Last updated: September 29, 2026
Remworth Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of and is incorporated into the Terms of Service ("Terms") between NSR ONE, LLC, a New York limited liability company, doing business as Remworth ("Remworth," "we," "us," or "our"), and the business that has agreed to the Terms ("Customer," "you," or "your"). This DPA governs the Processing of Personal Data in connection with the Service. Where this DPA conflicts with the Terms with respect to the Processing of Personal Data, this DPA controls.
By using the Service after the effective date above, you agree to this DPA on behalf of the entity you represent, and you warrant that you have authority to bind that entity.
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms.
- "Amazon DPP" means the Amazon Acceptable Use Policy and the Amazon Selling Partner API Data Protection Policy, as updated by Amazon from time to time.
- "Amazon Information" means data we obtain from Amazon's Selling Partner API ("SP-API") on your authorization, including order IDs, SKUs/ASINs, quantities, sale amounts, fees, settlements, refunds, reimbursements, removals, inventory ledger, and listing/catalog data. Coarse ship-to geography (city, state/region, postal code, and country) is a separate, expressly-named buyer-derived category — the only buyer-derived data retained — and is not part of "Amazon Information" (see Annex 1 §E).
- "CCPA" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, and its regulations.
- "Controller" means the entity that determines the purposes and means of Processing Personal Data (including a "business" under the CCPA).
- "Customer Data" means all data you submit to, or that we Process on your behalf through, the Service, including Amazon Information.
- "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the CCPA, and the Virginia, Colorado, Connecticut, and Texas consumer data protection acts (collectively, "US State Privacy Laws").
- "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
- "Personal Data" or "Personal Information" means information relating to an identified or identifiable person, as defined by applicable Data Protection Laws, that is contained within Customer Data.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed under this DPA.
- "Processing" (and "Process") means any operation performed on Personal Data, whether or not by automated means.
- "Processor" means the entity that Processes Personal Data on behalf of a Controller (including a "service provider" under the CCPA).
- "SCCs" means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "Subprocessor" means a third party we engage to Process Personal Data.
- "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (the "UK IDTA/Addendum").
2. Roles of the Parties and Data Flow
2.1 Dual role of Remworth. The Service processes two categories of data with different role allocations:
(a) Book-of-record data (Remworth as Processor). With respect to Amazon Information and your other financial and operational records that we Process to provide the Service to you, you are the Controller and Remworth is the Processor acting on your documented instructions. You authorize SP-API access to your Amazon Seller Central account, and you are responsible for having a lawful basis for the Amazon Information you direct us to Process.
(b) Account, team, billing, website, and marketing data (Remworth as Controller). With respect to the Personal Data of your account administrators and team members that we Process to create and secure accounts, authenticate users, bill you, provide support, secure the Service, and (on unauthenticated marketing pages) market the Service, Remworth acts as a Controller and Processes such data in accordance with our Privacy Policy. To the extent Remworth engages third parties for these Controller purposes, it does so as a Controller contracting its own Subprocessors.
2.2 Amazon flow-down. You and Remworth acknowledge that Amazon Information is subject to the Amazon DPP. The obligations imposed on developers and on data recipients under the Amazon DPP flow down to Remworth as Processor and, in turn, are flowed down by Remworth to its Subprocessors that receive Amazon Information, by written contract imposing equivalent obligations. Nothing in this DPA authorizes any Processing of Amazon Information that the Amazon DPP prohibits.
2.3 Amazon-data firewall. Amazon Information is used only to provide you your own Service and to meet legal, tax, and accounting requirements. Amazon Information is never sold, licensed, shared for cross-context behavioral advertising, used to market to or target Amazon customers, or fed to advertising or analytics tools. Advertising and analytics tags run only on unauthenticated marketing pages and never on authenticated application or financial-data pages.
3. Scope and Instructions
3.1 Documented instructions. Remworth will Process Personal Data for which it acts as Processor only on your documented instructions, including with regard to international transfers, unless required to Process otherwise by applicable law to which Remworth is subject. This DPA, the Terms, your configuration and use of the Service, and your written requests through supported channels constitute your complete and final instructions.
