Legal
Data Processing Agreement
How BestWebby processes personal data on behalf of merchants: the instructions we act on, the measures in place, the sub-processors involved, and what happens to the data at the end.
Last updated: September 2026 · Controller: You (the Merchant) · Processor: BestWebby
Scope and Purpose
This Data Processing Agreement (“DPA”) supplements the Merchant Terms of Service between BestWebby (“Processor”) and the merchant (“Controller”) and governs the processing of personal data of the Controller's customers and contacts in connection with the BestWebby platform.
Processing Instructions
BestWebby will process personal data only on documented instructions from the Controller (i.e., as configured in the Platform settings), unless required to do so by law.
Security Measures
BestWebby implements the following technical and organizational measures:
- Column-level encryption of sensitive credentials and secrets
- TLS 1.3 encryption in transit
- Access controls with least-privilege principles
- Regular security assessments
- Incident response procedures with 72-hour breach notification
Sub-processors
BestWebby uses the sub-processors listed at bestwebby.com/security. BestWebby will notify Controllers before engaging new sub-processors.
Data Subject Rights
BestWebby will assist Controllers in responding to data subject requests (access, erasure, portability) within 30 days of request.
Termination
Upon termination of the merchant relationship, BestWebby will delete or return all personal data within 90 days, unless retention is required by law. Where the Controller closes its account, the data is kept for those 90 days so the account can be restored, and is then deleted.
Where an invoice is still unpaid 15 days after its payment link is sent, the account is disabled under clause 13 of the Merchant Terms of Service. The Controller can still export its data while the account is disabled. An account that stays disabled is deleted 30 days after it was disabled, following warnings sent 14, 7 and 2 days before deletion, and is not deleted until each of those warnings has been sent. Deleted data cannot be recovered.
After deletion, for either reason, BestWebby keeps the account's invoices, payment records, records of acceptance of the terms, and records of the notices sent to the Controller for 6 years, as the law requires and to show what happened. These are BestWebby's own billing and legal records, not personal data processed on the Controller's behalf, and they do not include the Controller's store content or customer data.
Governing Law
This DPA is governed by the laws of the Province of Ontario, Canada, and, where applicable, EU GDPR requirements.
Contact
DPA inquiries can be sent through our contact form.