Sequence Commerce
Data Processing Agreement (DPA)
Sequence Commerce Data Processing Agreement for GDPR compliance. Learn how we process personal data as your processor and protect data subject rights.
Last Updated: June 9, 2025
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Sequence Commerce, Inc. (“Processor”) and the Customer (“Controller”) for the purchase of services from Processor.
1. Definitions
“Personal Data” means any information relating to an identified or identifiable natural person.
“Processing” means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, or deletion.
“Data Subject” means the individual to whom Personal Data relates.
“Applicable Law” means all applicable data protection laws including GDPR, CCPA, and other relevant regulations.
2. Processing of Personal Data
2.1 Scope and Roles
- Customer is the Controller of Personal Data
- Sequence Commerce is the Processor acting on Controller’s behalf
- This DPA applies to all Personal Data processed by Processor
2.2 Processor’s Obligations
Processor shall:
- Process Personal Data only on documented instructions from Controller
- Ensure persons authorized to process Personal Data have committed to confidentiality
- Implement appropriate technical and organizational security measures
- Not engage subprocessors without Controller’s prior authorization
- Assist Controller in responding to data subject requests
- Delete or return all Personal Data upon termination
2.3 Controller’s Obligations
Controller shall:
- Ensure lawful basis for Processing
- Provide necessary instructions for Processing
- Ensure accuracy of Personal Data
- Comply with all applicable data protection laws
3. Security Measures
3.1 Technical Measures
- Encryption of data at rest and in transit
- Access controls and authentication systems
- Regular security testing and assessments
- Network security and firewalls
- Intrusion detection systems
3.2 Organizational Measures
- Security awareness training
- Access on need-to-know basis
- Background checks for personnel
- Incident response procedures
- Regular security audits
4. Subprocessors
4.1 Authorized Subprocessors
Controller agrees to the subprocessors listed at [www.sequencecommerce.com/subprocessors]
4.2 New Subprocessors
- Processor will notify Controller of new subprocessors
- Controller has 30 days to object to new subprocessors
- Processor ensures subprocessors comply with this DPA
5. Data Subject Rights
Processor shall assist Controller in fulfilling obligations to respond to data subject requests for:
- Access to Personal Data
- Rectification of Personal Data
- Erasure of Personal Data
- Restriction of Processing
- Data portability
- Objection to Processing
6. Personal Data Breach
6.1 Notification
Processor shall notify Controller without undue delay upon becoming aware of a Personal Data breach
6.2 Information Provided
- Nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences
- Measures taken or proposed
6.3 Cooperation
Processor shall cooperate with Controller in investigating and mitigating the breach
7. Data Transfers
7.1 Transfer Mechanisms
For transfers outside the EEA, parties shall ensure:
- Standard Contractual Clauses are in place
- Appropriate safeguards exist
- Data subject rights are protected
7.2 Transfer Impact Assessment
Processor has conducted assessments confirming transfers can be performed lawfully
8. Audit Rights
8.1 Controller Rights
Controller may audit Processor’s compliance with this DPA through:
- Written questionnaires
- Remote audits
- On-site inspections (with reasonable notice)
8.2 Audit Procedures
- Maximum one audit per year unless breach occurs
- Costs borne by Controller
- Confidentiality agreements required
9. Duration and Termination
9.1 Duration
This DPA remains in effect for the duration of the Services Agreement
9.2 Termination
Upon termination, Processor shall:
- Stop Processing Personal Data
- Delete or return Personal Data as instructed
- Provide certification of deletion
10. Liability and Indemnification
10.1 Liability Cap
Liability under this DPA is subject to the limitations in the Terms of Service
10.2 Indemnification
Each party shall indemnify the other against claims arising from its breach of this DPA
11. Governing Law
This DPA is governed by the laws specified in the Terms of Service
12. Order of Precedence
In case of conflict:
- Applicable data protection laws
- This DPA
- Terms of Service
- Privacy Policy
Annex 1: Processing Details
Categories of Data Subjects
- Customers
- Website visitors
- Newsletter subscribers
- Business contacts
Categories of Personal Data
- Contact information (name, email, phone)
- Account data (username, preferences)
- Transaction data (orders, payments)
- Usage data (browsing behavior)
- Communication data (support tickets)
Processing Purposes
- Order fulfillment
- Customer service
- Marketing (with consent)
- Legal compliance
- Fraud prevention
- Service improvement
Processing Duration
- Active account data: Duration of relationship
- Transaction records: 7 years
- Marketing data: Until consent withdrawn
- Log data: 90 days
Annex 2: Security Measures
Technical Safeguards
- AES-256 encryption
- TLS 1.3 for data transmission
- Multi-factor authentication
- Regular vulnerability scanning
- Automated backup systems
Organizational Safeguards
- ISO 27001 certification
- Annual security training
- Incident response team
- Business continuity planning
- Vendor security assessments
How to Execute This DPA
For Business Customers
- Download the DPA template
- Complete company information
- Sign and return to: legal@sequencecommerce.com
For Enterprise Customers
Custom DPAs available upon request
Standard Execution
By using our Services, you agree to this DPA as published
Contact Information
General Inquiries: Email: contact@sequencecommerce.com
This DPA is incorporated into and subject to the terms of the Sequence Commerce Terms of Service.