Data Processing Agreement
SellerSlice LLC — Mission Control
| Document version | v1.0 |
| Effective date | June 1, 2026 |
| Last updated | June 1, 2026 |
| Incorporation | Forms part of the Terms of Service and is accepted (clickwrap) by every business customer at signup |
| Companion documents | Privacy Policy (v2.1) · Sub-processors · Data Retention Policy · Security & Trust · Legal Hub |
📌 TL;DR — The plain-language version
This summary is not the agreement — the numbered clauses are.
- What this is. When SellerSlice processes personal data on your behalf (your client-portal content and the Amazon data you authorize), you are the controller and we are the processor. This DPA sets the rules for that, as Article 28 GDPR and equivalent laws require.
- We follow your instructions. We process that data only to provide the Service and only as you've instructed.
- We keep it secure and confidential, use vetted sub-processors (listed at /subprocessors) and tell you before adding new ones, help you answer data-subject requests and breaches, and delete or return the data when our relationship ends.
- Your Amazon data gets the stricter treatment in your Privacy Policy §12 and the Terms §8 — deleted on disconnect, never pooled across clients.
- Cross-border transfers are covered by the Standard Contractual Clauses, the UK Addendum, and the Data Privacy Framework.
Table of Contents
- Parties and roles
- Definitions
- Scope and instructions
- Confidentiality
- Security of processing
- Sub-processors
- Assistance with data-subject requests
- Breach notification and DPIA assistance
- Deletion and return of data
- Audits and demonstrating compliance
- International transfers
- Jurisdiction-specific terms
- Liability, term, and order of precedence
- Appendix 1 — Details of processing
- Appendix 2 — Technical and organizational measures
- Appendix 3 — Approved sub-processors and transfer mechanisms
1. Parties and roles
This Data Processing Agreement ("DPA") is between SellerSlice LLC ("SellerSlice," "Processor") and the business customer that accepts the Terms of Service ("Customer," "Controller"). It is incorporated into and forms part of the Terms.
Role mapping:
- For Customer Data that Customer uploads, generates, or authorizes us to access on its behalf (client-portal content; Amazon Information accessed under Customer's OAuth authorization), Customer is the Controller and SellerSlice is the Processor.
- For SellerSlice's own processing — account administration, billing, security, audit logging, and SellerSlice's marketing — SellerSlice is an independent controller, governed by the Privacy Policy, not this DPA.
- Amazon is an independent controller of the data it holds and exposes through its APIs; it is not SellerSlice's sub-processor.
This DPA prevails over any conflicting term in the Terms with respect to the processing of Customer Personal Data.
2. Definitions
Capitalized terms not defined here have the meaning given in the Terms or in applicable Data Protection Law (GDPR (EU) 2016/679; UK GDPR and the Data Protection Act 2018; the CCPA/CPRA and other US state privacy laws; Canada's PIPEDA and Québec Law 25; Mexico's LFPDPPP; and Australia's Privacy Act 1988). "Customer Personal Data" means personal data within Customer Data that SellerSlice processes on Customer's behalf. "Sub-processor" means a third party engaged by SellerSlice to process Customer Personal Data. "Personal Data Breach," "Controller," "Processor," "Data Subject," and "Processing" have the meanings in Data Protection Law.
3. Scope and instructions
SellerSlice will process Customer Personal Data only:
- to provide, secure, support, and maintain the Service under the Terms;
- in accordance with Customer's documented instructions (the Terms, this DPA, Customer's configuration and use of the Service, and any further written instructions Customer gives); and
- as required by law, in which case SellerSlice will inform Customer of that legal requirement before processing unless the law prohibits it.
SellerSlice will tell Customer if, in its opinion, an instruction infringes Data Protection Law. The subject matter, duration, nature, purpose, data types, and data-subject categories are set out in Appendix 1.
4. Confidentiality
SellerSlice ensures that personnel authorized to process Customer Personal Data are bound by a duty of confidentiality, are trained appropriately, and access Customer Personal Data only on a job-duty need-to-know basis under role-based controls, with access reviewed periodically and revoked promptly on role change or departure.
