Legal
Data Processing Agreement
Last updated: September 11, 2026.
1. Roles
For storefront customer data, the Merchant is the controller / business and Flokte is the processor / service provider. Flokte processes that data only on the Merchant's documented instructions (the Terms, this DPA, and settings the Merchant configures in the app), and for no independent purpose. Flokte is not a consumer reporting agency and does not act as one.
2. Scope and purpose
- Subject matter: return-abuse detection and the reward / restriction rules the Merchant configures.
- Duration: the term of the Merchant's use of Flokte, plus the deletion period in Section 8.
- Categories of data subjects: the Merchant's storefront customers.
- Categories of personal data: name, email, and address as provided by the platform; order and return records; coarse geography; and the classification and factors Flokte derives.
- Special categories: none requested or knowingly processed.
3. Flokte's obligations
- Process personal data only on documented instructions, and tell the Merchant if an instruction appears to violate applicable law.
- Not sell personal data, not share it with other merchants, and not combine one Merchant's data with another's.
- Bind personnel with access to confidentiality obligations and limit access to those who need it.
- Implement the technical and organizational measures in Section 5.
- Assist the Merchant with data-subject requests, security, breach notification, and any required impact assessments.
4. Sub-processors
The Merchant authorizes Flokte to use the sub-processors listed at /legal/subprocessors. Flokte will give at least [30] days' notice of any new sub-processor and will impose data-protection terms on each that are no less protective than this DPA. The Merchant may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Merchant may terminate.
5. Security measures
Encryption of personal data in transit and at rest; least-privilege internal access; an append-only audit log of scores, actions, and disputes; separated test and production environments; and breach-notification readiness. Current detail is on the Security & trust page.
6. Data-subject requests
If Flokte receives a request from a storefront customer to access, correct, delete, or opt out, Flokte will route it to the relevant Merchant and assist the Merchant in responding, including by correcting or deleting data on the Merchant's instruction. Flokte also honors the platform's data-request, customer-redaction, and shop-redaction webhooks.
7. Personal-data breach
Flokte will notify the Merchant without undue delay, and within [72] hours of becoming aware, of any personal-data breach affecting the Merchant's data, with the information the Merchant needs to meet its own notification obligations.
8. Return and deletion
On termination, or on the Merchant's written request, Flokte will delete or return the Merchant's personal data within [30] days and delete existing copies, except where retention is required by law. Routine retention limits per data type are enforced on a schedule during the term.
9. Audits
Flokte will make available the information necessary to demonstrate compliance with this DPA and will contribute to audits, including by providing its then-current security documentation and any third-party reports it holds. On-site audits require reasonable advance written notice and are limited to once per twelve (12) months unless a regulator requires otherwise.
10. International transfers
At launch, Flokte processes data in [region] and does not knowingly process data of EU/UK data subjects. If that changes, an appropriate transfer mechanism (such as the Standard Contractual Clauses) will be incorporated here before any such processing begins.
11. Order of precedence
On any conflict about data protection, this DPA controls over the Terms of Service.