1. Purpose and scope
This Data Processing Addendum (“DPA”) supplements and is incorporated by reference into the Funnelish Terms of Service (available at funnelish.com/tos), together with any additional terms applicable to the Funnelish services you use (together, the “Terms”), between you, the individual or entity that has created a Funnelish account (“you”, “your” or “Merchant”), and Ginigo Ltd., a company registered in England and Wales under number 10169897 with registered office at Gw 522, 5th floor The Grange, 100 High Street, London, N14 6BN, trading as “Funnelish” (“Funnelish”, “we”, “us” or “our”). In case of any conflict between the Terms and this DPA, this DPA prevails with respect to the processing of Customer Personal Data.
1.1 Your account data
When you sign up for Funnelish, we collect certain account and subscription-related data from you, such as your name, email address, contact details and billing information (“Merchant Account Data”). We act as the Data Controller of Merchant Account Data, and our processing of it is described in our Privacy Policy (funnelish.com/privacy-policy), not this DPA.
1.2 Your customers’ data
When you use the Funnelish platform to build funnels, stores and checkout flows and to sell to your own customers, you collect personal data from those customers — for example at checkout or through forms on your pages (“Customer Personal Data”). You act as the Data Controller of Customer Personal Data, and Funnelish acts as your Data Processor when we host, store and otherwise process it on your behalf in order to provide the Services.
1.3 Purpose of this DPA
This DPA sets out the parties’ respective rights and obligations under Applicable Data Protection Laws — including Article 28(3) of the UK GDPR and the EU GDPR — with respect to Funnelish’s processing of Customer Personal Data as your Processor.
2. Definitions
Capitalised terms not defined in this DPA have the meaning given in the Terms. In this DPA:
“Applicable Data Protection Laws” means any data protection or privacy laws applicable to the processing of Personal Data under the Terms, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), the UK GDPR and the UK Data Protection Act 2018, each as amended, updated or replaced from time to time;
“Customer” means an individual who visits, engages with, or purchases from, a funnel, store or page you operate using the Services;
“Data Controller”, “Data Processor”, “Data Subject”, “Personal Data”, “processing” and “Personal Data Breach” have the meanings given in Applicable Data Protection Laws;
“Customer Personal Data” means Personal Data from or about your Customers that we process on your behalf in providing the Services, as described in Appendix A;
“Sub-processor” means any third party engaged by Funnelish to process Customer Personal Data on your behalf;
“Standard Contractual Clauses” means the standard contractual clauses approved by the European Commission in decision 2021/914/EC of 4 June 2021, and “UK Addendum” means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner’s Office under s.119A(1) of the Data Protection Act 2018, in each case as amended or replaced from time to time.
3. Nature of the processing and roles of the parties
You are the Data Controller and Funnelish is the Data Processor with respect to Customer Personal Data. Funnelish processes Customer Personal Data only in order to provide, maintain and improve the Services in accordance with the Terms and your instructions. The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are described in Appendix A.
The parties agree that the Terms, this DPA and your use and configuration of the Services together constitute your complete and documented instructions to Funnelish regarding the processing of Customer Personal Data (“Documented Instructions”).
4. Your obligations
As Data Controller of Customer Personal Data, you are responsible for complying with Applicable Data Protection Laws in your use of the Services. In particular, you represent and warrant that:
you have a valid legal basis for the processing of Customer Personal Data, including making it available to Funnelish, and have provided all notices and obtained all consents, rights and permissions required under Applicable Data Protection Laws, including posting an up-to-date and accurate privacy policy on your funnels and storefronts;
your Documented Instructions are lawful, and you will not instruct Funnelish to process Customer Personal Data in violation of Applicable Data Protection Laws;
you provide your Customers with the ability to exercise their rights over their Personal Data as required by Applicable Data Protection Laws; and
you will notify us promptly of any regulatory or Data Subject inquiry or complaint concerning the processing of Customer Personal Data by Funnelish, unless prohibited by law.
5. Our obligations as your Processor
5.1 Documented instructions
We will process Customer Personal Data only in accordance with your Documented Instructions, unless we are required to process it otherwise by law to which we are subject — in which case we will inform you of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.
