Legal · Agreement

Data Processing Agreement

This Data Processing Agreement (“DPA”) is entered into by and between Silk Commerce Corp., a California corporation, with offices at 47 Discovery, Suite 100, Irvine, CA 92782 (“Company,” “we,” “us,” or “our”) and the customer identified in the applicable Order Form or account registration (“Customer,” “you,” or “your”), and forms part of, and is incorporated by reference into, the Agreement (as defined in our Terms of Service) governing Customer’s use of LightningAI, including Lightning Reviews, Lightning Connector, Lightning Returns, and our other product modules (the “Services”). Capitalized terms not defined in this DPA have the meaning given in the Agreement.

This DPA applies only to the extent we process Customer Personal Data on Customer’s behalf in the course of providing the Services, and does not apply to Account Information, which is governed by our Privacy Policy.

Definitions

  1. 1.1

    “Applicable Data Protection Laws” means all data protection and privacy laws applicable to the processing of Customer Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018 (“UK Data Protection Laws”), the Swiss Federal Act on Data Protection (“Swiss FADP”), and applicable US state privacy laws (collectively, “US Privacy Laws”), each as amended or superseded from time to time.

  2. 1.2

    “Customer Personal Data” means any personal data (as defined under Applicable Data Protection Laws) that we process on Customer’s behalf in connection with the Services, including personal data of Customer’s end customers submitted through Lightning Reviews, Lightning Connector, or Lightning Returns, but excluding Account Information.

  3. 1.3

    “Data Subject” means the identified or identifiable natural person to whom Customer Personal Data relates.

  4. 1.4

    “Security Incident” means a breach of security leading to the accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to, Customer Personal Data.

  5. 1.5

    “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as approved by the European Commission in Commission Implementing Decision (EU) 2021/914, as may be amended, replaced, or superseded.

  6. 1.6

    “Sub-processor” means any third party (including our affiliates) engaged by us to process Customer Personal Data in order to provide the Services.

  7. 1.7

    “Processing,” “controller,” “processor,” and “personal data” have the meanings given in the GDPR, and equivalent terms under other Applicable Data Protection Laws (e.g., “business,” “service provider,” “sell,” and “share” under US Privacy Laws) will be interpreted accordingly.

Roles of the Parties

  1. 2.1

    As between the parties, Customer is the controller (or “business,” under US Privacy Laws) of Customer Personal Data, and we are the processor (or “service provider” or “processor,” as applicable) acting on Customer’s behalf and documented instructions.

  2. 2.2

    This DPA applies to the processing of Customer Personal Data of any affiliate of Customer that is permitted to use the Services under the Agreement, in which case “Customer” as used in this DPA includes that affiliate. Customer represents and warrants that it is authorized to enter into this DPA, and to give instructions under this DPA, on behalf of any such affiliate.

  3. 2.3

    Details of the categories of Data Subjects, categories of Customer Personal Data, and purpose, nature, and duration of processing are set out in Schedule 1.

Customer Instructions

  1. 3.1

    We will process Customer Personal Data only in accordance with Customer’s documented instructions, which include (a) the Agreement, (b) Customer’s configuration and use of features within the Services, and (c) any additional written instructions given by Customer, unless we are required to do otherwise by applicable law, in which case we will inform Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.

  2. 3.2

    We will promptly notify Customer if, in our opinion, an instruction from Customer violates Applicable Data Protection Laws.

Confidentiality

We will ensure that personnel authorized to process Customer Personal Data are subject to a binding written obligation of confidentiality (whether contractual or statutory).

Sub-processors

  1. 5.1

    Customer generally authorizes us to engage Sub-processors to process Customer Personal Data, provided that we (a) impose data protection terms on each Sub-processor that are no less protective than this DPA, and (b) remain liable to Customer for each Sub-processor’s performance of its obligations.

