1. Scope and roles
This DPA applies when PriceIQ processes personal data for a customer under the Terms, an order form, or an enterprise agreement. The customer acts as controller and 700 Apps acts as processor unless applicable law assigns different roles. A signed DPA or order form may provide customer-specific terms.
2. Processing instructions
PriceIQ processes customer personal data only to provide, secure, support, and improve the contracted service; follow documented customer configuration; meet legal duties; or as otherwise agreed in writing. We will notify the customer if an instruction appears unlawful where permitted.
3. Data and subjects
Processing may cover workspace users, customer personnel, ecommerce contacts, and individuals represented in customer-imported data. Data may include identity, business contact, account, transaction, catalog, pricing, integration, support, usage, and security information. Customers must avoid unnecessary sensitive data.
4. Security and confidentiality
Personnel and service providers with access are bound by confidentiality. PriceIQ maintains proportionate technical and organizational measures including tenant isolation, access control, credential encryption, audit trails, rate limiting, monitored deployment, backups, and incident handling.
5. Subprocessors and transfers
The customer authorizes subprocessors reasonably required for hosting, database, email, payment, monitoring, and support. 700 Apps remains responsible for processor obligations passed to subprocessors and will use lawful transfer safeguards where data crosses jurisdictions.
6. Assistance and incidents
Taking account of the processing, PriceIQ will reasonably assist with data-subject requests, security assessments, breach obligations, and impact assessments. We will notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available relevant information.
7. Return, deletion, and audits
During the service, customers can export tenant data and submit governed erasure requests. At termination, data is returned or deleted according to the agreement, legal-retention requirements, and backup cycles. On reasonable written request, we provide relevant compliance information and support proportionate audits subject to confidentiality and operational safeguards.
8. Order of precedence and execution
This published DPA is the standard baseline and does not by itself identify customer-specific instructions, subprocessors, or transfer terms. If executed with an order or enterprise agreement, it forms part of that agreement. Signed negotiated terms prevail over this page in case of conflict. Request an execution copy at info@700-apps.com.