Legal
Data processing addendum
The addendum offered to Enterprise and Partner accounts: who does what with personal data, how it is protected, and the sub-processor schedule it refers to.
- In force from
- Owner
- Martin Clavell
- Operated by
- BEMATIC ONLINE SAS
At a glance
- You are the controller; BEMATIC ONLINE SAS is the processor.
- It applies without signature to Enterprise and Partner accounts; a countersigned copy is available.
- We process personal data only on your documented instructions.
- A breach is notified in time for you to meet the GDPR’s 72 hours.
- Transfers rest on Uruguay’s EU adequacy decision, then the Data Privacy Framework or the Standard Contractual Clauses.
- Governed by Uruguayan law, with the courts of Montevideo.
01The parties and roles
The customer is the controller of the personal data processed under their account. BEMATIC ONLINE SAS, which operates SuiteAnalytics and is owned by Martin Clavell, is the processor. This addendum applies where the customer’s use of SuiteAnalytics involves personal data and takes effect with the terms of service.
It is governed by the laws of the Oriental Republic of Uruguay, and the the courts of Montevideo, Uruguay have exclusive jurisdiction over any dispute arising from it.
02What is processed, and why
Subject matter. Auditing a SuiteCommerce storefront the customer has verified, or — for a partner account — a storefront covered by the partner clauses of the terms, and producing reports from it.
Categories of data subject. The customer’s own users: the people who hold accounts with us on the customer’s behalf. Incidentally, any person named in the public text of the storefront being audited — an author on a blog page, a name in a testimonial.
Categories of personal data. Account holders’ email addresses and names; the billing contact held by our payment processor; in the audit log, for each sign-in, sign-out and action of a user, the network it came from truncated to the first three parts of an IPv4 address or the first three groups of an IPv6 one, and the browser and operating system, kept 24 months and shown to the customer’s own owners; and the storefront content described above. The relationship an organization declares to a storefront at signup is recorded against the organization, not the person, and is a self-declared business fact rather than a verified one. No special categories of data are processed, and none are requested.
What is never processed. Nothing behind a storefront login is fetched, and no order, customer or shopper data is read. That is a scope decision enforced at the crawler, not a setting. Configuration values that look like credentials are recorded by path, length and character classes, and the value itself is discarded.
03Instructions
We process personal data only on the customer’s documented instructions, which are this addendum, the terms of service and the actions the customer takes in the product. We tell the customer if an instruction appears to conflict with applicable law rather than carrying it out.
04Confidentiality
Everyone with access to personal data processed under this addendum is bound to confidentiality, and access is granted on the least privilege the task needs.
05Security
Transport is HTTPS throughout. Every query against customer data is scoped to the customer’s organization at the data layer rather than in a view. Destinations for alerts and webhooks are stored sealed under a key the application service alone holds, and the key can be rotated without a customer noticing. Secrets are never written to a log: what may be logged is an allowlist, and a field outside it is dropped. These are the measures we operate, described so a customer’s reviewer can check them against what the product does.
06Sub-processors
Customers are notified before a sub-processor is added. Enterprise customers may object. The schedule below is generated from the same source as the sub-processor list in the terms, so the two cannot differ.
| Sub-processor | Purpose | What it can see |
|---|---|---|
| Railway | Hosting, Postgres | Everything the application holds, at the infrastructure level |
| Cloudflare R2 | Object storage: HTML, DOM dumps, screenshots, bundles, PDFs | Stored objects |
| PayPal | Payments | The payer’s PayPal account and payment instrument, and what is being paid for. We never see card data |
| Resend | Transactional email | Recipient address and the body of our own emails |
| Sentry | Error monitoring | Stack traces and request metadata, allowlist-scrubbed |
| OpenAI | classifier, analyst and writer model roles | Redacted evidence slices only |
| Anthropic | Second adapter for the same roles, switchable per role by configuration | Redacted evidence slices only |
| GeneratePDF | PDF rendering | The report Markdown we send it, for an account entitled to a PDF, from our API service only |
| Google (Google Analytics) | Website analytics on our public pages, behind a consent banner | Pages viewed, referrer, device, browser and approximate location on public pages; a cookie identifier only after you accept. Never signed-in pages or reports |
| Microsoft (Clarity) | Session recordings and heatmaps of our public pages, only after you accept | How a public page was used — clicks, scrolls, mouse movement and the page as shown — with form contents masked. Never signed-in pages or reports |
| Google (reCAPTCHA) | Telling people from bots on the sign-in, sign-up, contact, opt-out and pre-check forms and the admin sign-in | On those pages only: your IP address, browser and device details and how the page was used, to produce a score. Not used for advertising |
07International transfers
The operator is established in Uruguay, which the European Commission recognizes as providing an adequate level of protection for personal data (Decision 2012/484/EU, confirmed in its 2024 review), so personal data transferred to us from the European Economic Area needs no further safeguard. Where a sub-processor processes personal data outside the region it came from — most of ours are established in the United States — the transfer relies on that provider’s certification under the EU–U.S. Data Privacy Framework where it holds one, and otherwise on the Standard Contractual Clauses in its data processing terms.
08Assisting the controller
We assist the customer with requests from data subjects — access, correction, erasure, portability — and with data protection impact assessments and prior consultations, using the information the product already holds. A request about a specific audit can be answered from the audit log, which records who requested a crawl of which domain and which report it produced.
09Personal data breach
We notify the customer without undue delay after becoming aware of a personal data breach affecting their data. Where the General Data Protection Regulation applies, that is the 72 hours it allows a controller to notify its supervisory authority, and we notify in time for the customer to meet it rather than at the deadline itself. The notice states what happened, which data and how many records are affected as far as we know at the time, what we have done, and what we are still doing. We send a first notice with what is known rather than a complete one later.
10Deletion and return
On termination, deleting the customer’s organization deletes its audits, snapshots, findings, reports, comparisons, alerts, schedules, destinations and credit ledger, and purges the stored objects those rows pointed at — the raw HTML, the DOM dumps, the screenshots and the PDFs. The purge lists each prefix empty before it reports itself done. What survives is the audit log with the organization detached, and the payment records our payment processor keeps for the statutory period, which are theirs rather than ours to delete. Retention before termination is the schedule in the privacy notice, which is generated from the same constants the deletion sweep reads.
Separately from this addendum, the owner of a storefront the customer audited may ask us directly to delete what we hold about that domain, and we will within 30 days of confirming they control it. That request is not the customer’s to refuse and we do not ask their permission — an opt-out by a merchant who is not our customer is a promise we make to the person it protects, and one a partner agreement cannot bargain away. We tell the customer that the data went.
11Audits and information
We make available the information needed to demonstrate compliance with this addendum. An Enterprise customer may audit, once in any twelve months and on thirty days’ written notice, at their own cost unless the audit finds a material breach of this addendum. We claim no certification and no third-party attestation: where a customer’s questionnaire asks for one, the honest answer is that we do not hold it.
12Execution
This page is the addendum, and it applies without signature to an Enterprise or Partner account from the date above. Where a customer’s procurement needs a countersigned copy, ask and we return one executed on behalf of the processor; a customer’s own paper is considered but this addendum is what we offer. Requests and questions about it go to [email protected].