Skip to content
ChatPPC

Data Processing Agreement

What we do with personal data when we are handling it on your behalf, what you are responsible for, and what we are not allowed to do with it.

Version 1.4 · Last updated 6 September 2026

Who this is between

This Data Processing Agreement is between The Barkworth & Hathaway Group Ltd, registered in England and Wales, company number 11255288, at 25 West Street, Storrington, United Kingdom, RH20 4DZ (“we”, “us”, “ChatPPC”), and the customer who subscribes to ChatPPC (“you”).

It forms part of our terms of service and applies automatically from the moment you start using ChatPPC. You do not need to sign it or ask us for it. If your organisation requires a signed copy on its own paper, email support@chat-ppc.ai and we will arrange it.

Order of precedence. Where this agreement and the terms of service disagree about the handling of personal data, this agreement wins.

Start here: how little of this actually applies

Most agreements of this kind begin by assuming the supplier is holding large quantities of personal data. In our case that assumption is wrong, and it is worth explaining why before the detail.

ChatPPC requests no restricted Amazon roles and holds none. Your buyers’ names, delivery addresses, email addresses and phone numbers never enter our systems. They are not stored, not processed, and not accessible to us — not because we choose not to look, but because we never receive them. Amazon gates buyer identity behind four restricted roles, and we hold no approval for any of them.

Order and inventory records do reach us, without those fields. We need to know what sold and what is in stock to judge whether a product can be advertised profitably; we do not need to know who bought it, and we are not able to find out.

What we do hold is advertising and sales data, inventory and listing status, fee estimates, search query performance, and the cost information you give us. That is commercial data about products, not personal data about people.

So the personal data we process on your behalf is limited to what is described in Annex 1, and in most accounts it amounts to very little. This agreement exists to govern that narrow set properly, and to give you something to hand to anyone who asks.

1. Definitions

Applicable data protection law means the UK GDPR, the Data Protection Act 2018, and — where it applies to your use of ChatPPC — Regulation (EU) 2016/679 (the EU GDPR), each as amended or replaced.

Controller, processor, data subject, personal data, processing and special category data have the meanings given to them in applicable data protection law.

Customer personal data means personal data that we process on your behalf under this agreement, as described in Annex 1.

Security incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, customer personal data.

Sub-processor means a third party engaged by us to process customer personal data.

2. Who is responsible for what

Data protection law distinguishes between the party that decides why data is processed (the controller) and the party that processes it on the controller’s instructions (the processor). We occupy different roles for different data, and the distinction matters.

Your account data — we are the controller. Your name, email address and billing details are ours to hold, because we decide why we hold them: to provide and bill for the service. This agreement does not cover that. Our privacy policy does.

Customer personal data — we are the processor and you are the controller. Where any of the Amazon data you authorise us to access, or the information you give us, contains personal data, you decide the purpose and we act on your instructions. This agreement covers that, and only that.

Your own AI assistant — not ours to govern. When you ask ChatPPC a question inside your AI assistant, the data needed to answer it is returned into that assistant’s session because you asked for it. Your relationship with that provider is between you and them, and we are not a party to it.

3. What you are responsible for

This is a two-sided agreement, and these are yours:

  1. You must have the right to give us the data you give us, including the right to authorise our access to the Amazon accounts you connect.
  2. You must have a lawful basis for the processing you instruct, and must have given any privacy notices and obtained any consents your own obligations require.
  3. You must not put special category data into ChatPPC. That means data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation. The service is not designed for it, our security measures are not calibrated for it, and we do not expect to receive it. The same applies to criminal offence data, and to any data about children.
  4. You are responsible for the accounts and credentials you control, and for who in your organisation you give access to.

If you become aware that special category data has reached us, tell us and we will delete it.

4. What we will and will not do

We will:

  1. Process customer personal data only on your documented instructions. Your instructions are: this agreement, our terms of service, and the actions you take within the service. If we are ever required by law to process it otherwise, we will tell you first unless the law forbids us from doing so. If we believe an instruction breaches applicable data protection law, we will tell you.
  2. Keep it confidential. Anyone with access is bound by a duty of confidentiality, and access is granted on the basis of job duties only.
  3. Secure it. The measures we take are set out in Annex 2 and described in full on our security page. We will not weaken them during the term of your subscription.
  4. Help you meet your own obligations. If one of your data subjects exercises their rights and you need our help to answer, we will provide it. If a data subject contacts us directly, we will not respond substantively — we will pass the request to you, because it is yours to answer. We will also assist with your obligations around security, breach notification and data protection impact assessments, taking into account what we know and what you already have access to.
  5. Tell you quickly if something goes wrong. See §7.
  6. Give it back, or destroy it, when you leave. See §8.
  7. Show our working. See §6.

