DATA PROCESSING AGREEMENT (DPA)
Effective date: August 1, 2026
This Data Processing Agreement ("DPA") forms part of, and is
incorporated into, the Terms of Use between InClick Inc.,
Delaware ("InClick," "Processor," "we," "us") and the merchant
identified in the applicable InClick account ("Merchant,"
"Controller," "you"). It applies whenever InClick processes
Personal Data on Merchant's behalf in the course of providing
the Service, including where the General Data Protection
Regulation (Regulation (EU) 2016/679, "GDPR") or the UK GDPR
applies to that processing (for example, because Merchant's end
customers are located in the European Economic Area ("EEA") or
the United Kingdom).
If there is a conflict between this DPA and the Terms of Use on
a matter of data protection, this DPA controls.
1. DEFINITIONS
Terms such as "Personal Data," "Processing," "Controller,"
"Processor," "Data Subject," "Supervisory Authority," and
"Personal Data Breach" have the meanings given in the GDPR.
In addition:
• "Merchant Personal Data" means Personal Data
that InClick processes on Merchant's behalf in the course of
providing the Service — primarily, personal data about
Merchant's own end customers (for example, name, contact
details, and order information), and, where applicable,
personal data about Merchant's own staff who use the Service.
• "Sub-processor" means any third party
InClick engages to process Merchant Personal Data on
InClick's behalf.
• "EU SCCs" means the Standard Contractual
Clauses annexed to European Commission Implementing Decision
(EU) 2021/914 of 4 June 2021.
2. ROLES OF THE PARTIES
2.1
For Merchant Personal Data, Merchant is the Controller and
InClick is the Processor. Merchant determines what personal
data is collected from its customers and why; InClick processes
that data only to build, operate, and support Merchant's store
as described in the Terms of Use and this DPA.
2.2
InClick processes Merchant Personal Data only:
(a) to provide, maintain, and improve the Service (including
AI-assisted store generation, order management, the copilot
assistant, and customer communications Merchant enables);
(b) on Merchant's documented instructions, which include the
instructions built into the Service's normal operation and any
additional written instructions Merchant gives; and
(c) as required by applicable law, in which case InClick will
inform Merchant of that legal requirement before processing,
unless the law prohibits this.
2.3
InClick will promptly inform Merchant if, in InClick's opinion,
an instruction from Merchant infringes the GDPR or another
applicable data protection law.
2.4
Separately from Merchant Personal Data, InClick acts as an
independent Controller for account and billing data it collects
directly from Merchant to operate the InClick account
relationship (for example, Merchant's own name, email, and
payment details for its subscription). InClick's Privacy Policy
describes that processing.
3. NATURE, PURPOSE, AND CATEGORIES OF PROCESSING
Details of the processing are set out in Annex I. In summary:
InClick processes Merchant Personal Data to build and run
Merchant's online store — generating and hosting the storefront
and product catalog, processing and tracking orders, handling
shipping/pickup logistics, operating the copilot (including,
where Merchant enables it, responding to Merchant's customers),
and providing customer support to Merchant.
4. CONFIDENTIALITY
InClick ensures that any person it authorizes to process
Merchant Personal Data (including employees and contractors) is
subject to an appropriate duty of confidentiality, whether
contractual or statutory.
5. SECURITY OF PROCESSING
InClick implements appropriate technical and organizational
measures to protect Merchant Personal Data against accidental
or unlawful destruction, loss, alteration, unauthorized
disclosure, or access, as described in Annex II. Merchant
acknowledges that these measures reflect a generally recognized
industry standard and are reviewed and updated periodically,
rather than being tied to a specific named certification unless
otherwise stated in writing.
6. SUB-PROCESSORS
6.1 General authorization
Merchant gives InClick general authorization to engage
Sub-processors to help provide the Service, subject to this
Section 6. InClick's current Sub-processors are listed in
Annex III.
6.2 Flow-down obligations
InClick imposes data protection obligations on each
Sub-processor that are substantially equivalent to those in this
DPA, and InClick remains liable to Merchant for a Sub-processor's
performance of those obligations.
6.3 Notice of changes
InClick will update Annex III and give Merchant reasonable
advance notice (for example, by posting an update and/or
notifying account administrators) before adding or replacing a
Sub-processor that will process Merchant Personal Data.
6.4 Right to object
If Merchant has a reasonable, documented data-protection
objection to a new Sub-processor, Merchant may notify InClick
within 14 days of the notice. The parties will work in good
faith to address the objection; if they cannot resolve it,
either party may treat that specific processing as a material
breach and Merchant's remedy is to terminate the affected part
of the Service, without penalty for the unused portion.
7. INTERNATIONAL TRANSFERS
7.1 Primary processing location
InClick's primary processing of Merchant Personal Data takes
place in Israel. The European Commission has recognized Israel
as providing an adequate level of data protection (Commission
Decision 2011/61/EU), so transfers of Merchant Personal Data
from the EEA to InClick in Israel do not require Standard
Contractual Clauses or another additional transfer mechanism.
7.2 Sub-processor transfers
Where a Sub-processor processes Merchant Personal Data outside
the EEA, the UK, Switzerland, or a country the European
Commission recognizes as adequate, InClick ensures that
transfer is covered by an appropriate safeguard — in particular,
the EU SCCs (Module 3: processor-to-processor, or Module 4:
processor-to-controller, as applicable), the UK International
Data Transfer Addendum, or the Sub-processor's own recognized
certification (for example, the EU-U.S. Data Privacy Framework,
where applicable). Copies of the relevant safeguards are
available to Merchant on request.
