Data Processing Agreement

How Caldik processes and protects personal data on behalf of merchants.

Last updated: July 26, 2026

This Data Processing Agreement governs Caldik’s processing of personal data on behalf of a merchant in connection with the Services.

1. Parties and incorporation#

This Data Processing Agreement (“DPA”) is entered into between Caldik, ABN 84916006495, and the person or entity that has accepted the Caldik Terms of Service or entered into an order form for the Services (“Merchant”).

This DPA forms part of the Terms of Service and applies when Caldik processes Covered Personal Data on behalf of Merchant. It becomes effective when Merchant accepts the Terms of Service, signs an order form incorporating it, or begins using a feature that causes Caldik to process Covered Personal Data on Merchant’s behalf.

If there is a conflict, the following order applies for data-processing matters: an executed order form or negotiated data-processing addendum, this DPA, the Terms of Service, and other incorporated policies. The European Commission’s applicable Standard Contractual Clauses prevail to the extent required for a restricted transfer and inconsistent with this DPA.

2. Definitions#

  • “Applicable Data Protection Law” means privacy and data-protection law applying to the processing, including the Australian Privacy Act 1988 and Australian Privacy Principles, the EU General Data Protection Regulation, the UK GDPR, and implementing or replacement law where applicable.

  • “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given by Applicable Data Protection Law.

  • “Covered Personal Data” means Personal Data processed by Caldik on behalf of Merchant through the Services, excluding information Caldik processes independently as a Controller.

  • “Merchant Data” means content, records, files, customer data, configuration, and other information submitted to or generated through Merchant’s use of the Services.

  • “Subprocessor” means a third party appointed by Caldik to process Covered Personal Data on behalf of Merchant.

  • “Services” has the meaning in the Terms of Service.

3. Roles of the parties#

Merchant is the Controller or Processor, as applicable, for Covered Personal Data. Caldik is the Processor acting on Merchant’s documented instructions. If Merchant acts as a Processor for another Controller, Merchant confirms that it is authorised to appoint Caldik as a Subprocessor and to give the instructions in this DPA.

Each party is independently responsible for compliance with the obligations that apply to it. Merchant is responsible for the lawfulness, fairness, accuracy, transparency, and scope of Merchant’s collection and use of Covered Personal Data, including its legal basis, notices, consents, customer contracts, retention decisions, and responses as Controller.

Caldik acts as an independent Controller for account administration, subscription billing, platform security, fraud and abuse prevention, legal compliance, service communications, product improvement using appropriately aggregated or de-identified information, and other purposes described in the Privacy Policy. This DPA does not apply to that independent Controller processing.

4. Merchant instructions#

Caldik will process Covered Personal Data only on Merchant’s documented instructions, unless required by applicable law. The Terms of Service, this DPA, an order form, Merchant’s configuration, feature selections, API calls, support requests, and ordinary use of the Services constitute documented instructions.

Merchant instructs Caldik to process Covered Personal Data to provide, secure, maintain, monitor, support, and improve the requested Services; operate storefronts, orders, analytics, builds, deployments, digital delivery, APIs, webhooks, integrations, and AI features; prevent abuse and fraud; resolve incidents; and comply with applicable law.

If Caldik believes an instruction infringes Applicable Data Protection Law, Caldik will inform Merchant unless prohibited by law and may suspend the affected processing until the parties resolve the issue. Caldik is not required to provide legal advice or independently verify every Merchant instruction.

5. Processing details#

Subject matter and duration#

The subject matter is the processing required to provide the Services selected and configured by Merchant. Processing continues for the term of Merchant’s use of the Services and any limited period required for return, deletion, backup expiry, security, dispute resolution, or legal compliance.

Nature and purpose#

  • Hosting, organising, displaying, transmitting, securing, backing up, retrieving, deleting, and otherwise managing Merchant Data.

  • Operating storefront accounts, customers, orders, products, subscriptions, digital delivery, websites, domains, APIs, webhooks, integrations, builds, deployments, support, and analytics.

  • Providing Ask AI, AI-assisted website building, generated content or code, recommendations, search, support, moderation, and automated acceptable-use review where enabled or required to protect the Services.

  • Monitoring performance, preventing fraud and abuse, investigating security or policy events, and maintaining reliable infrastructure.

  • Carrying out additional processing expressly requested through the dashboard, API, support, an order form, or documented written instruction.

