Version 1.1 · Effective date: on publication of version 1.1

Data Processing Agreement

This document is public information and is not legal advice. Obtain advice for your specific situation.

This Data Processing Agreement (DPA) applies when Catalogix processes personal data for a business customer using the Catalogix service. It forms part of the customer’s agreement for the service. Catalogix is the processor and the customer is the controller, unless the parties document another role for a particular processing activity. Each party will comply with applicable data protection law.

1. Documented instructions and scope

Catalogix processes customer personal data only on the customer’s documented instructions, including to provide, secure, support and improve the service as described in the service agreement and public documentation. The customer determines the purposes and means of processing, categories of data and retention periods. Catalogix will inform the customer if an instruction appears to infringe applicable law and may suspend that instruction while seeking clarification.

The service is designed for supplier catalogue and product data. The customer must not upload sensitive personal data, payment data, customer records, employee records or regulated data unless the parties have agreed in writing that the service is suitable and the required safeguards are in place.

2. Processing details and confidentiality

The subject matter is hosting, organising, comparing and exporting the customer’s files and related account records. Processing lasts for the term of the service and any limited period needed to return or delete data. Catalogix ensures that persons authorised to process personal data are bound by confidentiality obligations.

3. Security

Catalogix applies reasonable technical and organisational measures appropriate to the service and its risks, including authenticated access, organisation-level access separation, password hashing, session controls and operational access controls. Catalogix does not promise a particular security certification or absolute security. The customer is responsible for access management on its side and for reviewing the suitability of the service for its data.

4. Personal-data incidents

Catalogix will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data, to the extent information is available. The notice will describe the known nature of the incident, likely consequences and mitigation steps. Catalogix will reasonably cooperate with the customer’s response and will not make a public attribution that identifies the customer without good reason or legal obligation.

5. Assistance

Taking account of the nature of processing and information available to Catalogix, Catalogix will reasonably assist with data-subject requests, security obligations, breach notifications, impact assessments and consultations with supervisory authorities. The customer remains responsible for responding to data subjects and regulators. Assistance that is disproportionate or outside ordinary service support may be subject to reasonable charges agreed in advance.

6. Audits and information

Catalogix will make information reasonably necessary to demonstrate compliance available to the customer, subject to confidentiality and security restrictions. A customer may request one remote audit or questionnaire per year on reasonable notice, and additional reviews after a material incident or where required by law. Audits must not disrupt the service or expose another customer’s information.

7. Subprocessors

The customer authorises Catalogix to use the subprocessors listed on the public Subprocessors page. Catalogix will impose written data-protection obligations on subprocessors and remains responsible for their processing as required by applicable law. Catalogix will provide notice of a material intended change where required; the customer may raise a reasonable, specific objection on data-protection grounds.

8. International transfers

Catalogix will not knowingly make a restricted international transfer of customer personal data without a lawful transfer mechanism. The parties will document any applicable safeguards before such transfer. No region, adequacy decision, standard contractual clause or transfer location is promised by this public DPA; contractual owner confirmation is pending where the provider list marks it as pending.

9. Return, deletion and retention

The following periods are calendar days or months. Original supplier uploads are retained while the organisation is active and deleted on an explicit user request or no later than 30 days after organisation closure. Processed catalogue data, mappings and versions are retained while the organisation is active, with a 30-day recovery period after closure. Generated exports are retained for 30 days.

Transactional email records and related webhook events are retained for 90 days. Bounce and complaint suppression data is retained only as a hash until 24 months after the last relevant event. Checkout attempts and growth events are retained for 24 months. Audit logs are retained for 24 months, and application and security logs for 90 days. Analytics and attribution data is retained for no more than 13 months. Sentry events are retained for 30 days only if optional Sentry monitoring is configured.

Backups are retained for no more than 35 days where supported by the relevant infrastructure and contractually confirmed; no universal provider capability or actual backup period is promised here. Invoices and fiscally relevant billing records are retained for 7 years. Evidence of acceptance of the Terms and Privacy Policy is retained for 7 years after the agreement ends. Deletion-job records are retained until successful completion and for 90 days afterwards.

A legal hold may delay deletion only as an explicit, limited and auditable exception, for no longer than demonstrably necessary. At the end of a hold, the normal deletion schedule applies. Customers should export any data they need before closure; Catalogix is not a permanent archive.

10. Liability and precedence

The service agreement governs fees, warranties, liability and termination. If this DPA conflicts with the service agreement on data processing, this DPA controls for that conflict. Nothing in this DPA limits mandatory rights or obligations under applicable data protection law.

Annex 1 — Processing description

Data subjects: business users and contacts whose details the customer puts into the service. Data categories: account and organisation details, contact details, supplier and catalogue records, support correspondence and operational identifiers. Special-category data: not intended and must not be uploaded. Operations: collection through the service, hosting, organisation, comparison, transformation, export, support and deletion. Purpose: provide the customer’s catalogue workflow. Duration: the service term plus the return/deletion period.

Annex 2 — Approved subprocessors and service providers

Replit provides application hosting and Replit App Storage, backed by Google Cloud Storage (GCS), for private files. The application database infrastructure processes account, organisation and catalogue records; its provider chain and contractual details must be confirmed against the current arrangements. Resend is a transactional email provider only when transactional sending is activated and configured. Zoho is used for the business mailbox and reply-to correspondence to the extent actually used. Stripe processes billing only when billing is enabled and used. Sentry is an optional monitoring provider and receives monitoring data only when configured. Provider location, contract terms and transfer safeguards must be checked against the current provider arrangements; this public DPA does not promise a particular region, certification or transfer location.

Contact: hello@catalogix.io