Data Processing Agreement
How FLUF Ltd processes personal data on behalf of merchants using FLUF Connect
1. Introduction and Scope
This Data Processing Agreement ("DPA") is entered into between FLUF Ltd, a company registered in England and Wales under Company Number 12635755 ("FLUF", "we", "us"), and the merchant, seller, or business that uses FLUF Connect ("you", "the Merchant").
Effective Date: 31 July 2026
Last Updated: 31 July 2026
This DPA forms part of, and is incorporated by reference into, our Terms & Conditions (the "Agreement"). It applies whenever FLUF processes personal data on your behalf in the course of providing FLUF Connect — for example, when we retrieve an order from your Shopify store, eBay account, Depop shop, or any other connected marketplace, and that order contains your customer's name, email address, telephone number, or shipping address.
No signature is required for this DPA to take effect. By using FLUF Connect you accept the Agreement, and this DPA takes effect with it. If your organisation requires a countersigned copy for its own records, email [email protected] and we will provide one.
Where this DPA conflicts with any other part of the Agreement in relation to the processing of personal data, this DPA prevails.
2. Definitions
- "Data Protection Law" means the UK General Data Protection Regulation and the Data Protection Act 2018, Regulation (EU) 2016/679 ("EU GDPR") where applicable, and any other data protection or privacy law applicable to the processing under this DPA.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given to them in Data Protection Law.
- "Merchant Personal Data" means Personal Data that FLUF processes on your behalf under the Agreement — principally the personal data of your customers, contained in orders, shipping records, and messages retrieved from connected marketplaces.
- "Sub-processor" means any third party engaged by FLUF to process Merchant Personal Data.
- "Connected Marketplace" means any third-party sales channel you connect to FLUF Connect, including Shopify, eBay, Depop, Etsy, Vinted, Facebook Marketplace, and others.
3. Roles of the Parties
3.1 You are the Controller; we are the Processor
In respect of Merchant Personal Data, you are the Controller and FLUF is the Processor. You determine the purposes and means of processing your customers' personal data; we process it on your documented instructions in order to provide FLUF Connect.
You are responsible for ensuring that you have a lawful basis for the processing, that your own privacy notice accurately describes it, and that you are entitled to transfer your customers' personal data to us for the purposes set out in this DPA.
3.2 Where FLUF is a Controller
FLUF acts as an independent Controller in respect of the personal data of you and your team — your account details, billing information, support correspondence, and how you use the platform. That processing is not governed by this DPA; it is described in our Privacy Policy.
3.3 Connected Marketplaces
Each Connected Marketplace is an independent Controller in respect of the data it holds and the terms on which it makes that data available. This DPA does not govern, and FLUF is not responsible for, a Connected Marketplace's own processing of personal data.
4. Details of the Processing
This section sets out the information required by Article 28(3) of the UK GDPR.
4.1 Subject matter and duration
The subject matter is the provision of FLUF Connect: multi-marketplace listing, inventory synchronisation, order aggregation and fulfilment support. Processing continues for as long as you use FLUF Connect, and thereafter only as described in Section 11.
4.2 Nature and purpose of the processing
- Retrieving orders and order updates from Connected Marketplaces
- Aggregating orders from multiple marketplaces into a single view
- Synchronising inventory and delisting sold items across marketplaces
- Producing shipping labels, fulfilment records, and tracking updates
- Displaying buyer messages and enabling you to respond
- Storing, backing up, and securing the above
- Providing support to you when you ask us to investigate a specific order
We do not use your customers' personal data for our own purposes. It is not used to train AI models, is not sold, and is not used for FLUF's own marketing. Where we publish market insights, they are aggregated and de-identified as described in Section 4.5 of our Privacy Policy, and never include names, contact details, addresses, or payment details.
4.3 Types of Personal Data
- Identity: customer name, marketplace username or handle
- Contact: email address, telephone number
- Address: shipping and billing address, city, postcode, country
- Transaction: order reference, items purchased, quantities, prices, currency, order status, dates
- Fulfilment: carrier, tracking number, delivery status
- Communications: the content of buyer-seller messages where the marketplace exposes them
We do not require, and ask you not to send us, special category data (Article 9 UK GDPR) or full payment card numbers. Card payments for your own FLUF subscription are handled directly by Stripe; FLUF does not store card numbers.
4.4 Categories of Data Subject
- Your customers and prospective customers
- Recipients of orders you ship (where different from the buyer)
- People who message you through a Connected Marketplace
5. Processing on Documented Instructions
FLUF will process Merchant Personal Data only on your documented instructions, including in relation to transfers to a third country, unless required to do otherwise by law — in which case we will inform you of that legal requirement before processing, unless the law prohibits us from doing so.