Categories of Data Subjects#

  • Merchant account owners, personnel, contractors, developers, invited team members, and representatives.

  • Storefront visitors, customers, prospective customers, subscribers, recipients, reviewers, and support contacts.

  • Individuals whose information is included in Merchant content, files, communications, orders, analytics, support records, or integrations.

  • Other individuals whose Personal Data Merchant lawfully submits to the Services.

Types of Covered Personal Data#

  • Identity and contact information, account identifiers, usernames, organisation and role information.

  • Order, product, subscription, fulfilment, refund, support, invoice, tax, and transaction-related information.

  • Device, browser, IP address, approximate region, referral, storefront event, analytics, API, webhook, deployment, build, and security information.

  • Merchant content, source files, uploaded media, digital product files, communications, form submissions, and custom fields.

  • Wallet addresses, public keys, xpubs, blockchain transaction identifiers, assets, networks, amounts, confirmations, and order references. Private keys and recovery phrases are not required for the standard Storrik Crypto flow and must not be submitted.

  • AI prompts, selected storefront or account context, attachments, generated content or code, feedback, moderation indicators, and reviewer outcomes.

  • Any other Personal Data Merchant chooses to submit through supported fields or integrations.

Sensitive data#

The Services are not designed as a general-purpose repository for highly sensitive or special-category data unless a feature expressly supports it. Merchant must not submit such data unless it has a lawful basis, has completed appropriate risk assessment, and has configured safeguards suitable for that data.

6. Merchant obligations#

Merchant will:

  • Comply with Applicable Data Protection Law and process Personal Data only with an appropriate legal basis.

  • Give Data Subjects accurate privacy notices and obtain valid consent where required.

  • Issue lawful, specific, and technically feasible instructions to Caldik.

  • Maintain appropriate access controls and promptly remove access no longer required.

  • Configure retention, analytics, cookie consent, AI context, integrations, and storefront fields appropriately for its use case.

  • Avoid submitting secrets, private keys, recovery phrases, unnecessary sensitive information, or unlawful data.

  • Respond to Data Subject requests and regulatory enquiries for which Merchant is responsible.

  • Notify Caldik promptly of an instruction, account compromise, or incident that may affect Covered Personal Data.

7. Caldik obligations#

Caldik will:

  • Process Covered Personal Data only as permitted by this DPA and Merchant’s documented instructions.

  • Ensure personnel authorised to process Covered Personal Data are bound by confidentiality obligations.

  • Implement and maintain appropriate technical and organisational security measures.

  • Provide reasonable assistance with Data Subject requests, security, breach response, impact assessments, and regulator consultations as described below.

  • Maintain records and information reasonably necessary to demonstrate compliance with this DPA.

  • Delete or return Covered Personal Data at the end of the Services as described in this DPA, subject to legal retention and backup cycles.

  • Inform Merchant if Caldik can no longer meet a material obligation under this DPA.

8. Confidentiality#

Caldik will limit access to Covered Personal Data to personnel and providers who need it for authorised purposes. Those persons must be subject to contractual, professional, or statutory confidentiality obligations and receive privacy and security guidance appropriate to their role.

Merchant will treat non-public information about Caldik’s security, subprocessors, incidents, systems, and audit materials as Caldik Confidential Information and will use it only to assess and manage its use of the Services.

9. Security measures#

Caldik will implement technical and organisational measures appropriate to the nature, scope, context, and purposes of processing and the risk to individuals. The measures are described in Annex B and may evolve as technology, threats, and the Services change, provided overall protection is not materially reduced.

Merchant acknowledges that security is a shared responsibility. Caldik’s measures do not replace Merchant’s obligations for lawful configuration, endpoint and credential security, storefront code, integrations, permissions, backups, data minimisation, and incident response for systems Merchant controls.

10. EU storage and processing locations#

All Covered Personal Data stored by Caldik is stored on infrastructure located in the European Union. Caldik-controlled production databases, object storage, logs, backups, and retained AI feature records are stored in the European Union.

Subprocessors that persist Covered Personal Data on Caldik’s behalf must use European Union storage unless Merchant expressly enables a feature whose notice or order form identifies another location. Public blockchain data is distributed by the relevant network and is outside Caldik’s exclusive storage control.

Authorised personnel and Subprocessors may remotely access or transiently process Covered Personal Data from other countries to provide support, security, AI inference, payment connectivity, professional services, or incident response. Caldik will use a lawful transfer mechanism and supplementary safeguards where required.

