Data Processing Addendum
The terms on which we handle personal information belonging to our clients — their customers, their orders, their records.
The short version
- Your customers’ data is yours. We touch it only to build, run, and support what you hired us for.
- We do not sell it, share it for advertising, use it for our own purposes, or combine it with anyone else’s data.
- We name every sub-processor we use below, and we tell you before we add one.
- When we part ways, you get an export and we delete our copies.
When this applies
This addendum applies whenever King Sago Enterprise (“King Sago”, “we”, “us”) processes personal information on behalf of a client (“you”) as part of designing, building, hosting, maintaining, or supporting a website or application. It forms part of the agreement between us for that work, and it takes effect when that work starts.
It does not cover personal information we hold as a business in our own right — your contact details as our client, our correspondence with you, our invoices. That is covered by our Privacy Policy.
If you need this signed as a standalone document, or need terms specific to your own customers’ obligations, email us and we will put it in front of you.
Definitions
- Personal information — information that identifies, relates to, or could reasonably be linked with a particular person or household, as those terms are used in US state privacy laws.
- Client personal information — personal information we process on your behalf under this addendum, including information your customers and site visitors submit.
- Process — anything done with personal information: collecting, storing, organizing, using, disclosing, or deleting it.
- Applicable privacy laws — the privacy and data protection laws that apply to your business and to our processing for you, including the California Consumer Privacy Act as amended, the Florida Digital Bill of Rights, and comparable laws in other states.
- Sub-processor — a third party we engage that processes client personal information as part of delivering our services.
Our roles
You are the business or controller for client personal information. You decide what is collected, why, and how long it is kept, and you are responsible for having a lawful basis to collect it, for your own privacy notice, and for the consents and disclosures your customers are owed.
We are your service provider or processor. We act on your instructions. We have no independent relationship with your customers and do not decide the purposes of the processing.
What we process
The details vary by project. Typically:
| Item | Detail |
|---|---|
| Whose data | Your customers and site visitors; your staff who use the admin tools we build |
| Categories | Names, email addresses, phone numbers, shipping and billing addresses, order and transaction records, account details, photographs and listings you upload, messages and support requests, and technical data such as IP address and browser |
| Sensitive data | None by design. We do not build systems that collect government identifiers, health data, or precise location unless you ask for it in writing and we agree |
| Card details | Handled by your payment processor. Card numbers do not pass through, and are not stored on, systems we run |
| Purpose | Building, hosting, operating, supporting, backing up, and troubleshooting the site or application, and any other service you have hired us for |
| Duration | For as long as we provide the service, then as set out under Return and deletion |
Processing instructions
We process client personal information only on your documented instructions. Your instructions are: this addendum, our agreement for the work, the configuration and features you have asked us to build, and any further written instruction you give us. Running, supporting, securing, and backing up what we built for you counts as an instruction.
If we believe an instruction would break applicable privacy law, we will tell you rather than carry it out, and we will not be in breach for pausing while we sort it out.
What we will not do
- We will not sell client personal information, or share it for cross-context behavioral advertising.
- We will not keep, use, or disclose it for any purpose other than providing the services — including our own commercial purposes.
- We will not combine it with personal information we receive from anyone else, except as a privacy law permits a service provider to do.
- We will not use it to train machine learning or artificial intelligence models.
- We will not disclose it outside the relationship, except to the sub-processors named below or where the law requires it. If we are legally compelled to hand it over, we will tell you first unless we are forbidden to.
Confidentiality and people
We treat client personal information as confidential. Access is limited to the people who need it to deliver the work, each of them under a duty of confidentiality that survives the end of our engagement. Anyone working with us on your project — employee or contractor — is bound by terms at least as protective as these before they get access.