  2. 5.2

    Our current list of Sub-processors is available at https://legal.lightningcommerce.ai/subprocessors (or upon request to legal@lightningcommerce.ai). We will provide Customer at least fifteen (15) days’ advance notice before authorizing any new Sub-processor to process Customer Personal Data, by updating that list or notifying Customer directly.

  3. 5.3

    Customer may object to a new Sub-processor on reasonable data protection grounds by notifying us in writing within ten (10) days of our notice. If Customer objects, the parties will discuss the objection in good faith; if we cannot resolve the objection, Customer may terminate the portion of the Services that cannot be provided without the objected-to Sub-processor, as its sole remedy.

Data Subject Rights

  1. 6.1

    Customer is solely responsible for responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws (e.g., access, correction, deletion, portability, or objection).

  2. 6.2

    If we receive a request directly from a Data Subject relating to Customer Personal Data, we will not respond to the request directly (other than to confirm we have forwarded it) and will instead promptly forward it to Customer.

  3. 6.3

    Taking into account the nature of the processing, we will provide Customer with self-service functionality within the Services, and reasonable additional assistance where such functionality is insufficient, to help Customer respond to such requests. We may charge Customer a reasonable fee for assistance beyond what is included in the Services, to the extent permitted by Applicable Data Protection Laws.

Security Measures

We will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Security Incidents, as described in Schedule 2. Customer is responsible for reviewing the information made available by us relating to security and making an independent determination as to whether the Services meet Customer’s requirements, including any obligations under Applicable Data Protection Laws.

Security Incident Notification

If we become aware of a Security Incident affecting Customer Personal Data, we will, without undue delay: (a) notify Customer in writing; (b) provide reasonably available information regarding the nature of the Security Incident, its likely consequences, and measures taken or proposed to address it; (c) take reasonable steps to contain, investigate, and mitigate the Security Incident; and (d) reasonably cooperate with Customer’s own investigation and notification obligations to regulators or affected Data Subjects. Our notification of, or response to, a Security Incident is not an acknowledgment of fault or liability.

Audits

  1. 9.1

    Upon Customer’s written request, and no more than once per twelve (12) month period, we will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including a copy of our then-current ISO/IEC 27001 certificate and, if available, any other relevant third-party audit report or certification.

  2. 9.2

    If such reports are not sufficient to meet Customer’s audit obligations under Applicable Data Protection Laws (or following a Security Incident, or at the request of a supervisory authority), Customer may request an audit of our relevant processing activities, subject to at least fourteen (14) days’ prior written notice, a mutually agreed scope and timing, and execution during normal business hours in a manner that does not unreasonably interfere with our business operations. Customer will bear its own costs and reimburse our reasonable costs of facilitating such an audit.

Return and Deletion of Data

Upon termination or expiration of the Agreement, and subject to Customer’s request made before such termination or expiration, we will (a) make Customer Personal Data available for export using self-service functionality within the Services, and (b) delete remaining copies of Customer Personal Data within ninety (90) days, except to the extent we are required to retain copies under applicable law, or need to retain copies to establish, exercise, or defend legal claims.

International Data Transfers

  1. 11.1

    We will not transfer Customer Personal Data outside of the country of origin unless we ensure that appropriate safeguards are in place pursuant to Applicable Data Protection Laws.

  2. 11.2

    EEA, UK, and Switzerland. To the extent our processing of Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland involves a transfer of that data to a country not deemed by the applicable authority to provide an adequate level of protection, the transfer will be governed by the Standard Contractual Clauses, which are hereby incorporated by reference, with Customer as the “data exporter” and Company as the “data importer,” using Module Two (controller to processor) where Customer is a controller and Module Three (processor to processor) where Customer is itself a processor. For transfers subject to UK Data Protection Laws, the parties additionally incorporate the UK Information Commissioner’s International Data Transfer Addendum to the SCCs. For transfers subject to the Swiss FADP, the SCCs apply with the modifications necessary to reflect Swiss law, including that the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

  3. 11.3

    Government Access Requests. If we receive a legally binding request from a public authority for disclosure of Customer Personal Data, we will, unless legally prohibited from doing so, notify Customer promptly and disclose only the minimum amount of Customer Personal Data necessary to comply with the request, using reasonable efforts to challenge the request where we believe it is unlawful or overbroad.

