to process Customer Personal Data. Our current sub-processors are listed on our Sub-processors page. We impose data protection obligations on each sub-processor that are materially equivalent to those in this addendum, and we remain responsible for their performance. We will give you a way to receive notice of intended changes so you can object on reasonable data protection grounds.

8. International transfers

Our core hosting is within the European Union (Germany and Finland). Where Customer Personal Data is transferred outside the UK, we will ensure an approved transfer mechanism is in place, such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum. See the safeguards column on our Sub-processors page.

9. Assistance to you

Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, so far as possible, to respond to data subject requests and to meet your obligations around security, breach notification, data protection impact assessments, and prior consultation with the ICO.

10. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information you reasonably need to meet your own notification obligations.

11. Return and deletion

On termination of the Services, and at your choice, we will delete or return Customer Personal Data, and delete existing copies unless we are required by law to retain them. Our standard retention periods are set out in the Privacy Policy.

12. Audits

We will make available information reasonably necessary to demonstrate our compliance with UK GDPR Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits.

13. Contact

To request a signed DPA or ask a question, contact [email protected].