We will not:

  • Use your data for our own purposes, including to train models, build benchmarks, or generate market insight.
  • Sell it, or share it for behavioural advertising.
  • Disclose it to, or aggregate it with, another customer’s data. Ever.
  • Combine it with data from any other source outside our direct relationship with you.
  • Share it with anyone not named as a sub-processor in §5.
  • Transfer it outside the UK or the European Economic Area for our own purposes.

5. Sub-processors

You give us general authorisation to use the sub-processors below. A provider only qualifies as one, and only appears here, if all three of these hold: it acts on our instructions under contract and not for its own purposes; it is bound by written terms no less protective than this agreement; and it is one we can stand behind, because we remain liable to you for their acts and omissions as if they were our own. A provider we do not direct is not one we can promise for, so it does not go on this list.

Vercel Inc.

What they do
Application hosting and serverless compute
Where data sits
Dublin, Ireland (eu-west-1)
Entity
Incorporated in the United States
Amazon data
Receives Amazon Information

Supabase Inc.

What they do
Database hosting
Where data sits
Ireland (eu-west-1)
Entity
Incorporated in the United States
Amazon data
Receives Amazon Information

Resend Inc.

What they do
Transactional email delivery
Where data sits
Ireland (eu-west-1)
Entity
Incorporated in the United States
Amazon data
Receives no Amazon Information

The last row answers a narrower question than the list itself, and the two answers differ. Being a sub-processor means a provider may handle personal data we hold on your behalf. Receiving Amazon Information means data retrieved from your Amazon account passes through it. Our email provider is the first but not the second: sign-in links and service notices carry no Amazon data. We state both because Amazon’s Data Protection Policy asks solution providers to name everyone in the second group, and a reader comparing the two lists deserves to know why they are not the same length.

Each operates its own data processing terms, including Standard Contractual Clauses and the UK International Data Transfer Addendum, which govern any access from outside the EEA in the course of operating their services. Where each one stores customer personal data is stated above, and today that is Ireland for all of them.

We will not appoint a sub-processor that stores customer personal data outside the European Economic Area without telling you first under the change process below, naming the country and the safeguard relied on. That is a commitment about what we will do, rather than a description of today’s list — a description would stop being true the moment the list changed, and you would have no way of knowing.

Providers who are not sub-processors. We also use providers to handle data where we are the controller rather than you — your account details, your billing. They are not sub-processors, this agreement does not cover them, and they are named in our privacy policy instead. Some categories of provider, a payment processor among them, also process for their own regulatory purposes and so could never satisfy the conditions above. That is why they are named there and not here.

Changes. If we intend to add or replace a sub-processor, we will tell you by email at least 30 days beforehand. You may object on reasonable data protection grounds within 14 days of that notice. We will work with you in good faith to resolve it; if we cannot, you may cancel your subscription without penalty and we will refund any unused prepaid period.

6. Information and audits

You are entitled to satisfy yourself that we are doing what this agreement says. In practice:

  1. Ask us. We will answer questions about our processing in writing, and provide the information you reasonably need to demonstrate compliance, within 30 days.
  2. Read what we publish. Our security page describes the controls that are actually in place, and is deliberately honest about what we do not hold: as at the date of this version, no SOC 2 report, no ISO 27001 certification and no third-party penetration test.
  3. Accept a report where one exists. Where we hold a current third-party audit report or certification — dated within the last twelve months, with no material change to the controls it covers — you agree that providing it satisfies your audit rights under applicable data protection law. We will tell you when we first hold one.
  4. Audit, where it is genuinely needed. Where no such report exists, or where an audit is required by a regulator or follows a security incident affecting your data, you may audit us, or appoint an independent auditor bound by confidentiality to do so. Except in those two cases, an audit may take place no more than once in any twelve-month period, on 30 days’ written notice, during business hours, without disrupting the service, and at your cost. Findings are confidential to both of us.

Those limits exist because we are a small company, not because we have anything to hide.

7. Security incidents

If we become aware of a security incident affecting customer personal data, we will notify you without undue delay and in any event within 48 hours, giving you what we know at that point rather than waiting until we know everything.

We will tell you what happened, what data is affected, what we are doing about it, and who to contact. We will keep you updated as we learn more, take reasonable steps to contain and mitigate it, and help you meet your own notification deadlines — which for most controllers means 72 hours to the Information Commissioner’s Office.

Notifying you is not an admission of fault or liability.

Where the incident also involves Amazon information, we notify Amazon within 24 hours as their data protection policy requires. That is separate from, and in addition to, telling you.