Your instructions are given by: (a) this DPA and the Agreement; (b) your configuration of FLUF Connect, including which marketplaces you connect, which features you enable, and which automations you switch on; and (c) any specific written instruction you send to [email protected].
If we consider that an instruction infringes Data Protection Law, we will tell you without undue delay and may suspend performance of that instruction until it is withdrawn or amended.
5.1 Confidentiality
FLUF ensures that every person authorised to process Merchant Personal Data is bound by an obligation of confidentiality, and is granted access only to the extent necessary to perform their role.
6. Security of Processing
FLUF implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR. The measures in force are described in Section 7.
We review these measures as the platform changes. We may update them, but we will not reduce the overall level of security provided.
7. Technical and Organisational Measures
7.1 Encryption
- Customer identity data is encrypted at the database column level using AES-256-GCM with a unique initialisation vector per value. This covers customer name, email address, telephone number, and shipping name, address, city, postcode and phone. A version marker is stored alongside each value so the encryption scheme can be rotated.
- Marketplace credentials — access tokens and API keys for your connected shops — are encrypted at rest.
- All data in transit is encrypted using TLS, between your browser and FLUF, and between FLUF and every Connected Marketplace and Sub-processor.
- Backups are encrypted. The primary backup repository is encrypted at rest, and our offsite backup provider applies server-side encryption.
7.2 Preventing leakage into logs
Credentials, session cookies, and authorisation headers are stripped centrally by a single redaction layer before any diagnostic data is written to disk, rather than at each individual point in the code that writes a log. Application logs are rotated daily, compressed, and deleted after 60 days, so logs do not become a permanent secondary store of personal data.
7.3 Resilience and recovery
- Backups follow a 3-2-1 pattern: three copies, on two kinds of media, with at least one held by a separate offsite provider.
- The primary backup runs four times daily, giving a worst-case recovery point of approximately six hours. Point-in-time database recovery reaches back twelve months.
- Automated integrity checks reject an undersized or incomplete backup rather than allowing it to overwrite a known-good copy, and a daily probe confirms that the newest archive actually contains a database dump.
- Backup health is reported daily and monitored.
7.4 Access control and accountability
- Administrative access to production systems is restricted to a small number of named operators, using individual credentials and key-based authentication.
- Access to Merchant Personal Data is limited to what is necessary to operate the Service and to support you.
- Access to your customers' personal data is logged. Every read of a customer name, address, telephone number, or email is recorded to a dedicated audit trail with the account that performed it, the time, the originating IP address, the purpose, and how many records were involved. The log deliberately records field names and never the values, so that the audit trail cannot itself become a second copy of the data. Entries are retained for 12 months and reviewed weekly.
- Deletions of product and listing records are written to an immutable audit trail at the database level, so that the origin of any destructive change is recoverable after the fact.
- Development and testing are performed against separate, non-production data.
7.5 Incident response
FLUF maintains a written security incident response policy covering severity classification, roles and escalation, detection, containment, evidence preservation, assessment, notification, recovery, and post-incident review. It records the notification deadlines in Section 11 as binding commitments and names the person accountable for each step. It is reviewed annually.
What we do not currently hold: FLUF does not hold a SOC 2, ISO 27001, or equivalent third-party security certification. We state this plainly rather than implying accreditation we do not have. The measures above are nonetheless in force and are described accurately.
8. Sub-processors
8.1 General authorisation
You give FLUF a general authorisation to engage Sub-processors to process Merchant Personal Data. We impose data protection obligations on every Sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
8.2 Current Sub-processors
The following Sub-processors may process Merchant Personal Data as at the date of this DPA:
| Sub-processor | Purpose | Data it may access | Location |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting, database, primary backup storage | All Merchant Personal Data (at rest, encrypted as described in Section 7.1) | Germany / Finland (EEA) |
| Backblaze, Inc. | Offsite encrypted backup copy | Encrypted database backups | United States |
| Cloudflare, Inc. | Content delivery, DNS, and web application firewall | Data in transit; IP addresses | Global edge network |
| OpenAI | AI-generated listing titles, descriptions, and category suggestions | Product and listing content only — not customer identity, contact, or address data | United States / Ireland |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Billing for your FLUF subscription | Your own billing details — not your customers' data | United States / Ireland |
8.3 Changes to Sub-processors
We will update this page before engaging a new Sub-processor that will process Merchant Personal Data, and will give you at least 30 days' notice by email to your account address. If you reasonably object to a new Sub-processor on data protection grounds within that period, you may tell us at [email protected]. We will work with you in good faith to find an alternative; if none is available, you may terminate the affected part of the Service without penalty.
9. International Transfers
Merchant Personal Data is stored primarily within the European Economic Area. Where a Sub-processor listed in Section 8.2 processes data outside the UK or EEA, that transfer is made on the basis of an appropriate safeguard under Chapter V of the UK GDPR — in practice, the UK International Data Transfer Addendum and/or the EU Standard Contractual Clauses incorporated into that provider's own data processing agreement, together with any supplementary measures required by the circumstances of the transfer.
