Data processing addendum.
The contract that governs how we handle your customers’ personal data. It applies automatically — you do not need to sign anything.
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Freewebstore Terms of Service (the "Agreement") between you ("you", "Customer", "Controller") and Freewebstore ("we", "us", "Processor"). You do not need to sign it. By accepting the Agreement you accept this DPA.
If there is any conflict between this DPA and the Agreement in respect of the processing of Customer Personal Data, this DPA prevails.
1. Definitions
"Customer Personal Data" means personal data that we process on your behalf, through the Freewebstore platform, in order to provide the Services — principally data relating to your storefront's visitors and customers.
"Services" means the Freewebstore e-commerce platform and related services provided under the Agreement.
"Data Protection Law" means the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR and the Data Protection Act 2018, and any other data protection law applicable to our processing of Customer Personal Data.
"Controller", "Processor", "Data Subject", "Personal Data Breach", "Sub-processor" and "processing" have the meanings given in the GDPR.
2. Roles of the parties
You are the Controller of Customer Personal Data. For the operation of your store — your customers' accounts, orders, addresses, contact details, communications and the content of your store — we are your Processor, and we process that data only on your documented instructions.
We do not sell Customer Personal Data, and we do not use it to train machine-learning models.
There are three narrow purposes for which we process data originating from your storefront as an independent Controller rather than as your Processor. We set them out because you need to be able to describe them accurately in your own privacy notice.
(a) Platform security and abuse prevention. We record the IP addresses of storefront visitors and use them to detect and block attacks, bots and abusive traffic across the whole platform. IP addresses held for this purpose are deleted after 7 days. Legal basis: our legitimate interests in the security of our network and services (Article 6(1)(f); see Recital 49).
(b) Fraud prevention. We analyse signals from stores on the platform, including patterns in order data, to detect fraudulent stores and payment fraud and to protect other merchants, shoppers and ourselves. Where an AI service assists that analysis, data is sent for the purposes of that analysis only, under contractual terms that prohibit the provider from using it to train its models. Legal basis: our legitimate interests, and compliance with our legal and payment-scheme obligations.
(c) Operating and improving the platform. We record page-view analytics for every storefront, both to provide you with your store statistics and to run, monitor and improve the platform. Visitor IP addresses in this dataset are pseudonymised before storage, and the dataset is retained for 365 days. Legal basis: our legitimate interests.
We also process the following as an independent Controller: your own merchant account and billing data; analytics about visitors to our own websites at freewebstore.com and freewebstore.co.uk; and messages sent through your store's contact form, which we screen automatically for fraud and for breaches of our platform terms. That processing is governed by our Privacy Policy and not by this DPA.
3. Subject matter, duration, nature and purpose
| Subject matter | Provision of the Freewebstore e-commerce platform |
| Duration | The term of the Agreement, plus the deletion period in clause 10 |
| Nature and purpose | Hosting a storefront; receiving and processing orders; processing payments through the payment provider you choose; sending transactional email to your customers on your behalf; providing you with reporting about your own store |
| Types of personal data | Name; email address; billing and delivery address; telephone number; order and transaction history; account credentials (stored hashed); IP address and device/browser information; any data your customers enter into forms you configure |
| Categories of Data Subject | Your storefront's visitors and customers; any staff accounts you create |
| Special category data | None is required by the Services. If you configure your store to collect it, you do so as Controller and on your own lawful basis |
Payment card data is out of scope. Card details pass from your customer's browser directly to your payment provider; they are not stored, processed or transmitted by Freewebstore systems.
4. Your instructions
We process Customer Personal Data only on your documented instructions, which comprise the Agreement, this DPA, the configuration choices you make in your control panel, and any further written instruction you give us.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We may also process Customer Personal Data where required to do so by law, in which case we will inform you first unless the law prohibits it.
5. Confidentiality
We ensure that anyone authorised to process Customer Personal Data is subject to an appropriate duty of confidentiality, and that access is limited to those who need it to provide the Services or to support you.
6. Security
We implement appropriate technical and organisational measures to protect Customer Personal Data. Those measures are set out in Annex 1 — Technical and Organisational Measures below and form part of this DPA. We may update them from time to time provided the level of protection is not reduced.
7. Sub-processors
You give us general authorisation to engage Sub-processors. Our current Sub-processors are listed at our Privacy Policy, which states the date on which it was last updated.
We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
Changes. We will give you at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data. We will give that notice through your primary account contact, or by email to your primary account contact.
Objection. You may object on reasonable data-protection grounds within 30 days of the notice. If you do not object within that period you are deemed to have consented. If you object and we are unable or unwilling to accommodate the objection, your remedy is to terminate your use of the affected Services within 30 days of our response, without penalty for the unused portion of any prepaid fees.
8. Assistance with data subject requests
Taking into account the nature of the processing, we assist you in responding to requests from Data Subjects by providing self-service tooling in your control panel:
- Erasure / anonymisation — a per-customer anonymisation function that hashes address and telephone fields across every stored address, replaces the email address with a random value, rewrites the associated orders, removes the customer from the subscriber list, and deletes their marketing-preferences record. A hard delete is also available.
- Access and portability — a customer export.
- Rectification — customer records can be edited directly.
If a Data Subject contacts us directly about your store, we will not respond substantively; we will direct them to you and, where we can identify your store, tell you.
9. Personal Data Breaches
We notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide the information you reasonably need to meet your own notification obligations. Notifying you is not an admission of fault.
10. Deletion and return
On termination, or on your written request, we delete Customer Personal Data. Store closure triggers an automated cascade that removes customer, order and product records.
