Discover Our Referral Program
→

Trendful Data Processing Addendum

This Trendful Data Processing Addendum ("Addendum") amends and forms part of the Trendful Terms of Service (the "Agreement") by and between you and Trendful Inc., a Delaware corporation located at 16497 Acoustic Loop, Land O Lakes, FL 34638 ("Trendful"). This Addendum applies to Trendful’s Processing of Personal Data on your behalf in the course of providing the Services. All capitalized terms not defined in this Addendum have the meaning given to them in the Agreement.

1. Definitions

1.1. "Data Protection Legislation" means European Union Regulation 2016/679 (the "General Data Protection Regulation" or "GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (together, the "CCPA"), each as applicable, together with any legislation or regulation implementing, made pursuant to, amending, or replacing any of them, and any other applicable data protection or privacy legislation.

1.2. "Data Processor", "Data Controller", "Data Subject", "Processing", "Subprocessor", and "Supervisory Authority" shall be interpreted in accordance with the GDPR.

1.3. "Service Provider" shall be interpreted in accordance with the CCPA.

1.4. "Personal Data" means information that relates to, or could reasonably be linked with, an identified or identifiable Data Subject who visits or engages in transactions with your business through the Services (a "Customer"), and which Trendful Processes as a Data Processor or Service Provider in the course of providing you with the Services, including through the Trendful Admin, the Sell Form, the Resale App, and in-person intake.

1.5. "Data Subject Request" means a request from or on behalf of a Customer to exercise rights under Data Protection Legislation, including access, erasure, rectification, restriction, objection, or portability of that Customer’s Personal Data.

1.6. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914, together with, where applicable, the UK International Data Transfer Addendum and any Swiss amendments.

2. Roles and Scope

2.1. As between the parties, you are the Data Controller (or Business) and Trendful is the Data Processor (or Service Provider) with respect to the Personal Data. Where you act as a processor on behalf of a third-party controller, you warrant that you have the authority to instruct Trendful as a subprocessor and to enter into this Addendum.

2.2. This Addendum applies to all Personal Data Processed by Trendful on your behalf through any of the Services, regardless of the intake channel through which the Personal Data is collected.

2.3. The subject matter, duration, nature and purpose of the Processing, the categories of Data Subjects, and the types of Personal Data are described in Annex 1.

3. Processing of Personal Data

3.1. Trendful will Process the Personal Data only as a Data Processor or Service Provider, and only for the purpose of providing the Services in accordance with your documented instructions (provided such instructions are commensurate with the functionality of the Services), the Agreement, this Addendum, and as you may subsequently agree in writing. The Agreement, together with your configuration and use of the Services, constitutes your documented instructions.

3.2. If Trendful is required by law to Process the Personal Data for any other purpose, Trendful will provide you with prior notice of that requirement unless the law prohibits such notice.

3.3. Trendful will notify you if, in Trendful’s opinion, an instruction for the Processing of Personal Data infringes applicable Data Protection Legislation.

3.4. Trendful will notify you promptly, to the extent permitted by law, upon receiving an inquiry or complaint from a Supervisory Authority relating to Trendful’s Processing of the Personal Data.

4. Confidentiality of Processing

Trendful will ensure that personnel authorized to Process the Personal Data are subject to confidentiality obligations that restrict their ability to disclose the Personal Data, and that access is limited to those personnel who require access to perform Trendful’s obligations under the Agreement.

5. Security

Trendful will implement and maintain appropriate technical and organizational measures to protect the Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, theft, alteration, or disclosure. These measures shall be appropriate to the harm that might result from such events and to the nature of the Personal Data to be protected. A description of Trendful’s technical and organizational measures is set out in Annex 2.

6. Personal Data Breach

Trendful will notify you without undue delay after becoming aware of and confirming any accidental, unauthorized, or unlawful Processing of, disclosure of, or access to the Personal Data (a “Personal Data Breach”). Such notice will include the information reasonably available to Trendful to help you meet any obligations to report or notify the Personal Data Breach under Data Protection Legislation. Trendful’s notification of or response to a Personal Data Breach is not an acknowledgment of fault or liability.

7. Data Subject Requests and Assistance

7.1. Trendful will implement reasonable technical and organizational measures enabling you to fulfill Data Subject Requests that you are obligated to fulfill under Data Protection Legislation. As between the parties, you are responsible for responding to Data Subject Requests, consistent with your responsibilities under the Agreement, including Section 25.6.9 of the Terms of Service.

7.2. If Trendful receives a Data Subject Request directly from a Customer, Trendful will, to the extent permitted by law, direct the Customer to you or promptly inform you rather than responding directly, except as required by law.

7.3. Upon request, Trendful will provide reasonable information and assistance to help you complete data protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of the Processing and the information available to Trendful.

7.4. Upon request, Trendful will provide up-to-date attestations, reports, or extracts thereof, where available, from a source charged with auditing Trendful’s data protection practices (such as external auditors, internal audit, or data protection auditors), or suitable certifications, to enable you to assess compliance with this Addendum.