7.3 Incorporation of the EU SCCs
To the extent the EU SCCs are required under Section 7.2 for a
given transfer, the parties agree that the EU SCCs are
incorporated into this DPA by reference, with the appropriate
Module completed according to the transfer in question, and
with the details in Annex I, Annex II, and Annex III of this DPA
serving as Annexes I, II, and III of the EU SCCs for that
purpose.
8. ASSISTANCE TO MERCHANT
8.1 Data subject requests
Taking into account the nature of the processing, InClick will
provide reasonable assistance to help Merchant respond to
requests from Data Subjects exercising their rights under
applicable data protection law (access, rectification, erasure,
restriction, portability, and objection). Where an end customer
contacts InClick directly about their data, InClick will refer
that request to Merchant without undue delay.
8.2 Data protection impact assessments
InClick will provide reasonably requested information to help
Merchant carry out data protection impact assessments and,
where required, prior consultations with a Supervisory
Authority, to the extent this relates to InClick's processing
and information is not otherwise available to Merchant.
9. PERSONAL DATA BREACH NOTIFICATION
InClick will notify Merchant without undue delay, and in any
event within 72 hours of becoming aware, after confirming a
Personal Data Breach affecting Merchant Personal Data. That
notice will describe, to the extent then known: the nature of
the breach; the categories and approximate number of Data
Subjects and records affected; likely consequences; and
measures taken or proposed to address the breach. InClick will
provide updates as more information becomes available and will
reasonably cooperate with Merchant's own notification
obligations to Supervisory Authorities or Data Subjects.
10. AUDITS
On reasonable written request, no more than once per 12-month
period (unless required by a Supervisory Authority or following
a Personal Data Breach), InClick will make available information
reasonably necessary to demonstrate compliance with this DPA,
and will allow for, and contribute to, an audit conducted by
Merchant or an independent third-party auditor engaged by
Merchant, subject to reasonable confidentiality protections and
at Merchant's expense, and conducted so as to minimize
disruption to InClick's operations and other customers.
11. RETURN OR DELETION OF DATA
On termination of the Service, and subject to Section 4.5 of
the Terms of Use, InClick will, at Merchant's choice, delete or
return all Merchant Personal Data within 90 days, except to the
extent applicable law requires InClick to retain some or all of
it — in which case InClick will continue to protect that data
under this DPA's obligations for as long as it is retained.
12. LIABILITY
Each party's liability arising out of or in connection with
this DPA is subject to the limitations and exclusions of
liability set out in the Terms of Use.
13. TERM
This DPA takes effect on the effective date above and remains
in effect for as long as InClick processes Merchant Personal
Data on Merchant's behalf under the Terms of Use.
ANNEX I — DETAILS OF PROCESSING
A. List of Parties
Data exporter: Merchant, as identified in the
InClick account (Controller).
Data importer: InClick Inc., Delaware
("InClick"), Processor, located in Israel.
B. Description of Processing
Categories of Data Subjects:
Merchant's end customers (people who place or attempt to place
orders through Merchant's store); Merchant's own staff users,
where applicable.
Categories of Personal Data:
Name; email address; phone number; shipping/billing address;
order history and contents; communications with Merchant's
copilot or support (where enabled); limited payment metadata
needed to reconcile orders (full card data is processed directly
by the payment processor, not stored by InClick — see Section
4.3 of the Terms of Use).
Special categories of data:
None are intentionally collected or processed. Merchant must
not configure the Service to collect special category data
(health, biometric, etc.) about its customers.
Nature of processing:
Collection, storage, organization, structuring, retrieval, use,
generation of AI-assisted content and responses, transmission
(e.g., order confirmations, shipping updates), and deletion.
Purpose of processing:
Providing the store-building and store-management Service
described in the Terms of Use, including order processing,
payment coordination, shipping/pickup coordination, and
copilot-assisted customer communication.
Duration:
For the term of the Terms of Use, and thereafter as described
in Section 11 of this DPA.
Frequency:
Continuous, for as long as the Service is in use.
ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES
InClick maintains a program of technical and organizational
measures appropriate to the risk, generally consistent with
recognized industry practice, including:
• encryption of Personal Data in transit (e.g., TLS) and
encryption of Personal Data at rest where supported by the
underlying infrastructure;
• access controls limiting access to Merchant Personal Data
to personnel who need it to perform the Service, with
authentication requirements for internal systems;
• logging and monitoring of access to production systems that
store Merchant Personal Data;
• a documented incident response process, including the
notification process described in Section 9;
• regular review and patching of infrastructure and
application dependencies;
• confidentiality obligations for employees and contractors
as described in Section 4;
• vendor/Sub-processor due diligence before onboarding, and
contractual flow-down of data protection obligations as
described in Section 6;
• backups and a documented process for restoring service in
the event of an incident.
[InClick to update this Annex with any specific certifications
(e.g., SOC 2, ISO 27001) or additional controls it maintains,
once confirmed.]
ANNEX III — SUB-PROCESSORS
Stripe, Inc. — Payment processing — [To be
confirmed — Stripe's published data processing locations]
[Hosting provider] — Application hosting and
data storage — Israel
[Email/SMS provider] — Order confirmations and
customer notifications — [Location]
[Analytics provider] — Product/store analytics
— [Location]
InClick will keep this list current and notify Merchant of
changes as described in Section 6.3.
This DPA is a template prepared to reflect InClick's product as
currently understood and is not a substitute for advice from a
qualified data protection lawyer. Before publishing or signing
this DPA, have it reviewed by counsel — in particular Annex III
(confirm actual Sub-processors and their processing locations),
Annex II (confirm actual security measures and any
certifications), and Section 7 (confirm whether any
Sub-processor transfer requires SCCs and which Module applies).