11. Subprocessors#

Merchant gives Caldik general written authorisation to appoint Subprocessors. Caldik maintains a current non-public list that identifies each Subprocessor, its service, the categories of Personal Data involved, and its principal processing location where reasonably available. Merchant may request the list by emailing support@caldik.com.

Caldik will impose written data-protection obligations on each Subprocessor that are no less protective in material respects than the obligations applicable to Caldik under this DPA. Caldik remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.

Caldik will provide at least 30 days’ prior notice of a new Subprocessor where reasonably practicable. Merchant may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable solution, which may include avoiding the Subprocessor, changing a feature, or terminating the affected Service. If no reasonable solution is available, Merchant may terminate the affected Service before the new Subprocessor begins processing and receive any refund required by the Refund Policy or applicable law.

12. AI providers and automated review#

Where an AI provider processes Covered Personal Data to provide Ask AI, AI-assisted website building, generated output, moderation, or automated acceptable-use review, that provider will be treated as a Subprocessor when required by law.

Caldik will configure AI providers to avoid using Covered Personal Data to train general-purpose models for unrelated customers unless Merchant expressly opts in or gives documented permission. Caldik may use de-identified or aggregated safety, quality, and performance information that is not Personal Data.

Merchant controls the prompts, attachments, and account or storefront context it submits or enables. Merchant must not submit information that is unnecessary, unlawful, or outside its authority. Generated output is not guaranteed to be accurate and must be reviewed before use.

Automated acceptable-use signals may prioritise or recommend review. Caldik will provide a reasonable method to request human review of a material adverse enforcement decision where required by law or reasonably available.

13. Data Subject requests#

Taking into account the nature of processing, Caldik will provide reasonable technical and organisational assistance to help Merchant respond to requests to access, correct, delete, restrict, object to, or port Covered Personal Data.

If Caldik receives a request relating to Covered Personal Data for which Merchant is responsible, Caldik may refer the requester to Merchant and notify Merchant where legally permitted. Caldik will not independently respond on Merchant’s behalf unless Merchant instructs it, law requires it, or the response concerns Caldik’s independent Controller processing.

Merchant is responsible for verifying the requester, deciding the lawful response, and using available self-service tools before requesting additional assistance. Material custom assistance may be charged at an agreed rate where permitted by law.

14. Personal Data Breaches#

Caldik will notify Merchant without undue delay after becoming aware of a confirmed Personal Data Breach affecting Covered Personal Data. Notification may be provided to the account, security, privacy, or other designated contact.

Where available, notice will describe the nature of the breach, affected data and individuals, likely consequences, measures taken or proposed, and a contact for further information. Caldik may provide information in phases as the investigation continues.

Caldik’s notification is not an admission of fault or liability. Merchant is responsible for determining whether it must notify individuals, regulators, customers, or other parties, but Caldik will provide reasonable assistance and relevant information in its possession.

15. Impact assessments and regulator assistance#

Taking into account the nature of processing and information available, Caldik will provide reasonable assistance with data-protection impact assessments and prior consultation with a Supervisory Authority where the requested assessment relates to Caldik’s processing of Covered Personal Data.

Merchant must first use documentation, security information, settings, and self-service material made available by Caldik. Custom assistance may be subject to reasonable fees where permitted by law, except where required because of Caldik’s breach of this DPA.

16. Audits and information#

Caldik will make available information reasonably necessary to demonstrate compliance with this DPA, which may include policies, security summaries, certifications, questionnaires, Subprocessor information, and independent audit reports where available.

If that information is insufficient, Merchant may request an audit no more than once in any 12-month period, unless a confirmed breach, regulator request, or credible evidence reasonably requires another audit. Audits must be proportionate, during normal business hours, on reasonable notice, conducted by an independent qualified auditor, and must avoid disruption, access to other customers’ data, and exposure of security-sensitive information.

Merchant bears audit costs unless the audit identifies a material breach by Caldik. Caldik may satisfy an on-site request through an independent report or scoped remote review where that provides substantially equivalent assurance.

17. Return and deletion#

During the subscription, Merchant may use available export and deletion features. On termination, Caldik will delete or return Covered Personal Data in accordance with Merchant’s instruction, the plan’s retention rules, the Terms of Service, and this DPA.

