Data processing addendum
The addendum offered to Enterprise and Partner accounts, with the sub-processor schedule it refers to.
In force from 2026-09-21. This page is the addendum: it applies to an Enterprise or Partner account on acceptance of the terms, and a countersigned copy is available on request. Everything below describes what the product actually does. One clause still carries a marker, because the transfer mechanism follows from where the operator is established and that is not yet settled.
1. The parties and roles
The customer is the controller of the personal data processed under their account. BEMATIC ONLINE SAS, trading as SuiteAnalytics (martinclavell.com) is the processor, operating SuiteAnalytics. This addendum applies where the customer’s use of SuiteAnalytics involves personal data and takes effect with the terms of service.
It is governed by [to be supplied: the governing law and the courts that hear a dispute].
2. What is processed, and why
Subject matter. Auditing a SuiteCommerce storefront the customer has verified, or — for a partner account — a storefront covered by the partner clauses of the terms, and producing reports from it.
Categories of data subject. The customer’s own users: the people who hold accounts with us on the customer’s behalf. Incidentally, any person named in the public text of the storefront being audited — an author on a blog page, a name in a testimonial.
Categories of personal data. Account holders’ e-mail addresses and names; the billing contact held by our payment processor; hashed addresses and user-agent hashes in the audit log; and the storefront content described above. The relationship an organisation declares to a storefront at signup is recorded against the organisation, not the person, and is a self-declared business fact rather than a verified one. No special categories of data are processed, and none are requested.
What is never processed. Nothing behind a storefront login is fetched, and no order, customer or shopper data is read. That is a scope decision enforced at the crawler, not a setting. Configuration values that look like credentials are recorded by path, length and character classes, and the value itself is discarded.
3. Instructions
We process personal data only on the customer’s documented instructions, which are this addendum, the terms of service and the actions the customer takes in the product. We tell the customer if an instruction appears to conflict with applicable law rather than carrying it out.
4. Confidentiality
Everyone with access to personal data processed under this addendum is bound to confidentiality, and access is granted on the least privilege the task needs.
5. Security
Transport is HTTPS throughout. Every query against customer data is scoped to the customer’s organisation at the data layer rather than in a view. Destinations for alerts and webhooks are stored sealed under a key the application service alone holds, and the key can be rotated without a customer noticing. Secrets are never written to a log: what may be logged is an allowlist, and a field outside it is dropped. These are the measures we operate, described so a customer’s reviewer can check them against what the product does.
6. Sub-processors
Customers are notified before a sub-processor is added. Enterprise customers may object. The schedule below is generated from the same source as the public sub-processor page, so the two cannot differ.
| Sub-processor | Purpose | What it can see |
|---|---|---|
| Railway | Hosting, Postgres | Everything the application holds, at the infrastructure level |
| Cloudflare R2 | Object storage: HTML, DOM dumps, screenshots, bundles, PDFs | Stored objects |
| PayPal | Payments | The payer’s PayPal account and payment instrument, and what is being paid for. We never see card data |
| Resend | Transactional e-mail | Recipient address and the body of our own e-mails |
| Sentry | Error monitoring | Stack traces and request metadata, allowlist-scrubbed |
| OpenAI | classifier, analyst and writer model roles | Redacted evidence slices only |
| Anthropic | Second adapter for the same roles, switchable per role by configuration | Redacted evidence slices only |
| mdtopdf | PDF rendering | The report Markdown we send it, for an account entitled to a PDF, from our API service only |
7. International transfers
Where personal data leaves the region it was collected in, the transfer relies on [to be supplied: the transfer mechanism for personal data leaving its region, which follows from where the operator is established].
8. Assisting the controller
We assist the customer with requests from data subjects — access, correction, erasure, portability — and with data protection impact assessments and prior consultations, using the information the product already holds. A request about a specific audit can be answered from the audit log, which records who requested a crawl of which domain and which report it produced.
9. Personal data breach
We notify the customer without undue delay after becoming aware of a personal data breach affecting their data. Where the General Data Protection Regulation applies, that is the 72 hours it allows a controller to notify its supervisory authority, and we notify in time for the customer to meet it rather than at the deadline itself. The notice states what happened, which data and how many records are affected as far as we know at the time, what we have done, and what we are still doing. We send a first notice with what is known rather than a complete one later.
10. Deletion and return
On termination, deleting the customer’s organisation deletes its audits, snapshots, findings, reports, comparisons, alerts, schedules, destinations and credit ledger, and purges the stored objects those rows pointed at — the raw HTML, the DOM dumps, the screenshots and the PDFs. The purge lists each prefix empty before it reports itself done. What survives is the audit log with the organisation detached, and the payment records our payment processor keeps for the statutory period, which are theirs rather than ours to delete. Retention before termination is the table in the privacy notice, which is generated from the same constants the deletion sweep reads.
Separately from this addendum, the owner of a storefront the customer audited may ask us directly to delete what we hold about that domain, and we will within 30 days of confirming they control it. That request is not the customer’s to refuse and we do not ask their permission — an opt-out by a merchant who is not our customer is a promise we make to the person it protects, and one a partner agreement cannot bargain away. We tell the customer that the data went.
11. Audits and information
We make available the information needed to demonstrate compliance with this addendum. An Enterprise customer may audit, once in any twelve months and on thirty days’ written notice, at their own cost unless the audit finds a material breach of this addendum. We claim no certification and no third-party attestation: where a customer’s questionnaire asks for one, the honest answer is that we do not hold it.
12. Execution
This page is the addendum, and it applies without signature to an Enterprise or Partner account from the date above. Where a customer’s procurement needs a countersigned copy, ask and we return one executed on behalf of the processor; a customer’s own paper is considered but this addendum is what we offer. Requests and questions about it go to [email protected].