Data Processing Addendum

Effective September 9, 2026

Pending legal review. This document describes how CreditDesk actually operates and names the contracting entity, address and governing law, but it has not been reviewed by qualified counsel. Before CreditDesk is offered to merchants it should be reviewed by a lawyer in the relevant jurisdictions.

This Addendum forms part of the CreditDesk Terms of Service and governs our processing of personal data about a merchant's customers. It applies where the GDPR, UK GDPR, or comparable data protection law applies to that processing. The processor is Lead Kings LLC, 290 Fern Ct, Hampton, GA 30228, United States; the merchant is the controller.

1. Roles

The merchant is the controller of personal data relating to their customers. CreditDesk is the processor of that data and processes it only on the merchant's documented instructions.

The merchant's instructions consist of these terms, the configuration the merchant chooses in the app, and any further written instruction the merchant gives us. We will tell the merchant if, in our opinion, an instruction infringes applicable data protection law.

2. Subject matter and duration

  • Subject matter: provision of credit control, accounts receivable and collections functionality to the merchant.
  • Duration: for as long as the app is installed, plus the deletion period described in section 8.
  • Nature and purpose: reading order, company and buyer records from the merchant's store; deriving a receivables ledger; enforcing merchant-configured credit limits; and sending payment reminders and statements on the merchant's behalf.
  • Categories of data subject: the merchant's business customers and the individual contacts at those customers.
  • Categories of personal data: name, email address, company affiliation, and order and payment amounts, dates and status. No special categories of personal data are processed. No payment card or bank account data is processed.

3. Confidentiality

We ensure that personnel authorised to process personal data are bound by appropriate obligations of confidentiality and receive guidance on their responsibilities.

4. Security

We implement appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Those measures are described in the Annex below and in our Security Incident Response Policy.

5. Sub-processors

The merchant provides general authorisation for us to engage the sub-processors listed in our Privacy Policy. We impose data protection obligations on each sub-processor no less protective than those in this Addendum, and we remain responsible for their performance.

We will give notice before adding or replacing a sub-processor. A merchant who reasonably objects on data protection grounds may terminate the affected service without penalty for the remainder of the paid period.

6. Assistance to the controller

  • We will assist the merchant, by appropriate technical and organisational measures and insofar as possible, in responding to requests from data subjects exercising their rights. The app provides export and deletion functionality, and we act on the redaction requests Shopify forwards to us.
  • We will assist the merchant in ensuring compliance with their obligations relating to security, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to us.

7. Personal data breaches

We will notify the merchant without undue delay after becoming aware of a personal data breach affecting their data, and will provide the information the merchant reasonably needs to meet their own notification obligations. Our internal process, including severity classification, escalation and evidence handling, is set out in our Security Incident Response Policy.

8. Return and deletion

On termination, and at the merchant's choice, we will delete or return the personal data we process on their behalf. In practice deletion is automatic: all data for an uninstalled store is permanently deleted 30 days after uninstall, and immediately on a shop redaction request. Merchants who require a copy should export it before uninstalling.

9. Audits

We will make available to the merchant the information reasonably necessary to demonstrate compliance with this Addendum, and will allow for and contribute to audits conducted by the merchant or an auditor they mandate. Audits are on reasonable notice, no more than once in any twelve month period unless required by a supervisory authority, during business hours, subject to confidentiality, and conducted so as not to disrupt our operations or the security of other merchants' data.

10. International transfers

Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we do so under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this Addendum by reference and prevail over it in the event of conflict.

Annex — technical and organisational measures

  • Encryption of personal data in transit using TLS, and at rest across database storage, cache, object storage and backups. Store access credentials are additionally encrypted at the application layer using a key that can be rotated without downtime.
  • Logical separation of each merchant's data, enforced in application code so that every query for merchant-owned data is constrained to a single merchant, and verified by an automated test that fails the build if the control is bypassed.
  • Signature verification of all inbound webhooks before processing, and rejection of replayed deliveries.
  • Access control limiting production access to personnel who require it, with an audit log recording actions that change data.
  • Separation of test and production environments, with distinct databases, caches and credentials. Production personal data is not copied into test environments.
  • Backups with point-in-time recovery over a 30-day window, encrypted to the same standard as production, with restores exercised periodically.
  • Retention limits enforced automatically, including deletion 30 days after uninstall and immediate deletion on redaction request.
  • Monitoring and alerting covering application errors, failures of the tenant isolation control, ledger reconciliation drift, and degradation of credit enforcement, feeding a documented incident response process.