Data processing agreement
Last updated: 25 August 2026
This agreement is between MAXINVENT LTD (company number 17323733) ("MaxInvent", the "Processor") and the customer identified in the customer terms of service (the "Controller"). It forms part of that agreement and satisfies Article 28(3) of the UK GDPR.
Version 1.0, in force from 25 August 2026. "UK Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended. Terms such as controller, processor, personal data, processing, personal data breach and data subject have the meanings given in the UK GDPR.
1. Roles
The Controller determines the purposes and means of processing the personal data it puts into the Service. MaxInvent processes that personal data as processor, on the Controller's instructions.
MaxInvent is an independent controller, and this agreement does not apply, for: the accounts of individuals who administer the Service, billing records, support correspondence, and MaxInvent's own security and audit logs. That processing is described in MaxInvent's privacy policy.
Marketplaces, couriers, payment providers and accounting providers that the Controller connects are not MaxInvent's sub-processors. Each determines its own purposes for the personal data it receives and acts as an independent controller in respect of it. MaxInvent transmits personal data to them on the Controller's instruction, which the Controller gives by enabling the connection.
2. Instructions
MaxInvent will process personal data only on the Controller's documented instructions, which comprise this agreement, the customer terms, the Controller's configuration and use of the Service, and any further written instruction the parties agree.
MaxInvent will tell the Controller if, in its opinion, an instruction infringes UK Data Protection Law, and may suspend performance of that instruction until it is confirmed, withdrawn or amended. MaxInvent is not obliged to give legal advice, and telling the Controller does not transfer the Controller's own accountability.
MaxInvent will not process the personal data for its own purposes. In particular it will not use it to train machine learning models, to produce benchmarks or market analysis, or for its own product analytics, whether in identifiable or aggregated form.
3. Subject matter and details of processing
Subject matter. Provision of a hosted inventory, order, dispatch and multichannel commerce platform.
Duration. The term of the customer terms, plus the post-termination period in clause 10.
Nature and purpose. Storage, organisation, retrieval, adaptation, transmission to marketplaces and couriers the Controller selects, and erasure, in each case for the purpose of operating the Controller's commerce and fulfilment operations.
Categories of data subject. The Controller's customers and their contacts; end buyers on connected marketplaces; delivery recipients; the Controller's employees, drivers and other users of the Service; contacts at the Controller's suppliers.
Categories of personal data. Identification and contact details; delivery and billing addresses; order, invoice and payment records; account credentials and authentication data; free-text notes entered by the Controller's users; where the Controller uses those features, driver location data and photographs or signatures captured on delivery; supplier contact and bank details.
Special category and criminal offence data
The Service is not designed for special category data within Article 9, or criminal offence data within Article 10, and the Controller must not submit it without MaxInvent's prior written agreement.
We state it that way rather than recording "none", because several fields accept free text and the Controller's users are therefore capable of entering such data. If they do, the Service will process it and neither party is served by a schedule that says otherwise.
Where either party becomes aware that such data has been submitted without agreement, it will tell the other promptly. The parties will then agree whether to remove it or to put appropriate safeguards in place, and MaxInvent may restrict access to the affected records in the meantime. This does not relieve the Controller of responsibility for the instruction it gave.
4. Confidentiality
MaxInvent will ensure that each person it authorises to process the personal data is subject to a duty of confidentiality, is made aware of the confidential nature of the data, and has access only to what their role requires.
5. Security
MaxInvent will implement appropriate technical and organisational measures under Article 32, having regard to the state of the art, the cost of implementation and the risks to data subjects. The measures in force at the date of this agreement are described in the security overview, which forms the technical and organisational measures schedule to this agreement.
MaxInvent may change those measures, provided it does not materially reduce the overall level of protection. Because Article 32(1)(d) requires regular testing and evaluation of effectiveness, MaxInvent will review the measures at least annually and on any material change to the Service.
The security overview describes what MaxInvent operates and, deliberately, what it does not. The Controller should read it before deciding that the Service is appropriate for its processing, and remains responsible for that assessment.
6. Sub-processors
The Controller gives general authorisation for MaxInvent to engage sub-processors. The current list, with the purpose and location of each, is at maxinvent.uk/legal/sub-processors.
MaxInvent will impose on each sub-processor, by written contract, data protection obligations equivalent to those in this agreement, and remains liable to the Controller for a sub-processor's failure to fulfil them.
MaxInvent will give at least 30 days' notice of an intended new or replacement sub-processor, by email to the Controller's notified contact and by updating that page. The Controller may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith, and MaxInvent will use reasonable efforts to make the Service available without the sub-processor or by an alternative means.
If that is not reasonably possible, the Controller may terminate the affected part of the Service, or the customer terms, without penalty, and MaxInvent will refund fees paid for any period after termination takes effect. This is a right to leave rather than a veto: a general authorisation cannot in practice give one customer a block on MaxInvent's supply chain, and pretending otherwise would make the clause unworkable.
MaxInvent may appoint a replacement sub-processor without notice where it is urgently required to maintain security or continuity of the Service, and will notify the Controller as soon as reasonably practicable afterwards.
