מסמכים משפטיים
תנאי עיבוד מידע
ההסכם שחל על המידע האישי של הלקוחות שלכם: מה מותר לנו לעשות בו, מי עוד נוגע בו, איך הוא מוגן ואיך הוא נמחק.
עודכן לאחרונה
המסמך מתפרסם באנגלית, והנוסח האנגלי הוא הנוסח המחייב.
These terms, and how they are entered into
These Data Processing Terms are entered into between you (the Merchant, referred to as “you”) and B.F Entreprises, trading as Jeweliful, of [REGISTERED ADDRESS] (“Jeweliful”, “we”, “us”).
They form part of, and are incorporated by reference into, the agreement under which we supply the Jeweliful service to you. You enter into them when you install the Jeweliful app on your store, or when you create or use a Jeweliful account, whichever happens first. Where they conflict with any other part of that agreement, these terms prevail on anything concerning the personal data of your customers.
They are in writing in electronic form, which is the form data protection law requires and allows. You can print this page or save it, and we will send you a copy on request.
Changing these terms
We may need to change these terms, for example when the law changes or when we change a service provider. We will not do it by quietly editing this page. We will tell you in advance, by email to the address on your account or in the dashboard, and say what changed and when it takes effect. If a change is one you cannot accept, you may end the affected part of the service before it takes effect, and we will not charge you for doing so. The date at the top of this page always shows the version in force.
What the words mean
- Customer Personal Data means personal data about your customers or the recipients of your orders that we process on your behalf under the agreement. Annex A describes it.
- Data Protection Law means every law about personal data that applies to processing under these terms, including the EU General Data Protection Regulation, the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended.
- Controller, processor, personal data, data subject, processing and personal data breach have the meanings the GDPR gives them. Business, service provider, contractor, sell, share and business purpose have the meanings the California Consumer Privacy Act gives them.
- Subprocessor means anyone we engage to process Customer Personal Data on our behalf. Annex B lists them.
- Standard Contractual Clauses means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
Which of us is responsible for what
For Customer Personal Data you are the controller and we are your processor. Where you are yourself a processor for someone else, you are the processor and we are your subprocessor, and these terms apply as if references to you were references to that controller.
You are responsible for having a lawful basis for the processing you ask us to perform, for giving your customers the privacy information the law requires them to have, and for the accuracy of what you send us. We do not have a route to your customers: we hold no buyer email addresses at all, by design, so the notice a data subject is owed can only come from you.
For the personal data we hold about you and your business, we are the controller. That is described in our Privacy Policy and is outside these terms.
We process only on your instructions
We process Customer Personal Data only on your documented instructions, including in relation to transfers to another country, unless a law we are subject to requires otherwise. If that ever happens, we will tell you before we process, unless that law forbids us to tell you.
Your instructions are:
- the agreement between us, including these terms;
- the actions you take in the Jeweliful dashboard and the app, including sending us an order, changing an order, and asking us to erase data;
- any other instruction you give us in writing, including by email, which we agree to follow.
The purposes those instructions cover are the ones in Annex A and no others: importing the orders you send us, making the pieces on them, packing them with your branding, shipping them to the recipient you named, writing tracking back to your store, and supporting you about those orders.
If we think an instruction you give us breaks Data Protection Law, we will tell you immediately and may pause that processing until it is resolved.
What you must not send us
The gift message and personalization fields are free text, and your customers can type anything into them. Do not instruct us to process, and please do not design a checkout that invites, special categories of personal data in them: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data, data about health, sex life or sexual orientation, or data about criminal offences. The service is not built to handle it, and we do not agree to process it.
Confidentiality
Everyone we allow to process Customer Personal Data, whether an employee, a contractor or an agency worker, is bound to keep it confidential, either by a written undertaking to us or by a professional duty of confidence. That obligation survives the end of their engagement.
We grant access on a need-to-know basis only, and we keep a log of every occasion on which one of our people reads or exports Customer Personal Data, recording who, what, why and when.
Security
We implement and maintain technical and organisational measures appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing. Those measures are set out in Annex C. In summary they cover the encryption of personal data; the ongoing confidentiality, integrity, availability and resilience of our systems; our ability to restore access to data after an incident; and the regular testing and review of the measures themselves.
We may update the measures as the service changes, provided the level of protection is not reduced.
Subprocessors
You give us general written authorisation to engage the subprocessors listed in Annex B, and to engage others in accordance with this section.