3.2 Duty to inform. Where Remworth is required by law to Process Personal Data otherwise than on your instructions, Remworth will inform you of that legal requirement before Processing, unless the law prohibits such disclosure on important grounds of public interest.
3.3 Duty to flag infringing instructions. Remworth will promptly inform you if, in its opinion, an instruction infringes applicable Data Protection Laws. In such a case, Remworth may suspend performance of the affected instruction (without liability) until you confirm, amend, or withdraw it.
3.4 Compliance. Each party will comply with its obligations under applicable Data Protection Laws. You are responsible for the lawfulness of the Personal Data you provide and the instructions you give.
4. Confidentiality
Remworth ensures that all personnel authorized to Process Personal Data are bound by written confidentiality obligations (or an appropriate statutory obligation of confidentiality), are trained on their data-protection responsibilities, and access Personal Data only on a least-privilege, need-to-know basis. Internal administrative and support access is limited to designated administrator accounts; support access to Customer Data is through a dedicated read-only interface; administrative operations that modify Customer Data are audit-logged; and no administrative or support surface exposes decrypted secrets.
5. Security Measures
5.1 Remworth implements and maintains the technical and organizational security measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk to Data Subjects.
5.2 Without limiting Annex 2, these measures include: encryption of data in transit using TLS 1.2 or higher; encryption of sensitive credentials at rest using AES-128 (with HMAC-SHA256 authentication) and, for the object-storage layer, AES-256; support for RSA-2048 or stronger where asymmetric cryptography is used; a managed key lifecycle with keys held only in environment configuration (never in the database or source code), at least annual key rotation, and immediate revocation of any compromised key; encrypted backups; pseudonymization and minimization where feasible; and measures to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems, including regular testing and the ability to restore availability and access to Personal Data in a timely manner after an incident.
5.3 You are responsible for your own use of the Service, including securing your account credentials, configuring team roles appropriately, and maintaining the confidentiality of your SP-API credentials and Aura API key.
6. Subprocessors
6.1 General authorization. You provide general written authorization for Remworth to engage Subprocessors to Process Personal Data, subject to this Section 6. The current Subprocessors are listed in Annex 3.
6.2 Flow-down. Remworth imposes on each Subprocessor, by written contract, data-protection obligations that are substantially equivalent to and no less protective than those in this DPA, including the applicable SCC/UK Addendum terms and the Amazon DPP flow-down where the Subprocessor receives Amazon Information. Remworth remains fully liable to you for each Subprocessor's performance of its data-protection obligations.
6.3 Notice of changes and right to object. Remworth will maintain and publish its current Subprocessor list and will give you advance notice (by updating the list and, where you subscribe, by email or in-product notice) at least thirty (30) days before authorizing a new Subprocessor. You may object on reasonable, documented data-protection grounds within fifteen (15) days of that notice. The parties will work in good faith to resolve the objection; if it cannot be resolved and Remworth cannot provide the affected feature without the new Subprocessor, your sole remedy is to terminate the affected portion of the Service.
7. Assistance with Data-Subject and Consumer Rights
7.1 Taking into account the nature of the Processing, Remworth will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise Data-Subject or consumer rights (access, rectification, erasure, restriction, portability, objection, opt-out of sale/sharing, and similar rights) under Data Protection Laws.
7.2 If Remworth receives such a request directly from a Data Subject or consumer relating to Personal Data Processed on your behalf, Remworth will, unless legally required to act, promptly forward the request to you and will not respond to it except on your documented instructions.
8. Assistance with Security, Breach, and Assessments
Taking into account the nature of Processing and the information available to it, Remworth will assist you in ensuring compliance with your obligations relating to (a) security of Processing, (b) notification of Personal Data Breaches to supervisory authorities and Data Subjects, (c) data protection impact assessments and data-protection assessments, and (d) prior consultation with supervisory authorities.
9. Personal Data Breach Notification
9.1 Remworth will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed on your behalf, and in any event in time to allow you to meet your own notification duties (including any 72-hour obligation under the GDPR).
