WholesaleAI Data Processing Addendum
Last updated: 14 July 2026
This Data Processing Addendum (DPA) forms part of the WholesaleAI Terms of Service between the Shopify merchant (Controller) and Realtime Comms Ltd, incorporated in England and Wales (Processor).
1. Processing instructions
The Processor will process personal data only to provide WholesaleAI, on the Controller's documented instructions, and as required by law. Installing, configuring and using the app are documented instructions. The Controller determines the lawful basis, recipients, target regions and outreach it approves.
2. Processing details
Processing lasts for the merchant's use of WholesaleAI and the limited retention period stated in the Privacy Policy. It includes collection, organisation, verification, storage, retrieval, drafting, transmission, suppression and deletion. Data subjects may include merchant personnel, business prospects, wholesale applicants and approved buyers. Data may include names, business contact details, company details, application content, Shopify customer identifiers, attributed order details and service activity. Special-category data is not intended for processing.
3. Confidentiality and security
The Processor limits personal-data access to authorised personnel bound by confidentiality and maintains appropriate technical and organisational measures, including encryption in transit and at rest, encrypted backups, production/development separation, least-privilege access, authentication, audit events, rate limiting, retention controls and incident-response procedures.
4. Sub-processors and transfers
The Controller authorises sub-processors needed to operate the features it uses, including Shopify, Apify, OpenAI, MillionVerifier, BounceBan, AnyMailFinder, Resend, Microsoft Azure Communication Services and Cloudflare. Realtime Comms Ltd remains responsible for its processor obligations and uses applicable transfer safeguards where required. Material sub-processor changes will be reflected in the Privacy Policy; a merchant may object on reasonable data-protection grounds by contacting us before continuing to use the affected feature.
5. Assistance
Taking account of the processing and information available to it, the Processor will reasonably assist with data-subject requests, security, breach notification, impact assessments and regulator consultations. The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data.
6. Deletion and return
On termination or a valid Shopify deletion webhook, the Processor will delete Controller data unless law requires retention. Encrypted backups expire within 30 days. Minimal suppression data may remain where needed to honour an opt-out and prevent further contact.
7. Information and audits
The Processor will provide information reasonably necessary to demonstrate compliance and permit a proportionate audit on reasonable advance notice, subject to confidentiality, security and avoidance of disruption. Existing reports and written evidence may be used first.
8. Contact
Data-protection enquiries: support@realtimecomms.co.uk