Adherely
Back to Adherely

Last updated August 27, 2026

Data Processing Addendum

This addendum explains the instructions, safeguards, subprocessors, assistance, and deletion commitments that apply to merchant customer data.

1. When this addendum applies

This Data Processing Addendum, or DPA, forms part of the Adherely Terms of Service when Adherely processes personal data on behalf of a merchant. It applies for the period in which Adherely processes that data to provide the merchant's service.

The merchant is the controller or business for merchant customer data, and Adherely is its processor or service provider. Adherely may act as an independent controller for merchant-account administration, service security, abuse prevention, legal compliance, and Adherely's own SMS consent and opt-out records. Those activities are governed by the Privacy Policy.

2. Merchant instructions

Adherely will process merchant customer data only on documented, lawful instructions from the merchant, including instructions expressed through configured programs, connected integrations, dashboard actions, support requests, the Terms of Service, and this DPA. Adherely will notify the merchant if an instruction appears to violate applicable data-protection law, unless law prohibits that notice.

The merchant is responsible for the lawfulness, accuracy, and scope of its instructions and for giving required notices. A commerce order, customer record, or scan is not SMS consent. Merchants may not direct Adherely to bypass the service's consent and opt-out controls or to process protected health information or other special-category data.

3. Confidentiality and security

Adherely limits access to personal data to people and service providers who need it for their role and who are subject to confidentiality obligations. Adherely maintains reasonable technical and organizational safeguards appropriate to the service and risk, including authenticated merchant access, tenant ownership checks, encryption in transit, encryption of stored commerce credentials, restricted server-side database access, signed-webhook validation, data minimization, operational retention controls, and incident response procedures.

The merchant is responsible for its own account security, user access, connected-store permissions, endpoint security, and lawful program configuration. More information is available on the Security page.

4. Subprocessors

The merchant gives Adherely general authorization to use the subprocessors listed on the Subprocessors page. Adherely requires each subprocessor to protect personal data under terms appropriate to its role and remains responsible for its subprocessors to the extent required by applicable law.

Before a material new subprocessor begins processing merchant customer data, Adherely will provide notice through the merchant's contact email or dashboard. A merchant may raise a reasonable data-protection objection by emailing privacy@adherely.co within 15 days after notice. The parties will work in good faith on a practical solution; if none is available, the merchant may stop the affected feature or cancel the affected service.

5. Individual rights and compliance assistance

Taking into account the nature of processing, Adherely will reasonably assist the merchant with verified requests to access, correct, export, restrict, object to, or delete personal data. If Adherely receives a request concerning data it processes only for a merchant, it may route that request to the merchant and will not respond on the merchant's behalf unless instructed or legally required.

Adherely will also provide information reasonably needed for the merchant's data-protection impact assessments, regulator consultations, and demonstration of compliance, considering the information available to Adherely.

6. Security incidents

Adherely will notify the affected merchant without undue delay after becoming aware of a personal-data breach involving merchant customer data. Notice will include available information about the nature of the incident, affected data, likely consequences, containment or remediation, and a contact for follow-up. Adherely will provide reasonable assistance, while the merchant remains responsible for any regulator or individual notice required of it as controller.

7. Return, deletion, and retention

On a merchant's verified instruction or after the service ends, Adherely will delete or return merchant customer data unless law requires retention. Limited records may be retained to document consent and opt-out, prevent fraud or webhook replay, settle transactions, protect security, or establish legal claims. Retained data remains protected and is not used for another purpose.

Data in backups or isolated recovery systems will remain protected and expire through the ordinary backup lifecycle rather than being restored to active use. The Privacy Policy describes operational retention windows and the verified deletion-request process.

8. International transfers

If personal data is transferred across a border that requires a transfer mechanism, Adherely will use an available lawful mechanism, such as an adequacy decision or applicable standard contractual clauses, and will require appropriate protection from relevant subprocessors.

9. Audit information

On reasonable written request, Adherely will provide information needed to demonstrate compliance with this DPA. If that information is not sufficient, the parties will agree on a proportionate review that protects other customers, confidential information, and service security. Reviews may not unreasonably disrupt the service.

10. Processing details

Purpose: operate merchant-configured product-use programs, enrollment, check-ins, messaging, progress, eligible rewards, refill timing, attribution, analytics, support, security, and related integrations.

People: merchant users, prospective and enrolled customers, message recipients, store customers connected to eligible orders, and support contacts.

Data: account and store identifiers, first name, phone number, email where available, consent and opt-out records, program and timezone preferences, check-ins, message delivery and reply records, progress, reward and refill activity, minimized commerce references, and security or support metadata.

Duration: the merchant's trial or paid service plus the documented retention period needed for deletion, legal obligations, security, and dispute handling.

11. Contact

DPA questions, rights-assistance requests, and subprocessor objections can be sent to privacy@adherely.co.