9.2 The notification will describe, to the extent known and as it becomes available: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address and mitigate the breach. Remworth will provide reasonable cooperation and updates.
9.3 Amazon incident timeline. Where a security incident involves Amazon Information, Remworth will also cooperate with the Amazon DPP's expectation that Amazon be notified of a qualifying incident within twenty-four (24) hours of detection, and will provide you the information needed to meet that expectation.
9.4 Notification of a breach is not an acknowledgment of fault or liability.
10. Return and Deletion of Personal Data
10.1 On termination. Upon expiry or termination of the Service, and at your choice, Remworth will delete or return all Personal Data Processed on your behalf, and delete existing copies, except to the extent retention is required by applicable law or a legitimate legal, tax, or accounting basis. You can initiate deletion yourself: an account owner can delete the organization from Settings → Delete account (after first removing team members), and an individual team member can remove their own account from Settings at any time; you may also request deletion by emailing [email protected]. Account deletion immediately cancels the subscription, disconnects Amazon, and wipes the stored SP-API credentials and Aura API key, and schedules permanent deletion of all associated Personal Data and Amazon Information after a 30-day recoverable grace period, during which the owner can restore the account using a link emailed at the time of deletion; backup copies age out within about 30 days, subject to the legal, tax, and accounting retention carve-outs in this Section 10.
10.2 Amazon deletion schedule. In addition, and consistent with the Amazon DPP:
(a) Any buyer Personal Information that is inadvertently received will be deleted or anonymized within thirty (30) days of order delivery. Remworth does not collect or store Amazon buyer names, street addresses, email addresses, phone numbers, or gift messages; the only buyer-derived data retained is coarse ship-to geography (city, state/region, postal code, country).
(b) Stored SP-API credentials and the Aura API key are deleted promptly upon Amazon disconnect, team off-boarding, or account closure.
(c) Associated Amazon Information is deleted within thirty (30) days of an Amazon deletion request or of your disconnect/off-boarding/account closure, subject to legal and tax retention carve-outs.
(d) Amazon Information that is not Personal Data (order IDs, SKUs, revenue, fees, and similar financial figures) is retained while your account is active and as needed to provide the Service. Consistent with the Amazon DPP, we do not retain such non-personal Amazon Information beyond eighteen (18) months from its retrieval, except where a legal, tax, or accounting obligation — including your own bookkeeping and record-keeping, which is a core purpose of the Service — requires longer retention, or unless you request earlier deletion.
10.3 Backups. Backups are retained for thirty (30) days and are encrypted; Personal Data in backups is deleted on the ordinary backup-rotation cycle following deletion from the live system.
10.4 Security and support logs. Security and support access logs are retained for at least twelve (12) months.
11. Records, Audits, and Inspections
11.1 Remworth will make available to you information reasonably necessary to demonstrate compliance with this DPA and will maintain records of its Processing activities carried out on your behalf as required by Data Protection Laws.
11.2 Remworth will allow for and contribute to audits, including inspections, conducted by you or an independent auditor you mandate. This audit right is satisfied primarily by Remworth providing available third-party certifications, attestations, and audit reports. If those are insufficient to demonstrate compliance with a specific, documented concern, you may conduct, no more than once per twelve-month period (except following a Personal Data Breach or where required by a supervisory authority), an audit on reasonable prior written notice, during business hours, subject to confidentiality, and without unreasonably disrupting Remworth's operations.
11.3 Amazon audits. Remworth will cooperate with audits and assessments that Amazon (and its affiliates and contractors) is entitled to conduct in respect of Amazon Information, and will extend reasonable cooperation to such audits as required by the Amazon DPP.
12. International Transfers
12.1 Remworth will Process and transfer Personal Data internationally only where a valid transfer mechanism is in place. The parties do not rely on the EU-US Data Privacy Framework as a transfer mechanism under this DPA.
