The terms that apply whenever we handle personal data on your behalf. You are the controller, we are the processor. Plain wording, same legal effect.
You are the controller. You decide why and how the personal data in your shop and your accounts is used. Budrus is the processor: we act on your instructions and for no other purpose.
For the data you give us about yourself, such as your own contact and billing details, we are the controller instead, and our privacy policy covers that.
We do not need, and do not ask for, your customers' names, addresses, orders or payment details. Please do not send them to us.
We process only on your documented instructions, which are your plan, this page, and anything you tell us in writing afterwards. If we believe an instruction breaks data protection law, we will say so before acting on it. If the law obliges us to process something without your instruction, we will tell you first unless the law forbids us from telling you.
Everyone at Budrus who can reach your data is bound by confidentiality, is told what they may and may not do with it, and is given access only where the work actually requires it.
We apply measures appropriate to the risk. In practice that means access limited to the people who need it, multi-factor authentication on the accounts that hold data, encryption in transit, read-only access wherever read-only is enough, one customer's material kept separate from another's, and access removed as soon as someone stops working on your brand.
You give general authorisation for us to use sub-processors. Each one is under a written contract with obligations no weaker than these, and we remain responsible for what they do. We use them in these categories: website and form hosting, email delivery, search and market data, payment and invoicing, and, where you have connected it, your own Google account on a read-only basis.
The current list by name is available on request. We will tell you at least 30 days before adding or replacing one, and you may object on reasonable data protection grounds. If we cannot resolve your objection, you can end the affected part of the service without penalty.
We keep processing inside the European Economic Area wherever we can. Where a sub-processor processes outside it, the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses. Ask and we will tell you which applies to which provider.
We will help you, as far as the nature of the service allows, with responding to people exercising their rights, with impact assessments, with consulting a supervisory authority, and with keeping the processing secure. If someone contacts us directly about their data, we pass them to you rather than answering on your behalf.
If personal data we hold for you is lost, exposed or accessed without authority, we tell you without undue delay and in any case within 48 hours of becoming aware of it. We tell you what we know, what we are doing about it, and what you may need to report onwards.
When your plan ends you have 30 days to ask for your material back. After that we delete it and confirm when it is done, apart from anything the law requires us to keep, and routine backups, which expire on their own cycle and stay protected until they do.
We will give you the information you reasonably need to satisfy yourself that we are meeting these terms. If your company needs more than that, we will agree a sensible check in advance, once a year, at your cost, arranged so that it does not disturb other customers.
Where these terms and the terms of service disagree about personal data, these terms win.