DATA PROCESSING AGREEMENT (DPA)
Effective date: August 1, 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Use between InClick Inc., Delaware ("InClick," "Processor," "we," "us") and the merchant identified in the applicable InClick account ("Merchant," "Controller," "you"). It applies whenever InClick processes Personal Data on Merchant's behalf in the course of providing the Service, including where the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") or the UK GDPR applies to that processing (for example, because Merchant's end customers are located in the European Economic Area ("EEA") or the United Kingdom).
If there is a conflict between this DPA and the Terms of Use on a matter of data protection, this DPA controls.
1. DEFINITIONS
Terms such as "Personal Data," "Processing," "Controller," "Processor," "Data Subject," "Supervisory Authority," and "Personal Data Breach" have the meanings given in the GDPR. In addition:
"Merchant Personal Data" means Personal Data that InClick processes on Merchant's behalf in the course of providing the Service — primarily, personal data about Merchant's own end customers (for example, name, contact details, and order information), and, where applicable, personal data about Merchant's own staff who use the Service.
"Sub-processor" means any third party InClick engages to process Merchant Personal Data on InClick's behalf.
"EU SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
2. ROLES OF THE PARTIES
2.1
For Merchant Personal Data, Merchant is the Controller and InClick is the Processor. Merchant determines what personal data is collected from its customers and why; InClick processes that data only to build, operate, and support Merchant's store as described in the Terms of Use and this DPA.
2.2
InClick processes Merchant Personal Data only:
(a) to provide, maintain, and improve the Service (including AI-assisted store generation, order management, the copilot assistant, and customer communications Merchant enables);
(b) on Merchant's documented instructions, which include the instructions built into the Service's normal operation and any additional written instructions Merchant gives; and
(c) as required by applicable law, in which case InClick will inform Merchant of that legal requirement before processing, unless the law prohibits this.
2.3
InClick will promptly inform Merchant if, in InClick's opinion, an instruction from Merchant infringes the GDPR or another applicable data protection law.
2.4
Separately from Merchant Personal Data, InClick acts as an independent Controller for account and billing data it collects directly from Merchant to operate the InClick account relationship (for example, Merchant's own name, email, and payment details for its subscription). InClick's Privacy Policy describes that processing.
3. NATURE, PURPOSE, AND CATEGORIES OF PROCESSING
Details of the processing are set out in Annex I. In summary: InClick processes Merchant Personal Data to build and run Merchant's online store — generating and hosting the storefront and product catalog, processing and tracking orders, handling shipping/pickup logistics, operating the copilot (including, where Merchant enables it, responding to Merchant's customers), and providing customer support to Merchant.
4. CONFIDENTIALITY
InClick ensures that any person it authorizes to process Merchant Personal Data (including employees and contractors) is subject to an appropriate duty of confidentiality, whether contractual or statutory.
5. SECURITY OF PROCESSING
InClick implements appropriate technical and organizational measures to protect Merchant Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II. Merchant acknowledges that these measures reflect a generally recognized industry standard and are reviewed and updated periodically, rather than being tied to a specific named certification unless otherwise stated in writing.
6. SUB-PROCESSORS
6.1 General authorization
Merchant gives InClick general authorization to engage Sub-processors to help provide the Service, subject to this Section 6. InClick's current Sub-processors are listed in Annex III.
6.2 Flow-down obligations
InClick imposes data protection obligations on each Sub-processor that are substantially equivalent to those in this DPA, and InClick remains liable to Merchant for a Sub-processor's performance of those obligations.
6.3 Notice of changes
InClick will update Annex III and give Merchant reasonable advance notice (for example, by posting an update and/or notifying account administrators) before adding or replacing a Sub-processor that will process Merchant Personal Data.
6.4 Right to object
If Merchant has a reasonable, documented data-protection objection to a new Sub-processor, Merchant may notify InClick within 14 days of the notice. The parties will work in good faith to address the objection; if they cannot resolve it, either party may treat that specific processing as a material breach and Merchant's remedy is to terminate the affected part of the Service, without penalty for the unused portion.
7. INTERNATIONAL TRANSFERS
7.1 Primary processing location
InClick's primary processing of Merchant Personal Data takes place in Israel. The European Commission has recognized Israel as providing an adequate level of data protection (Commission Decision 2011/61/EU), so transfers of Merchant Personal Data from the EEA to InClick in Israel do not require Standard Contractual Clauses or another additional transfer mechanism.
7.2 Sub-processor transfers
Where a Sub-processor processes Merchant Personal Data outside the EEA, the UK, Switzerland, or a country the European Commission recognizes as adequate, InClick ensures that transfer is covered by an appropriate safeguard — in particular, the EU SCCs (Module 3: processor-to-processor, or Module 4: processor-to-controller, as applicable), the UK International Data Transfer Addendum, or the Sub-processor's own recognized certification (for example, the EU-U.S. Data Privacy Framework, where applicable). Copies of the relevant safeguards are available to Merchant on request.
7.3 Incorporation of the EU SCCs
To the extent the EU SCCs are required under Section 7.2 for a given transfer, the parties agree that the EU SCCs are incorporated into this DPA by reference, with the appropriate Module completed according to the transfer in question, and with the details in Annex I, Annex II, and Annex III of this DPA serving as Annexes I, II, and III of the EU SCCs for that purpose.
