Last updated: August 24, 2026
Data Processing Agreement
1. Parties and Roles
This Data Processing Agreement (DPA) applies where a merchant using the TriveniCo platform acts as the data controller of its customers' personal data and TriveniCo acts as the data processor on that merchant's behalf. In this arrangement, the merchant determines the purposes and means of processing, and TriveniCo processes the data solely to provide the Services.
2. Scope and Purpose of Processing
TriveniCo processes customer data for the purpose of operating the merchant's storefront, marketplace listings, point-of-sale, orders, payments, CRM, analytics, and related features. TriveniCo processes personal data only on documented instructions from the merchant, including instructions transmitted through the configuration of the Services.
3. Categories of Data and Data Subjects
The categories of personal data processed include:
- Customer identifiers such as name, email address, phone number, and shipping address.
- Order and transaction details, including purchase history and payment references.
- Storefront interaction data such as messages, reviews, and support inquiries.
The data subjects are the merchant's customers, prospective customers, and other individuals whose data the merchant submits to the Services.
4. Duration of Processing
TriveniCo processes customer data for the duration of the merchant's use of the Services and for any period thereafter required to comply with legal obligations, resolve disputes, or enforce agreements, subject to the deletion and return provisions below.
5. Subprocessors
TriveniCo may engage subprocessors to help deliver the Services, including hosting, payment, email, analytics, and support providers. TriveniCo enters into written agreements with each subprocessor imposing data protection obligations consistent with this DPA and remains responsible for their performance. TriveniCo will maintain an up-to-date list of subprocessors and inform merchants of intended changes.
6. Security Measures
TriveniCo implements and maintains appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, network monitoring, and payment processing that follows PCI DSS requirements. TriveniCo regularly reviews its security practices and will report material security incidents to merchants without undue delay.
7. Data Subject Rights and Cooperation
TriveniCo will provide reasonable assistance to merchants in responding to requests from data subjects to exercise their rights, such as access, rectification, erasure, and portability. Where a data subject contacts TriveniCo directly, TriveniCo will forward the request to the relevant merchant to the extent permitted by law.
8. Breach Notification
TriveniCo will notify affected merchants without undue delay after becoming aware of a personal data breach involving their customer data, and will provide information reasonably necessary for the merchant to meet its own notification obligations.
9. Deletion and Return of Data
Upon termination of the Services, TriveniCo will, at the merchant's choice, delete or return the customer data, except where TriveniCo is required by law to retain copies. TriveniCo will delete such data within a reasonable timeframe after the termination of the Services or the expiry of any mandatory retention period.
10. Contact
For questions about this Data Processing Agreement, contact TriveniCo at legal@trivenico.com.