v2026.2.0
Data Processing Addendum
eListSync · Last updated August 17, 2026 · v2026.2.0
Last updated: August 17, 2026
This Data Processing Addendum ("DPA") forms part of the eListSync Terms of Service (or other written agreement) between the customer identified in the account ("Customer") and eListSync ("Processor") for the Service at elistsync.com. It applies when Processor processes Personal Data on Customer's behalf in connection with product ingest, catalog storage, destination publishing, and inventory sync.
If there is a conflict between this DPA and the Terms on data-protection matters, this DPA controls. Capitalized terms not defined here have the meaning in the Terms or in applicable data-protection law (including GDPR, UK GDPR, and comparable laws).
1. Roles
Customer is the Controller (or a Processor acting for a third-party controller). eListSync is the Processor for Customer Personal Data processed to deliver the Service.
Customer Personal Data typically includes product and listing metadata, variant and inventory fields, destination account identifiers, and technical logs tied to Customer's workspace. It may include personal data of Customer's staff (operator emails) and, if Customer puts it in listings, data relating to Customer's end buyers. eListSync does not decide the purposes of marketplace selling; Customer does.
eListSync remains an independent controller for website analytics of visitors, its own employee data, and support tickets as described in the Privacy Policy.
2. Customer instructions
Processor will process Customer Personal Data only:
- To provide the Service (ingest, normalize, queue, publish to destinations Customer connects, reconcile inventory, and show sync logs)
- As documented in the Terms, this DPA, and the product documentation
- As required by law, in which case Processor will notify Customer unless legally prohibited
Customer instructs Processor to transmit listing and inventory payloads to Shopify, Amazon SP-API, TikTok Shop, WooCommerce, Medusa or compatible custom REST, Walmart, and/or eBay solely to the extent Customer has connected those destinations. Customer is responsible for the lawfulness of those instructions, including marketplace terms and notices to data subjects.
3. Details of processing
Subject matter: multi-channel listing and inventory synchronization software.
Duration: the term of the account plus the retention periods in the Privacy Policy and Section 8.
Nature: collection, storage, structuring, hosting, transmission to Customer-selected APIs, logging, and deletion.
Purpose: perform the Service on Customer's documented instructions.
Types of personal data: account identifiers of operators; IP and user-agent on API calls; product fields that may contain names or images of people if Customer supplies them; destination seller IDs.
Data subjects: Customer's staff and contractors; optionally persons depicted in catalog media; not typically Customer's retail buyers unless Customer stores buyer PII in the catalog (which we discourage).
4. Confidentiality and personnel
Processor ensures persons authorized to process Customer Personal Data are bound by confidentiality and receive security awareness appropriate to their role. Access to production secrets and databases is limited to personnel who need it to operate or debug the Service.
5. Security
Processor implements technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS)
- Encryption of destination credentials at rest
- Access control, unique credentials, and session cookies for the operator app
- Tenant isolation, including row-level security in the operator data store where deployed
- Queue isolation and circuit breakers so a failing destination does not dump unconstrained traffic
- Immutable hashing (SHA-256) of legal-acceptance records when that feature is enabled
- Logging and monitoring of administrative access
Customer is responsible for the strength of its passwords, the scope of marketplace tokens it grants, and for not uploading unlawful content.
6. Subprocessors
Customer authorizes Processor to use subprocessors for compute, object storage, managed Postgres, Redis-compatible queues, email delivery, and error monitoring. Processor will impose data-protection terms no less protective than this DPA.
A current description of subprocessors is available on request from support@elistsync.com and may be listed in workspace settings when the operator app is live. Processor will give Customer notice of material subprocessor changes and a reasonable objection window for Enterprise customers as set out in an order form. If Customer reasonably objects and the parties cannot agree, Customer may terminate the affected Service.
Marketplaces Customer connects are not Processor's subprocessors; they receive data because Customer instructed a publish.
7. International transfers
Processor may transfer Customer Personal Data to regions where it or its subprocessors operate. Where GDPR Chapter V applies, Processor will use an approved transfer mechanism (for example EU Standard Contractual Clauses) with the relevant subprocessor, or rely on an adequacy decision. Customer instructs Processor to send data to marketplaces in the regions those APIs require.
8. Assistance, notices, and deletion
Taking into account the nature of processing, Processor will assist Customer with data-subject requests, DPIAs, and consultations with authorities, at Customer's cost if the assistance is excessive relative to the plan.
Processor will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with information reasonably available at the time.
On termination or Customer's written request, Processor will delete or return Customer Personal Data from production systems within 30 days, except copies in encrypted backups until rotation, and except data Processor must retain as independent controller (billing, security, hashed consent) or by law.
9. Audits
Upon reasonable written notice, not more than once per 12 months (unless a regulator or confirmed breach requires more), Processor will provide Customer with available security summaries or third-party reports. On-site audits, if required by mandatory law or an Enterprise agreement, are scheduled to minimize disruption and may be billed at Processor's standard professional rates.
10. Liability
Liability under this DPA is subject to the limitations in the Terms, except that nothing in this DPA limits liability that cannot be limited under data-protection law.
11. Governing law
This DPA follows the governing law and venue of the Terms unless mandatory data-protection law requires otherwise.
12. Contact
Privacy and DPA requests: support@elistsync.com
Phone / WhatsApp: +92 302 6210978