Skip to Main Content

Appriss Retail Global Data Processing Agreement

Effective July 2026

This Data Processing Agreement (“DPA”) forms part of and is subject to the terms and conditions of the Master License and Services Agreement by and between You (the party listed as “Client” under an applicable Order Form) and Appriss Retail (“Appriss”). 

This DPA reflects the parties’ commitment to abide by Data Protection Laws concerning the Processing of Personal Data in connection with Appriss’s provision of services to You pursuant to a lawfully executed Order Form. All capitalized terms that are not expressly defined in this DPA will have the meanings given to them in the MLSA or Order Form. If and to the extent language in this DPA conflicts with the MLSA or Order, this DPA shall control as applicable to Appriss’ processing of Personal Information. 

This DPA will become legally binding upon the effective date of a fully executed Order Form and shall survive for so long as Appriss Processes Your Personal Data. 

1. Definitions.

For the purposes of this DPA, the following terms and those defined within the body of this DPA apply.

1.1. “Artificial Intelligence or AI” means a machine-based system that can, for a given set of human-defined objectives, make predictions, recommendations, or decisions influencing real or virtual environments.

1.2. “AI System” means any machine-based system, including Algorithmic AI and generative or adaptive models, that infers from its inputs how to generate outputs such as predictions, content, recommendations, or decisions.

1.3. “Personal Data” means Personal Data Processed by Appriss on your behalf.

1.4. “Data Protection Laws” means the applicable data privacy, data protection, and cybersecurity laws, rules and regulations to which the Personal Data are subject. “Data Protection Laws” may include, but are not limited to, the California Consumer Privacy Act of 2018 (“CCPA”); the EU General Data Protection Regulation 2016/679 (“GDPR”) and its respective national implementing legislations; the Swiss Federal Act on Data Protection; the United Kingdom General Data Protection Regulation; and the United Kingdom Data Protection Act 2018 (in each case, as amended, adopted, or superseded from time to time).

1.5. “Personal Data” has the meaning assigned to the term “personal data” or “personal information” under applicable Data Protection Laws.

1.6. “Process” or “Processing” means any operation or set of operations which is performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction. References to ‘Processing’ under this DPA include Processing performed by or through AI Systems as defined herein.

1.7. “Security Incident(s)” means the breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data attributable to Appriss.

1.8. “Services” means the services that Appriss performs under an Order Form.

1.9. “Subprocessor(s)” means Appriss’s authorized vendors and third-party service providers that Process Personal Data on your behalf.

2. Processing Terms for Personal Data

2.1. Documented Instructions. Appriss shall Process Personal Data to provide the Services in accordance with the MLSA, this DPA, the Order Form, any applicable Statement of Work, and any instructions agreed upon by You. Appriss will, unless legally prohibited from doing so, inform You in writing if we reasonably believe that there is a conflict between Your instructions and applicable law. Appriss shall process Personal Data in the role of “Processor” and “Service Provider,” as those terms are defined by Data Protection Laws, on your behalf. You shall be the “Controller” and/or “Business,” with respect to the Processing of Personal Data pursuant to an Order Form.

2.2. Authorization to Use Subprocessors. To the extent necessary to fulfill Appriss’s contractual obligations under the Order Form, You hereby authorize Appriss to engage Subprocessors, including those listed here: www.apprissretail.com/subprocessors/, which list may be updated at Appriss’s reasonable discretion from time to time. Continued use of the Services after the effective date of a subprocessor change constitutes acceptance of the updated subprocessor list.

2.4. Appriss and Subprocessor Compliance. Appriss shall (i) enter into a written agreement with Subprocessors regarding such Subprocessors’ Processing of Personal Data that imposes on such Subprocessors data protection requirements for Personal Data that are consistent with this DPA; and (ii) remain responsible for Appriss’s Subprocessors’ performance of obligations with respect to the Processing of Personal Data.

2.5. Right to Object to Subprocessors. Where required by Data Protection Laws, Appriss will notify You via email prior to engaging any new Subprocessors that Process Personal Data and allow you ten (10) days to object. If You have legitimate objections to the appointment of any new Subprocessor, the parties will work together in good faith to resolve the grounds for the objection. If You do not object to the appointment of new Subprocessor within the notice period, then You shall be deemed to have given consent to the inclusion of the new Subprocessor.

2.6. Confidentiality. Any person authorized to Process Personal Data must contractually agree to maintain the confidentiality of such information or be under an appropriate statutory obligation of confidentiality.

2.7. Personal Data Inquiries and Requests. Where required by Data Protection Laws, Appriss agrees to provide reasonable assistance and comply with reasonable instructions from You related to any requests from individuals exercising their rights in Personal Data granted to them under Data Protection Laws. You shall be responsible for reimbursing Appriss for all costs (including internal costs, third-party cost, and legal fees) reasonably and properly incurred by Appriss arising from performing it obligations under this section.

2.8. Prohibited Uses of Personal Data. Appriss shall not (i) sell or share Personal Data as the terms “sell” or “share” are defined by the CCPA or (ii) retain, use, combine, or disclose Personal Data for any purpose other than as described in this DPA or permitted under Data Protection Laws.

2.9. Data Protection Impact Assessment and Prior Consultation. Where required by Data Protection Laws, Appriss agrees to provide reasonable assistance to You where, in Your reasonable judgement, the type of Processing performed by Appriss requires a data protection impact assessment and/or prior consultation with the relevant data protection authorities. You will reimburse Appriss for all costs (including internal costs, third-party cost, and legal fees) reasonably and properly incurred by Appriss arising from performing it obligations under this section.