You can export your customer list at any time before termination. Export before you close your store; we cannot guarantee retrieval afterwards.
Backups. Deletion acts on live records. Our database backups operate on a rolling 35-day window, so deleted data may remain restorable from backup for up to 35 days after deletion, after which it is overwritten in the ordinary course. Backups are not used to restore individual records and are protected by the same measures as live data.
11. International transfers
All Customer Personal Data is stored and processed in the European Union (Ireland, eu-west-1).
Where a Sub-processor processes Customer Personal Data outside the EEA, that transfer is made under an adequacy decision, or under the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 (Modules Two and Three), or under the EU-US Data Privacy Framework where the recipient is certified. For transfers from the United Kingdom we rely on the UK International Data Transfer Addendum. The transfer mechanism applicable to each Sub-processor is stated in its row in our Privacy Policy.
12. Your responsibilities, and the boundary of ours
You are responsible for:
- having a lawful basis for the data you collect through your store, and for your own privacy notice and cookie disclosures;
- the accuracy and lawfulness of the instructions you give us;
- anything you add to your store. Custom code, your own tracking pixels, analytics accounts, embedded widgets, third-party apps and any Advanced CSS/JS are outside this DPA. Where they process personal data, the provider is your own processor or sub-processor, to be disclosed in your own privacy policy — not ours.
13. Audit
We make available the information necessary to demonstrate compliance with Article 28, including this DPA, our technical and organisational measures in Annex 1 below, our Sub-processor list, and our current PCI DSS attestation on request.
Where that information is not sufficient, you may request an audit no more than once in any twelve months, on at least 30 days' written notice, during business hours, subject to confidentiality, and without access to other customers' data or to systems where such access would compromise their security. You bear your own costs and our reasonable costs.
14. Changes to this DPA
We may update this DPA. We will post the updated version at /legal/dpa.html with a new "Last updated" date and, where the change is material, give notice as set out in clause 7. Your continued use of the Services after an updated DPA is posted constitutes your acceptance of it. Previous versions, with the dates during which they were in force, are available on request from privacy@freewebstore.com.
15. Contact
Data protection enquiries: privacy@freewebstore.com
freewebstore Ltd. Slater Terrace, On The Banks, Sandygate, Burnley, Lancashire, BB11 1BU, United Kingdom
Security issues: security@freewebstore.com
Annex 1 — Technical and Organisational Measures
These are the measures referred to in clause 6. They form part of this DPA. Last reviewed 4 September 2026.
1. Data location
All Customer Personal Data is stored and processed in the EU (AWS eu-west-1, Ireland), except where a Sub-processor listed at our Privacy Policy processes it elsewhere under the transfer mechanism stated in that list.
2. Encryption
| In transit | TLS 1.2 or 1.3 for all connections to storefronts, the control panel and our APIs. TLS 1.0 and 1.1 are disabled at the edge |
| At rest — databases | All database tables holding personal data are encrypted at rest |
| At rest — object storage | AES-256 (SSE-S3) server-side encryption |
| Passwords | Never stored in plain text |
3. Access control
- Access to production systems is limited to a small number of named administrators.
- Every account with console access to our cloud infrastructure has multi-factor authentication enabled.
- Service-to-service access uses scoped machine identities rather than shared credentials, and cross-account access uses assumed roles rather than static keys.
- Password policy: minimum 12 characters, requiring upper case, lower case, number and symbol.
- Merchant authentication uses a managed identity provider with JWT sessions and optional two-factor authentication.
4. Network and application security
- A web application firewall sits in front of every storefront and the control panel, with managed rule sets for common attack classes and rate limiting.
- Automated abuse detection blocks IP addresses responsible for attacks, and can apply a temporary challenge to traffic for a store under attack.
- Bot checks (reCAPTCHA or Turnstile) protect public forms.
- Administrative interfaces are not exposed to the public internet without authentication.
5. Payment card security
Card details never reach our systems. Payment providers collect card data in their own hosted fields or on their own pages. We hold only the card scheme, the last four digits, the wallet type and the provider's transaction reference. We are assessed under PCI DSS SAQ A, attested 23 June 2026.
6. Logging and monitoring
- Application and infrastructure events are logged centrally to a queryable store.
- Application log retention is 30 days.
- Automated alerting covers error-rate and abuse conditions, with notification to an internal channel.
7. Backup and resilience
- Databases have point-in-time recovery enabled with a rolling 35-day window.
- The platform runs across multiple availability zones behind managed load balancing, with automatic instance replacement on health-check failure.
- Cache contents are not backed up, and hold no data that is not recoverable from the primary store.
8. Data retention and deletion
- Personal data is retained for as long as needed to provide the Services, and deleted on store closure through an automated cascade covering customer, order and product records.
- Merchants have self-service tooling to anonymise or delete an individual customer.
- Deleted data may remain restorable from backup for up to 35 days (see section 7).
- Deleted storefront page content leaves a recoverable version for one day.
9. Personnel
Access to personal data is limited to personnel who need it to provide or support the Services, and those personnel are subject to a duty of confidentiality.
10. Sub-processor management
We impose data protection obligations on our Sub-processors no less protective than those we owe to our merchants, and we remain liable for their performance. Our current Sub-processors, the data they may process and the transfer mechanism relied on for each are published at our Privacy Policy.
11. Law enforcement requests
We disclose personal data to law enforcement only where legally compelled. Where we are lawfully able to do so, we notify the affected merchant before disclosing.
12. Reporting a vulnerability
If you believe you have found a security vulnerability, email security@freewebstore.com. We will acknowledge your report and keep you informed.