ECOSYS360 LEGAL
Ecosys360 Ecosys360 — Retail & Ops Suite
Sign up

Documents

  • Overview
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Data Processing Addendum

Legal · v2026-07-29

Data Processing Addendum

Processor terms when you store customer or staff data in Ecosys360.

Last updated 29 July 2026

1. Purpose and incorporation

This Data Processing Addendum (“DPA”) forms part of the agreement between your organisation (“Customer”, “you”) and Ecosys360 (“Processor”, “we”, “us”) for use of Ecosys360 Retail & Ops Suite (the “Service”).

It applies when we process personal data on your behalf in connection with the Service. It is intended to meet the requirements of Article 28 of the EU GDPR and corresponding UK GDPR obligations, and similar processor requirements under other applicable laws where relevant.

If there is a conflict between this DPA and other terms regarding personal data processing, this DPA prevails for that subject.

2. Roles and definitions

For personal data that Customer uploads into or generates within Ecosys360 workspaces — for example customer, employee, supplier, shopper, or other operational records — Customer is the controller and Ecosys360 is the processor, unless otherwise agreed in writing.

For Ecosys360 platform account administration data (for example login email, membership metadata, billing contacts for the platform relationship), Ecosys360 typically acts as an independent controller as described in the Privacy Policy. That controller processing is outside the processor obligations in this DPA except where the same record is also Customer personal data.

“Personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in the GDPR (or UK GDPR, as applicable). “Customer Personal Data” means personal data processed by us as processor on behalf of Customer in the Service.

3. Subject matter, duration, nature, and purpose

Subject matter: hosting and processing of Customer Personal Data in the multi-tenant Service modules Customer enables (such as POS, catalog, HR, payroll, ecommerce, logistics, and related features).

Duration: for the term of Customer’s use of the Service and any post-termination retention period required to wind down, delete, or return data as described herein.

Nature and purpose: storage, retrieval, transmission, display, backup, security logging, and related processing necessary to provide, secure, support, and maintain the Service according to Customer’s configuration and instructions.

Types of data subjects may include Customer’s staff users, retail or wholesale customers, suppliers, ecommerce end customers, and other individuals whose data Customer chooses to store.

Types of personal data depend on Customer’s use and may include identity and contact details, transaction and purchase history, employment-related fields, location or branch associations, and files Customer uploads. Customer must not instruct us to process data it is not entitled to process.

4. Customer instructions

We will process Customer Personal Data only: (a) to provide the Service; (b) on Customer’s documented instructions (including configuration, API calls, and admin actions within the product); and (c) as required by applicable law (in which case we will inform Customer of that legal requirement before processing, unless the law prohibits such notice).

Customer is responsible for the lawfulness of its instructions, for providing required notices to data subjects, and for obtaining any consents or other lawful bases needed under GDPR Art. 6 (and Art. 9 where special-category data is involved).

If we reasonably believe an instruction infringes GDPR or UK GDPR, we will inform Customer without undue delay.

5. Confidentiality

We ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Access to Customer workspaces by our personnel is limited to what is needed for support, security, operations, or as otherwise instructed by Customer (for example, authorised impersonation or troubleshooting where offered and logged).

6. Security measures

Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as risks to individuals, we implement appropriate technical and organisational measures to protect Customer Personal Data, including measures aimed at:

  • Encryption of data in transit (HTTPS/TLS)
  • Access control, authentication, and role-based permissions within the application
  • Tenant isolation in application logic so one customer’s workspace data is not exposed to another
  • Password hashing for platform credentials and protection of session credentials
  • Logging and monitoring proportionate to detecting abuse and security incidents
  • Personnel and process controls appropriate to a hosted SaaS environment

7. Sub-processors

Customer authorises us to engage infrastructure and service sub-processors necessary to host, store, deliver email, process platform payments, and otherwise operate Ecosys360.

We will impose data-protection obligations on sub-processors that are no less protective than those in this DPA, and we remain responsible to Customer for the sub-processor’s performance of those obligations as required by GDPR Art. 28.

On request to app.flakescapital@gmail.com, we will provide information about the categories of sub-processors then in use. We will give Customer reasonable notice of intended additions or replacements of material sub-processors where practicable, and Customer may object on reasonable data-protection grounds. If we cannot accommodate a reasonable objection, Customer may terminate the affected Service as its sole remedy.

8. Assistance with data-subject rights

Taking into account the nature of the processing, we will assist Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of Customer’s obligation to respond to requests to exercise data-subject rights under GDPR Chapter III.

If we receive a request directly from a data subject relating to Customer Personal Data, we will, where feasible, direct the individual to Customer and/or notify Customer, unless prohibited by law. Customer remains responsible for responding to the individual.

9. DPIAs and prior consultation

Taking into account the nature of processing and information available to us, we will assist Customer with data protection impact assessments and prior consultations with supervisory authorities that relate to processing of Customer Personal Data in the Service, upon reasonable request.

10. Personal data breaches

We will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

Notification will include, where available: a description of the nature of the breach; categories and approximate numbers of data subjects and records concerned; likely consequences; and measures taken or proposed to address the breach and mitigate adverse effects.

We will cooperate reasonably with Customer’s investigation and any required notifications to authorities or individuals. Our notification is not an admission of fault or liability.

11. Return and deletion

During the term, Customer may export Customer Content using available product features (for example reports or exports where offered).

Upon termination or expiry of the workspace/Service, we will delete or return Customer Personal Data in accordance with product capabilities and the Privacy Policy, within a commercially reasonable period, except where retention is required by applicable law or needed for secure backup rotation, dispute resolution, or fraud prevention (in which case data remains subject to confidentiality and is isolated from active processing where practicable).

Customer should export any data it needs before termination.

12. Audits and information

Upon reasonable written request, and no more than once per year unless a breach or material suspicion of non-compliance justifies more frequent review, we will make available information necessary to demonstrate compliance with this DPA, which may include security summaries or questionnaire responses.

On-site or intrusive audits are subject to reasonable notice, confidentiality, scope limits that protect other customers’ data, and reimbursement of our reasonable costs unless a material breach of this DPA is confirmed. We may satisfy audit rights through third-party certifications or reports where available.

13. International transfers

Where Customer Personal Data is transferred internationally, the parties will ensure a valid transfer mechanism under GDPR Chapter V (or UK equivalent) applies — for example an adequacy decision or Standard Contractual Clauses (with UK addendum where required).

Customer authorises us to enter into SCCs with sub-processors on Customer’s behalf as needed to lawfully transfer Customer Personal Data for the Service.

14. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent liability cannot be limited under applicable data-protection law.

15. Order of precedence and changes

We may update this DPA to reflect legal or operational changes. Material updates will follow the same notice practices as changes to the Terms. Continued use of the Service after the effective date constitutes acceptance where permitted by law.

Last updated: 29 July 2026.

16. Contact

Privacy and DPA contact: app.flakescapital@gmail.com.

General support: app.flakescapital@gmail.com.