Before a new subprocessor begins processing Customer Personal Data, we will update Annex B and tell you, at least 10days beforehand or as promptly as our own provider’s notice to us allows if that is shorter. We give you that number rather than the customary thirty because it is one we can actually keep: some of our own providers give us as little as five days’ notice of their changes, and a promise of thirty would be a promise broken the first time one of them moved.
If you object to a new subprocessor on reasonable data protection grounds, tell us within ten days of our notice. We will discuss it with you in good faith and look for an alternative. If we cannot find one, you may stop using the affected part of the service and end the agreement for it, without penalty and with a refund of anything you paid in advance for a period you will not now receive.
We impose on every subprocessor, by written contract, data protection obligations that offer an equivalent level of protection to the ones in these terms. Where a subprocessor fails to meet them, we remain fully liable to you for its performance.
Where you are yourself a processor and we are your subprocessor, the authorisation and the right to object in this section belong to your own controller, and you must pass our notice on to them and pass their objection back to us. That is what the Standard Contractual Clauses require in that arrangement, and it is why we send the notice to you rather than deciding for ourselves who further down the chain should receive it.
Helping you answer your customers
If one of your customers exercises a right against you, we will help you answer, by appropriate technical and organisational measures and as far as it is possible for us to do so. If a request reaches us directly, we will not answer it ourselves. We will pass it to you without undue delay and tell the person that you are the one who decides.
For stores connected over Shopify, three of those routes are automatic. They run at POST /api/channels/shopify/webhook, which verifies the request’s signature and refuses anything unsigned:
| When | What happens | By when |
|---|---|---|
| A buyer asks the merchant what data is held about them | We compile everything we hold about that buyer and deliver it to the store owner, who answers their customer. | Within 30 days of the request reaching us |
| A buyer asks the merchant to erase their data | The buyer's details on the named orders are erased: the address block, the phone number, the gift message and the personalization text. Orders we already produced and shipped are kept as transaction records, which we are required to retain; every retained record is counted and logged. | On receipt, and within 30 days at the latest |
| A merchant uninstalls the app | The store's buyer data is erased and the stored access credentials for that store are destroyed, under the same retention carve-out for orders already fulfilled. | 48 hours after the uninstall |
For orders you placed by hand, or for anything the three routes do not cover, write to us and we will act on your instruction.
Helping you with your other obligations
Taking into account the nature of the processing and the information available to us, we will help you meet your own obligations to keep personal data secure, to notify a regulator and your customers of a breach, to carry out a data protection impact assessment, and to consult a regulator where one is needed. In practice that means giving you the information we hold about how the processing works, what measures protect it, where data is held and who has access to it.
If you ask for help that goes beyond what Data Protection Law and these terms require of us, we may agree a reasonable fee for it first. We will never make routine assistance conditional on payment.
Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any event within 48 hours. We do not assess first whether the breach is likely to be risky to your customers, because that judgement is yours to make and your own 72-hour clock starts when we tell you.
Our notification will describe, as far as we know it at the time:
- what happened, including the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures we have taken or propose to take, including anything to mitigate the effects;
- a contact point for more information.
Where we cannot give all of it at once, we will give what we have and follow with the rest without undue further delay. Notifying you, or responding to an incident, is not an admission of fault or liability by us.
Notifying a supervisory authority and your customers is yours to do, as controller. We will not do it in your name, and we will not do it without telling you.
Returning and deleting data
You can ask us to delete Customer Personal Data at any time, and the routes in section 8 do it on request. At the end of the agreement, at your choice, we will return it to you or delete it.
- For 30 days after the agreement ends you can export your data from the dashboard or ask us for a copy of it.
- After that window we delete it from our live systems.
- Copies in our backups are deleted on the ordinary backup rotation. Until they are, they are put beyond use: nothing reads them except a restore, and they remain covered by these terms.
Information and audits
We will make available to you all the information necessary to demonstrate that we comply with this document, and allow for and contribute to audits.
First, the information itself
On written request, and under a duty of confidence, we will give you the current version of these terms and their annexes, our description of the technical and organisational measures, our subprocessor list, where data is held, who has access to it, and the most recent audit or assessment report we hold. For most questions that is the answer, and it is quicker than an audit.
