Legal
Data Processing Agreement
How BestWebby processes personal data on behalf of merchants: the instructions we act on, the measures in place, the sub-processors involved, and what happens to the data at the end.
Last updated: May 2026 · Controller: You (the Merchant) · Processor: BestWebby
Scope and Purpose
This Data Processing Agreement (“DPA”) supplements the Terms of Servicebetween BestWebby (“Processor”) and the merchant (“Controller”) and governs the processing of personal data of the Controller's customers and contacts in connection with the BestWebby platform.
Processing Instructions
BestWebby will process personal data only on documented instructions from the Controller (i.e., as configured in the Platform settings), unless required to do so by law.
Security Measures
BestWebby implements the following technical and organizational measures:
- Column-level encryption of sensitive credentials and secrets
- TLS 1.3 encryption in transit
- Access controls with least-privilege principles
- Regular security assessments
- Incident response procedures with 72-hour breach notification
Sub-processors
BestWebby uses the sub-processors listed at bestwebby.com/security. BestWebby will notify Controllers before engaging new sub-processors.
Data Subject Rights
BestWebby will assist Controllers in responding to data subject requests (access, erasure, portability) within 30 days of request.
Termination
Upon termination of the merchant relationship, BestWebby will delete or return all personal data within 90 days, unless retention is required by law.
Governing Law
This DPA is governed by the laws of the Province of Ontario, Canada, and, where applicable, EU GDPR requirements.
Contact
DPA inquiries can be sent through our contact form.