5.2 Confidentiality
We ensure that persons authorised by us to process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and that access is limited to personnel who need it to provide the Services.
5.3 Security
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, we implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, theft, alteration or disclosure. Our current measures are described in Appendix B.
5.4 Sub-processors
You provide a general authorisation for Funnelish to engage Sub-processors, including our affiliates, to process Customer Personal Data in connection with the Services. We maintain a current list of Sub-processors at [funnelish.com/legal/subprocessors – or Appendix C], and will provide a mechanism for you to receive notice of any intended addition or replacement of a Sub-processor at least [30] days in advance. You may object to a new Sub-processor on reasonable data-protection grounds; if we are unable or unwilling to accommodate your objection, you may terminate your use of the affected Services in accordance with the Terms. Where we engage a Sub-processor, we do so under a written contract imposing data-protection obligations substantially the same as those in this DPA, and we remain fully liable to you for the performance of each Sub-processor’s obligations.
5.5 Assistance
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance, by appropriate technical and organisational measures and insofar as possible, to help you: (a) respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws; and (b) comply with your obligations regarding security of processing, Personal Data Breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 of the UK and EU GDPR). If we receive a request directly from one of your Customers, we will not respond to it ourselves (except to direct the Customer to you) and will forward it to you without undue delay.
5.6 Personal Data Breach notification
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Our notification will describe, to the extent the information is reasonably available to us, the nature of the breach (including, where possible, the categories and approximate number of Data Subjects and records concerned), its likely consequences, the measures taken or proposed to address it, and a contact point for further information. Our notification of a Personal Data Breach is not an acknowledgement of fault or liability.
5.7 Deletion and return
During your use of the Services, you can access, export and delete Customer Personal Data using the tools available in your account. Following termination of the Services, we will, at your choice, delete or return Customer Personal Data and delete existing copies, except where retention is required by law or occurs under our standard backup and retention cycles — in which case we will continue to protect the retained data in accordance with this DPA and delete it at the end of the applicable retention period. Our standard retention periods are described in Appendix A.
5.8 Audits and demonstrating compliance
We will make available to you information reasonably necessary to demonstrate compliance with our obligations under Article 28 of the UK and EU GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. We may satisfy an audit request by providing, subject to confidentiality, our most recent third-party audit report or certification [e.g. GDPR audit report / ISO 27001 / SOC 2 – confirm what exists after the Sprinto audit]. Any further audit must be reasonable in scope, agreed in advance, conducted during business hours no more than once annually (unless required by Applicable Data Protection Laws or a supervisory authority), and subject to confidentiality obligations.
5.9 Unlawful instructions
We will inform you immediately if, in our opinion, one of your instructions infringes Applicable Data Protection Laws. We are not, however, obliged to actively monitor your compliance with Applicable Data Protection Laws.
6. International data transfers
You acknowledge that Customer Personal Data may be transferred to, and processed in, countries outside the UK and the European Economic Area, including the United States, where Funnelish or its Sub-processors operate. Any such transfer is made in compliance with Applicable Data Protection Laws, using one or more of the following safeguards as applicable to the transfer:
an adequacy decision or adequacy regulations covering the destination country;
the Standard Contractual Clauses (2021), which are incorporated into this DPA by reference for transfers they govern, completed with the information in Appendix A and Appendix B;
the UK Addendum to the Standard Contractual Clauses, for transfers subject to UK GDPR;
the EU-U.S. Data Privacy Framework and its UK Extension, where the recipient is certified under that framework; or
any successor or replacement transfer mechanism approved under Applicable Data Protection Laws.
If a transfer mechanism we rely on is amended, replaced or invalidated, we may adopt an alternative lawful transfer mechanism, and the updated mechanism will apply to transfers under this DPA.
7. Precedence, changes and contact
Conflicts between the Terms or our Privacy Policy on the one hand, and this DPA on the other, are resolved in favour of this DPA with respect to the processing of Customer Personal Data. We may update this DPA from time to time by posting the amended version at [funnelish.com/dpa]; amendments take effect on the date of posting, and your continued use of the Services after that date constitutes your acceptance of the amended DPA. If you have questions about this DPA or wish to exercise any right under it, contact us at support@funnelish.com, or by post at Ginigo Ltd., 191 Friern Barnet Lane, London, England, N20 0NN.