Then, an audit if that is genuinely not enough
If the information above does not let you verify our compliance, or if a regulator requires it, you or an auditor you appoint may audit us. So that an audit is workable for a business of our size, the following apply, and none of them is intended to prevent an audit the law entitles you to:
- once in any twelve months, and more often if a personal data breach has occurred or a regulator requires it;
- on at least 30 days' written notice, at a time we agree, during business hours;
- limited to facilities and systems we control, and to Customer Personal Data that is yours;
- conducted by someone suitably qualified and independent, who is not a competitor of ours, and who is under a confidentiality obligation;
- in a way that does not materially disrupt the running of the service;
- with each of us bearing our own costs, and with the findings treated as confidential by both of us.
We may propose an auditor. Whether to accept the proposal, and what the audit covers, remains your decision.
Sending data between countries
Where the data actually is
We operate from Israel. The application and its database run on providers in the United States and, for the database, in the region we have configured with a provider incorporated in Singapore. Orders are produced and posted in the United States. Annex B names each provider and the country it contracts from.
So a transfer can happen in two places: from you to us, and from us to a provider in Annex B. This section covers both.
Where a transfer is covered by an adequacy decision
We do not list adequate countries here, because the list changes and a list in a contract goes stale without anyone noticing. Adequacy means a decision in force under Article 45 of the GDPR, the United Kingdom’s adequacy regulations, or the Swiss Federal Council’s list, as those stand at the time of the transfer. Transfers from the European Economic Area and the United Kingdom to Israel are covered by such a decision today, so no further mechanism is needed for them.
Where it is not
The Standard Contractual Clauses are incorporated into these terms and take effect between us. They are incorporated unamended: nothing in these terms modifies them, and everything here only supplements them. Module Two applies where you are a controller and we are your processor; Module Three applies where you are a processor and we are your subprocessor. For each:
- the docking clause in Clause 7 does not apply;
- in Clause 9, Option 2 applies, and the notice period for a change of subprocessor is the one in section 7 above;
- the optional wording in Clause 11 does not apply;
- under Clause 17, Option 1, the clauses are governed by the law of Ireland, and under Clause 18(b) disputes are resolved before the courts of Ireland;
- Annexes A, B and C of this document serve as Annexes I, III and II of the clauses respectively.
For transfers subject to United Kingdom law, the EU clauses are not enough on their own. The International Data Transfer Addendum issued by the Information Commissioner also applies, and its Part 2 is incorporated in these words: “Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.” In Table 4 of the Addendum, neither party may end it when it is revised, so that a reissued Addendum takes effect without either of us having to re-paper the agreement.
For transfers subject to Swiss law, the Standard Contractual Clauses apply with these adaptations: references to the GDPR are read as references to the Swiss Federal Act on Data Protection; the competent supervisory authority is the Federal Data Protection and Information Commissioner; and nothing in the reference to a Member State prevents a data subject in Switzerland from bringing proceedings in Switzerland under Clause 18(c).
By entering into the agreement you are treated as having signed the Standard Contractual Clauses and the Addendum, including their annexes. No handwritten signature is needed. Where they conflict with anything else in these terms, they prevail.
California
Where the California Consumer Privacy Act applies to you, you are the business and we are your service provider. We receive Customer Personal Data from you, or on your behalf, only for the business purposes set out in Annex A, and you disclose it to us only for those purposes. They are stated there specifically, and not by a general reference to this agreement, because the regulations require exactly that.
We are prohibited from, and we will not:
- sell or share the personal information;
- retain, use or disclose it for any purpose other than the business purposes specified in Annex A, including for any commercial purpose of our own;
- retain, use or disclose it outside the direct business relationship between us;
- combine it with personal information we receive from or on behalf of anyone else, or that we collect from our own interaction with a consumer, except where the regulations expressly permit it for a business purpose.
We also undertake that:
- we will comply with the applicable requirements of the CCPA and provide the same level of privacy protection it requires of you;
- you may take reasonable and appropriate steps to satisfy yourself that we use the personal information consistently with your obligations, which section 12 puts into practice;
- you may, on notice, take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information by us;
- we will notify you if we determine that we can no longer meet our obligations under the CCPA;
- we will enable you to comply with consumer requests, and you will tell us of any request we need to act on and give us what we need in order to act on it;
- where we engage a subcontractor to help us process personal information for you, we will notify you and put in place a written contract binding it to all of the requirements in this section.
Duration, liability, and what is not in this document
These terms apply for as long as we process Customer Personal Data for you, and the sections that by their nature should survive, including confidentiality, deletion and audit, survive the end of the agreement until we no longer hold any of it.
Liability under these terms is subject to the limitations and exclusions in the agreement they form part of. There is deliberately no separate cap, indemnity or governing-law clause for the agreement as a whole in this document. Those belong to the commercial agreement, and a second quieter set of them here would only create a conflict.