8. ASSISTANCE TO MERCHANT
8.1 Data subject requests
Taking into account the nature of the processing, InClick will provide reasonable assistance to help Merchant respond to requests from Data Subjects exercising their rights under applicable data protection law (access, rectification, erasure, restriction, portability, and objection). Where an end customer contacts InClick directly about their data, InClick will refer that request to Merchant without undue delay.
8.2 Data protection impact assessments
InClick will provide reasonably requested information to help Merchant carry out data protection impact assessments and, where required, prior consultations with a Supervisory Authority, to the extent this relates to InClick's processing and information is not otherwise available to Merchant.
9. PERSONAL DATA BREACH NOTIFICATION
InClick will notify Merchant without undue delay, and in any event within 72 hours of becoming aware, after confirming a Personal Data Breach affecting Merchant Personal Data. That notice will describe, to the extent then known: the nature of the breach; the categories and approximate number of Data Subjects and records affected; likely consequences; and measures taken or proposed to address the breach. InClick will provide updates as more information becomes available and will reasonably cooperate with Merchant's own notification obligations to Supervisory Authorities or Data Subjects.
10. AUDITS
On reasonable written request, no more than once per 12-month period (unless required by a Supervisory Authority or following a Personal Data Breach), InClick will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for, and contribute to, an audit conducted by Merchant or an independent third-party auditor engaged by Merchant, subject to reasonable confidentiality protections and at Merchant's expense, and conducted so as to minimize disruption to InClick's operations and other customers.
11. RETURN OR DELETION OF DATA
On termination of the Service, and subject to Section 4.5 of the Terms of Use, InClick will, at Merchant's choice, delete or return all Merchant Personal Data within 90 days, except to the extent applicable law requires InClick to retain some or all of it — in which case InClick will continue to protect that data under this DPA's obligations for as long as it is retained.
12. LIABILITY
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Use.
13. TERM
This DPA takes effect on the effective date above and remains in effect for as long as InClick processes Merchant Personal Data on Merchant's behalf under the Terms of Use.
ANNEX I — DETAILS OF PROCESSING
A. List of Parties
Data exporter: Merchant, as identified in the InClick account (Controller).
Data importer: InClick Inc., Delaware ("InClick"), Processor, located in Israel.
B. Description of Processing
Categories of Data Subjects: Merchant's end customers (people who place or attempt to place orders through Merchant's store); Merchant's own staff users, where applicable.
Categories of Personal Data: Name; email address; phone number; shipping/billing address; order history and contents; communications with Merchant's copilot or support (where enabled); limited payment metadata needed to reconcile orders (full card data is processed directly by the payment processor, not stored by InClick — see Section 4.3 of the Terms of Use).
Special categories of data: None are intentionally collected or processed. Merchant must not configure the Service to collect special category data (health, biometric, etc.) about its customers.
Nature of processing: Collection, storage, organization, structuring, retrieval, use, generation of AI-assisted content and responses, transmission (e.g., order confirmations, shipping updates), and deletion.
Purpose of processing: Providing the store-building and store-management Service described in the Terms of Use, including order processing, payment coordination, shipping/pickup coordination, and copilot-assisted customer communication.
Duration: For the term of the Terms of Use, and thereafter as described in Section 11 of this DPA.
Frequency: Continuous, for as long as the Service is in use.
ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES
InClick maintains a program of technical and organizational measures appropriate to the risk, generally consistent with recognized industry practice, including:
• encryption of Personal Data in transit (e.g., TLS) and encryption of Personal Data at rest where supported by the underlying infrastructure;
• access controls limiting access to Merchant Personal Data to personnel who need it to perform the Service, with authentication requirements for internal systems;
• logging and monitoring of access to production systems that store Merchant Personal Data;
• a documented incident response process, including the notification process described in Section 9;
• regular review and patching of infrastructure and application dependencies;
• confidentiality obligations for employees and contractors as described in Section 4;
• vendor/Sub-processor due diligence before onboarding, and contractual flow-down of data protection obligations as described in Section 6;
• backups and a documented process for restoring service in the event of an incident.
[InClick to update this Annex with any specific certifications (e.g., SOC 2, ISO 27001) or additional controls it maintains, once confirmed.]
ANNEX III — SUB-PROCESSORS
Stripe, Inc. — Payment processing — [To be confirmed — Stripe's published data processing locations]
[Hosting provider] — Application hosting and data storage — Israel
[Email/SMS provider] — Order confirmations and customer notifications — [Location]
[Analytics provider] — Product/store analytics — [Location]
InClick will keep this list current and notify Merchant of changes as described in Section 6.3.
This DPA is a template prepared to reflect InClick's product as currently understood and is not a substitute for advice from a qualified data protection lawyer. Before publishing or signing this DPA, have it reviewed by counsel — in particular Annex III (confirm actual Sub-processors and their processing locations), Annex II (confirm actual security measures and any certifications), and Section 7 (confirm whether any Sub-processor transfer requires SCCs and which Module applies).