Legal
Data Processing Addendum
Last modified: September 21, 2026
This Data Processing Addendum (“DPA”) forms part of the Pentane Terms of Service (the “Terms”) between Pentane (“Pentane”) and the customer that has accepted the Terms (“Customer”). It applies to Pentane’s processing of Customer Personal Data in providing the Services. Capitalized terms not defined here have the meanings in the Terms. In the event of conflict between this DPA and the Terms with respect to Customer Personal Data, this DPA controls.
1. Definitions
“Customer Personal Data” Personal Information contained in Your Data that Pentane processes on Customer’s behalf, as described in Annex 1.
“Data Protection Laws” all laws applicable to the processing of Customer Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”), and other U.S. state comprehensive privacy laws.
“Sub-processor” a third party engaged by Pentane to process Customer Personal Data on Pentane’s behalf.
“Security Incident” a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Pentane’s possession or control.
“Standard Contractual Clauses” or “SCCs” the standard contractual clauses approved by the European Commission in Decision 2021/914 (Module Two: controller to processor), and the UK International Data Transfer Addendum issued by the UK Information Commissioner, in each case as amended or replaced.
The terms “controller,” “processor,” “data subject,” “processing,” “business,” “service provider,” “sell,” and “share” have the meanings given in the applicable Data Protection Laws.
2. Roles and Scope
Customer is the controller (or business) of Customer Personal Data, and Pentane is the processor (or service provider). Where Customer itself acts as a processor for a third-party controller, Customer represents that its instructions to Pentane are consistent with that controller’s instructions, and Pentane acts as Customer’s sub-processor. Annex 1 sets out the subject matter, duration, nature and purpose of processing, the categories of data subjects, and the categories of Customer Personal Data.
3. Customer Instructions and Obligations
3.1 Pentane will process Customer Personal Data only on Customer’s documented instructions, which consist of the Terms, this DPA, Customer’s configuration of the Services and Connected Accounts, and any further written instructions Customer provides that are consistent with the Terms. Pentane will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is confirmed or modified.
3.2 Customer is responsible for the lawfulness of Customer Personal Data and its instructions, including that it has provided all notices and obtained all consents and lawful bases required by Data Protection Laws for Pentane and its Sub-processors to process Customer Personal Data for the purposes described in Annex 1 — including, where Customer has purchased Ad Management Services, for the use of customer identifiers and conversion data for advertising audience matching, suppression, and measurement.
3.3 Customer will not provide Pentane with, or connect to the Services any account containing, special categories of personal data (such as health, biometric, or precise geolocation data) or data subject to sector-specific regulation (such as HIPAA or GLBA) unless Pentane has agreed in writing.
4. Pentane Obligations
4.1 Confidentiality. Pentane will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and process it only as needed to provide the Services.
4.2 Security. Pentane will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against Security Incidents, as described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of processing.
4.3 Data subject requests. Taking into account the nature of the processing, Pentane will assist Customer, by appropriate technical and organizational measures, in responding to requests from data subjects to exercise their rights under Data Protection Laws. If Pentane receives such a request directly, it will, to the extent legally permitted, refer the data subject to Customer and notify Customer. Pentane will act on verified requests forwarded by Customer, including Shopify customer data-request and erasure webhooks, within the time required by Data Protection Laws.
4.4 Compliance assistance. Pentane will provide reasonable assistance to Customer with data protection impact assessments and consultations with supervisory authorities, to the extent required by Data Protection Laws and relating to Pentane’s processing.
4.5 Security Incidents. Pentane will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed, to the extent known, and will be supplemented as information becomes available. Pentane’s notice is not an admission of fault or liability.
4.6 Deletion and return. Within thirty (30) days after termination of the Terms or on Customer’s written request, Pentane will delete Customer Personal Data, except (a) as retained in routine backups for a limited period, subject to the same protections, until overwritten; (b) as required to be retained by law; and (c) Usage Data that does not identify any individual. During the Data Retrieval Period in the Terms, Customer may export Customer Personal Data using the Platform’s available export features.
4.7 Information and audit. Pentane will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable written security questionnaires and, where available, summaries of third-party assessments. Where Data Protection Laws grant Customer an audit right that cannot be satisfied by such information, Customer (or an independent auditor bound by confidentiality) may conduct an audit no more than once per year, on at least thirty (30) days’ written notice, during business hours, at Customer’s expense, and without unreasonable disruption to Pentane’s operations or access to other customers’ data.
5. Sub-processors
5.1 Customer generally authorizes Pentane to engage Sub-processors, including the Sub-processors listed in Annex 3, to process Customer Personal Data. Pentane will impose on each Sub-processor data-protection obligations that are no less protective than those in this DPA, and Pentane remains responsible for each Sub-processor’s performance.
5.2 Pentane will maintain the current list of Sub-processors at the location stated in Annex 3 and will give Customer at least fifteen (15) days’ notice (by updating that list and notifying Customer through the Platform or by email) before authorizing a new Sub-processor to process Customer Personal Data. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection in good faith within thirty (30) days, Customer may terminate the affected Services on written notice.
5.3 Plenum. Where Customer has purchased Ad Management Services, Plenum Labs LLC, an Affiliate of Pentane, acts as a Sub-processor for the audience, suppression, and measurement processing described in Annex 1. Where Customer has separately accepted Plenum’s Master Services Agreement, Plenum’s own data processing terms govern Plenum’s processing under that agreement, and this DPA governs only the Customer Personal Data Pentane provides to Plenum on Customer’s instructions.