12.2 EU transfers. To the extent the Processing of Personal Data protected by the EU GDPR involves a restricted transfer, the SCCs are incorporated into this DPA by reference and apply as follows:
(a) Module Two (Controller to Processor) applies where you are the Controller and Remworth is the Processor;
(b) Module Three (Processor to Subprocessor) applies where you act as Processor for a third-party Controller and Remworth is your Subprocessor, and to onward transfers by Remworth to its Subprocessors.
(c) Docking clause (Clause 7) applies; Clause 9 Option 2 (general written authorization) applies, with the advance-notice period for that Option being the thirty (30) days specified in Section 6.3; Clause 11 optional independent dispute-resolution language does not apply; Clause 17 governing law and Clause 18 forum are those of the EU Member State identified in your account details or, failing that, Ireland; and the Annexes of the SCCs are populated by Annexes 1–3 of this DPA.
12.3 UK transfers. For Personal Data protected by the UK GDPR, the SCCs as implemented above apply as varied by the UK IDTA/Addendum, which is incorporated by reference; the "Addendum EU SCCs" are the SCCs completed under Section 12.2, and Tables 1–3 and the "Mandatory Clauses" of the UK Addendum are completed with the information in this DPA and its Annexes.
12.4 Transfer risk assessment. Remworth commits to carrying out and, on reasonable request, sharing the results of a transfer risk assessment for restricted transfers, and to implementing supplementary measures where necessary.
12.5 In the event of a conflict between the SCCs/UK Addendum and this DPA, the SCCs/UK Addendum prevail with respect to the restricted transfer.
13. CCPA Service-Provider Terms
Where Remworth Processes Personal Information subject to the CCPA on your behalf, Remworth acts as a service provider, and:
13.1 Remworth Processes such Personal Information solely to perform the Service (the specified business purposes) under the Terms and this DPA, and for no other purpose;
13.2 Remworth will not sell or share such Personal Information;
13.3 Remworth will not retain, use, or disclose such Personal Information for any purpose other than the specified business purposes, including outside the direct business relationship between you and Remworth, unless expressly permitted by the CCPA;
13.4 Remworth will not combine such Personal Information with Personal Information it receives from, or on behalf of, other persons, or collects from its own interactions with the consumer, except as permitted by the CCPA;
13.5 Remworth certifies that it understands and will comply with the restrictions in this Section 13;
13.6 Remworth will notify you if it determines it can no longer meet its obligations under the CCPA; and
13.7 You may take reasonable and appropriate steps to help ensure Remworth uses Personal Information consistent with your CCPA obligations, and to stop and remediate unauthorized use.
14. Other US State Privacy Laws (VA, CO, CT, TX)
Where Remworth Processes Personal Data as a processor under the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, or the Texas Data Privacy and Security Act, Remworth will: (a) adhere to your instructions and Process Personal Data only for the nature and purpose of Processing set out in Annex 1; (b) Process only the types of Personal Data and for the duration described in Annex 1, respecting both parties' rights and obligations; (c) ensure each person Processing Personal Data is subject to a duty of confidentiality; (d) at your direction, delete or return all Personal Data at the end of the provision of Services unless retention is required by law; (e) on reasonable request, make available information necessary to demonstrate compliance and allow and cooperate with reasonable assessments/audits (which may be satisfied by a qualified independent assessor's report); and (f) engage Subprocessors only under a written contract that imposes equivalent obligations (Section 6).
15. Advertising and Analytics - Boundary and Future Vendor Role
15.1 No advertising or analytics tag operates on the authenticated application. Behaviour analytics (Hotjar, a Subprocessor - Annex 3, item 11) and advertising measurement (the Reddit Pixel, operated by Reddit, Inc. as an independent controller - Annex 3, item 12) operate on the unauthenticated marketing site at remworth.com only. As an unconditional commitment, no analytics, session-recording, or advertising tag will ever operate on app.remworth.com, on any authenticated page, or on any page displaying financial data or Amazon Information, and none will ever touch Amazon Information (Section 2.3). Cloudflare's cookieless Web Analytics beacon records page views and load performance on both surfaces; it sets no cookie, assigns no identifier, and has no access to Amazon Information.