8. Subprocessors

8.1. You acknowledge and agree that Trendful may engage Subprocessors to Process the Personal Data. Trendful’s engagement of each Subprocessor will comply with Data Protection Legislation and will be governed by a contract requiring the Subprocessor to provide protections for the Personal Data that are comparable to those in this Addendum. Trendful remains responsible for its Subprocessors’ performance of their obligations.

8.2. A current list of Subprocessors is available at https://www.trendful.com/legal/subprocessors.

8.3. Trendful will provide notice of the addition of a new Subprocessor (by updating the list, by email, or through the Trendful Admin) at least thirty (30) days before that Subprocessor begins Processing the Personal Data. If you reasonably object to a new Subprocessor on data protection grounds within that period, the parties will work in good faith to resolve the objection. If the objection cannot be resolved, you may, as your sole remedy, terminate the affected Services in accordance with the Agreement and your Trendful Enterprise Plan Agreement, if applicable.

9. International Data Transfers

9.1. When a Data Subject is located in the European Economic Area, the United Kingdom, or Switzerland, the provision of the Services may involve the transfer of Personal Data to other regions, including the United States. Trendful will ensure that any such transfer is carried out in compliance with applicable Data Protection Legislation.

9.2. Where Trendful Processes Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland, and that Processing involves a transfer to a country not covered by an adequacy decision, the transfer is governed by the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this Addendum by reference. You act as data exporter and Trendful acts as data importer. For transfers from the United Kingdom, the Clauses apply as varied by the International Data Transfer Addendum issued by the UK Information Commissioner’s Office. For transfers from Switzerland, they apply with the amendments required by the Swiss Federal Data Protection and Information Commissioner. The options and annexes required by the Clauses are completed in Annex 3.

10. CCPA / CPRA Service Provider Terms

The following applies to Personal Data subject to the CCPA. The parties acknowledge that Personal Data is disclosed to Trendful only for the limited and specified purpose of providing the Services (a “Business Purpose”). Trendful, acting as a Service Provider, certifies that it will:

  • not sell or share the Personal Data, as “sell” and “share” are defined under the CCPA;
  • not retain, use, or disclose the Personal Data for any purpose other than the Business Purpose of providing the Services, or as otherwise permitted by the CCPA, including outside the direct business relationship between the parties;
  • not combine the Personal Data with personal information that Trendful receives from, or on behalf of, another person, or collects from its own interaction with the Customer, except as permitted by the CCPA;
  • comply with the applicable obligations of a Service Provider under the CCPA and provide the Personal Data the same level of privacy protection as required of businesses under the CCPA; and
  • notify you if Trendful determines that it can no longer meet its obligations under the CCPA.

You have the right to take reasonable and appropriate steps to help ensure that Trendful uses the Personal Data in a manner consistent with your obligations under the CCPA, and, upon notice, to stop and remediate unauthorized use of the Personal Data.

11. Return and Deletion of Personal Data

11.1. Upon termination or expiration of the Agreement, Trendful will delete or anonymize the Personal Data in accordance with the data retention and deletion lifecycle set out in Section 25.6 of the Terms of Service, including the retention window and the holds that apply where an unpaid balance, open payout, open shipping or insurance claim, or open dispute remains outstanding.

11.2. During the retention window described in Section 25.6 of the Terms of Service (currently ninety (90) days following termination), you may request a copy or export of the Personal Data, and Trendful will provide it in a commercially reasonable format, except where an Account never activated or where providing it is not reasonably practicable.

11.3. Trendful may retain Personal Data to the extent required by applicable law, and for so long as required, after which it will be deleted or anonymized. Personal Data residing in routine backups is deleted on Trendful’s standard backup rotation schedule and is not necessarily purged at the same time as data in active production systems.

12. Audits

Trendful will make available information reasonably necessary to demonstrate compliance with this Addendum and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice, confidentiality obligations, frequency limits, and Trendful’s security and operational requirements. The attestations, reports, and certifications described in Section 7.4 will be Trendful’s primary means of demonstrating compliance.

13. Liability

Each party’s liability arising out of or related to this Addendum, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party’s liability means the aggregate liability of that party under the Agreement and this Addendum together.

14. Conflict, Amendment, and Governing Law

14.1. Precedence. In the event of any conflict or inconsistency between the provisions of the Agreement and this Addendum with respect to the Processing of Personal Data, the provisions of this Addendum shall prevail. In the event of any conflict between this Addendum and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

14.2. Continuing Effect. Except as specifically modified and amended in this Addendum, all of the terms, provisions, and requirements contained in the Agreement remain in full force and effect and govern this Addendum. If any provision of this Addendum is held illegal or unenforceable in a judicial or arbitral proceeding, that provision shall be severed and shall be inoperative, and the remainder of this Addendum shall remain operative and binding on the parties.

