About these terms
These data processing terms form part of the terms of service between Wehda LLC (“we”, “us”) and the business that uses WEĦDA (“you”), and “the terms” means both together. They are the contract that privacy laws, such as the California Consumer Privacy Act (CCPA) and similar US state laws, the GDPR and the UK GDPR, require between you and us for personal information about your buyers that WEĦDA receives from you or for you (“buyers’ information”). Where the rest of the terms conflict with them, these data processing terms prevail, but the terms’ Limitation of liability applies to them.
You are the controller of buyers’ information (under the CCPA, the business), and we are your processor (under the CCPA, your service provider). You tell your buyers, in your own privacy policy, that you use WEĦDA and what it receives about their orders, as our privacy notice describes.
Where the GDPR or the UK GDPR applies, you, the other stores involved and we are joint controllers of the part of WEĦDA that works across stores: checking a coupon from one store’s gift when it is used at another, crediting the store that gave it, and our accounting of exposure between stores. For that part, you, the other stores involved and we agree that each store informs its own buyers about it and handles their requests with its platform’s privacy tools, and that we act on those requests, keep that part secure and deal with any breach in it, telling the stores involved without undue delay.
Your instructions
You give us buyers’ information, and instruct us to process it, only to provide WEĦDA to you: to decide and show gifts; to create, change and end coupons and wallet passes; to check coupons, credit sales between stores and show stores the results; to keep our accounting of exposure between stores; to carry out privacy requests; and to keep WEĦDA secure and prevent fraud. These data processing terms, your settings and your privacy requests are your instructions. You confirm that you may give us buyers’ information for these purposes, and you pass us, through your platform’s privacy tools, your buyers’ privacy requests that we must act on, with what we need to act on them.
Our duties
We:
- process buyers’ information only on your instructions;
- don’t sell or share it, as those laws use those words, and don’t keep, use or disclose it for any other purpose or outside our direct business relationship with you, or combine it with other personal information, except as those laws allow;
- comply with those laws as they apply to us, and give it the same level of protection they require of you;
- keep it confidential, bind the people who process it to confidentiality, and protect it with reasonable security measures appropriate to the risk. We are responsible for the security of WEĦDA, and you for the security of your store, its platform and host, and your accounts;
- act on your buyers’ privacy requests, including by erasing the information they name;
- tell you if we can no longer meet these duties, and let you, on notice, take reasonable and appropriate steps to stop and remediate unauthorised use, including disconnecting your store;
- allow, and cooperate with, reasonable and appropriate steps you take to check that we meet these data processing terms, including audits and inspections by you or an auditor you choose, at your cost, and give you the information you need for them;
- let other companies process it for us only under written contracts with the same duties. You agree to those named below. We’ll email you at least 30 days before we add or replace one. If you object, we won’t use it for your buyers’ information, and either of us may end the terms; and
- when your store leaves, delete it or make it anonymous, as you direct by accepting the terms and as our privacy notice describes, except our accounting of exposure between stores and what a law requires us to keep.
Stores in the European Union and the United Kingdom
If your store is established in the European Union, the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 form part of the terms for buyers’ information you send us: Module Two (controller to processor) for what we process for you, and Module One (controller to controller) for the part shared between stores. You are the data exporter, and we are the data importer. Clause 7 and the option in clause 11(a) don’t apply; under clause 9(a), option 2 applies, with the 30 days’ notice above; under clause 13, the supervisory authority is the one responsible for your store; and under clauses 17 and 18, the law and courts of the EU country where your store is established apply. The details of the processing below complete Annex I. The measures in our privacy notice’s section Security, and your platform’s privacy tools, through which we help you answer your buyers’ requests, complete Annex II. Your acceptance of the terms and our admission of your store count as each of us signing those clauses, including Annex I.
If your store is established in the United Kingdom, those clauses apply with the same choices and details, together with the International Data Transfer Addendum to them issued by the UK Information Commissioner, except where the Addendum sets its own terms. The Addendum’s Part 2 is Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses. The terms complete its tables from when you accept them, and under its Table 4, we, as importer, may end it.
If your store is established in the European Union or the United Kingdom, what these data processing terms take from our privacy notice is the notice as it stood when you accepted the terms, and a change to Annex I or II applies to your store only once you accept it in writing, except adding or replacing a company under clause 9(a).
If WEĦDA shows you information about the buyers of a store established in the European Union or the United Kingdom, protect it as Module One of those clauses requires of us. If anything in the terms, including Limitation of liability and the indemnity, conflicts with those clauses or that Addendum, they prevail.
Details of the processing
- Parties: you, at the address and email address you gave us when you accepted the terms, as controller; and Wehda LLC, a Wyoming limited liability company, 30 N Gould St, STE R, Sheridan, WY 82801, USA, [email protected], as processor and, for the part shared between stores, joint controller.
- Subject matter and duration: WEĦDA for your store, while your store uses it and afterwards only as these data processing terms allow.
- People: buyers who order from your store or use a WEĦDA coupon at it.
- Information: what our privacy notice lists about them and their orders, gifts, coupons and wallet passes. Shopify’s order notifications also carry what the buyer bought and can carry their contact details, which WEĦDA doesn’t keep. No sensitive information is meant to be sent.
- Processing: automated collection, storage, use, disclosure, erasure and anonymisation, continuously, for the purposes above. Under the Standard Contractual Clauses, Module One covers the part shared between stores, and Module Two the rest.
- How long: as our privacy notice’s section How long we keep information describes.
- Companies that process it for us: Google Cloud, which runs our servers and database, and Cloudflare, which carries all traffic to them.