15.2 Any behavioral-analytics or advertising tag runs only on the unauthenticated marketing site, its vendor is named in Annex 3 before any processing begins, and where that vendor acts for its own purposes it is characterized as an independent or joint controller rather than a Subprocessor, with the appropriate controller-to-controller terms documented. The Reddit Pixel is such a case: Reddit, Inc. processes the marketing-page visit data it receives (page address, a random browser identifier, a click identifier, IP address, device and browser details) as an independent controller under its own privacy policy and advertising terms. No Customer Personal Data processed under this DPA, and no Amazon Information, reaches it.
16. Amazon Security-Controls Attestation
Consistent with the Amazon DPP, Remworth attests that it maintains, at minimum: no hardcoded credentials in code or configuration repositories; mandatory multi-factor authentication (TOTP) for all application accounts; a 12-character minimum password policy with four character classes, password-history/re-use controls, a 365-day maximum password age, and hashing of stored passwords with bcrypt; account lockout after a defined number of failed login attempts; rotation of credentials and API keys, with immediate revocation of compromised keys; endpoint anti-malware protection, with automatic updates and tamper protection, on workstations with access to Personal Data, alongside server workloads that run as immutable containers rebuilt from a pinned base image on every deployment; least-privilege access limited to trained personnel; automated vulnerability scanning of application dependencies on every relevant code change and on a recurring schedule, with independent third-party penetration testing to be introduced as the Service scales; remediation service levels targeting critical findings within approximately seven (7) days and high findings within approximately thirty (30) days; and geographically recoverable backups, encrypted at rest, with restoration procedures exercised against real backups.
17. Consent Position
No end-user consent is collected, no consent banner is presented, and no end-user consent records exist or are retained. The Service and its marketing site are offered to business users in the United States only (Annex 1 SS I), and no advertising or cross-site tracking technology is used on the authenticated application or on any page displaying Customer Personal Data or Amazon Information.
Behaviour analytics (Hotjar) and advertising measurement (the Reddit Pixel) on the marketing site (Section 15 and Annex 3) are disclosed in the published Cookie Policy together with opt-out routes: the Global Privacy Control and Do Not Track browser signals, which keep both tools from loading; the Your Privacy Choices page at remworth.com/privacy-choices/, which switches the Reddit Pixel off for that browser; Hotjar's own cross-site opt-out; and ordinary browser cookie controls. No such technology operates on the authenticated application, so no Customer Personal Data processed under this DPA is subject to it.
The Service and its marketing site are offered in the United States only (Annex 1 SS I). No consent mechanism is operated for EEA/UK visitors; the marketing-page tools rely on the published disclosures and the opt-out routes above. If that approach changes, we will implement the required mechanism and amend this DPA before any such change takes effect.
18. Liability, Precedence, and Governing Law
18.1 Each party's and its affiliates' aggregate liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms, and any reference in the Terms to a party's liability means the aggregate liability of that party and its affiliates under the Terms and this DPA together. The SCCs' and UK Addendum's own liability provisions govern to the extent required by law with respect to a restricted transfer.
18.2 This DPA is incorporated into and forms part of the Terms. With respect to the Processing of Personal Data, this DPA controls over any conflicting provision of the Terms; the SCCs/UK Addendum control over this DPA for a restricted transfer (Section 12.5).
18.3 This DPA is governed by the law of New York, and the parties submit to the exclusive venue of the state and federal courts located in Nassau County, New York, consistent with the Terms, except where the SCCs, UK Addendum, or non-waivable Data Protection Laws require otherwise for a given transfer or Data Subject.
19. Confirmation of Key Subprocessors
For the avoidance of doubt, Stripe, Inc. (payment processing and subscription/billing management) and Microsoft Corporation (Microsoft 365 / Microsoft Graph transactional email delivery) are engaged as Subprocessors and appear in the Subprocessor list in Annex 3.
