Legal · Eleo

Data Processing Agreement

Last updated: August 28, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Eleo and a merchant or business customer (“Customer”) when Eleo processes personal data on the Customer's behalf in providing the Services. It applies from the date the Customer accepts or uses the relevant Service.

1. Roles and scope

Customer is the controller and Eleo is the processor for personal data Customer submits or directs Eleo to process, such as customer, supplier, employee, contact, order, inventory-linked and communications data (“Customer Data”). Processing covers hosting, organising, transmitting, supporting, securing, backing up, retrieving and deleting Customer Data for the agreement's duration. Data subjects may include Customer's customers, prospects, staff, contractors and suppliers. Eleo remains an independent controller for its own account, billing, security, legal and marketplace-operator purposes described in the Privacy & Cookie Policy.

2. Instructions and compliance

Eleo will process Customer Data only on documented instructions in the agreement, Customer's configured use of the Services and lawful support requests, unless law requires otherwise. Customer is responsible for lawful instructions, notices, consents, data accuracy and responding as controller. Eleo will notify Customer if an instruction appears to violate applicable data-protection law, unless prohibited.

3. Confidentiality and security

Eleo limits Customer Data access to authorised people bound by confidentiality and maintains proportionate technical and organisational safeguards, including access controls, authentication, encryption in transit, logging, monitoring, backups and incident procedures. Customer must configure permissions appropriately and protect credentials and endpoints under its control.

4. Subprocessors and transfers

Customer authorises the vendors on our Subprocessors List. Eleo will impose data-protection obligations appropriate to their services and remains responsible for their processing to the extent required by law. We will update the list and provide notice of a material new subprocessor where the agreement or law requires it. Customer may raise a reasonable, documented data-protection objection; the parties will seek a practical solution. International transfers will use a lawful transfer mechanism and appropriate safeguards.

5. Assistance and incidents

Taking account of the processing and information available, Eleo will reasonably assist Customer with data-subject requests, security, breach notifications, impact assessments and regulator consultations. Eleo will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data and provide available information needed for Customer's obligations. Customer remains responsible for its notices and regulatory decisions.

6. Return, deletion and audits

On termination or Customer's lawful instruction, Eleo will return or delete Customer Data within a reasonable period, except where law, dispute preservation or secure backup cycles require retention. Retained data remains protected and isolated from ordinary use. On reasonable written request, Eleo will provide information needed to demonstrate compliance. Audits must be proportionate, protect other customers and Eleo security, avoid unnecessary disruption, and use existing reports before an on-site inspection unless law requires otherwise.

7. Order of terms and contact

This DPA prevails over conflicting contract terms only for its subject. Liability follows the underlying agreement except where applicable law requires otherwise. Data-protection questions and signed-DPA requests: [email protected].