This Data Processing Agreement ("DPA") forms part of the Terms of Service between ACD Logistics, LLC ("Processor," "we," "our," or "us") and the customer using AIMventory ("Controller," "you," or "your"). This DPA governs the processing of personal data and business data by the Processor on behalf of the Controller.
You are the Controller of your data. We are the Processor acting on your behalf. We process data only as necessary to provide the Service and as instructed by you.
| Category | Examples |
|---|---|
| Account data | Name, email, phone, business name, timezone |
| Inventory data | Product names, SKUs, sizes, barcodes, costs, prices, quantities, conditions |
| Transaction data | Sales, purchase orders, payouts, fulfillments |
| Vendor/customer records | Names, emails, addresses, pricing tiers, notes |
| Marketplace data | Listings, credentials, sync metadata, order data from connected platforms |
| Usage data | IP addresses, device identifiers, feature usage, error logs |
We process data solely for the following purposes:
We treat all Business Data as confidential. We will not disclose, sell, license, or otherwise make available your Business Data to any third party except as described in this DPA.
We may use your Business Data internally to operate, maintain, troubleshoot, improve, and develop the Service. This includes customer support, debugging, performance optimization, and feature development. We may also generate and use aggregate or de-identified data derived from Business Data for analytics and Service improvement, provided such data does not identify you or any individual and cannot reasonably be used to reconstruct your confidential business information.
We will not:
Access to your data is limited to our personnel who require it to provide the Service. All personnel with access are bound by written confidentiality obligations. We maintain role-based access controls and audit logs for access to customer data.
We acknowledge that your Business Data may be subject to non-disclosure agreements with your suppliers, brands, or business partners. Our confidentiality obligations under this DPA are designed to be compatible with standard commercial NDAs. Data shared with connected platforms occurs only at your direction and configuration — we do not independently share your data with marketplaces or third parties.
You consent to our use of the following categories of subprocessors:
We require all subprocessors to enter into written agreements that impose data protection obligations no less protective than those in this DPA. We remain responsible for our subprocessors' compliance.
We will provide notice before engaging a new subprocessor that processes Customer Data. If you reasonably object to a new subprocessor, we will work with you to find an alternative or allow you to terminate the affected portion of the Service.
We implement and maintain appropriate technical and organizational measures, including:
In the event of a Data Breach affecting your data, we will notify you without undue delay and no later than seventy-two (72) hours after becoming aware of the breach. The notification will include:
We retain your data for as long as necessary to provide the Service and as described in our Privacy Policy. Business records required for legal, tax, or accounting purposes may be retained as required by applicable law.
Upon termination of your account, we will make your data available for export for a commercially reasonable period (no less than thirty (30) days). After this period, we will delete or anonymize your data within ninety (90) days, except where retention is required by law. We will confirm deletion in writing upon request.
We will assist you in responding to data subject requests, including requests to:
Upon reasonable written request (no more than once per year), we will provide you with information necessary to demonstrate our compliance with this DPA. This may include security documentation, third-party audit reports or certifications, and written responses to reasonable inquiries.
Data is processed and stored in the United States. If your use of the Service involves the transfer of personal data from jurisdictions with data transfer restrictions, we will implement appropriate safeguards, such as standard contractual clauses, to ensure lawful transfer.
This DPA is effective as long as we process data on your behalf. The confidentiality obligations in Section 3 survive termination and continue for three (3) years after the last date we process your data, or indefinitely for trade secrets to the extent protected by applicable law.
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to data processing and confidentiality matters.