Annex 1 — Description of Processing
A. List of parties. - Data exporter / Controller: the Customer identified in the Terms (and, where the Customer is itself a processor for a third-party controller, that third-party controller). Contact: the account administrator email on file. - Data importer / Processor: NSR ONE, LLC, a New York limited liability company, d/b/a Remworth. Contact: [email protected].
B. Subject-matter. Provision of the Remworth hosted software platform (bookkeeping/P&L analytics, inventory tracking, product-sourcing analysis, and automated repricing) for Amazon FBA sellers.
C. Duration. For the term of the Terms, plus the retention and deletion periods described in Section 10.
D. Nature and purpose of Processing. Collection, storage, organization, structuring, retrieval, computation, analysis, display, transmission to authorized Subprocessors, backup, and deletion of Customer Data, in order to provide the Service, secure it, support it, and meet legal/tax obligations.
E. Types of Personal Data. - Account and team identifiers: business email, name, company name, hashed password, role, and team-member records. - Billing data: Stripe customer/subscription identifiers, plan and billing status, and optionally the last four digits of a payment card the Customer records for its own cashback bookkeeping (not used to charge the Customer). - Order and financial data (Amazon Information): order IDs, SKUs/ASINs, quantities, sale amounts, fees, settlements, refunds, reimbursements, removals, inventory ledger, and catalog data. - Coarse ship-to geography: city, state/region, postal code, and country (the only buyer-derived data retained). - Sensitive credentials: SP-API credentials and the Aura API key (encrypted at rest); multi-factor authentication secrets (TOTP seeds, encrypted at rest) and recovery-code hashes. - Customer operations data: purchase orders, inbound shipments, supplier invoice files, receiving photos, and the Customer's own ship-from name/address/phone. - Usage and device data: log data, IP address, and usage counters. No analytics or advertising identifiers are Processed within the Service; the marketing site's Hotjar and Reddit Pixel identifiers sit outside the Processing covered by this DPA (Section 15).
F. Special categories of data. None are intended to be Processed. The Customer must not submit special-category data.
G. Categories of Data Subjects. The Customer's account administrators and team members; the Customer's own supplier/ship-from contacts. Amazon buyers/end consumers are not Processed beyond coarse ship-to geography; buyer names, street addresses, email addresses, phone numbers, and gift messages are not collected or stored.
H. Frequency of transfer. Continuous/on demand for the duration of the Service.
I. Competent supervisory authority (SCC Clause 13). Determined by the data exporter's place of establishment in the EEA or, where the exporter is not EEA-established, as provided by Article 27 GDPR arrangements. Remworth will appoint EU and UK Article 27 representatives if and when it offers the Service to EEA/UK residents.
Annex 2 — Technical and Organizational Security Measures
Encryption in transit. TLS 1.2 or higher / HTTPS for all traffic and third-party API calls.
Encryption at rest. SP-API credentials, the Aura API key, and multi-factor authentication secrets are encrypted with Fernet (AES-128-CBC + HMAC-SHA256) using rotating keys held only in environment configuration, never in the database or source code. Object storage (Cloudflare R2) applies AES-256 at rest. Passwords are hashed with bcrypt; multi-factor recovery codes are stored as hashes.
Key management. Managed key lifecycle with at least annual key rotation, immediate revocation of any compromised key, and no hardcoded credentials in code or configuration.
Backups and resilience. Nightly database backups, verified structurally readable before upload, stored in an access-isolated Cloudflare R2 bucket with 30-day retention; backups are encrypted at rest by the storage layer (AES-256) and held on infrastructure separate from the primary database; restoration procedures are exercised against real backups on a recurring basis.
Access control and isolation. Mandatory multi-factor authentication (TOTP) for all application accounts; authenticated sessions use signed JSON Web Tokens that expire within 24 hours and are revoked on password change, enforced on every request, with an explicit logout additionally revoking the presented token server-side; a 12-character minimum password policy with four character classes, password-history controls, and a 365-day maximum password age; account lockout after failed login attempts; strict per-organization data isolation; least-privilege team roles; internal administrative and support access is limited to designated administrator accounts, support access to Customer Data is through a dedicated read-only interface, administrative operations that modify Customer Data are audit-logged, and no administrative or support surface exposes decrypted secrets.
