Skip to main content

Legal

Data Processing Agreement

How we process personal data on behalf of merchants: what we process and why, the measures in place, the sub-processors involved, transfers, breach notice, audits, and what happens to the data at the end. It is part of the agreement every merchant accepts when signing up; the binding copy is at dashboard.bestwebby.com/legal/dpa.

Last updated: September 2026 · Controller: You (the Merchant) · Processor: Joorus Inc. (Best Webby)

Scope and parties

This Data Processing Agreement ("DPA") forms part of the Merchant Terms of Service (dashboard.bestwebby.com/legal/merchant-terms) between Joorus Inc., trading as Best Webby ("Best Webby", "we", the "Processor"), and the business that holds a Best Webby account ("you", the "Controller"). It applies whenever we process personal data on your behalf in providing the platform. If this DPA and the Merchant Terms conflict about the processing of personal data, this DPA prevails.

Details of the processing

  • Subject matter: providing the Best Webby platform to you under the Merchant Terms.
  • Duration: for as long as your account exists, and afterwards until the personal data is deleted under clause 11.
  • Nature and purpose: hosting, storing, organising, displaying, transmitting and otherwise processing personal data as needed to run the storefronts, point of sale, orders, customer communications, support tools and other features you choose to use.
  • Categories of data subjects: your customers and prospective customers, the people you send messages to, your staff and other users you add to your account, and anyone else whose personal data you upload.
  • Types of personal data: contact details (name, email address, phone number, postal address); order, payment-status and transaction history (card numbers are handled by the payment provider and are not stored by us); account and sign-in data; messages and support conversations; voice clips a shopper records to use voice search; device and usage data; and any other personal data you upload.
  • Special categories: the platform is not designed for special categories of personal data. Do not upload them unless the law allows it and you have told us in writing.

Your instructions

We process personal data only on your documented instructions, including about transfers to other countries. The Merchant Terms, this DPA, and the way you configure and use the platform are your instructions. If the law requires us to process personal data in some other way, we will tell you before we do, unless the law forbids that. We will tell you promptly if we believe an instruction breaks data protection law.

Confidentiality

Everyone we authorise to process personal data is bound by a duty of confidentiality, by contract or by law, and has access only as far as their role needs.

Security

We implement technical and organisational measures appropriate to the risk, including:

  • encryption in transit with TLS 1.2 or higher (TLS 1.3 preferred) and HTTP Strict Transport Security;
  • column-level encryption of sensitive credentials and secrets;
  • database-level isolation of each merchant's data;
  • least-privilege access, with a second factor required for platform administration in the application;
  • regular backups.

We may change these measures, but not in a way that lowers the overall level of protection. The status of each of our controls is published at bestwebby.com/trust.

Sub-processors

You give us general authorisation to engage sub-processors. The current list, with what each one does, where it processes personal data and the safeguard for data leaving the EU, is published at bestwebby.com/security#sub-processors.

At least 30 days before we add or replace a sub-processor, we will email the account owner's email address. You may object on reasonable data protection grounds within that period. If we cannot reasonably address your objection, you may close your account before the change takes effect, and you pay only for the time you used.

We bind every sub-processor to data protection obligations that protect personal data at least as well as this DPA does, and we remain responsible to you for how they perform them.

Transfers outside the EU

Platform data is stored in the European Union, in Germany. Some sub-processors process personal data in other countries, as the published list shows. Where personal data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, we rely on the safeguard the list states for that sub-processor: the EU-U.S. Data Privacy Framework (with its UK Extension and the Swiss-U.S. framework) where the recipient is certified, and otherwise the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum and the Swiss amendments where they apply. Joorus Inc. is established in Canada, which the European Commission recognises as providing adequate protection for organisations subject to PIPEDA.

Help with data subject requests

Taking into account the nature of the processing, we help you, by appropriate technical and organisational measures, to answer requests from people exercising their rights of access, rectification, erasure, restriction, portability and objection. The platform lets you export and delete your customers' data yourself. Where you need more help, we will give it within 30 days of your request. If someone contacts us directly about personal data we process for you, we will pass the request to you and will not answer it ourselves unless you instruct us to.

Personal data breaches

We will notify you without undue delay after we become aware of a personal data breach affecting personal data we process for you. As the information becomes available, we will give you what you reasonably need to meet your own obligations, including to notify a supervisory authority or the people affected, and we will take reasonable steps to contain the breach and limit its effects.

Other help

Taking into account the nature of the processing and the information available to us, we will give you reasonable help with your own security obligations, with data protection impact assessments, and with any prior consultation with a supervisory authority, as far as they relate to our processing for you.

End of processing

Upon termination of the merchant relationship, we will delete or return all personal data within 90 days, unless the law requires us to keep it. Where you close your account, the data is kept for those 90 days so the account can be restored, and is then deleted.

Where an invoice is still unpaid 15 days after its payment link is sent, the account is disabled under clause 13 of the Merchant Terms of Service. You can still export your data while the account is disabled. An account that stays disabled is deleted 30 days after it was disabled, following warnings sent 14, 7 and 2 days before deletion, and is not deleted until each of those warnings has been sent. Deleted data cannot be recovered.

After deletion, for either reason, we keep the account's invoices, payment records, records of acceptance of the terms, and records of the notices sent to you for 6 years, as the law requires and to show what happened. These are our own billing and legal records, not personal data processed on your behalf, and they do not include your store content or customer data.

Audits and information

We make available to you the information reasonably necessary to demonstrate that we meet this DPA, including the control status register published at bestwebby.com/trust, and we will answer your reasonable written security and data protection questions. Where that is not enough, or a supervisory authority requires it, we will allow and contribute to audits, including inspections, by you or an independent auditor you appoint who is bound by confidentiality. You will give us at least 30 days' written notice of an audit, and it will take place during business hours and not more than once in any twelve months, unless there has been a personal data breach or a supervisory authority requires it.

Governing law

This DPA is governed by the law that governs the Merchant Terms. Where the GDPR, the UK GDPR or other data protection law applies to the processing, nothing in this DPA reduces the protection that law requires, and the Standard Contractual Clauses, where they apply, are governed by the law they specify.

Contact

Questions about this DPA, or about how we process personal data for you: [email protected], or by post to Joorus Inc., 250 Consumers Road, Suite 908, Toronto, Ontario M2J 4V6, Canada.