Commercer LLC – Policy
Data Processing Addendum
Between Customer (Controller) and Commercer LLC (Processor).
- Provider:
- Commercer LLC (Wyoming, USA)
- Address:
- 33 N Gould St, Sheridan, WY 82801, USA
- Effective date:
- July 10, 2026
- Version:
- v1.0
1. Scope and roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Customer and Commercer LLC. It applies where Commercer processes Personal Data on behalf of Customer in the course of providing the service. In that context Customer is the Controller and Commercer is the Processor. Terms not defined here have the meanings given in the GDPR or in the Agreement.
Where required by law, this DPA also incorporates the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA, and comparable state and national privacy laws.
2. Processing details
- Subject matter: provision of the Commercer service.
- Duration: for the term of the Agreement and any post-termination period during which data is retained under the Privacy Policy.
- Nature and purpose: hosting, storage, retrieval, canonicalization, generation, and transmission of Customer Data as directed by Customer's use of the service.
- Categories of data subjects: Customer's personnel and, to the extent Customer submits it, Customer's end users, suppliers, and other individuals identified in catalog or store data.
- Categories of personal data: identifiers, contact data, employment data, usage data, and any personal data Customer chooses to submit. Customer will not submit special-category or sensitive data except as necessary for its business use of the service.
3. Commercer's obligations
- Process Personal Data only on documented instructions from Customer, including as embodied in the Agreement and Customer's configuration of the service.
- Ensure that personnel authorized to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organizational measures as described in Annex II.
- Assist Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting Customer's obligations under Articles 32–36 GDPR.
- Notify Customer without undue delay, and in any event within seventy-two hours of becoming aware, of a Personal Data breach affecting Customer Data.
- At Customer's choice, delete or return Personal Data at the end of the provision of services and delete existing copies unless applicable law requires retention.
- Make available to Customer information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 7.
4. Sub-processing
Customer authorizes Commercer to engage sub-processors listed in Annex III. Commercer will impose data-protection terms on sub-processors that are no less protective than those in this DPA and remains liable for their acts and omissions with respect to Personal Data.
Commercer will provide at least thirty days' prior notice of any addition or replacement of a sub-processor through the marketing site or in-product. Customer may object on reasonable data-protection grounds within that notice period; if the parties cannot resolve the objection, Customer may terminate the affected part of the service and receive a refund of prepaid, unused fees for the terminated portion.
5. International transfers
Where Commercer transfers Personal Data out of the EEA, UK, or Switzerland to a country not recognized as providing an adequate level of protection, the parties incorporate the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914) Module Two (controller to processor) or Module Three (processor to processor) as applicable, together with the UK International Data Transfer Addendum and the Swiss addendum where relevant. Where the parties have entered into a separate signed set of Clauses, those Clauses control over this reference.
6. Data-subject requests and cooperation
- Commercer will promptly forward to Customer any data-subject request it receives that relates to Customer Data and will not respond directly except to confirm the request has been forwarded.
- Commercer will provide reasonable assistance to Customer in fulfilling requests, subject to fees for disproportionate effort as permitted by law.
- Commercer will assist Customer with data-protection impact assessments and prior consultations with supervisory authorities to the extent required.
7. Audits
Commercer will make available on request the most recent third-party audit reports and security summaries it holds (which, at the effective date, may be limited given the service's stage). Customer may, no more than once per twelve months and on thirty days' written notice, request additional information reasonably necessary to demonstrate compliance with this DPA. On-site audits are permitted only where required by law or a supervisory authority, at Customer's cost, subject to reasonable confidentiality and security controls, and scheduled to minimize disruption.
8. AI processing scope
When Customer or its users invoke AI-assisted features, Commercer transmits the necessary inputs to model providers (routed through the Lovable AI Gateway) for the sole purpose of returning the requested output. Commercer does not use identifiable Customer Data to train shared or foundation models. Only aggregated and de-identified operational signals may be used to improve orchestration, prompt quality, and evaluation. Where a model provider offers a no-training tier, Commercer routes traffic on that tier so that provider does not train its own models on Customer traffic. This section forms part of Commercer's documented instructions.
9. US state privacy laws (CCPA/CPRA and similar)
Commercer acts as a "service provider" (California), "processor" (Colorado, Connecticut, Virginia, and similar states), and equivalent under other US state privacy laws. Commercer will not (a) sell or share Personal Data, (b) retain, use, or disclose Personal Data outside the direct business relationship or the purposes specified in the Agreement, or (c) combine Personal Data received under the Agreement with personal information received from other sources, except as expressly permitted by law. Commercer certifies that it understands these restrictions.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits either party's liability to a data subject under applicable data-protection law.
11. Order of precedence
In the event of a conflict, the order of precedence is: (a) the EU Standard Contractual Clauses (where they apply); (b) this DPA; (c) the Agreement.
12. Term
This DPA is effective on the effective date of the Agreement and remains in force for as long as Commercer processes Personal Data on behalf of Customer.
Annex I – Description of processing
- Data exporter (Controller): Customer, as identified in the Agreement.
- Data importer (Processor): Commercer LLC, 33 N Gould St, Sheridan, WY 82801, USA. Contact: dpo@commercer.io.
- Categories of data subjects: Customer personnel; and, to the extent Customer submits it, Customer's end users, suppliers, and other individuals identified in catalog or store data.
- Categories of personal data: identifiers (name, email, account), contact data, employment role, usage data, technical logs, and any personal data Customer chooses to submit through the service.
- Sensitive data: Customer will not submit special-category data unless necessary for its use of the service; if submitted, Customer is responsible for the applicable legal basis and safeguards.
- Frequency: continuous for the term.
- Nature and purpose of processing: as described in Section 2.
- Retention: for the term and post-termination window as described in the Privacy Policy.
- Competent supervisory authority: to be determined per Clause 13. Commercer LLC is established in the United States and, at this time, has not appointed an Article 27 representative in the EEA or UK. If Customer's use of the service requires Commercer to appoint one, the parties will address it by written amendment.
Annex II – Technical and organizational measures
- Access control: role-based access to production systems, least-privilege permissions, multi-factor authentication for administrators, and secret management with rotation.
- Encryption: TLS 1.2 or higher for data in transit; AES-256 or equivalent for data at rest.
- Segregation: logical tenant separation with row-level security policies enforced at the database layer.
- Change control: version-controlled infrastructure, code review, and staged deployments.
- Backups: automated periodic backups with rotation.
- Logging and monitoring: application, security, and audit logs with anomaly monitoring.
- Vulnerability management: dependency scanning and prompt remediation of critical findings.
- Incident response: documented procedure covering detection, containment, investigation, notification, and post-incident review.
- Personnel: confidentiality obligations and security awareness for personnel with access to Customer Data.
- Vendor management: assessment of subprocessors before engagement and periodic review.
- Business continuity: documented recovery procedures and periodic tabletop exercises as the organization scales.
Annex III – Approved sub-processors
The current list of sub-processors is maintained in-product and on the marketing site. Commercer will provide at least thirty days' prior notice of any addition or replacement of a sub-processor.
Shopify is not a Commercer sub-processor. Shopify is a destination platform to which Customer directs Commercer to write, and Shopify processes that data under its own agreement with Customer.
Signatures
This DPA takes effect on the effective date of the Agreement. Where a signed counterpart is required, sign below:
For Customer
- Signature:
- ______________________
- Name:
- ______________________
- Title:
- ______________________
- Date:
- ______________________
For Commercer LLC
- Signature:
- ______________________
- Name:
- Jordan Hall
- Title:
- Authorized Signatory
- Date:
- ______________________