7. International transfers
The Service is hosted in the United Kingdom. Encrypted disaster-recovery database snapshots are held in Ireland, which is covered by UK adequacy regulations, so no additional transfer safeguard is required for them.
Some sub-processors process personal data outside the United Kingdom. Where they do, MaxInvent will ensure a transfer mechanism permitted by UK Data Protection Law is in place, such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with any supplementary measures the transfer risk assessment identifies. The sub-processor list identifies the location of each.
MaxInvent will not transfer the personal data to a country without an adequacy determination except under such a mechanism, and enters into it as the Controller's agent for that purpose where required.
8. Data subject rights
The Controller is responsible for responding to requests from its own data subjects. MaxInvent will not respond to such a request itself, other than to direct the individual to the Controller, unless legally required or the Controller asks it to.
MaxInvent will provide reasonable assistance to enable the Controller to respond within the statutory period. That assistance comprises:
- the self-service tools in the Service, which the Controller can use to find, correct, export and delete records itself;
- where a request cannot be satisfied with those tools, searching for and providing the relevant personal data, or carrying out a correction or erasure, on the Controller's written instruction;
- notifying the Controller without undue delay if MaxInvent receives a request that appears to relate to the Controller's data, and within 5 business days at the latest.
MaxInvent will acknowledge an assistance request within 3 business days and will respond substantively in time for the Controller to meet its own deadline, provided the Controller allows a reasonable period. MaxInvent will tell the Controller promptly if a request is not achievable in the time available, so that the Controller can rely on an extension where the UK GDPR permits one.
Assistance under this clause is provided at no charge. Where a request is manifestly excessive in volume or frequency, or requires substantial bespoke engineering, MaxInvent may charge its reasonable costs, agreed in advance in writing. MaxInvent will not use a charge, or the absence of agreement about one, as a reason to fail to provide assistance the UK GDPR requires.
9. Personal data breaches and other assistance
MaxInvent will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data.
Notification is deliberately tied to becoming aware rather than to completing an investigation. The Controller's own 72-hour clock under Article 33 starts when it becomes aware, so a clause that waits for confirmed facts would put the Controller in breach. The first notification will therefore contain what is known at the time, and MaxInvent will provide further information in phases as the investigation progresses, including where the initial assessment turns out to be wrong.
The notification will include, to the extent known:
- the nature of the breach and when it is believed to have occurred;
- the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the measures taken or proposed, including to mitigate adverse effects;
- a contact point for further information.
MaxInvent will not notify the Information Commissioner or any data subject about a breach affecting the Controller's personal data unless legally required to do so or the Controller asks it to. That decision is the Controller's.
MaxInvent will provide reasonable assistance to the Controller with data protection impact assessments and prior consultation under Articles 35 and 36, so far as they relate to MaxInvent's processing. Where the Controller uses the driver location or delivery image features, MaxInvent will make available the information the Controller needs for its assessment.
10. Deletion and return
On expiry or termination of the customer terms, MaxInvent will delete the personal data it processes for the Controller, save for any copy the law requires it to keep, and will confirm deletion in writing on request.
Before deletion, MaxInvent will keep the data available for 30 days so that the Controller can export it, in line with clause 14 of the customer terms. The Controller may instead instruct MaxInvent in writing during that period to return the data or to delete it earlier.
Backups
Deletion from the live Service does not immediately remove personal data from encrypted backups, which expire on a rolling schedule of up to 35 days. During that period the backups are retained solely for disaster recovery, are not accessed for any other purpose, are not used to reinstate deleted records except as part of a whole-system recovery, and expire automatically without further action.
We describe this rather than promising immediate deletion from backups, because immediate deletion from an encrypted rolling backup set is not something we can honestly undertake, and the Information Commissioner's guidance on putting data beyond use is directed at exactly this situation.
11. Information and audit
MaxInvent will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits and inspections in accordance with this clause.
In the first instance MaxInvent will satisfy a request by providing written information: its security overview, its sub-processor list, its answers to a reasonable security questionnaire, and any third-party report or certification it holds at the time.
Where that information is not sufficient for the Controller to meet its obligations under UK Data Protection Law, or where the Controller is required by a regulator to inspect, the Controller may audit or inspect MaxInvent's processing. Such an audit will be on at least 30 days' written notice, during business hours, no more than once in any 12-month period except following a personal data breach affecting the Controller or where a regulator requires it, subject to confidentiality undertakings, and conducted so as not to disrupt MaxInvent's business or the security or confidentiality of other customers' data.
Each party bears its own costs, except that MaxInvent may charge its reasonable costs for an audit that is repeated within 12 months other than for one of the reasons above. The written information route is a first step, not a substitute for the Article 28(3)(h) right, which is preserved.
12. Liability
The liability provisions in clause 15 of the customer terms apply to this agreement.
Nothing in this agreement limits a data subject's rights, or either party's liability to a data subject or to a supervisory authority, under UK Data Protection Law. Those rights arise by statute and are not ours to cap.
13. General
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
If any provision of this agreement conflicts with the customer terms on a matter of data protection, this agreement prevails. If UK Data Protection Law changes such that this agreement no longer satisfies it, the parties will negotiate in good faith to amend it.
Data protection enquiries: support@maxinvent.uk.