Sub-processors
You authorize us to use the sub-processors below. Each is bound by a written contract with obligations at least as protective as this addendum, and we remain responsible to you for their performance.
| Sub-processor | What it does | Where |
|---|---|---|
| Google LLC — Firebase Hosting | Serves the site and its assets; request logging | United States |
| Google LLC — Cloud Firestore | Stores application data and backups | United States (multi-region) |
| Google LLC — Cloud Functions | Runs server-side logic such as order and notification handling | United States |
| Google LLC — Gmail | Delivers transactional and notification email | United States |
| Google LLC — Google Analytics | Site analytics, where you have asked for it | United States |
Services you contract with directly — your payment processor, your shipping carrier, your accounting or email marketing tools — are not our sub-processors, even where we connect your site to them. They handle your customers’ data under their own agreements with you.
If we plan to add or replace a sub-processor, we will give you at least 30 days’ notice by email. If you reasonably object on data protection grounds within that time, we will work with you on an alternative; if there is not one, either of us may end the affected service without penalty for the unused portion.
Security
We keep technical and organizational measures appropriate to the data and to the size of our business, including:
- Encryption in transit over HTTPS/TLS, and encryption at rest by our hosting provider.
- Database rules that deny public reads by default, so submitted data is not readable from a browser.
- Server-side handling of anything privileged, with credentials kept out of client-side code and out of version control.
- Two-factor authentication on administrative accounts, and least-privilege access limited to people working on your project.
- Automated backups, and restoration testing when we make significant changes.
- Prompt application of security updates to the code and dependencies we maintain for you.
We may change specific measures as technology moves, provided overall security is not weakened.
If there is a breach
If we become aware of a security incident that led to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of client personal information, we will notify you without undue delay and in any event within 72 hours of confirming it.
The notice will cover what we know: what happened, when, which categories of data and roughly how many people are affected, the likely consequences, what we have done to contain it, and what we are doing next. We will keep you updated as we learn more, and we will help you meet any notification obligation you have to your customers or a regulator. Deciding whether and how to notify your customers is yours to make.
Helping with customer requests
When one of your customers asks to access, correct, delete, or receive a copy of their data, that request is yours to answer. We will help — by giving you the tools to do it yourself where we have built them, and by acting on your instruction where we have not.
If such a request reaches us directly, we will not answer it on our own account. We will pass it to you promptly and tell the person that we have.
We will also give you reasonable help, at your cost where the effort is substantial, with data protection assessments and with regulator inquiries that concern our processing for you.
Return and deletion
You can ask for an export of your data at any time while we work together, and we will provide it in a common machine-readable format within a reasonable period.
When our engagement ends, we will export your data for you and then delete our copies within 30 days of the export, unless you ask us to delete it sooner or the law requires us to keep it. Copies inside routine backups expire on their own cycle, within 90 days, and remain protected by this addendum until they do.
We will confirm deletion in writing on request.
Checking our compliance
On request, no more than once a year, we will answer a reasonable written questionnaire about the measures in this addendum and provide the documentation we have. If a privacy law gives you a right to a further audit or inspection, we will arrange one at a mutually agreed time, during business hours, without disrupting other clients, under confidentiality, and at your cost.
Where processing happens
We operate from Florida and our sub-processors store and process client personal information in the United States. If your project needs data kept in a specific region, or needs transfer mechanisms for personal data coming from outside the US, tell us before we build — it changes what we set up, and we will agree the terms with you in writing.
Liability and precedence
Each party’s liability under this addendum is subject to the limitations and exclusions in our agreement for the work, except where applicable privacy law does not allow them to be limited.
If this addendum conflicts with any other terms between us about the handling of client personal information, this addendum controls on that point. Everything else in our agreement stays as it is.
Changes
We may update this addendum to reflect a change in the law, in our sub-processors, or in how we work. The current version is always the one on this page, with its date at the top. If a change materially reduces your protections, we will tell active clients by email before it takes effect.
Contact
To ask about this addendum, request a signed copy, send a processing instruction, or report a concern:
This addendum describes how we handle data we hold for clients. It is not legal advice, and it does not replace advice on your own obligations to your customers. See also our Privacy Policy and Terms of Use.