Version 1.1 · Last updated 23 September 2026
Data Processing Addendum
This Addendum applies when an authorized Seller representative separately accepts its applicable version in the app. A testing-access request, account creation, or general Terms acceptance does not accept it.
1. Execution and parties
This Data Processing Addendum (the “Addendum”) is between Brick Pulse, LLC (“Brick Pulse”) and the Seller whose business account is identified in the app (“Seller”). It supplements the applicable service agreement and becomes effective for Seller-directed processing when a person authorized to bind Seller separately accepts the applicable version in the app on Seller's behalf. The app records the accepted version. This Addendum controls over conflicting service terms for that processing. It does not cover Brick Pulse's independent account, security, billing, or legal-compliance processing described in the Privacy Policy.
The public policy page and a testing-access request do not collect DPA acceptance. This version is not yet available through the app's separate DPA acceptance control; do not treat this page as assent or as an active processing authorization. “Personal Data,” “Controller,” “Processor,” and related terms have the meanings given by applicable data protection law.
2. Processing and instructions
Seller acts as Controller or equivalent business and Brick Pulse acts as Processor or service provider for the Seller-directed processing described in Schedule A, to the extent those roles apply under applicable law. Seller instructs Brick Pulse to process Personal Data only to provide and secure the service described in this Schedule A. Seller may issue further written instructions consistent with the service and law. Brick Pulse will notify Seller if it reasonably believes an instruction violates applicable data protection law and may suspend the affected processing until the instruction is resolved. Brick Pulse may process or disclose data when law requires it, and will notify Seller unless legally prohibited.
Seller is responsible for having authority and a lawful basis for its instructions and for providing required notices to people whose data it submits. Seller will not direct Brick Pulse to process data beyond the purposes, categories, people, and duration entered in Schedule A.
3. Confidentiality and security
Brick Pulse will limit access to personnel who need it to provide the service and require those personnel to protect information they access. Brick Pulse will maintain technical and organizational measures appropriate to the processing and described in Schedule A. The current app encrypts buyer personal information at rest, requires multi-factor authentication for account access, and encrypts backups. The schedule must identify additional measures, systems, and any limitation relevant to the processing before the DPA-enabled service is made available.
4. Subprocessors and transfers
Seller authorizes only the subprocessors identified with their roles, data, and locations in Schedule A. Brick Pulse will bind an authorized subprocessor to written privacy and security duties appropriate to its work and remains responsible for its performance as required by applicable law. Brick Pulse will give Seller reasonable advance written notice of a proposed subprocessor change. Seller may object in writing on reasonable data-protection grounds before that subprocessor handles Seller Personal Data. The parties will work in good faith on a resolution and address any unresolved objection under the applicable service agreement and law. The proposed subprocessor will not handle the affected Seller Personal Data while the objection remains unresolved.
The Service Providers page describes provider purposes and current known status. Provider roles, processing locations, safeguards, and transfer arrangements that have not been verified are not represented as established or authorized by this Addendum. Those facts must be verified and disclosed before DPA-enabled processing is made available. No country, transfer mechanism, or provider location is inferred from an address or provider name.
5. Requests, incidents, and audits
Taking account of the processing, Brick Pulse will reasonably assist Seller with verified requests to exercise applicable data rights and with required impact assessments or regulator consultations. If Brick Pulse receives a request directly about Seller Personal Data, it will refer the person to Seller unless law requires Brick Pulse to respond.
Brick Pulse will notify Seller without undue delay after confirming a personal-data breach involving Seller Personal Data and will provide information reasonably available to help Seller investigate and meet its obligations. The parties will cooperate in good faith on containment, remediation, and required notices. The notice will be sent to the Seller's registered or updated privacy contact in its account.
Brick Pulse will make information reasonably necessary to demonstrate compliance with this Addendum available to Seller. Seller may conduct a reasonable audit, including through a qualified independent auditor, on reasonable advance notice and subject to confidentiality, safety, and protection of other customers' data. The parties will agree on scope and logistics in good faith; an audit may not access another customer's data or create an unreasonable security risk or service disruption.
6. End of processing
When the applicable service ends, Seller may request return or deletion of Seller Personal Data, subject to applicable law and the retention periods stated in the Privacy Policy. Current app capabilities include inventory CSV export but not complete account export or account-wide deletion; contact support for a privacy request. Encrypted backups expire after 30 days; buyer-identifying information follows the 90-day redaction rule described in the Privacy Policy, subject to open disputes and legal holds.
Schedule A — standard processing details
This standard schedule is part of the Addendum accepted in the app.
| Parties | Brick Pulse, LLC and the Seller business account identified in the app |
|---|---|
| Subject matter and duration | Seller inventory and order workflow for the term of the applicable service, subject to the Privacy Policy retention periods |
| Purpose and operations | Receive, organize, store, display, and use Seller-directed inventory, order, and fulfillment data to provide and secure the service |
| Personal Data | Buyer names and contact or delivery details, order and item identifiers, order status, and fulfillment events included in Seller records |
| People | Seller's buyers and customers; Seller account users where their information is included in Seller-directed records |
| Instructions | This Addendum and Seller's authorized use of the service, including instructions submitted through app functions |
| Subprocessors, roles, locations, and transfers | See the current Service Providers page. Provider roles, locations, safeguards, and transfer arrangements must be verified and disclosed before corresponding processing is made available. |
| Security | Technical and organizational measures described in section 3 and the Privacy Policy |
| Retention and deletion | Privacy Policy periods: encrypted backups expire after 30 days; buyer-identifying data is redacted under the 90-day rule, subject to disputes and legal holds |
| Brick Pulse privacy contact | support@brickpulse.app |
| Seller privacy and breach contact | The privacy contact registered or later updated in Seller's account |
7. Electronic acceptance
A person authorized to bind Seller accepts this Addendum electronically in the app on Seller's behalf. The app records the accepted version. Separate DPA acceptance is required; it is not inferred from a testing-access request, account creation, general Terms acceptance, or use of the service. No wet signature, Brick Pulse countersignature, or individual manual review is required.
A material change to this Addendum will be presented as a new version for separate Seller acceptance before continued Seller-directed processing under the changed terms.