2.10 Demonstrable Compliance. Upon Your reasonable request Appriss agrees to provide information reasonably necessary to demonstrate compliance with this DPA and permit You to take reasonable steps to stop and remediate unauthorized use of Personal Data.

2.11. Service Optimization. Where permitted by Data Protection Laws, Appriss may Process Personal Data: (i) for its internal uses to build or improve the quality of its services; (ii) to detect Security Incidents; (iii) to protect against fraudulent or illegal activity, including, where authorized under appliable law, to analyze, retain, and process Personal Data in conjunction with Appriss’s data and other customers’ data to create metadata to operate its products for the express purpose of detecting security incidents and protecting against malicious, deceptive, fraudulent, or illegal activity.

2.12. Aggregation and De-Identification. Appriss may: (i) compile aggregated and/or de-identified information in connection with providing the Services provided that such information cannot reasonably be used to identify You or any data subject to whom Personal Data relates (“Aggregated and/or De-Identified Data”); and (ii) use Aggregated and/or De-Identified Data for its lawful business purposes.

3. Information Security Program.

3.1. Security Measures. Appriss shall use commercially reasonable efforts to implement and maintain reasonable administrative, technical, and physical safeguards designed to protect Personal Data. Such safeguards shall include the measures described in Annex II in the Appendix.

4. Security Incidents.

4.1. Notice. Upon becoming aware of a Security Incident, Appriss agrees to provide written notice without undue delay and within the time frame required under Data Protection Laws to Your contact as specified in an Order Form. Where possible, such notice will include all available details required under Data Protection Laws for You to comply with your notification obligations to regulatory authorities or individuals affected by the Security Incident.

5. Cross-Border Transfers of Personal Data.

5.1. Cross-Border Transfers of Personal Data. You authorize Appriss and its Subprocessors to access or host Personal Information in the following locations: United States, European Economic Area, United Kingdom, Colombia, North America, and India.

5.2. EEA, Swiss, and UK Standard Contractual Clauses. If Appriss or its Subprocessors Process Personal Data originating in the European Economic Area, Switzerland, and/or United Kingdom in a country that has not been found to provide an adequate level of protection under applicable Data Protection Laws, the parties agree that the Standard Contractual Clauses, available here, shall apply.

6. Audits.

6.1. Where Data Protection Laws afford You an audit right, You (or your appointed representative) may carry out an audit of Appriss’s policies, procedures, and records relevant to the Processing of Personal Data. Any audit must be: (i) conducted during Appriss’s regular business hours; (ii) with reasonable advance notice to Appriss; (iii) carried out in a manner that prevents unnecessary disruption to Appriss’s operations; and (iv) subject to reasonable confidentiality procedures. In addition, any audit shall be limited to once per year, unless an audit is carried out at the direction of a government authority having proper jurisdiction. You shall reimburse Appriss for all costs (including internal costs, third-party cost, and legal fees) reasonably and properly incurred by Appriss arising from performing it obligations under this section. You shall not be entitled to directly test or access any systems or networks as part of its audit rights herein.

7. Personal Data Deletion.

Within ninety (90) days of the expiry or termination of the Order Form, Appriss will either return or delete all Personal Data (excluding any back-up or archival copies which shall be deleted in accordance with Appriss’s data retention schedule), except where Appriss is required to retain copies under applicable laws, in which case Appriss will isolate and protect that Personal Data from any further Processing except to the extent required by applicable laws. If you do not inform Appriss of your choice to require the return or deletion of such Personal Data within 90 days of the termination or expiry of the Order, then Appriss shall delete the Personal Data.  You acknowledge that Appriss may continue to process information derived from Personal Data in anonymised, aggregated reports during the term and following termination of the Order. 

8. Your Obligations.

You represent and warrant that: (i) you have complied and will comply with Data Protection Laws; (ii) you have provided data subjects whose Personal Data will be Processed in connection with an Order Form with a privacy notice or similar document that clearly and accurately describes your practices with respect to the Processing of Personal Data, including your sharing of their Personal Data with third-party service providers, who may combine it with other sources of Personal Data, to protect against security incidents and malicious, deceptive, fraudulent, or illegal activity; (iii) you have obtained and will obtain and continue to have, during the term, all necessary rights, lawful bases, authorizations, consents, and licenses for the Processing of Personal Data as contemplated by the Order Form, the MLSA, and this DPA; (iv) Appriss’s Processing of Personal Data in accordance with the MLSA, DPA, or Order Form will not violate Data Protection Laws or cause a breach of any agreement or obligations between you and any third party; and (v) as of the date of the Order Form and during its Term, the technical and organizational measures described in Annex II in the Appendix meet the requirements set out in Section 4 with respect to the Personal Data processed by Appriss under this DPA. 

9. Processing Details.

9.1. Subject Matter. Fraud and retail abuse prevention and retail optimization.

9.2. Duration. The Processing will continue until the expiration or termination of the Order Form.

9.3. Categories of Data Subjects. Your customers, vendors, and employees.

9.4. Nature and Purpose of the Processing. The purpose of the Processing is to analyze Your transaction data to provide fraud prevention, loss prevention, and related services.

9.5. Types of Personal Data. Your customer transaction information and employee information.

10. Miscellaneous.

10.1. Notwithstanding anything to the contrary in the Standard Contractual Clauses or this DPA, Appriss shall not be required to provide legal advice to You and nothing provided by Appriss shall be construed by You as legal advice.

10.2. Each Relevant Party shall remain responsible for its compliance and the compliance of all its employees, agents and third parties with the obligations under the Agreement.

11. Contact Information.

11.1. Unless you provide a separate contact for notices in writing to Appriss, Appriss shall use the Client representative contact stated in the Order Form as the contact for all notices. Appriss’s notice contact shall be dg-legal@apprissretail.com.