Intsell

Store Data Processing Addendum

This Addendum governs Intsell's processing, on behalf of a Store, of optional customer names or notes entered into selections.

Version
1.0
Effective
3 August 2026
Privacy noticeFree-use termsData processing addendumSubprocessorsRetention and deletionAcceptable use

1. Parties and Roles

The Store is controller of personal data concerning its customers because it determines the purposes and means of that processing. Intsell is processor and acts only on the Store's documented instructions. Intsell remains an independent controller for platform-user account and security data.

2. Subject Matter, Nature, and Duration

Processing consists of hosting, displaying, securing, backing up, and deleting an optional customer name or selection note used to personalize a product selection.

Processing continues for the active selection and a 30-day cleanup period after expiry. The Store may issue an earlier deletion instruction.

3. Data Subjects and Data Types

Data subjects are the Store's existing or prospective customers. Data types are an optional name, short identifying label, or selection note. Special-category data, identity numbers, payment data, health data, and unnecessary contact details are outside scope and must not be entered.

4. Store Obligations

The Store is responsible for identifying a valid legal basis, providing required notices, applying data minimization, managing user permissions, and ensuring that its instructions comply with applicable law. Intsell may suspend an instruction it reasonably considers unlawful and notify the Store.

5. Intsell Obligations

Intsell processes personal data only to provide the service and follow documented Store instructions; limits access to authorized persons subject to confidentiality; and does not sell or use the data for its own purposes.

On termination or a valid deletion instruction, Intsell deletes or anonymizes the data except where applicable law requires retention.

6. Security

Intsell maintains risk-appropriate technical and organizational measures, including tenant separation, role-based access, authentication, private-media controls, expiring selection links, logging, backup, and incident management. The Store is responsible for the security of user accounts, passwords, and devices.

7. Subprocessors

The Store gives general authorization for the providers listed on the Subprocessors page. Intsell imposes substantially equivalent data-protection duties on each subprocessor and gives reasonable notice of a material change.

The Store may object on reasonable data-protection grounds at info@intsell.app. If the parties cannot find a reasonable solution, the Store may discontinue the affected service.

8. Data-Subject and Audit Assistance

Taking account of the nature of processing, Intsell provides reasonable technical and organizational assistance with data-subject requests, data-protection impact assessments, and required regulator consultation.

Intsell makes information reasonably necessary to demonstrate compliance available. Audits are conducted with regard to confidentiality, security, and other customers' data and should first rely on independent reports and documentation.

9. Personal Data Breach

After becoming aware of a confirmed breach affecting personal data processed for the Store, Intsell notifies the Store without undue delay and provides available information on the nature of the incident, affected data categories, likely consequences, and measures taken so that the Store can meet its notification duties.

10. International Transfers and Priority

International transfers are managed under applicable KVKK and GDPR requirements and provider contracts. If this Addendum conflicts with the Free-Use Terms on personal-data processing, this Addendum prevails.

Back to account creation