5. Security of processing
Taking into account the state of the art and the risks, SellerSlice implements appropriate technical and organizational measures to protect Customer Personal Data, as described in Appendix 2 (and summarized at Security & Trust). SellerSlice may update these measures provided the level of protection is not materially reduced.
6. Sub-processors
Customer provides general authorization for SellerSlice to engage Sub-processors to process Customer Personal Data. The current Sub-processors are listed at /subprocessors and in Appendix 3. SellerSlice:
- imposes data-protection obligations on each Sub-processor by written contract that are no less protective than this DPA (including, where relevant, the appropriate Standard Contractual Clauses);
- remains responsible to Customer for each Sub-processor's performance; and
- will give Customer at least 30 days' advance notice (via the Sub-processors page subscribe mechanism and/or email) before adding or replacing a Sub-processor, during which Customer may object on reasonable data-protection grounds. If the parties cannot resolve a good-faith objection, Customer may terminate the affected part of the Service as its exclusive remedy.
7. Assistance with data-subject requests
SellerSlice will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures (insofar as possible) to respond to requests by Data Subjects to exercise their rights under Data Protection Law. If SellerSlice receives such a request directly relating to Customer's data, it will, unless legally required to act, advise the Data Subject to contact Customer and will not respond except on Customer's instruction. SellerSlice's Data Request form and privacy@sellerslice.com support this assistance.
8. Breach notification and DPIA assistance
- Breach. SellerSlice will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the information Customer reasonably needs to meet its own notification obligations. (SellerSlice's distinct regulatory clocks — including the 24-hour Amazon channel — are described in the Privacy Policy §13.)
- DPIAs and prior consultation. SellerSlice will provide reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities (GDPR Arts. 35–36), taking into account the information available to it.
9. Deletion and return of data
On termination or expiry of the Service, SellerSlice will, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless law requires storage. Specifically: a 30-day soft-delete grace period applies to the account; Amazon Information is deleted (not anonymized) within 30 days of disconnection or termination per Privacy Policy §12.4; and records SellerSlice is legally required to retain (e.g., tax, security/audit logs ≥12 months, consent proof) are retained only for the required period and remain protected and access-restricted. See the Data Retention Policy.
10. Audits and demonstrating compliance
SellerSlice will make available information reasonably necessary to demonstrate compliance with this DPA. To minimize disruption and protect the confidentiality and security of all customers in a multi-tenant environment, SellerSlice may satisfy audit requests by providing third-party certifications and reports (e.g., SOC 2 reports and its hosting providers' compliance reports) where available. On-site or independent audits may be conducted no more than once per year, on reasonable prior notice, during business hours, subject to confidentiality, and at Customer's expense, where required by Data Protection Law and not satisfied by the available reports.
11. International transfers
Where SellerSlice transfers Customer Personal Data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer is governed by an appropriate safeguard, applied per recipient and destination:
- EU SCCs (Commission Implementing Decision (EU) 2021/914), with the module appropriate to the relationship (controller-to-processor or, where SellerSlice onward-transfers, processor-to-processor);
- the UK International Data Transfer Addendum to the EU SCCs for UK personal data;
- the Swiss addendum where applicable; and
- the EU-US / Swiss-US Data Privacy Framework as a secondary mechanism for DPF-certified Sub-processors (Stripe, Vercel).
Where the SCCs are incorporated, they prevail over this DPA in case of conflict, and Appendices 1–3 populate their annexes.
12. Jurisdiction-specific terms
- Australia (APP 8 / s. 16C). SellerSlice takes reasonable steps to ensure overseas recipients handle Customer Personal Data consistently with the Australian Privacy Principles and acknowledges the accountability framework in s. 16C of the Privacy Act 1988.
- Canada / Québec (Law 25). This DPA constitutes the written agreement contemplated by Québec Law 25 s. 17 for transfers of Québec personal information; SellerSlice supports Customer's privacy impact assessments and the openness and consent obligations under PIPEDA and Law 25.
