Create your own ecommerce website and start selling successfully with ShopWired today

Create your ecommerce website on ShopWired today.
Start today with 14 days free

Create your own ecommerce website and start selling successfully with ShopWired today

Create your ecommerce website on ShopWired today.
Start today with 14 days free

Data Processor Agreement

Last updated: 1st March 2026

This Data Processor Agreement ("DPA") forms part of and amends the ShopWired Terms & Conditions ("Agreement") entered into between you ("Customer") and Platform 21 Limited, trading as ShopWired.

Platform 21 Limited is incorporated in England and Wales with company number 12507062 and its registered office is at Suite 3 Queens Chambers, 61 Boldmere Road, Sutton Coldfield, England, B73 5XA.

This DPA is intended to satisfy Article 28 UK GDPR and, where applicable, Article 28 EU GDPR.

A. Overview and definitions

  1. In this DPA:

    i) "Company" means Platform 21 Limited trading as ShopWired.

    ii) "Customer" means the person or organisation using the Service.

    iii) "Data Protection Legislation" means all applicable data protection legislation including the UK GDPR, Data Protection Act 2018, PECR, the EU GDPR where applicable, together with any legislation replacing or supplementing them.

    iv) "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", "Sub-Processor" and "Supervisory Authority" have the meanings given by the applicable Data Protection Legislation.

    v) "Service" means the ecommerce platform and associated services supplied by the Company.

B. Roles of the parties

  1. The Customer acts as Controller of Personal Data processed through the Service except where it acts as Processor for another Controller.
  2. The Company acts as Processor when processing Personal Data on behalf of the Customer for the purpose of providing the Service.
  3. The Company may also process certain Personal Data as an independent Controller where required to comply with legal obligations, regulatory requirements, fraud prevention, billing, security monitoring or other legitimate business purposes.
  4. The Company shall process Personal Data only on the documented instructions of the Customer unless otherwise required by applicable law.
In plain English

This agreement explains how ShopWired processes personal data on your behalf.

It has been updated to reflect the UK GDPR and current data protection law.

Most of the time you decide why customer data is collected and ShopWired processes it for you. In limited situations, such as legal compliance or fraud prevention, ShopWired processes data for its own legal obligations.

ShopWired will only process your data in accordance with your instructions unless the law requires otherwise.

C. Processing of Personal Data

  1. The Company shall Process Personal Data solely for the purpose of providing, maintaining, securing and supporting the Service in accordance with the Agreement and this DPA.
  2. The subject matter of the Processing is the provision of the ShopWired ecommerce platform and associated services.
  3. The duration of the Processing shall be for the duration of the Agreement unless applicable law requires a longer retention period.
  4. The categories of Data Subjects may include the Customer's employees, administrators, end customers, prospective customers, suppliers and any individuals whose Personal Data is uploaded into the Service.
  5. The categories of Personal Data may include names, postal addresses, email addresses, telephone numbers, IP addresses, order history, delivery information, customer communications and other Personal Data uploaded by the Customer.
  6. The Customer shall not intentionally upload Special Category Personal Data unless the Company has expressly agreed in writing that such Processing forms part of the Service.
  7. The Customer remains responsible for ensuring that it has a lawful basis for collecting and providing Personal Data to the Company.
In plain English

ShopWired only processes customer information so it can provide the services you have subscribed to.

You remain responsible for collecting customer data lawfully and ensuring that you have the appropriate privacy notices and legal basis.

Unless we've specifically agreed otherwise, you should not store sensitive personal data such as health, biometric or criminal records within ShopWired.

D. Sub-Processors

  1. The Company may engage Sub-Processors to assist in providing the Service.
  2. Current ShopWired group Sub-Processors include ShopWired Operations Limited, ShopWired Payments Limited and ShopWired Experts Limited.
  3. The Company may appoint or replace Sub-Processors from time to time and shall ensure each is bound by written contractual obligations providing substantially equivalent protection for Personal Data.
  4. An up-to-date list of Sub-Processors will be made available on request or published on the ShopWired website.

