This Data Processing Agreement ("DPA") applies to the processing of personal information by PeakGen Consulting LLC, doing business as RetailGenie("Processor", "we") on behalf of the retailer customer ("Controller", "you") that uses the RetailGenie Services (as defined in the Terms of Service). This DPA forms part of, and is governed by, those Terms.
1. Definitions
- Personal Information means any information relating to an identified or identifiable individual that Controller submits to or processes through the Services.
- Processing has the meaning given to it under applicable data protection law and includes any operation performed on Personal Information.
- Subprocessor means a third party engaged by RetailGenie to process Personal Information on Controller's behalf.
- Other capitalized terms have the meaning given in the Terms or applicable data protection law.
2. Roles & scope
Controller is the data controller (or business, under CCPA) of the Personal Information it submits to the Services. RetailGenie is the data processor (or service provider, under CCPA). RetailGenie will process Personal Information only on the documented instructions of Controller as set out in the Terms, in Controller's use of the Services, and in this DPA.
3. Categories of data & data subjects
- Data subjects: Controller's end customers, leads, employees, and any individual whose information Controller submits to the Services.
- Identifiers: name, address, email, phone, customer reference IDs.
- Commercial information: invoices, returns, financing applications, loyalty points, communication history.
- Operational metadata: timestamps, IP addresses for security and auditing.
- Geolocation: limited to delivery driver location during in-flight deliveries.
4. RetailGenie's obligations
- Process Personal Information only as instructed by Controller and as necessary to provide the Services.
- Ensure persons authorized to process Personal Information are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see Section 6).
- Notify Controller without undue delay of any confirmed security incident involving Personal Information.
- Assist Controller (taking into account the nature of processing and the information available) with responding to data subject requests and with security, breach notification, and impact assessments where required.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
5. Controller's obligations
- Provide accurate documented instructions and ensure your instructions comply with applicable law.
- Obtain and maintain any legally required consents from data subjects, including TCPA / CAN-SPAM consents for messages sent via the Services.
- Respond to data subject requests directed to you (we will assist with the technical aspects).
6. Subprocessors
Controller authorizes RetailGenie to engage the subprocessors below to deliver the Services. RetailGenie will (a) enter into a written agreement with each subprocessor imposing data protection obligations substantially similar to those in this DPA, and (b) remain liable for each subprocessor's performance.
Current subprocessors:
- Supabase, Inc. — Database, authentication, object storage. Data is hosted in the United States.
- Vercel, Inc. — Application hosting and edge delivery.
- Anthropic PBC — Large-language-model inference for AI-assisted features (natural-language invoice composition, sales coaching, narrative reports). Customer Personal Information is scrubbed and redacted before being sent for inference.
- Resend — Transactional email delivery.
- Twilio Inc. — SMS delivery and inbound webhooks.
- Helcim Inc. — Card payment processing. Full card numbers are tokenized and not stored by RetailGenie.
- Sentry (Functional Software, Inc.) — Error tracking. PII is configured to be scrubbed where reasonably possible.
- Intuit (QuickBooks Online) — Optional accounting sync. Only invoked if Controller connects QBO from within the Services.
- Mapbox — Optional map rendering for delivery routing. Only invoked when Controller uses delivery-mapping features.
We will give Controller at least 30 days' notice before engaging a new subprocessor or replacing a subprocessor in a way that materially changes the scope of processing. If Controller has a reasonable objection on data protection grounds, Controller may terminate the affected Services within that 30-day window.
7. Security measures
We maintain technical and organizational measures designed to protect Personal Information, including:
- TLS 1.2+ for data in transit; encryption at rest for integration credentials (pgcrypto-backed).
- Row-level security policies enforcing tenant isolation in the database.
- Role-based access control with the principle of least privilege.
- Immutable audit logging for sensitive actions (role changes, credential writes, invoice voids).
- Per-staff rate limiting on AI and sensitive endpoints.
- PII redaction in prompts sent to LLM subprocessors.
- Regular review of access logs and security incidents.
8. International transfers
Personal Information is primarily hosted in the United States. Where Personal Information is transferred to a country that does not have an adequacy decision under applicable law, the parties will rely on the Standard Contractual Clauses or another lawful transfer mechanism, as applicable.
9. Data subject requests
Controller is responsible for responding to requests from data subjects exercising their rights under applicable law (access, deletion, correction, portability, opt-out). RetailGenie will provide reasonable technical assistance to enable Controller to fulfill those requests within the time required by law.
10. Incident notification
RetailGenie will notify Controller without undue delay, and in no event later than 72 hours, after becoming aware of any unauthorized access, acquisition, or disclosure of Personal Information processed under this DPA. The notification will include the information then known about the incident and our remediation steps. Controller is responsible for notifying its own data subjects and regulators as required by law.
11. Return or deletion of Personal Information
On termination of the Services, RetailGenie will retain Personal Information for the period stated in the Terms (typically 30 days) to allow Controller to export its data, and will then delete or de-identify Personal Information in our active systems. Backup copies are deleted on our normal backup-rotation cycle. We may retain Personal Information longer to the extent required by applicable law.
12. Audits
On reasonable written request and no more than once per year (except as required by applicable law or in connection with a confirmed incident), RetailGenie will provide Controller with information reasonably necessary to demonstrate compliance with this DPA. Audits will be conducted at Controller's expense, during normal business hours, and subject to confidentiality obligations.
13. Liability & conflicts
Each party's liability under this DPA is subject to the limitation of liability section of the Terms of Service. If any provision of this DPA conflicts with the Terms, this DPA controls with respect to the processing of Personal Information.
14. Contact
Questions about this DPA, to request a signed copy, or to submit a data protection inquiry: austin@retailgenie.io.