Skip to content
Legal

Data Processing Addendum

When NitroSearch indexes your catalogue, you are the data controller and we are your processor. This addendum summarises how we handle that role. It forms part of our Terms.

Last updated 2026-07-20

Pre-launch draft. This is a plain-English summary for review; the binding DPA (with completed company details and Annexes) will be finalised with legal counsel before launch.

1. Roles

For personal data contained in your store’s catalogue and search traffic, you are the controller and [TO BE CONFIRMED: registered company name] is the processor, acting only on your documented instructions (which include your use of the service as configured).

2. Nature and purpose of processing

We process your catalogue data to provide search: indexing it into our search engine, keeping it in sync, and returning results to your shoppers. In practice this data is product information (titles, prices, images, stock, taxonomies), which is typically not personal data — but where it is, this addendum governs it.

3. Data residency

All processing takes place on EU-based infrastructure. We do not move your data outside the EU except where a listed subprocessor operates under appropriate safeguards (see §6).

4. Security

We apply appropriate technical and organisational measures, including encryption in transit, scoped and rotated access credentials, isolation between tenants, least-privilege access, and audit logging of privileged actions. Search keys are scoped so one store can never read another’s data.

5. Sub-processing

You authorise us to engage the subprocessors listed on our Subprocessors page. We impose data-protection terms on each that are no less protective than this addendum, and we’ll give notice of new subprocessors so you can object.

6. International transfers

Where a subprocessor is established outside the EU/UK, transfers are covered by an adequacy decision or Standard Contractual Clauses (and the UK addendum where applicable).

7. Assistance, breach notification & deletion

We assist you with data-subject requests and with your own security and DPIA obligations. We notify you without undue delay on becoming aware of a personal-data breach affecting your data. On termination we delete or return your data and reduce the search index to zero, subject to any legal retention.

8. Audits

We make available the information necessary to demonstrate compliance and will accommodate reasonable audits, subject to confidentiality and security constraints.

Questions about this addendum: [email protected].