Appendix A – Details of the processing
Subject matter | Provision of the Funnelish Services to the Merchant, including funnel and store building, checkout, order processing, subscriptions and related features. |
Duration | The duration of the Terms, plus the period until deletion or return of Customer Personal Data under Section 5.7. |
Nature of the processing | Collection (at checkout and via forms on Merchant pages), recording, hosting, storage, retrieval, use, transmission to payment and fulfilment providers, and deletion, as described in the Terms. |
Purpose of the processing | The performance of the Services as described in the Terms, including enabling the Merchant to process orders, payments, subscriptions and fulfilment for its Customers. |
Categories of Data Subjects | Customers of the Merchant — individuals who visit, engage with, or purchase from the Merchant’s funnels, stores or pages. |
Categories of Personal Data | Customer name; email address; shipping and billing address; phone number; order and transaction details; payment status (payment card data is processed by payment providers, not stored by Funnelish – confirm); IP address; device, browser and network information; activity on the Merchant’s pages; any other Personal Data the Merchant or its Customers choose to submit through the Services. |
Sensitive data | Not intended to be processed. If Merchants may collect sensitive data through their funnels, state the additional safeguards and consent requirements that apply. |
Frequency of the transfer | Continuous, for the duration of the Terms. |
Retention | Customer Personal Data is retained only for as long as there is a valid reason to store or process it in connection with the Services. Deletion is initiated upon termination of the Services, at the end of any agreed retention period, or upon a validated deletion request from the Merchant. Data is permanently deleted from storage, databases and backups using secure deletion methods designed to prevent recovery, with backup copies purged in accordance with our backup retention cycle. We may retain data where required to comply with legal obligations, resolve disputes or enforce agreements, and may anonymise data as an alternative to deletion where lawful. Confirmation of completed deletion is available on request. |
Competent supervisory authority | The UK Information Commissioner’s Office and/or the supervisory authority determined in accordance with Applicable Data Protection Laws and, where relevant, the Standard Contractual Clauses. |
Appendix B – Security measures
Funnelish maintains an information security programme that includes the following technical and organisational measures. [Complete each item from the internal policies maintained in the compliance programme — Data Protection, Data Classification, Data Retention and Data Breach Notification policies — describing outcomes, not internal policy text.]
Encryption
All Customer Personal Data is encrypted in transit (TLS) and at rest.
Access control
Role-based access on least-privilege principles; multi-factor authentication for administrative and production access; access reviewed regularly and revoked on role change or departure; access activity logged.
Availability, backup and recovery
Redundant cloud infrastructure; continuous/scheduled backups; documented business-continuity and disaster-recovery procedures with periodic testing.
Vulnerability and change management
Vulnerability management and testing programme; controlled, logged and reviewed changes to production systems.
Incident response
Documented incident response and Personal Data Breach notification procedures, including detection, escalation, mitigation, and notification consistent with Section 5.6.
Personnel
Confidentiality obligations in employment terms; periodic security-awareness training.
Data lifecycle
Data classification and handling standards; defined retention and secure deletion processes.
We review these measures from time to time and may update this Appendix; updates will not materially reduce the overall level of protection during the term of the Services.
Appendix C – Sub-processors
The Sub-processors currently engaged by Funnelish to process Customer Personal Data are listed below [or: are listed at funnelish.com/legal/subprocessors, which forms part of this DPA]. Each Sub-processor processes Customer Personal Data only in connection with the Services and for the duration of its agreement with Funnelish.
Sub-processor | Purpose / processing activity | Location & transfer safeguard |
Cloud hosting provider | Google Cloud, Fastly, Cloudflare | Global (GBP), Global edge.. |
Payment gateway(s) | Spreedly, Stripe, PayPal, Airwallex, Checkout.com, NMI, Mollie, Klarna, Razorpay | Global |
Email / notification provider | Sendgrid, Twillio | Global |
Analytics / infrastructure | ClickHouse Cloud | Global (GBP) |