8. Deletion and return

When your subscription ends, or at any point on your request, you can export everything you have given us — cost bases with their derivations, your settings, your proposals and your audit history.

On a verified deletion request we hard-delete the customer personal data we hold for you within 72 hours, and confirm in writing when it is done. Where your subscription simply ends, your data remains available for export for 30 days, after which we delete it on the same basis.

Deletion destroys the Amazon refresh tokens we hold, irrecoverably, so ChatPPC can no longer act on your Amazon accounts. Amazon does not allow an application to withdraw its own authorisation on your Amazon account, so our written confirmation includes the short steps to remove ChatPPC’s access there too.

The only exception is where the law requires us to keep something — records we must retain for tax and accounting purposes, for example. Anything retained on that basis stays protected by this agreement for as long as we hold it.

9. International transfers

We are established in the United Kingdom, and customer personal data is stored and processed in the European Economic Area.

Where you are established in the EEA, our processing as your processor in the UK relies on the European Commission’s adequacy decision for the United Kingdom. If that decision lapses, is revoked, or is held invalid, the parties will without undue delay put in place the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, which are deemed incorporated into this agreement from that date without further action.

Where you are established in the United Kingdom, no restricted transfer arises between us.

Any access to customer personal data from outside the EEA by a sub-processor, in the course of operating its own service, is governed by that sub-processor’s own transfer safeguards as described in §5.

10. Liability

Our liability under this agreement is subject to the same limits set out in our terms of service, and those limits apply to all claims under both documents taken together rather than to each separately.

Nothing here limits either party’s liability where the law does not permit it to be limited, and nothing here affects any right a data subject has directly against either of us.

11. Term, changes and law

This agreement lasts as long as we process customer personal data for you, and survives the end of your subscription until that data has been deleted.

Where we change it in a way that materially affects you, we will give at least 30 days’ notice by email, and you may cancel before the change takes effect if you do not accept it. Where a change in law requires an amendment, we will negotiate one with you in good faith.

It is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

Questions: support@chat-ppc.ai.

Annex 1 — Details of the processing

Subject matter. Providing the ChatPPC service: analysing your Amazon advertising and product economics, and proposing advertising and listing-copy changes for your approval.

Duration. For as long as your subscription is active, plus the deletion period described in §8.

Nature and purpose. Storing, organising, analysing and returning data to you and to the AI assistant session you direct it into, in order to calculate break-even figures, evaluate advertising decisions against them, and help you improve your listing copy.

Frequency of transfer. Continuous, for as long as your subscription is active.

Types of personal data. Limited, and in most accounts minimal:

  • Contact details of any additional users you invite to your account.
  • Any personal data incidentally present in the Amazon data you connect — for example, a person’s name appearing inside a campaign name, a search term or a listing field, because you or a shopper put it there.

Categories of data subject. Your own staff or authorised users, and any individual whose details incidentally appear as above.

Special category data. None. Its submission is prohibited under §3.

Explicitly out of scope. Your buyers’ names, addresses, email addresses and phone numbers. We request no restricted Amazon roles, so we never receive this data, and it cannot be processed, exposed or disclosed by us. Order and inventory records are in scope and reach us with those fields absent.

Competent supervisory authority. The Information Commissioner’s Office (United Kingdom).

Annex 2 — Technical and organisational measures

These are the measures in place, as required by Article 32. Our security page describes them in more detail.

  • Encryption. All data encrypted in transit using TLS and encrypted at rest. Amazon refresh tokens encrypted at rest with a separate key, decrypted only inside the request handler that needs them, and never written to a log, returned in an API response, or exposed to a language model.
  • Separation between customers. Each customer’s data is logically isolated and enforced at the database layer rather than in application code, so a mistake in application logic cannot expose one customer’s data to another.
  • Access control. Access granted on the basis of job duties only, with multi-factor authentication required on every system holding customer data. Credentials held in a password manager, never shared between people, rotated at least annually and immediately on any suspected exposure.
  • Secrets management. Secrets held only in managed environment variables, never committed to source control, with automated secret scanning on every change to every branch.
  • Change control and reversibility. Every change to advertising or listing copy is proposed, confirmed by you, applied only after re-reading the live state, and written to an audit log with its previous state so it can be undone.
  • No credential collection. Authorisation is through Amazon’s own Login with Amazon flow. We never ask for, accept or store Amazon sign-in credentials.
  • Resilience and recovery. Managed database backups with point-in-time recovery, held within the same region.
  • Incident response. A written procedure with defined notification timelines: 48 hours to you, 24 hours to Amazon where Amazon information is involved, and 72 hours to the Information Commissioner’s Office where a personal data breach is reportable.
  • Review. These measures are reviewed at least every six months and after any incident.