14.3. Amendment. Trendful may amend this Addendum from time to time by posting the relevant amended and restated Addendum on Trendful’s website. For material changes, Trendful will provide notice through the Trendful Admin Account or by email to the primary Account email address. Such amendments are effective as of the date of posting. Your continued use of the Services after the amended Addendum is posted constitutes your acceptance of the amended Addendum. If you do not agree to any changes, you must discontinue use of the Services.

14.4. Governing Law and Dispute Resolution. This Addendum is governed by and construed in accordance with the laws of the State of Florida, without regard to principles of conflicts of laws, and any dispute or claim arising out of or in connection with this Addendum is subject to the governing law and dispute resolution provisions of the Agreement, including Section 12 of the Terms of Service, except where applicable Data Protection Legislation or the Standard Contractual Clauses require otherwise.

Annex 1 – Details of Processing

DetailDescription
Subject matterTrendful’s provision of the Services to you under the Agreement, including customer-to-business resale intake, offer management, shipping, and payouts.
Duration of ProcessingFor the term of the Agreement, plus the retention and deletion period described in Section 25.6 of the Terms of Service and Section 11 of this Addendum.
Nature and purposeCollection, storage, organization, retrieval, use, transmission, and deletion of Personal Data as necessary to provide the Services and enable you to manage resale transactions with your Customers.
Categories of Data SubjectsYour Customers (sellers and buyers of pre-owned goods), and other individuals whose Personal Data you submit to or collect through the Services.
Types of Personal DataIdentification and contact data (such as name, email address, mailing address, phone number); transaction and offer data; shipping and tracking data; and payout-related data (such as bank or PayPal details) as configured in the Services. You are responsible for not submitting special categories of Personal Data except as supported by the Services.
Frequency of transferContinuous, for the duration of the Agreement.

Annex 2 – Technical and Organizational Measures

This Annex also serves as Annex II to the Standard Contractual Clauses.

Trendful is not certified under SOC 2 or ISO 27001. The measures below describe what Trendful actually operates.

Encryption. Personal Data is encrypted in transit using TLS. Data at rest is encrypted by the underlying cloud platform.

Access control. All access to Personal Data is mediated by Trendful's API, which authenticates with service credentials. Direct client access to the production database is disabled at the datastore level. Within the Trendful Admin, access is role-based: owners and members hold different scopes, and sensitive areas such as payouts and preferences are gated separately.

Separation. Client data is logically separated by team, and every query is scoped to the requesting team.

Resilience and backups. The production database runs point-in-time recovery covering a rolling seven-day window. Full database exports are written to separate cloud storage twice weekly, deliberately more often than weekly so that a single failed run still leaves a copy newer than the point-in-time window. Authentication records are exported daily, because that store has no point-in-time recovery of its own.

Business continuity. Trendful maintains a documented business continuity and disaster recovery plan, reviewed periodically and made available to you on request under Section 12.

Subprocessor management. Subprocessors are engaged under contracts requiring protections comparable to this Addendum, and the current list is published at https://www.trendful.com/legal/subprocessors.

Monitoring and incident response. Application errors and performance are monitored continuously, and personal data breaches are handled as described in Section 6.

Annex 3 – Standard Contractual Clauses Information

This Annex completes the Standard Contractual Clauses incorporated by Section 9.2.

Module. Module Two, controller to processor.

Clause 7 (docking). Applicable.

Clause 9 (subprocessors). Option 2, general written authorisation, with the thirty (30) day notice period set out in Section 8.3.

Clause 11 (redress). The optional independent dispute resolution body is not used.

Clause 17 (governing law). The law of the EU Member State in which the data exporter is established. Where the exporter is not established in an EU Member State, the law of Ireland.

Clause 18 (forum). The courts of the EU Member State whose law governs under Clause 17.

UK transfers. The Clauses apply as varied by the ICO International Data Transfer Addendum. Tables 1 to 3 are completed by the information in this Annex; under Table 4, neither party may end the Addendum as set out in its Section 19.

Swiss transfers. References to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and "Member State" is read so as not to deprive Data Subjects in Switzerland of their right to sue in their place of habitual residence.

Annex I.A – Parties

Data exporter. You, the Trendful client identified in the Agreement, acting as controller in respect of the Personal Data described below. Contact details are those on your Account.

Data importer. Trendful Inc., a Delaware corporation, 16497 Acoustic Loop, Land O Lakes, FL 34638, United States, acting as processor. Contact: support@trendful.com.

Annex I.B – Description of Transfer

As set out in Annex 1 of this Addendum, which describes the subject matter, duration, nature and purpose, categories of Data Subjects, types of Personal Data, and frequency of transfer.

Annex I.C – Competent Supervisory Authority

The supervisory authority of the EU Member State in which the data exporter is established. Where the exporter is not established in an EU Member State but has appointed a representative, the authority of the Member State in which that representative is established. Where neither applies, the Irish Data Protection Commission.

Annex II – Technical and Organizational Measures

As set out in Annex 2 of this Addendum.

Annex III – Subprocessors

The subprocessors listed at https://www.trendful.com/legal/subprocessors, as updated in accordance with Section 8.