Data Processing Agreement
LGScommerce · last updated 23 September 2026
This agreement governs our processing of personal data on your behalf. It forms part of the Terms of Service and applies automatically — you do not need to sign a separate copy.
1. Roles
1.1 When your shoppers use your store, you are the controller of their personal data and we are the processor.
1.2 You decide what data is collected, why, and how long it is kept. We act only on your instructions.
1.3 For data about you as our customer — your account, your billing — we are the controller, and our Privacy Policy applies instead.
1.4 You confirm that you have a lawful basis for the processing you instruct, and that you have given your shoppers the information data protection law requires.
2. Subject matter and duration
2.1 Subject matter: providing hosted ecommerce software to you.
2.2 Duration: for as long as you have a subscription, plus the retention period in clause 9.
2.3 Nature and purpose: hosting, storing, transmitting, backing up and displaying store data so that your store operates and you can administer it.
3. Categories of data subject
- your shoppers, including people who register, order, book an event or table, sell cards to you, or contact you;
- your staff, for whom you create admin or till accounts.
4. Types of personal data
- identity and contact data — name, email address, telephone number, delivery and billing address;
- transaction data — orders, payments, refunds, returns, store credit and loyalty balances;
- account data — credentials in hashed form, marketing preference, patron code;
- correspondence — contact-form messages, return reasons, reviews;
- event and booking data — attendance, bookings, league standings;
- technical data — IP address, browser and device information, pages viewed and searches made.
4.1 Payment card numbers are not included. Card details pass directly from the shopper to Stripe and do not reach our systems.
4.2 The service is not designed for special category data, and you must not instruct us to process it.
5. Our obligations
5.1 We process personal data only on your documented instructions, which are these terms and your use of the service, unless required otherwise by law — in which case we will tell you first unless the law forbids it.
5.2 We ensure that people authorised to process the data are bound by confidentiality.
5.3 We implement appropriate technical and organisational measures — see clause 6.
5.4 We assist you, so far as reasonable, with data subject requests, with security incidents, and with data protection impact assessments.
5.5 We make available the information reasonably needed to demonstrate compliance with this agreement, and allow audits under clause 10.
5.6 We tell you if, in our opinion, an instruction infringes data protection law.
6. Security
6.1 Measures include:
- encryption in transit (TLS) for all connections to the service;
- encryption at rest for stored data and backups;
- passwords stored using a modern one-way hash, never in plain text;
- separation of every store's data by tenant, enforced in software on every request, so one shop cannot read another's;
- role-based access for your staff, so you can grant only what a job needs;
- restricted and logged administrative access on our side;
- regular backups, and patching of the software we run.
6.2 [Add any certification you hold — ISO 27001, SOC 2, Cyber Essentials — or state that you hold none.]
7. Sub-processors
7.1 You give general authorisation for us to appoint sub-processors. Those engaged today are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing and subscription billing | EU / US |
| Amazon Web Services | Hosting, storage and backups | [Region] |
| [Email provider] | Sending transactional and marketing email | [Region] |
7.2 Stripe is engaged by you directly for payment processing on your connected account, and in that respect is not our sub-processor.
7.3 We impose data protection obligations on each sub-processor no less protective than these, and remain liable to you for their performance.
7.4 We give [30 days'] notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds you may terminate the affected subscription without penalty, and we will refund the unused part of the period.
8. International transfers
8.1 Where a sub-processor processes personal data outside the United Kingdom, the transfer is made under an adequacy decision, standard contractual clauses, or another lawful mechanism.
8.2 Details of the mechanism relied upon are available on request.
9. Return and deletion
9.1 You can export your store's data at any time while the subscription is live.
9.2 After it ends we retain the data for 30 days so that you can export it, then delete it from live systems. Backups age out on our ordinary cycle.
9.3 We may retain data where law requires, for as long as it requires and for nothing else.
10. Audit
10.1 We will respond to reasonable written questions about our processing, no more than once a year unless there has been a security incident or a regulator requires otherwise.
10.2 Where an on-site audit is genuinely required, it must be on reasonable notice, during business hours, subject to confidentiality, and must not disrupt the service or risk another customer's data. [State whether you charge for audit support.]
11. Personal data breaches
11.1 We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your store's data.
11.2 The notification will describe what happened, the categories and approximate number of records concerned, the likely consequences, and the measures taken.
11.3 Reporting a breach to a supervisory authority, and to affected shoppers, is your responsibility as controller. We will give you the information you need to do it.
12. Assistance with data subject requests
12.1 The admin lets you find, correct, export and delete a shopper's data yourself, which is the quickest route.
12.2 If a shopper contacts us directly we will not respond substantively; we will tell them to contact you, and tell you it happened.
13. Liability
13.1 Liability under this agreement is subject to the limits in clause 15 of the Terms of Service.
14. Conflict
14.1 Where this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails.