Data protection

Data processing addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between Koudhai LLC (“Provider”) and a merchant that signs a MyPet Club order form (“Merchant”). It applies when Provider processes customer personal data for Merchant. If no signed service agreement exists, this page alone does not create a customer relationship.

Roles and instructions

Merchant is the controller or business for its customer relationship. Provider is the processor or service provider when it handles customer personal data to provide, secure, support, and improve the contracted service under Merchant’s documented instructions. Merchant is responsible for a lawful basis, required notices, and the accuracy and legality of its instructions.

Provider will not sell or share customer personal data, use it for cross-context behavioral advertising, or retain, use, or disclose it outside the direct business relationship except to provide the service, secure it, follow Merchant’s documented instructions, or as permitted or required by law.

Confidentiality and security

Provider will limit access to authorized personnel and require confidentiality. Provider will maintain safeguards appropriate to the risk, including tenant-scoped authorization, least-privilege service access, encryption in transit, managed encryption at rest where supported by the provider, secrets management, payment-webhook verification, audit and financial records, logging designed to avoid sensitive payloads, backup and recovery controls, and automated tenant-isolation tests.

Assistance

Taking into account the nature of processing and information available, Provider will reasonably assist Merchant with verified data-subject requests, security obligations, legally required impact assessments, regulator inquiries, and evidence of compliance. Merchant remains responsible for responding to its customers and regulators unless the parties agree otherwise.

Security incidents

Provider will notify Merchant without undue delay after confirming a security incident affecting customer personal data, provide available information needed for Merchant’s response, take reasonable containment and remediation steps, and provide updates as material information becomes available. Notification is not an admission of fault.

Subprocessors

Merchant authorizes the providers on the current Subprocessor Schedule. Provider will require applicable data-protection duties from subprocessors and remains responsible for their performance to the extent required by law. Provider will give reasonable advance notice of a material new subprocessor so Merchant may raise a documented data-protection objection.

Return and deletion

During the service term, Merchant may use available export and deletion controls. After termination or a lawful written instruction, Provider will return or delete customer personal data within a commercially reasonable period unless retention is legally required. Protected backup copies may remain until their ordinary expiration and will not be restored except for recovery or legal purposes.

International transfers

The launch service is offered to U.S. merchants. Merchant must not direct Provider to process restricted international data without first confirming the required safeguards. If an EEA, UK, or other restricted transfer becomes applicable, the parties will use the then-current lawful transfer mechanism and complete any required annexes before that processing begins.

Information and audits

Provider will make available information reasonably necessary to demonstrate compliance, including current security and subprocessor information. If that information is insufficient, Merchant may request a narrowly scoped review no more than once each year, or after a confirmed material incident, subject to confidentiality, reasonable notice, protection of other customers, and reimbursement of unusual third-party costs. No certification is promised.

Processing details

Contact and order of precedence

Email privacy@mypetclub.pet for privacy matters and security@mypetclub.pet for incidents. This DPA controls over conflicting service terms only for the processing of customer personal data. A signed order form controls commercial scope and identifies the Merchant.