Sellforte US Data Processing Appendix
Terms and Notices — Sellforte, Inc. — 2026-10-01
US. The contracting entity in the Order Form determines the applicable terms. For EU/rest of the world (excluding the US), see Sellforte Solutions Oy terms.
Appendix 1 US Data Processing Appendix
Version 2026-10-01
1 Scope and roles
1.1 Scope and definitions. This Data Processing Appendix, including Annexes A-C, applies to personal information Sellforte processes for the Customer under the Agreement (Customer Personal Data). It applies from first processing until all copies have been returned or deleted, subject to lawful retention. Privacy Laws means privacy, data security, breach notification, and electronic communications laws applicable to the relevant processing. Terms such as business, controller, processor, service provider, contractor, sell, and share have their applicable statutory meanings.
1.2 Roles. The Customer determines the purposes and instructions for processing Customer Personal Data and acts as a business or controller, or as a processor authorized by its controller. Sellforte acts as its processor or subprocessor and, where the California Consumer Privacy Act as amended (CCPA) applies, as a service provider or contractor. Sellforte's separate processing of business contact, billing, and limited platform administration records for its own purposes is described in the applicable privacy notice. Customer service content does not become own-purpose data because it appears in a support record, log, prompt, or recording.
1.3 Affiliates. Sellforte may use its Affiliates listed in Annex C as subprocessors to deliver the Services. Sellforte remains responsible for them as for its own performance and binds them in writing to obligations at least as protective as this DPA.
2 Instructions and permitted processing
2.1 Processing instructions. The Agreement, Annex B, and the Customer's authorized configurations and documented requests form the processing instructions. Sellforte will process Customer Personal Data only to perform the specific activities in Annex B or as required by applicable law. It will inform the Customer before legally required processing unless prohibited and promptly notify the Customer if it considers an instruction unlawful. It may suspend only the affected processing while the Parties resolve the issue.
2.2 Customer responsibilities. The Customer will provide lawful instructions and the rights, notices, consents, and source permissions required for collection, disclosure, and processing. Each Party must honor applicable consumer choices and statutory obligations within its control. Customer instructions cannot authorize a statutory violation or remove Sellforte's own obligations. Customer-selected External Services are outside Sellforte's subprocessor chain for their independent processing; Sellforte remains responsible for its own interfaces and access controls.
2.3 Use restrictions. Sellforte will not sell or share Customer Personal Data, use it for cross-context behavioral advertising, or use it to build profiles for other customers. It will not retain, use, or disclose it for unrelated commercial purposes, outside the direct business relationship with the Customer, or beyond the specified purposes, except for processing expressly permitted by applicable Privacy Laws. It will not combine it with personal information from other customers or its own interactions with individuals except where permitted by the applicable service-provider or processor rules for the specified purposes. These restrictions also apply to subprocessors. Sellforte certifies that it understands and will comply with the restrictions applicable to a CCPA contractor.
2.4 Compliance and oversight. Sellforte will comply with Privacy Laws applicable to its role and provide the level of protection required by the CCPA where it applies. It will notify the Customer promptly if it determines it can no longer comply. The Customer may take reasonable and appropriate steps to verify permitted use and to stop and remediate unauthorized processing, including the assessments in Section 8. Sellforte will cooperate with those steps.
2.5 Excluded data. Customer Personal Data must not include Sensitive Data or personal information about individuals known to be under 18 unless the Parties first sign a specific amendment identifying the data, purpose, applicable laws, permitted suppliers, locations, retention, and safeguards. Sensitive Data includes information treated as sensitive under applicable Privacy Laws and, in all cases, health or consumer health information, biometric identifiers used for identification, genetic information, precise geolocation, racial or ethnic origin, religious beliefs, sex life or sexual orientation, immigration or citizenship status, government identification numbers, financial account or payment-card credentials, private communications unrelated to the Services, and records identifying an individual as having requested or obtained specific video materials. This restriction does not prevent using necessary credentials through approved authentication and connector interfaces. The standard service does not include a HIPAA business associate arrangement, regulated biometric processing, or a children's service. An amendment cannot waive mandatory consent, age-related, or other protections. On discovering prohibited data, the Parties will stop unnecessary processing and arrange secure segregation, return, or deletion while meeting legal preservation duties.
2.6 No model training; deidentified data. Sellforte will not use Customer Content to train or improve general-purpose or generative AI models or authorize suppliers to do so. Customer-specific analytical modeling and permitted use of non-personal, anonymous business metrics remain governed by ToS Section 11. Anonymous Aggregate Data may be used only after effective deidentification and compliance with applicable source restrictions. Sellforte will maintain measures against reidentification, publicly commit to maintaining deidentified personal information in that form where Privacy Laws require, and bind permitted recipients to equivalent restrictions. Pseudonymous information remains protected personal information where applicable law so provides.
3 Personnel and security
3.1 Personnel and security measures. Persons authorized to process Customer Personal Data must have a need for access, receive appropriate privacy and security instruction, and be subject to confidentiality obligations. Sellforte will maintain the technical and organizational measures in Annex A, proportionate to the data and reasonably foreseeable risks, and will not materially reduce their overall protection during the subscription.
3.2 Allocation of security responsibilities. The Customer controls its own systems, permissions, source data, and independently selected providers. Sellforte controls its service security, delivery suppliers, and collection technology. The allocation does not excuse either Party's own breach or mandatory security duties.
4 Subprocessors
4.1 Authorized subprocessors. The Customer authorizes the subprocessors and downstream providers in the version of Annex C supplied with the Order Form, only for their stated functions and the enabled service configuration. Sellforte will maintain a reproducible current list of their legal entities, functions, and processing and access countries.
