Data Processing Addendum
Version 2026-07-31 · effective
Draft for owner and legal review. The routing, versioning, and acceptance mechanics around this document are production code. The prose is not legal advice and has not been reviewed by counsel. A countersigned copy is available on request.
This is a plain-language summary of how PpcGPT handles data it processes on your behalf.
Roles
You are the controller of your business data. PpcGPT is your processor: we process it to provide the service, on your instructions, and for nothing else.
Scope of processing
Subject matter. Operating the PpcGPT service for the Amazon stores you connect.
Duration. For as long as your account exists, plus the deletion window described in the Privacy Policy.
Categories of data. Your account details, your Amazon business data, the costs you enter, and records of what was approved. No buyer personal information — see the Privacy Policy for why that is a structural property rather than a promise.
Categories of data subject. Your team members. Not your buyers.
Our obligations
- Process only on your documented instructions.
- Keep the people with access bound to confidentiality.
- Apply the security measures described in the Privacy Policy.
- Engage subprocessors only as listed on the Subprocessors page, with 30 days' notice of changes.
- Assist you with data-subject requests and with security incidents.
- Delete your data when you ask, and give you the deletion certificate.
Security incidents
We will notify you without undue delay after becoming aware of a breach affecting your data, with what we know and what we are doing about it.
Transfers
Data is processed in the United States. Where a transfer mechanism is required, we rely on the standard contractual clauses.
Audit
We will respond to reasonable written questions about this addendum, and provide the documentation we hold, once per year.
Contact
privacy@ppcgpt.ai for a countersigned copy or any question about this addendum.