US State Privacy Law Terms

To the extent US Privacy Laws apply to our processing of Customer Personal Data, we will (a) not sell or share Customer Personal Data, or retain, use, or disclose it for any purpose other than providing the Services under the Agreement, or as otherwise permitted by US Privacy Laws; (b) not combine Customer Personal Data with personal data received from other sources, except as permitted by US Privacy Laws; and (c) provide the level of privacy protection required of a “service provider” or “processor” under US Privacy Laws.

Liability

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Any claims against us or our affiliates under this DPA may only be brought by the Customer entity that is party to the Agreement.

Term

This DPA takes effect on the date Customer agrees to the Agreement (or, for existing customers, the date we publish or otherwise notify Customer of this DPA) and remains in effect for as long as we process Customer Personal Data on Customer’s behalf.

Order of Precedence

In the event of a conflict between this DPA and the Agreement, this DPA governs with respect to the parties’ data protection obligations regarding Customer Personal Data. In the event of a conflict between this DPA and the Standard Contractual Clauses (where applicable), the Standard Contractual Clauses govern.

Contact

Questions about this DPA may be directed to legal@lightningcommerce.ai.

Schedule 1 — Details of Processing

Subject Matter: Our provision of the Services to Customer under the Agreement.

Duration: For the term of the Agreement, plus the period described in Section 10 above.

Nature and Purpose of Processing: Hosting, storage, and processing of Customer Personal Data as necessary to provide, maintain, and support the Services, including collecting and displaying product/service reviews (Lightning Reviews), synchronizing order, product, and customer data with Customer’s e-commerce and other connected platforms (Lightning Connector), and processing returns and refund requests (Lightning Returns).

Categories of Data Subjects: Customer’s end customers (e.g., purchasers who are asked to leave a review, whose orders are processed through Lightning Connector, or who submit a return through Lightning Returns), and Authorized Users of Customer’s account.

Categories of Customer Personal Data: Name, email address, phone number, mailing address, order and purchase history, product review content and ratings, return/refund details, IP address, and device or usage identifiers, as configured by Customer through its use of the Services. Customer should not submit any special categories of personal data or other Prohibited Data described in our Acceptable Use Policy.

Frequency of Transfer: Continuous, for as long as Customer uses the Services.

Schedule 2 — Security Measures

We maintain an information security management system certified to ISO/IEC 27001, and will provide a copy of our current certificate upon Customer’s reasonable request. Our program includes the following categories of technical and organizational measures, as applicable to the Services:

  • Access Controls: Role-based access on a need-to-know and least-privilege basis; unique user credentials; multi-factor authentication for administrative access; timely revocation of access upon personnel departure.

  • Encryption: Encryption of Customer Personal Data in transit using industry-standard protocols (e.g., TLS) and at rest using industry-standard encryption algorithms.

  • Network and System Security: Firewalls, network segmentation, and monitoring for unauthorized access; regular vulnerability scanning and patch management.

  • Physical Security: Data hosted with reputable cloud infrastructure providers that maintain physical and environmental safeguards for their data centers.

  • Personnel Security: Confidentiality obligations for personnel with access to Customer Personal Data; periodic security awareness training.

  • Change and Incident Management: Documented change management procedures; a security incident response plan, including procedures for detection, containment, and notification consistent with Section 8.

  • Business Continuity: Regular data backups and a business continuity/disaster recovery plan designed to restore availability of the Services in a timely manner following an incident.

  • Audit Logging: Logging and monitoring of access to production systems processing Customer Personal Data.