Skip to content
Legal

Data Processing Addendum

When NitroSearch indexes your catalogue, you are the data controller and we are your processor. This addendum summarises how we handle that role. It forms part of our Terms.

Last updated 2026-07-31

1. Roles

For personal data contained in your store’s catalogue and search traffic, you are the controller and NitroSearch is the processor, acting only on your documented instructions (which include your use of the service as configured).

2. Nature and purpose of processing

We process the store content you choose to index — your product catalogue, and optionally the titles and short summaries of your pages and blog posts — to provide search: indexing it into our search engine, keeping it in sync, and returning results to your shoppers. Indexing pages and posts is off unless you enable it, full page and post bodies are never copied, and content that is private, password-protected, unpublished or marked noindex is excluded. In practice this data is product information (titles, prices, images, stock, taxonomies), which is typically not personal data — but where it is, this addendum governs it.

We also process your store’s search traffic to provide aggregate search analytics on your behalf. The data categories are search queries and interaction events (result views, clicks, add-to-carts); events carry no shopper identifiers — no cookies, no IP addresses, no fingerprints, only a random short-lived token that links a search to its clicks within a single page visit and is deleted with the raw events. Retention: raw events are deleted after 90 days (purged within a further week); aggregate rollups are kept for up to 24 months, and everything is deleted with the rest of your data on termination (§7). Separately, we use aggregated, store-unattributable search statistics to improve ranking quality across the service — for that limited purpose we act as controller, not as your processor. As the controller for your storefront, you should reflect search-analytics collection in your own privacy notice.

3. Data residency

All processing takes place on infrastructure in the United Kingdom and/or European Union. Where a listed subprocessor operates outside the UK/EU, it does so under appropriate safeguards (see §6).

4. Security

We apply appropriate technical and organisational measures, including encryption in transit, scoped and rotated access credentials, isolation between tenants, least-privilege access, and audit logging of privileged actions. Search keys are scoped so one store can never read another’s data.

5. Sub-processing

You authorise us to engage the subprocessors listed on our Subprocessors page. We impose data-protection terms on each that are no less protective than this addendum, and we’ll give notice of new subprocessors so you can object.

6. International transfers

Where a subprocessor is established outside the EU/UK, transfers are covered by an adequacy decision or Standard Contractual Clauses (and the UK addendum where applicable).

7. Assistance, breach notification & deletion

We assist you with data-subject requests and with your own security and DPIA obligations. We notify you without undue delay on becoming aware of a personal-data breach affecting your data. On termination we delete or return your data and reduce the search index to zero, subject to any legal retention. Residual copies may persist in our encrypted operational backups for up to 30 days after deletion and are then destroyed on rotation; backup copies are used only for disaster recovery and are never used to reinstate deleted data.

8. Audits

We make available the information necessary to demonstrate compliance and will accommodate reasonable audits, subject to confidentiality and security constraints.

Questions about this addendum: [email protected].