If any part of these terms is held unenforceable, the rest continues to apply.
Annex A: details of the processing
| Item | Detail |
|---|---|
| Subject matter | Our production and fulfilment of the orders you send us, and the support we give you about them. |
| Duration | For as long as the agreement between us is in force, plus the period in section 11 needed to return or delete the data. |
| Nature of the processing | Receiving, storing, organising, reading, using, transmitting to our shipping provider, printing, erasing and destroying. |
| Purposes (the business purposes for California) | Importing an order from your store or from your manual entry; matching it to the pieces we make; manufacturing and personalizing those pieces; packing them with your branding; printing a shipping label and handing the parcel to a carrier; writing the tracking number back to your store; answering your questions about that order; and keeping the record of the transaction. Nothing else. |
| Categories of data subject | The people who buy from you, and any other recipient you name for an order, for example the person a gift is sent to. |
| Categories of personal data | Recipient name; Shipping address; Recipient phone number, where the order carries one; Gift message and personalization text; Order and line-item references. |
| Special categories of personal data | None. We do not ask for any, and section 4 says you must not send any. |
| Frequency of transfer | Continuous, for as long as your store is connected or you are placing orders. |
| Competent supervisory authority | For the Standard Contractual Clauses, the authority competent for you as data exporter, determined under Clause 13 of those clauses. |
| Your obligations and rights | Set out in these terms, in particular sections 3, 4, 7, 8, 11 and 12. |
Annex B: subprocessors
The three marked as receiving customer data are the only ones that can reach the personal data of your customers. The others are named for completeness: they process data about you and your account, which the Privacy Policy covers.
| Provider | Purpose | Customer data | What it receives |
|---|---|---|---|
| ShipStation Auctane LLC d/b/a ShipStation (United States) | Shipping labels and carrier hand-off | Yes | The ship-to block of each order we fulfil (recipient name, postal address and, where the order carries one, phone), together with the production detail the parcel needs: the engraving or personalization text and any note attached to the order. |
| Supabase Supabase Pte. Ltd (Singapore) | Managed Postgres database | Yes | The application database, in which order records and their ship-to details are stored, encrypted at rest. |
| Vercel Vercel Inc. (Delaware, United States) | Application hosting and file storage | Yes | The running application and its request logs (from which personal data is stripped before writing), plus product and brand imagery. Order data passes through in transit. |
| Stripe Stripe, LLC (United States) or Stripe Payments Europe, Limited (Ireland), per account location | Merchant billing and card payments | No | Merchant billing details and card credentials. Stripe acts on our instructions for taking payment, and also as a controller in its own right for fraud prevention and payment-network compliance, under its own privacy policy. No end-customer data is sent to Stripe. |
| Clerk Clerk, Inc. (United States) | Merchant sign-in and account security | No | Merchant account credentials, sessions and second factors. No end-customer data is sent to Clerk. |
| Resend Resend | Account and statement email | No | The address we send an account email to, and the contents of that email. No end-customer data is sent to Resend. |
Annex C: technical and organisational measures
These are the measures in place today. They answer both Article 32 of the GDPR and the protected customer data requirements the store platforms impose on us.
- Encryption in transit. Every connection to the service, and every connection from it to a provider, runs over TLS.
- Encryption at rest. The database and the file storage encrypt their contents with AES-256.
- A second layer over the keys to a merchant's store. The access tokens that let us read a connected store are encrypted field by field with a rotating key, on top of the storage encryption.
- Personal data is stripped from logs before they are written, and error reporting is configured to send none.
- An access log over end-customer data. Every read or export by our staff, and every send to our shipping provider, is recorded with who, what, why and when.
- Least privilege. Every route in the application is permission-guarded by construction, staff accounts exist only by invitation, and the ability to move money is narrower than the ability to fulfil an order.
- Separation of test and production. Development and preview environments run on their own databases and never receive production data.
- Retention limits that run on a schedule, with a hold switch that suspends every one of them while an incident is open.
- A written security incident response policy with severity levels, containment runbooks and notification duties.
We keep a written security incident response policy setting out severity levels, who decides what, containment steps for each kind of compromise, how evidence is preserved, and the notification duties in section 10. Our retention schedules are suspended in full while an incident or a legal hold is open, so nothing can be swept away while it is still needed.
How to reach us about these terms
Write to privacy@jeweliful.com, or to B.F Entreprises at [REGISTERED ADDRESS]. Mark anything urgent, including a suspected breach, as urgent in the subject line.