Skip to content
aster
ProductHow it worksPricingResources
中文Explore plans
ProductHow it worksPricingResourcesExplore plans
Back to legal center

Platform agreements

Data Processing Addendum and Schedules

Controller–processor terms with processing details, subprocessors, security and transfers.

Document version
draft-2026-10-10
Revised
October 10, 2026
Download bilingual agreementsRead the legal review checklist↗

On this page

  1. 1. Parties, scope and instructions
  2. 2. Processing description: subject and duration
  3. 3. Data types and data subjects
  4. 4. Controller duties and unlawful instructions
  5. 5. Confidentiality and security schedule
  6. 6. Subprocessor register and authorization
  7. 7. Changes and objections to subprocessors
  8. 8. International-transfer schedule
  9. 9. Individual rights and compliance assistance
  10. 10. Personal-data breach handling
  11. 11. Audits, records and regulatory cooperation
  12. 12. Return, deletion and survival

This document concerns Aster’s software service and its merchant customers. Store product sales remain the responsibility of the actual merchant.

1. Parties, scope and instructions

This draft DPA is proposed between order customer example (the “Controller”) and service provider example (the “Processor”) and becomes part of the service contract after valid acceptance by both parties. Personal data, processing and breach are interpreted under applicable data-protection law. The Processor processes store personal data only on demonstrable written instructions, including service settings, authorized tickets and this DPA. It may not use consumer data for its own advertising, sale, general-purpose model training or other independent purposes. Lawful independent processing outside this role requires separate notice and its own basis.

2. Processing description: subject and duration

The subject is the customer’s authorized stores: site generation, product presentation, customer accounts, carts, orders, fulfillment, payment status, refunds, support, abuse prevention and lawfully configured analytics. Operations include collection, recording, organization, hosting, retrieval, transmission, limited automated analysis, correction, export and deletion. Duration is the service term, a 30-day export period and the deletion periods permitted here. Stores, processing region and effective date are example. New purposes, special data or regions require prior updates to these schedules and authorization.

3. Data types and data subjects

Data subjects are customers, visitors, recipients, merchant administrators and support contacts. Permitted types are names, contact and address details, account identifiers, order items and amounts/currencies, fulfillment information, payment tokens and status, refund records, necessary device and security logs, consent records and support conversations. Full PANs, CVVs, passwords, private keys and unapproved health, biometric or other special-category data are prohibited. The default service does not target children; unavoidable children’s or protected data require a specific schedule after legality, necessity and enhanced safeguards are assessed.

4. Controller duties and unlawful instructions

The Controller is responsible for lawful sources and bases, accurate notices, necessary consent and duties to customers, and sends only necessary data. If the Processor considers an instruction contrary to applicable data-protection law, it must promptly explain the concern and pause the affected instruction pending clarification without inventing a new purpose. Where law compels processing, the Processor gives prior notice of the legal requirement where permitted. Authorized contacts must be designated: Controller example / privacy@example.com; Processor example / privacy@example.com.

5. Confidentiality and security schedule

The Processor ensures personnel with data access are bound to confidentiality and trained for their duties. Proposed minimum measures include tenant isolation, least privilege and administrator MFA, encryption in transit and at rest, separated keys, audit records, backups and restoration exercises, vulnerability management, change review and incident response. Algorithms, key custody, recovery targets, log lifetimes, isolation testing and owners are example and must be completed with implementation evidence before signature. Agreed protections must not be reduced without risk assessment. This schedule is not a security certification.

6. Subprocessor register and authorization

Where general written authorization is used, it authorizes the actual subprocessors identified in a complete register, not arbitrary providers. Each entry must state legal name example; service example (infrastructure/email/AI/support/monitoring); data types example; establishment and processing countries example; transfer mechanism example; and security schedule example. Current entries are unselected placeholders and do not authorize production transfers. The Processor must impose relevant obligations at least as protective as this DPA on subprocessors and remain responsible for their performance.

7. Changes and objections to subprocessors

Proposed additions or replacements require at least 30 days’ written notice of purpose, location and safeguards. The Controller may object during that period on specific data-protection grounds; the parties first consider an alternative provider, function restriction or other reasonable solution. Affected customer data must not be sent to the new provider while the objection is unresolved. If no reasonable alternative exists, the affected service may end with a refund of unused prepaid fees. Urgent security replacements require notice as far in advance as practicable and prompt details, without permanently eliminating objection rights.

8. International-transfer schedule

The data exporter example, importer example, destination example, remote-access locations example, authority example and mechanism example must each be completed. For restricted EU transfers without applicable adequacy, select an appropriate valid standard-clause module, complete its annexes, assess transfer risks and adopt necessary supplementary measures. UK transfers require a separate assessment of mechanisms such as the IDTA or UK Addendum. References to “GDPR,” “SCCs” or this paragraph do not execute a transfer agreement. If destination protections cannot be maintained, transfers must pause pending instructions for alternatives or deletion.

9. Individual rights and compliance assistance

Rights requests concerning Controller data must be forwarded without undue delay, with a proposed two-business-day forwarding target, and not substantively decided without authority. Considering processing nature and available information, the Processor assists access, correction, deletion, restriction, portability and objection requests, security duties, DPIAs and prior consultation. Assistance arrangements must not delay applicable statutory periods. Ordinary in-scope assistance is included in service fees; genuinely additional work requires an agreed price in advance and a fee dispute cannot block necessary legal duties.

10. Personal-data breach handling

On becoming aware of a personal-data breach affecting Controller data, the Processor notifies the Controller without undue delay, with a proposed initial target of 24 hours, without waiting for a complete investigation. The notice includes known nature, affected categories and scale, likely consequences, measures and a contact, followed by phased updates. The Processor preserves necessary evidence and cooperates in remediation, and does not notify individuals or authorities on the Controller’s behalf without authority unless legally compelled. The 24-hour target is a proposed contractual commitment requiring operational validation, distinct from regulatory deadlines applicable to controllers.

11. Audits, records and regulatory cooperation

The Processor supplies information needed to demonstrate this DPA’s performance, including relevant controls, assessments and remediation records. The Controller or a confidentiality-bound independent auditor may ordinarily conduct one reasonable audit annually; breaches, material noncompliance or regulatory requirements are not subject to that annual limit. Scheduling, scope safeguards and reasonable fees must not materially obstruct legally required inspection or expose other tenants’ data. Parties cooperate with lawful regulatory requirements. Third-party disclosure demands must be appropriately verified and notified to the Controller where permitted.

12. Return, deletion and survival

At service end, the Controller may choose return or deletion. The proposal provides a 30-day read-only export period, production-copy deletion within 30 days after that period, and backup deletion or irreversible anonymization through the documented rotation within 90 days of the same export-period end. Backups cannot be used for other purposes and restored copies must reapply deletion records. Legally necessary retention must identify its basis, categories, access restrictions and period, with deletion when that duty ends. Deletion confirmation is available on request. This DPA remains effective while covered data is retained; all incomplete schedules must be completed before production processing.

draft-2026-10-10Back to document top↑

RESPONSIBILITIES & TERMS

Continue reading

Other documents in the same category.

SaaS Terms of ServiceSubscription, Renewal, Cancellation and Refund PolicyPlatform Privacy Notice
aster

An AI team for independent brands and the people building what comes next.

ProductProductHow it worksPricing
ResourcesProduct design & architectureAll agreementsContact details
Legal & supportPrivacy policyBilling & cancellation
© 2026 Aster. ESTARTECH PTE.LTD. All rights reserved.
Back to top