Last updated: May 1, 2026
Effective date: May 1, 2026
This Data Processing Agreement ("DPA") forms part of the BidWise Terms of Service or other written agreement between XeroBit Inc., doing business as BidWise ("BidWise," "Processor," "Service Provider," "we," "us," or "our"), and the merchant or entity using BidWise ("Merchant," "Controller," "Business," "you," or "your").
This DPA applies when BidWise processes personal data or personal information on behalf of Merchant through the BidWise Shopify app. It is intended to support EU/UK GDPR, CCPA/CPRA, and similar privacy-law requirements.
"Applicable Data Protection Laws" means privacy, data protection, and data security laws that apply to the processing of personal data under this DPA, which may include the GDPR, UK GDPR, Swiss data protection law, CCPA, and other similar laws.
"Controller," "processor," "data subject," "personal data," "process," "processing," and "supervisory authority" have the meanings given in GDPR or similar Applicable Data Protection Laws.
"Business," "service provider," "contractor," "consumer," "personal information," "sell," and "share" have the meanings given in the CCPA, as amended.
"Merchant Data" means personal data or personal information that Merchant provides to BidWise or that BidWise processes on Merchant's behalf through the Service.
"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Merchant Data processed by BidWise.
"Subprocessor" means a third party engaged by BidWise to process Merchant Data on behalf of Merchant.
For Merchant Data processed through the BidWise app on behalf of Merchant, Merchant is the controller or business, and BidWise is the processor or service provider.
For personal data BidWise processes for its own business purposes, such as account administration, billing administration, support, website analytics, security, and legal compliance, BidWise may act as an independent controller or business. That processing is governed by the BidWise Privacy Policy, not this DPA.
BidWise will process Merchant Data only:
Merchant instructs BidWise to process Merchant Data for the purposes described in Schedule 1.
If BidWise believes an instruction violates Applicable Data Protection Laws, BidWise will notify Merchant unless prohibited by law.
Merchant is responsible for:
BidWise will ensure that personnel authorized to process Merchant Data are subject to confidentiality obligations and receive access only as needed to provide and support the Service.
BidWise will implement and maintain appropriate technical and organizational measures designed to protect Merchant Data against unauthorized or unlawful processing and accidental loss, destruction, alteration, disclosure, or access.
Current measures include, as applicable:
BidWise may update security measures over time, provided the updates do not materially reduce overall protection.
Merchant authorizes BidWise to use Subprocessors to provide the Service. BidWise will impose data protection obligations on Subprocessors that are materially consistent with this DPA.
Current Subprocessor categories are listed in Schedule 3. BidWise will provide notice of material changes to Subprocessors by updating its public Subprocessor list, in-app notice, email, or another reasonable method.
Merchant may object to a new Subprocessor on reasonable data protection grounds by contacting BidWise within 30 days after notice. If the parties cannot resolve the objection, Merchant may stop using the affected Service and terminate according to the Terms.
Taking into account the nature of processing, BidWise will reasonably assist Merchant in responding to data subject or consumer requests related to Merchant Data, including requests to access, delete, correct, restrict, object, or receive a portable copy, to the extent required by Applicable Data Protection Laws.
BidWise may provide self-service tools, exports, deletion workflows, or support assistance. If a buyer contacts BidWise directly about data processed for a merchant, BidWise may direct the buyer to the merchant or notify the merchant, unless legally required to act directly.
Where applicable, BidWise will support Shopify privacy/redaction request workflows related to customer data requests, customer redaction requests, and shop redaction requests. This DPA does not itself confirm that any specific webhook has passed technical review; it allocates responsibilities for processing and responding to such requests.
BidWise will notify Merchant without undue delay after confirming a Security Incident involving Merchant Data. Notice may include, to the extent known and legally permitted:
Merchant is responsible for determining whether notification to individuals, regulators, Shopify, or others is required, unless Applicable Data Protection Laws require BidWise to notify directly.
Upon reasonable written request, BidWise will provide information necessary to demonstrate compliance with this DPA, such as security summaries, Subprocessor information, or relevant documentation.
If required by Applicable Data Protection Laws, Merchant may request an audit no more than once per year, unless a Security Incident or legal requirement justifies more frequent review. Audits must be conducted with reasonable notice, during normal business hours, in a way that does not disrupt BidWise operations or compromise other customers' data or security. The parties will agree on scope, timing, confidentiality, and costs before an audit begins.
Upon termination of the Service or upon Merchant's valid request, BidWise will delete or return Merchant Data as required by Applicable Data Protection Laws, the Terms, and the Privacy Policy, unless retention is required or permitted by law.
Deletion may be subject to backup retention, legal hold, fraud prevention, dispute resolution, security investigation, accounting, or compliance obligations. Data retained for these purposes will remain protected and will not be processed for other purposes.
BidWise and its Subprocessors may process Merchant Data in countries other than the country where Merchant or data subjects are located.
Where Applicable Data Protection Laws require a transfer mechanism, the parties will use appropriate safeguards, which may include Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful mechanisms. If Standard Contractual Clauses are required, they are incorporated by reference to the extent applicable and completed as follows unless a separately signed version says otherwise:
To the extent the CCPA applies, BidWise will act as a service provider or contractor for Merchant Personal Information. BidWise will not:
Merchant makes Merchant Personal Information available to BidWise only for the limited and specified purposes described in this DPA. BidWise certifies that it understands and will comply with the restrictions in this section.
BidWise may process deidentified or aggregated data for analytics, benchmarking, security, service improvement, and reporting, provided the data cannot reasonably identify Merchant, buyers, or individuals. BidWise will not attempt to reidentify deidentified data except as permitted by law to test or maintain deidentification.
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms or other agreement between the parties, unless prohibited by Applicable Data Protection Laws.
If there is a conflict between this DPA and the Terms regarding processing of Merchant Data, this DPA controls for that conflict. If Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control for that conflict.
This DPA remains in effect while BidWise processes Merchant Data on behalf of Merchant and for as long as required by Applicable Data Protection Laws.
Privacy contact: contact@bidwiseapp.com Legal entity: XeroBit Inc. (doing business as BidWise)
BidWise processes Merchant Data to provide a Shopify app that enables private buyer offers, merchant review, counter offers, accepted-offer Draft Orders, transactional email notifications, analytics, operational support, security, and compliance workflows.
For the term of Merchant's use of BidWise and any post-termination retention period described in the Privacy Policy, Terms, this DPA, or applicable law.
BidWise is not designed to collect sensitive personal data. Merchant should not configure BidWise to collect sensitive personal data or encourage buyers to submit sensitive data in offer messages. If sensitive data is incidentally submitted, BidWise will process it only as necessary to provide the Service, secure the Service, comply with law, or delete it.
Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission, disclosure to Subprocessors, alignment, restriction, erasure, anonymization, aggregation, and destruction.
BidWise maintains security measures appropriate to the nature of the Service, including:
Current Subprocessors and service-provider categories include:
BidWise does not use website analytics or a third-party customer support/helpdesk provider.