Caldik may retain Covered Personal Data where required by law, to establish or defend legal claims, to prevent fraud or abuse, or in backups until ordinary expiry. Retained data remains protected by this DPA and will not be used for another purpose.

Deletion by Caldik cannot delete public blockchain records, information held independently by Merchant or another Controller, or data transferred to an integration under Merchant’s instruction.

18. International transfer mechanisms#

If processing under this DPA involves a restricted transfer for which a transfer mechanism is legally required, the parties incorporate the applicable European Commission Standard Contractual Clauses or UK transfer addendum by reference, using the module appropriate to the parties’ roles.

For the EU Standard Contractual Clauses, Module Two applies to Controller-to-Processor transfers and Module Three applies to Processor-to-Processor transfers. The docking clause applies, optional general Subprocessor authorisation applies with the notice period in this DPA, the competent supervisory authority and governing law are determined by the exporter’s establishment where required, and the courts specified by the clauses have jurisdiction.

The parties will provide the information required by the clauses using this DPA, the applicable order form, Privacy Policy, Subprocessor list, and security documentation. The parties will implement supplementary technical, contractual, or organisational measures where required by a transfer assessment.

19. Liability#

Liability arising under this DPA is subject to the exclusions and limitations in the Terms of Service to the maximum extent permitted by law. Nothing limits liability or Data Subject rights that cannot lawfully be limited under Applicable Data Protection Law or incorporated Standard Contractual Clauses.

20. Term and termination#

This DPA continues while Caldik processes Covered Personal Data on Merchant’s behalf. Termination of the Terms of Service terminates this DPA, except provisions that must continue for retained Covered Personal Data, confidentiality, audits, liability, deletion, and legal compliance.

21. Changes#

Caldik may update this DPA to reflect changes in law, the Services, security, Subprocessors, or regulatory guidance. Material changes will be notified as required by the Terms of Service or Applicable Data Protection Law. Changes will not materially reduce protection of Covered Personal Data during a current paid term without an appropriate legal or operational reason.

22. Contact#

Data-processing notices and requests may be sent to support@caldik.com. Legal notices may be sent to legal@caldik.com.

Annex A. Processing description#

The subject matter, duration, nature, purpose, Data Subjects, and data categories are described in sections 4 and 5 of this DPA, the Terms of Service, the applicable order form, and Merchant’s configuration and instructions.

Processing frequency is continuous or event-based as required by Merchant’s use of the Services. Retention follows the selected plan, Merchant configuration, backup cycles, legal requirements, and sections 10 and 17 of this DPA.

Annex B. Technical and organisational measures#

  • Access control. Role-based access, least-privilege practices, authentication controls, account permissions, and removal of access when no longer required.

  • Encryption. Encryption in transit using current transport security and encryption, hashing, or equivalent protection for selected stored data based on risk and architecture.

  • Infrastructure security. Network segmentation, hardened service configuration, patching, container and workload isolation, firewalling, and controlled administrative access.

  • Application security. Secure development practices, dependency management, testing, review, secret management, API authentication, webhook signing where supported, and abuse controls.

  • Logging and monitoring. Security, access, change, API, deployment, error, and system logs appropriate to detect incidents and support investigations.

  • Availability and resilience. Backups, redundancy appropriate to the service, capacity management, recovery processes, status monitoring, and tested incident procedures.

  • Personnel security. Confidentiality obligations, role-appropriate access, security awareness, and controlled support procedures.

  • Incident response. Triage, containment, investigation, remediation, recovery, evidence preservation, and legally required notifications.

  • Data minimisation and retention. Collection and retention controls, merchant configuration, deletion processes, backup expiry, and de-identification or aggregation where appropriate.

  • Subprocessor governance. Risk-based review, contracts, access limitation, processing instructions, location review, and ongoing management.

  • AI safeguards. Context limitation, provider configuration, prompt and output controls, moderation, testing, human review pathways, and restrictions on unrelated general-model training.

  • Physical security. Reliance on controlled data-centre facilities and cloud infrastructure with appropriate physical and environmental safeguards.

Annex C. Subprocessors and transfer information#

The current non-public Subprocessor list is available by request to support@caldik.com. The list and applicable service notices identify the function and location of material processing. Caldik’s stored Covered Personal Data is hosted in the European Union, subject to the distributed nature of public blockchain data and any expressly enabled feature notice.