This is the agreement between OrderZ and you, the merchant — it doesn't cover your own customers' relationship with your store. Your customers should see your own privacy notice, or the default one OrderZ provides if you haven't published your own.
This Data Processing Agreement ("DPA") applies between OrderZ (Zaroid Technologies) ("we", "us", the "Processor") and every merchant ("you", the "Controller") who creates a store on the OrderZ platform. It governs how we handle the personal data of your own customers ("your customers") that you collect through the OrderZ platform.
You are the data controller responsible for your customers' personal data: you decide what data to collect, why, and you are responsible for giving your customers proper notice, obtaining any required consent, and handling their requests to access or correct their data.
OrderZ acts as your data processor: we process your customers' data only to provide the platform to you, and only on your instructions as expressed through your use of the platform's features.
We maintain reasonable technical and organisational security measures to protect your customers' data against unauthorised access, loss, or misuse. We retain your customers' data only for as long as needed to provide the platform to you, or as required by law, and provide tools (consent capture, self-service data export, and deletion) so you can meet your own obligations to your customers.
If OrderZ becomes aware of a data breach affecting your store's customer data, we will notify you without undue delay. You remain responsible for notifying affected customers where required under applicable data protection laws, and OrderZ will provide reasonable assistance and information to facilitate such notifications.
Customer data associated with active store memberships, unredeemed loyalty rewards balances, or unexpired prepaid service packages (such as wellness/salon packages or dining vouchers) must be retained by the platform to honor ongoing contractual obligations between the merchant and the customer. Upon formal account closure, membership cancellation, or full package expiration, OrderZ provides a 30-day retention buffer period during which you retain full access to export your store's customer data, transaction records, package ledgers, and consent logs via our self-service data export tools. Following the expiration of the 30-day buffer period, OrderZ will permanently purge or anonymize customer data from active systems, except where continued retention is strictly required by statutory financial or tax auditing laws.
You remain responsible for: giving your customers notice of what data you collect and why; obtaining any consent required by the law that applies to you; responding to your customers' requests to access, correct, or delete their data (which you can do using the tools we provide); and ensuring your own use of the platform complies with the data protection law applicable to your business.
We use the following categories of third-party service providers to operate parts of the platform on your behalf: cloud infrastructure providers (hosting for the application and database your customers' data is stored in), SMS/messaging providers, email delivery providers, push notification providers, sign-in providers, and payment processors. These providers only process data as needed to deliver their service to us and are bound by their own confidentiality and security obligations.
We may update this DPA from time to time to reflect changes in the platform or in applicable law. Continued use of the platform after an update constitutes acceptance of the revised terms.