Skip to content

Last updated: August 24, 2026

Data Processing Agreement

1. Parties and Roles

This Data Processing Agreement (DPA) applies where a merchant using the TriveniCo platform acts as the data controller of its customers' personal data and TriveniCo acts as the data processor on that merchant's behalf. In this arrangement, the merchant determines the purposes and means of processing, and TriveniCo processes the data solely to provide the Services.

2. Scope and Purpose of Processing

TriveniCo processes customer data for the purpose of operating the merchant's storefront, marketplace listings, point-of-sale, orders, payments, CRM, analytics, and related features. TriveniCo processes personal data only on documented instructions from the merchant, including instructions transmitted through the configuration of the Services.

3. Categories of Data and Data Subjects

The categories of personal data processed include:

  • Customer identifiers such as name, email address, phone number, and shipping address.
  • Order and transaction details, including purchase history and payment references.
  • Storefront interaction data such as messages, reviews, and support inquiries.

The data subjects are the merchant's customers, prospective customers, and other individuals whose data the merchant submits to the Services.

4. Duration of Processing

TriveniCo processes customer data for the duration of the merchant's use of the Services and for any period thereafter required to comply with legal obligations, resolve disputes, or enforce agreements, subject to the deletion and return provisions below.

5. Subprocessors

TriveniCo may engage subprocessors to help deliver the Services, including hosting, payment, email, analytics, and support providers. TriveniCo enters into written agreements with each subprocessor imposing data protection obligations consistent with this DPA and remains responsible for their performance. TriveniCo will maintain an up-to-date list of subprocessors and inform merchants of intended changes.

6. Security Measures

TriveniCo implements and maintains appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, network monitoring, and payment processing that follows PCI DSS requirements. TriveniCo regularly reviews its security practices and will report material security incidents to merchants without undue delay.

7. Data Subject Rights and Cooperation

TriveniCo will provide reasonable assistance to merchants in responding to requests from data subjects to exercise their rights, such as access, rectification, erasure, and portability. Where a data subject contacts TriveniCo directly, TriveniCo will forward the request to the relevant merchant to the extent permitted by law.

8. Breach Notification

TriveniCo will notify affected merchants without undue delay after becoming aware of a personal data breach involving their customer data, and will provide information reasonably necessary for the merchant to meet its own notification obligations.

9. Deletion and Return of Data

Upon termination of the Services, TriveniCo will, at the merchant's choice, delete or return the customer data, except where TriveniCo is required by law to retain copies. TriveniCo will delete such data within a reasonable timeframe after the termination of the Services or the expiry of any mandatory retention period.

10. Contact

For questions about this Data Processing Agreement, contact TriveniCo at legal@trivenico.com.