Legal
Vulpy Commerce Data Processing Agreement
Effective date: September 3, 2026
This Data Processing Agreement (DPA) forms part of the agreement between Vulpy, Inc. (Vulpy, we, us, or our) and you (Customer) for the use of Vulpy Commerce (the Agreement). Capitalised terms not defined here have the meanings given in the Agreement or the Vulpy Commerce Privacy Policy.
This DPA applies where Vulpy processes Personal Data on behalf of Customer as a data processor or sub-processor under applicable data protection law, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and comparable legislation.
1. Definitions
Personal Data means information relating to an identified or identifiable natural person that Customer submits to or generates through Commerce, for which Customer is the controller.
Processing has the meaning given in applicable data protection law and includes any operation performed on Personal Data.
Sub-processor means a third party engaged by Vulpy to process Personal Data on Customer’s behalf.
Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission under Decision 2021/914/EU, or successor clauses.
2. Roles and scope
Customer is the controller of Personal Data submitted to or generated through Commerce. Vulpy is the processor of that Personal Data and processes it only on Customer’s documented instructions, including as set out in the Agreement and this DPA.
This DPA does not apply to Personal Data that Vulpy processes as a controller in connection with its own products, services, billing, or operations, which is governed by the Vulpy Commerce Privacy Policy.
3. Vulpy’s obligations as processor
Vulpy will:
- process Personal Data only on Customer’s documented instructions, including as permitted by the Agreement and this DPA, unless required to do otherwise by applicable law, in which case Vulpy will notify Customer before processing unless prohibited by law;
- ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations;
- implement and maintain reasonable technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access;
- notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer’s Personal Data;
- assist Customer in responding to requests from data subjects exercising their rights under applicable data protection law, taking into account the nature of the processing;
- assist Customer in meeting its obligations under applicable data protection law relating to security, breach notification, and data protection impact assessments, to the extent Vulpy can reasonably do so given the information available to it;
- at Customer’s election and upon written request, delete or return all Personal Data to Customer at the end of the Agreement, and delete existing copies unless retention is required by law; and
- make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and cooperate with reasonable audits or inspections conducted by Customer or a mandated auditor, subject to reasonable advance notice, confidentiality obligations, and scheduling constraints.
4. Customer’s obligations
Customer is responsible for the lawfulness of its instructions to Vulpy and for ensuring it has a lawful basis for any Personal Data it submits to or generates through Commerce. Customer will comply with applicable data protection law in connection with its use of Commerce and will not instruct Vulpy to process Personal Data in a manner that would cause Vulpy to violate applicable law.
5. Sub-processors
Vulpy may engage sub-processors to assist in providing Commerce. Vulpy will impose data protection obligations on sub-processors that are no less protective than those in this DPA.
Current sub-processors engaged by Vulpy for Commerce include infrastructure and hosting providers, payment processors (including Stripe), and email and support providers. Customer may request the current sub-processor list by emailing privacy@vulpy.io.
Vulpy will notify Customer of material changes to its sub-processors by updating this DPA, posting a notice, or emailing Customer. If Customer reasonably objects to a new sub-processor on data protection grounds, Customer may notify Vulpy within 30 days of the notice. The parties will work in good faith to resolve the objection; if the parties cannot agree, Customer may terminate the affected portion of the Agreement without penalty.
6. International transfers
Where Vulpy transfers Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country not recognised as providing an adequate level of protection, Vulpy will use appropriate safeguards, which may include Standard Contractual Clauses, UK International Data Transfer Agreements, or other lawful transfer mechanisms. Customer may request copies of applicable transfer mechanisms by emailing privacy@vulpy.io.
7. Security measures
Vulpy maintains reasonable technical and organisational measures for Commerce, which may include encryption of data in transit and at rest, access controls, logging and monitoring, and incident response procedures. Vulpy may update its measures over time provided that updates do not materially reduce the overall level of protection.
8. Data subject rights
To the extent Customer cannot fulfil a data subject’s request directly through Commerce’s administrative tools, Vulpy will provide reasonable assistance. Customer remains responsible for determining the validity of requests and for communicating with data subjects.
9. Data protection impact assessments
Vulpy will provide reasonable cooperation and information to assist Customer in conducting data protection impact assessments where required by applicable law.
10. Term and termination
This DPA takes effect when Customer accepts the Agreement and remains in effect until the Agreement ends. On expiry or termination of the Agreement, Vulpy will, at Customer’s election within 30 days of termination, delete or return Customer’s Personal Data and delete existing copies, unless retention is required by law.
11. Conflict
In the event of a conflict between this DPA and the Agreement with respect to the subject matter of this DPA, this DPA controls.
12. Governing law
This DPA is governed by the laws applicable to the Agreement unless required otherwise by applicable data protection law.
13. Contact
Data protection questions may be sent to privacy@vulpy.io.
Postal address: Vulpy, Inc., 8 The Green, Ste D, Dover, DE 19901, United States.