Fehrist legal center
Data Processing Terms
Last updated:
These Data Processing Terms ("DPT") form part of the agreement between the merchant ("Controller") and Fehrist ("Fehrist" or "Processor") when Fehrist processes merchant customer personal data to provide the Service. Capitalized terms not defined here have the meaning in the Terms of Service.
1. Scope and roles
The Controller determines the purposes and lawful means of processing merchant customer data. Fehrist processes that data on documented instructions to host storefronts, process checkouts and orders, manage customers and inventory, provide support, prevent fraud and perform other enabled platform functions. Fehrist remains an independent controller for its own account, billing, security and legal-compliance data as described in the Privacy Policy.
2. Controller instructions
The agreement, product configuration and authorized support requests are the Controller's documented instructions. Fehrist will notify the Controller if an instruction appears to violate applicable data-protection law, unless law prohibits the notice. The Controller is responsible for lawful collection, notices, consents, instructions and use of data.
3. Processing details
- Subject: provision and support of the Fehrist ecommerce Service.
- Duration: the account term plus export, deletion, backup and legally required retention periods.
- People: customers, prospective customers, recipients, merchant staff, suppliers and contacts whose data the Controller submits.
- Data: identifiers, contact and delivery details, order and payment references, product interactions, support records, device/usage data and merchant-defined fields.
- Sensitive data: not intentionally required. The Controller must not submit special-category or highly sensitive data unless the Service expressly supports it and the parties agree appropriate safeguards.
- Operations: collection, storage, organization, transmission, retrieval, support, analysis at the Controller's instruction, restriction, export and deletion.
4. Confidentiality
Fehrist ensures that people authorized to process merchant customer data are bound by confidentiality and receive access appropriate to their role.
5. Security
Fehrist maintains technical and organizational measures appropriate to risk, including encrypted transport, access control, credential protection, tenant-scoped authorization, logging, monitoring, backups, vulnerability management and incident response. Additional public information is available on the Security page.
6. Subprocessors
The Controller gives general authorization for Fehrist to use subprocessors needed for infrastructure, communications, security, analytics, support and enabled services. Fehrist will impose data-protection obligations appropriate to the service and remains responsible for its processing duties. A current list and change notices can be requested at privacy@fehrist.com. A Controller with a reasonable data-protection objection should contact us promptly; the parties will seek a practical alternative, which may include disabling the affected feature.
7. International transfers
Where merchant customer data is transferred across borders and law requires a transfer mechanism, the parties will rely on an applicable adequacy decision, approved contractual clauses or another lawful mechanism. Fehrist will provide reasonable information needed for a transfer assessment and apply supplementary safeguards where appropriate.
8. Individual requests
Taking into account the nature of processing, Fehrist provides product tools and reasonable assistance for access, correction, export, deletion, restriction and objection requests. If Fehrist receives a request relating to Controller data, it may direct the person to the Controller unless law requires a direct response.
9. Assessments and consultations
Fehrist will provide reasonable information to help the Controller complete legally required impact assessments or regulator consultations concerning the Service, considering the information available to Fehrist.
10. Security incidents
Fehrist will notify the Controller without undue delay after confirming a personal data breach affecting merchant customer data. Notice will include available information about the nature, likely consequences, affected data and mitigation, with updates as the investigation progresses. Notice is not an admission of fault. Security reports: security@fehrist.com.
11. Return and deletion
During the account term, the Controller may use available export tools. After termination and any stated export period, Fehrist will delete or anonymize merchant customer data in active systems unless law requires retention. Backup copies expire through normal secure rotation and remain protected and unavailable for ordinary use while retained.
12. Information and audits
Fehrist will make information reasonably necessary to demonstrate compliance available. Where documentation is insufficient and law grants an audit right, the Controller may request a proportionate audit no more than once annually, on reasonable notice, during business hours and subject to confidentiality, security and other customers' rights. The Controller bears its audit costs unless a material breach is found.
13. Government requests
Fehrist will review legally binding requests, challenge overbroad demands where reasonable, disclose only required information and notify the Controller unless prohibited by law.
14. Priority and contact
If these DPT conflict with the Terms on processing merchant customer data, these DPT control. Questions and requests: privacy@fehrist.com.