Data Processing Terms
Data Processing Terms
Effective September 15, 2026. Document version: CB-DPA-2026-09-15.
This agreement schedule applies to a merchant engagement and is completed before accessing protected shopper data. It identifies the merchant/controller, Branch & Button as processor for the agreed processing, contact points and the controlling service agreement. Branch & Button remains responsible for its separate controller activities such as its own billing and business contacts.
The schedule specifies subject matter, duration, purpose, processing activities, data-subject categories and exact personal-data categories. It excludes payment-card data, credentials and sensitive categories unless expressly required, assessed and separately authorized.
Branch & Button processes covered personal data only on documented instructions, including transfer instructions, except where law requires otherwise; we inform the merchant of a legal requirement where permitted. Personnel with access are subject to confidentiality obligations. We apply appropriate technical and organizational safeguards proportionate to risk; the engagement includes a truthful security schedule rather than unverified certifications or controls.
Subprocessors require the agreed authorization and written obligations consistent with these terms. We maintain an accurate schedule, give notice of material additions under an agreed notice/objection process, and remain responsible for required subprocessor obligations. AI providers are not exempt from these requirements. We do not send identifiable merchant evidence to an unapproved model service.
We notify the merchant without undue delay after becoming aware of a personal-data breach affecting the covered processing; provide available information, updates and reasonable cooperation. We do not invent a guaranteed hour-based SLA without an operational response process. We assist as required with data-subject requests, security assessments, impact assessments and lawful regulator inquiries, taking into account the nature of processing and information available.
At the merchant's choice after services end, we return or delete covered data, subject to legal retention duties; the engagement specifies the operational deletion and backup schedule. We provide information reasonably necessary to demonstrate compliance and allow the agreed audit process. We flag instructions believed to infringe applicable data-protection law.
Where a restricted international transfer requires a legal mechanism, the engagement attaches the correct current mechanism and completed annexes for the actual parties and locations. These terms do not themselves implement EU Standard Contractual Clauses or a UK transfer addendum. The applicable instrument is selected and completed for the engagement.