E. Security of Processing

  1. The Company shall implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Such measures may include encryption where appropriate, access controls, authentication mechanisms, logging and monitoring, vulnerability management, secure backup procedures, disaster recovery arrangements and regular security reviews.
  2. Security measures shall be reviewed periodically and may be updated to reflect changes in technology, threats and the nature of the Service.
  3. The Company shall take reasonable steps to ensure the ongoing confidentiality, integrity, availability and resilience of systems used to process Personal Data.

F. Confidentiality

  1. The Company shall ensure that personnel authorised to process Personal Data are subject to appropriate confidentiality obligations.
  2. Access to Personal Data shall be limited to those individuals who require access for the performance of their duties.

G. Assistance with Data Subject Rights

  1. The Company shall provide reasonable assistance to enable the Customer to respond to requests made by Data Subjects under applicable Data Protection Legislation.
  2. Where legally permitted, the Company shall notify the Customer if it receives a request directly from a Data Subject relating to Personal Data processed on the Customer's behalf.

H. Personal Data Breaches

  1. The Company shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on the Customer's behalf.
  2. Such notification shall include, where reasonably available, sufficient information to assist the Customer in complying with its legal obligations.
  3. The Company shall take appropriate steps to investigate, contain and remediate the effects of the Personal Data Breach.
In plain English

ShopWired uses carefully selected service providers to help deliver the platform. They must protect your customers' information to substantially the same standard as ShopWired.

We continually review our security controls and restrict access to customer data to authorised personnel only.

If a security incident affects your data, we'll tell you without undue delay and help you meet your legal obligations.

We'll also reasonably assist if one of your customers exercises their privacy rights.

I. International Transfers

  1. Where Personal Data is transferred outside the United Kingdom or European Economic Area, the Company shall ensure that appropriate safeguards are implemented in accordance with applicable Data Protection Legislation.

J. Return and Deletion of Personal Data

  1. Upon termination of the Agreement and at the Customer's written instruction, the Company shall delete or return Personal Data unless retention is required by law.
  2. The Company may retain information required for legal, regulatory, accounting or fraud prevention purposes for the applicable statutory retention period.

K. Audit and Compliance

  1. The Company shall make available information reasonably necessary to demonstrate compliance with this DPA.
  2. Where reasonably required, the parties shall cooperate in relation to information requests concerning the Processing of Personal Data.

L. General Provisions

  1. If any provision of this DPA is found to be unenforceable, the remaining provisions shall remain in full force and effect.
  2. This DPA forms part of the Agreement. Where there is any inconsistency, this DPA shall prevail in relation to the Processing of Personal Data.
  3. The Company may amend this DPA from time to time by publishing an updated version on the ShopWired website or otherwise notifying the Customer.
  4. This DPA shall be governed by the laws of England and Wales and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

Schedule 1 – Processing Details

Subject matterProvision of the ShopWired ecommerce platform and related services.
DurationFor the duration of the Agreement.
Nature of processingHosting, storage, transmission, support, backups, maintenance, payment integrations and related ecommerce functionality.
Categories of Data SubjectsCustomers, prospective customers, account users, employees, suppliers and other individuals whose Personal Data is uploaded by the Customer.
Categories of Personal DataNames, addresses, email addresses, telephone numbers, IP addresses, order information, customer communications, payment references and other Personal Data uploaded by the Customer.
Special category dataThe Customer should not intentionally upload Special Category Personal Data unless expressly agreed in writing.
In plain English

If data ever needs to leave the UK or EEA, ShopWired will use legally recognised safeguards.

When your contract ends, we'll delete or return your data unless the law requires us to keep some of it.

This agreement overrides the main Terms & Conditions where data protection is concerned.

The schedule summarises exactly what personal data ShopWired processes and why.