- Mexico (LFPDPPP). SellerSlice processes personal data as Customer's encargado, only on Customer's instructions, and supports the transfer-disclosure and consent requirements reflected in the Aviso de Privacidad.
- US state laws (CCPA/CPRA et al.). SellerSlice acts as a service provider / processor: it will not sell or share Customer Personal Data, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than providing the Service, and will not combine it with data from other sources except as permitted. SellerSlice certifies it understands and will comply with these restrictions.
13. Liability, term, and order of precedence
This DPA takes effect when Customer accepts the Terms and continues for as long as SellerSlice processes Customer Personal Data. Each party's liability under this DPA is subject to the limitations and exclusions in the Terms §22, except where Data Protection Law prohibits such limitation. In the event of conflict, the order of precedence is: (1) the SCCs (where incorporated), (2) this DPA, (3) the Terms, (4) any other agreement.
Appendix 1 — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Mission Control platform and agency services. |
| Duration | The term of the Service plus the deletion/retention periods in §9 and the Data Retention Policy. |
| Nature and purpose | Hosting, storing, organizing, analyzing, and otherwise processing Customer Data to operate the Service, including measuring the impact of work performed on Customer's own listings. |
| Types of personal data | Account and contact details of Customer's users; business and brand information; the content Customer creates or uploads; usage data. Amazon Information as described in Privacy Policy §12 (no buyer PII — no Restricted SP-API roles). |
| Categories of data subjects | Customer's authorized users (owners, admins, billing, members, viewers) and Customer's business contacts. |
| Special categories | None intended; Customer must not upload special-category data. |
Appendix 2 — Technical and organizational measures
- Encryption — AES-256 at rest; OAuth refresh tokens and connection secrets are additionally encrypted at the application layer with AES-256-GCM (key-versioned to support rotation) before storage; TLS 1.2+ in transit.
- Access control — Row-Level Security tenant isolation; role-based access from a verified JWT app-metadata role; least-privilege, job-duty-need access with periodic reviews and prompt deprovisioning; MFA and a 12-character minimum password for employees.
- Credential handling — OAuth refresh tokens stored encrypted; secrets managed via environment variables, never in source control; at least annual key rotation.
- Resilience and recovery — managed, backed-up infrastructure (Supabase/Vercel on AWS-backed regions); documented backup and recovery objectives.
- Vulnerability management — vulnerability scanning at least every 30 days; annual penetration testing; critical Amazon-Information vulnerabilities patched within 7 days, high-severity within 30 days.
- Logging and monitoring — audit logging of credential reads and sensitive operations; security/audit logs retained at least 12 months.
- Incident response — written incident-response plan with defined roles and the notification clocks in Privacy Policy §13.
Appendix 3 — Approved sub-processors and transfer mechanisms
The authoritative, dated list is maintained at /subprocessors. As of the effective date:
| Sub-processor | Purpose | Location | Transfer mechanism | Touches Amazon data |
|---|---|---|---|---|
| Supabase | Database / auth / realtime / storage | US | SCCs + UK Addendum | Yes |
| Vercel | Hosting / cron / Web Analytics | US | DPF + SCC fallback | Yes (hosting) |
| Vercel AI Gateway | AI inference routing | per Vercel | DPF + SCC fallback | Transient only |
| Resend | Transactional email | US | SCCs + UK Addendum | No |
| Stripe | Payment processing (independent controller) | US | DPF | No |
| Anthropic | AI copy generation/research | Confirmation pending | SCCs / DPF as applicable | Transient only |
| OpenAI | AI scoring / embeddings | Confirmation pending | SCCs / DPF as applicable | Transient only |
| xAI / Grok | Internal Morning Review / News search only | Confirmation pending | SCCs as applicable | No |
| Calendar / Meet integration | US | SCCs / DPF as applicable | No |
| Version | Effective | Summary |
|---|---|---|
| v1.0 | 2026-06-01 | Initial clickwrap DPA: Art. 28(3) terms, TOMs annex, sub-processor list + transfer mechanisms, controller/processor mapping, AU/Québec/Mexico/US-state terms. |