4.2 Subprocessor changes. Before an added or replacement subprocessor receives Customer Personal Data, Sellforte will give at least 30 days' written notice describing the change. The Customer may object within that period on reasonable data-protection grounds. The Parties will seek an appropriate alternative. If they cannot resolve the objection, the Customer may terminate the affected Services before the new processing begins, with the refund and fee treatment in ToS Section 17.8. Earlier processing requires the Customer's specific written authorization and lawful safeguards.
4.3 Subprocessor obligations. Sellforte will impose written obligations appropriate to the delegated processing that provide at least the protection required by this DPA and applicable Privacy Laws, including applicable CCPA restrictions. It will ensure the same requirements flow through downstream processing and remains responsible for its delivery chain.
5 Individual requests and assessments
5.1 Individual requests. Taking account of the processing and information available, Sellforte will reasonably and promptly assist the Customer with requests for access, correction, deletion, portability, restriction, and opt-outs, including legally recognized preference signals. It will promptly forward a request concerning Customer Personal Data to the Customer and act on instructions unless law requires a direct response. When the Customer instructs it in response to an individual's verified request, Sellforte will stop the affected processing. It will provide assistance early enough for the Customer to meet applicable deadlines when the Customer supplies a timely request and necessary information.
5.2 Assessments and authority inquiries. Sellforte will provide information reasonably needed for the Customer's legally required privacy, data-protection, or impact assessments, security and breach obligations, and inquiries by competent authorities. Reasonable standard assistance is included. Additional engineering or custom work requires an agreed charge; assistance required because of Sellforte's breach is not chargeable. A discussion about charges must not delay an urgent or legally required response.
6 Security incidents
6.1 Incident notification. A Security Incident means confirmed or reasonably believed accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Sellforte will notify the Customer promptly after becoming aware of a Security Incident, aiming to provide initial notice within 24 hours. It will not await a complete investigation. The notice will state the available nature, data and individuals affected, known or likely consequences, response measures, and contact details, with phased updates as facts become available. Shorter mandatory deadlines apply.
6.2 Incident response and costs. Sellforte will investigate, contain, mitigate, and remediate incidents within its responsibility and cooperate with the Customer. It will not notify individuals or authorities on the Customer's behalf without instructions unless required by law. The Customer remains responsible for notifications required of it; Sellforte remains responsible for its own. Notification is not an admission of fault or liability. Sellforte bears its ordinary incident-response costs. Other losses and reasonable additional work caused by the Customer's breach follow the Agreement, without delaying urgent action.
7 Return and deletion
7.1 Return or deletion. At the Customer's choice, Sellforte will return or delete Customer Personal Data and existing copies, including data in support records, logs, recordings, transcripts, prompts, and derived records. ToS Section 17.6 provides the 30-day retrieval period and active-system deletion timetable. Earlier lawful instructions and shorter deadlines under law or binding source terms prevail for all copies they cover.
7.2 Backups and retained records. Backup copies will expire on the agreed schedule, no later than 12 months after termination, and sooner where feasible or required. They remain isolated from ordinary processing and protected; deletion must be reapplied before restored data returns to normal use. This maximum does not permit retention contrary to applicable Privacy Laws or a shorter binding deletion deadline. Where retention is required by law, Sellforte will isolate the necessary records, limit processing to that requirement, and delete them when it ends. On request, Sellforte will confirm deletion and identify the basis and expected expiry of remaining lawful retention.
8 Compliance information and assessments
8.1 Compliance information and audits. Sellforte will make available information necessary to demonstrate compliance and permit and cooperate with reasonable assessments by the Customer or its designated independent assessor. The Parties will ordinarily use current independent reports and relevant documentation first. If those materials are insufficient, or a material incident, substantiated concern, or law requires further assessment, Sellforte will permit a proportionate audit or inspection with reasonable notice and confidentiality and security protections. The process must not prevent statutory assessment rights or exposure of a material compliance failure.
8.2 Assessment costs. Each Party bears ordinary assessment-support costs; the Customer pays its assessor and agreed additional assistance. Sellforte bears reasonable costs attributable to an assessment establishing its material breach. No fee or procedural condition may obstruct mandatory regulatory access or an assessment that law requires.
9 Locations and international safeguards
9.1 Processing locations. Primary hosting is in the United States unless the Order Form selects another supported region. Some processing, including support, development, data science, and supplier processing, may occur in the European Union, the United Kingdom, and other countries identified in Annex C for the authorized functions. Sellforte will not move primary hosting to a different agreed region without the required agreement and will maintain lawful safeguards for processing and access. Sellforte will not knowingly give a country of concern or covered person, as defined in 28 C.F.R. Part 202, access to Customer Personal Data.
9.2 Laws applicable to each entity. Each entity remains responsible for laws applicable to its own activities. If processing for the Customer is subject to the EU or UK GDPR or another regime requiring additional contract terms, the Parties will agree the necessary supplement before that processing begins.
9.3 Government requests. Sellforte will assess government requests, disclose only information legally required, and notify the Customer where lawful. It will challenge or seek narrowing of a request where required by applicable law or binding transfer safeguards and suspend an unlawful transfer if no compliant alternative is available.
10 Noncompliance and liability
10.1 Noncompliance. If Sellforte cannot comply, it will promptly notify the Customer and suspend affected processing where needed. The Customer may terminate affected Services if compliance is not restored within a reasonable period, no later than one month after a required suspension, or immediately where continued processing would be unlawful and cannot safely be isolated. Fees and refunds follow ToS Section 17.8.
10.2 Liability and precedence. ToS Section 16 governs contractual liability, including its special cap for DPA and privacy breaches. No contractual term waives an individual's statutory rights, a regulator's powers, or liability or recourse that applicable law or mandatory transfer terms prohibit limiting. This DPA prevails on Customer Personal Data processing; negotiated changes require the process in ToS Section 18.4.