You may request details of the safeguards applied to any specific transfer by writing to [email protected].
Where you connect a marketplace that operates outside the UK or EEA, the transfer of data between you and that marketplace is governed by your relationship with the marketplace, not by this DPA.
10. Assistance with Your Obligations
10.1 Data subject requests
Taking into account the nature of the processing, FLUF assists you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from Data Subjects exercising their rights under Data Protection Law.
FLUF Connect provides this in two ways:
- Directly in the platform — you can view, export, and delete the order and customer records held for your account.
- Automatically, where a marketplace supports it — for Shopify stores, FLUF implements the mandatory compliance webhooks. A customer data request returns the data we hold for that customer; a customer redaction request erases that customer's identifying data from our records; and a shop redaction request, sent after you uninstall the app, clears the stored credentials, deactivates the connection, and redacts the associated personal data. Each of these is cryptographically verified, and an unverifiable request is rejected.
If you receive a request that you cannot fulfil using the above, contact [email protected] and we will assist. If a Data Subject contacts FLUF directly about data we process on your behalf, we will not respond substantively; we will refer them to you and let you know.
10.2 Security, breach notification, DPIAs and prior consultation
FLUF assists you in ensuring compliance with your obligations under Articles 32 to 36 of the UK GDPR — security of processing, breach notification, data protection impact assessments, and prior consultation with a supervisory authority — taking into account the nature of the processing and the information available to us.
11. Personal Data Breach
FLUF will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Merchant Personal Data.
The notification will describe, so far as we are able at the time:
- the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
- the likely consequences;
- the measures taken or proposed to address it and to mitigate its effects; and
- a contact point for further information.
Where we cannot provide all of this at once, we will provide it in phases without further undue delay. We will notify you at your account email address. It is your responsibility as Controller to decide whether the breach must be reported to a supervisory authority or to affected Data Subjects, and to make any such report.
12. Deletion and Return of Data
At your choice, FLUF will delete or return all Merchant Personal Data at the end of the provision of services, and delete existing copies, unless storage is required by law.
- Export at any time. While your account is active you can export your product, order, and customer records from FLUF Connect.
- On disconnection of a marketplace, the stored credentials for that connection are cleared and the connection is deactivated.
- On termination or closure of your account, we delete or de-identify Merchant Personal Data within 90 days, save as set out below.
- Backups. Data already written to encrypted backups is removed as those backups age out on their normal retention cycle rather than being individually rewritten. Backup copies remain encrypted and are not used for any purpose other than restoration.
- Legal retention. Where we are required to retain transaction records for accounting or tax purposes, we retain the minimum necessary — the financial record — and redact the identifying personal data within it. Our general retention periods are set out in Section 5.1 of our Privacy Policy.
13. Audits and Information
FLUF makes available to you all information necessary to demonstrate compliance with the obligations in Article 28 of the UK GDPR, and allows for and contributes to audits, including inspections, conducted by you or an auditor you mandate.
In practice:
- We will respond to a reasonable written request for information, including a security questionnaire, within 30 days.
- An on-site or remote audit may be conducted once in any 12-month period, on at least 30 days' written notice, during business hours, and in a manner that does not disrupt the Service. More frequent audits may be conducted where required by a supervisory authority or following a Personal Data Breach affecting your data.
- Auditors must be bound by confidentiality, and must not be a competitor of FLUF.
- You bear your own costs and our reasonable costs of supporting an audit.
14. Liability, Term and Governing Law
This DPA takes effect when you begin using FLUF Connect and continues for as long as FLUF processes Merchant Personal Data. Sections 11, 12, and 13 survive termination for as long as FLUF retains any Merchant Personal Data.
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms & Conditions, to the fullest extent permitted by Data Protection Law. Nothing in this DPA limits any liability that cannot lawfully be limited, including a Data Subject's rights to compensation under Data Protection Law.
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, matching Section 15 of the Terms & Conditions.
14.1 Changes to this DPA
We may update this DPA to reflect changes in the Service, our Sub-processors, or the law. Where a change materially affects your rights, we will give you at least 30 days' notice by email to your account address before it takes effect. The "Last Updated" date at the top of this page always reflects the current version.
Data Protection Contact
For any question about this DPA, a data subject request, an audit request, or a security questionnaire:
Email: [email protected]
Company: FLUF Ltd, registered in England and Wales, Company Number 12635755
Response time: within 30 days, and without undue delay for breach-related matters
See also our Privacy Policy and Terms & Conditions.
Last Updated: 31 July 2026
This Data Processing Agreement is reviewed whenever the Service, our Sub-processors, or applicable data protection law changes.