Personnel. Confidentiality obligations, data-protection training, and least-privilege provisioning for all personnel with access to Personal Data.
Operational security. Endpoint anti-malware protection with automatic updates and tamper protection on workstations with access to Personal Data; server workloads run as immutable containers rebuilt from a pinned base image on every deployment; automated vulnerability scanning of application dependencies on every relevant code change and on a recurring schedule, with documented triage of findings; independent third-party penetration testing will be introduced as the Service scales; remediation targets of approximately 7 days for critical and 30 days for high findings.
Confidentiality, integrity, availability, and resilience. Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services, with pseudonymization and data minimization applied where feasible.
For transfers (SCC Annex II). The measures above constitute the technical and organizational measures, including the measures to ensure the security of the data, required to be described for any onward transfer to a Subprocessor.
Annex 3 — List of Subprocessors and Independent Controllers
This list matches the third-party/subprocessor list published in the Privacy Policy.
- Railway (Railway Corp.) — cloud application hosting and the PostgreSQL database — all application data — United States.
- Cloudflare, Inc. — DNS, CDN, DDoS protection, Cloudflare R2 object storage used for encrypted database backups, supplier invoice files and receiving photos, and the cookieless Cloudflare Web Analytics beacon measuring page views and load performance on both the marketing site and the application — all data at rest in backups and uploaded files; page request and performance data. The beacon sets no cookie, writes no client-side storage, collects no cross-site identifier, and has no access to Amazon Information — United States.
- Stripe, Inc. — payment processing and subscription/billing management (PCI-DSS Level 1) — Customer name, email, company, and billing metadata; full card numbers are handled by Stripe and are NOT stored by Remworth — United States.
- Microsoft Corporation (Microsoft 365 / Microsoft Graph) — transactional email delivery (password reset, sign-up, team invitations) — recipient email address and message content — United States.
- Keepa GmbH — Amazon product catalog, price, and rank reference data — product identifiers (ASINs) only; no Personal Data — Germany / European Union.
- OpenAI, L.L.C. — AI-assisted product-identity matching and packaging-photo identification — supplier/product titles and product-packaging photos the Customer uploads during receiving; no buyer or end-consumer Personal Data — United States.
- DataForSEO LLC — product search data (Google Shopping / Amazon) for the sourcing scanner — search terms and an optional coarse search location (postal code or coordinates) — United States / European Union.
- Aura (goaura.com) — automated repricing, using the Customer's own Aura API key — SKU, cost, and minimum/maximum price — United States.
- Shipping carriers — UPS, FedEx, USPS, DHL, and OnTrac — inbound-shipment tracking — tracking numbers for the Customer's own inbound shipments — United States.
- Google LLC — Google Fonts (web font delivery to the application only; the marketing site uses self-hosted fonts) — IP address and browser/user-agent data sent when a font file is requested — United States.
- Hotjar Ltd (part of the Contentsquare group) - behaviour analytics on public marketing pages only (aggregate usage, heatmaps, session recordings of those pages; keystroke input suppressed); never runs on the authenticated application - marketing-page visitor usage data (interactions, device and browser details, approximate IP-derived location); no Amazon Information - Malta / European Union.
- Reddit, Inc. - independent controller, not a Subprocessor (Section 15.2) - advertising measurement on public marketing pages only, through the Reddit Pixel (page visits, pricing-page views and trial-button clicks by visitors, so Reddit can report ad results and deliver Remworth's advertising on Reddit); never runs on the authenticated application - marketing-page visitor data (page address, a random browser identifier in a first-party cookie kept 90 days, a click identifier when arriving from a Reddit ad, IP address, device and browser details); no Customer Personal Data, no Amazon Information - United States.
Item 12 is listed separately as an independent controller rather than a Subprocessor (Section 15.2). If any other third party is later engaged in that capacity, it will be listed and characterized the same way.
Contacts. Privacy and data-rights requests: [email protected]. Legal notices: [email protected]. General support: [email protected].