6. CCPA and U.S. State Law Terms
To the extent Customer Personal Data is subject to the CCPA or another U.S. state privacy law, Pentane acts as a service provider or processor and: (a) will not sell or share Customer Personal Data; (b) will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Terms and this DPA, or outside the direct business relationship with Customer; (c) will not combine Customer Personal Data with personal information it receives from or on behalf of any other person, or collects from its own interactions with consumers, except as permitted for service providers under the CCPA; (d) will comply with applicable obligations under the CCPA and provide the same level of privacy protection it requires; (e) will notify Customer if it determines it can no longer meet its obligations under the CCPA; and (f) grants Customer the right, upon reasonable notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data. Pentane certifies that it understands these restrictions and will comply with them.
7. International Transfers
7.1 Pentane processes Customer Personal Data in the United States. To the extent Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to Pentane, the transfer is governed by the SCCs, which are incorporated into this DPA by reference, with Customer as data exporter and Pentane as data importer; Module Two applies; Clause 7 (docking) is included; Clause 9 Option 2 (general authorization) applies with the notice period in Section 5.2; Clause 11 optional language does not apply; Clause 13 and the governing-law and forum clauses are completed with the law and courts of Ireland (for the EU SCCs), England and Wales (for the UK Addendum), and Switzerland as applicable; and Annexes 1, 2, and 3 of this DPA serve as Annexes I, II, and III of the SCCs.
7.2 If Pentane adopts an alternative lawful transfer mechanism recognized under Data Protection Laws, Pentane may rely on it in place of the SCCs on notice to Customer.
8. Platform-Specific Requirements
Pentane processes data obtained from Connected Accounts in accordance with the data-protection requirements of the relevant platform, including the Shopify API License and Terms of Use (including mandatory compliance webhooks) and Amazon’s Data Protection Policy for Selling Partner API data, and applies any retention limits those requirements impose, which may be shorter than the retention periods in the Terms.
9. Liability; Term; General
9.1 Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Terms, and Pentane’s total liability under the Terms and this DPA combined will not exceed the cap stated in the Terms.
9.2 This DPA takes effect on the date Customer accepts the Terms and continues for as long as Pentane processes Customer Personal Data. Sections 4.6 and 9 survive termination.
9.3 This DPA is governed by the law governing the Terms, except where the SCCs require otherwise. Pentane may update this DPA on notice as required to reflect changes in Data Protection Laws or the Services, provided the update does not materially reduce the protections for Customer Personal Data.
Annex 1 — Details of Processing
Subject matter and duration. Pentane’s provision of the Platform and, where purchased, Ad Management Services, for the term of the Terms plus the deletion period in Section 4.6.
Nature and purpose. Retrieval of data from Customer’s Connected Accounts; calculation of profitability, margins, breakeven and budget guidance, and attribution; reconciliation of advertising results to orders; reporting and alerts; AI-assisted analysis; and, where Ad Management Services are purchased, advertising planning, management, and measurement, including providing hashed customer identifiers and conversion signals to Plenum and to advertising platforms for audience matching, suppression, and measurement at Customer’s direction.
Categories of data subjects. Customer’s customers and prospective customers (purchasers and site visitors of Customer’s stores); Customer’s Authorized Users and personnel.
Categories of Customer Personal Data. Order and refund records; names; email addresses; phone numbers; shipping and billing addresses; customer identifiers and hashed identifiers; purchase history and order values; advertising interaction and conversion data; Authorized User contact and login information.
Special categories. None. Customer will not provide special categories of personal data (Section 3.3).
Frequency. Continuous, via API synchronization, for the duration of the Services.
Annex 2 — Technical and Organizational Measures
Pentane maintains the following measures, as updated from time to time and described further in its security documentation at pentane.com/security:
(a) Encryption of Customer Personal Data in transit using TLS and at rest using industry-standard encryption provided by Pentane’s cloud infrastructure provider.
(b) Access control based on least privilege; role-based access to production systems; multi-factor authentication for administrative and infrastructure access; prompt revocation of access on personnel changes.
(c) Logical separation of each customer’s data within the Platform, with controls preventing cross-customer access or combination.
(d) Logging and monitoring of access to production systems and Customer Personal Data; retention of audit logs; alerting on anomalous activity.
(e) Secure development practices, including code review, dependency management, and segregated development, staging, and production environments.
(f) Backups stored encrypted, with periodic restoration testing, and retained for a limited period.
(g) Vendor management, including data-protection review of Sub-processors before engagement and contractual flow-down of security obligations.
(h) Incident response procedures for detecting, assessing, containing, and notifying Security Incidents, including the notice commitments in Section 4.5.
(i) Data minimization, including limiting data sent to AI model providers to what a feature requires, and hashing customer identifiers before providing them for advertising audience matching.
(j) Personnel confidentiality obligations and periodic security awareness training.
Annex 3 — Sub-processors
The current list of Sub-processors is maintained at pentane.com/subprocessors. As of the date of this DPA:
Amazon Web Services, Inc., Supabase, Vercel — hosting, storage, and compute — United States.
Plenum Labs LLC — Affiliate; advertising audience matching, suppression, and measurement for Customers that purchase Ad Management Services — United States.
Anthropic, OpenAI, Gemini — AI-assisted analysis features; no training on Customer Personal Data — United States.
Klaviyo, Resend, Gmail — transactional email and alerts to Authorized Users — United States.
Intercom — customer support — United States.
Google Analytics — Platform usage analytics (Authorized User data only) — United States.
Stripe, Inc. processes payment data for Pentane as an independent controller and is not a Sub-processor of Customer Personal Data.