Last updated and effective as of June 23, 2026.
This Data Processing Addendum (“DPA”) forms part of, and is incorporated into the certain STORE PLAN AGREEMENT, entered into by and between Brand and Leap (the “Main Agreement”), for the purchase of certain services from Leap (identified either as “Services” or otherwise in the Main Agreement, and hereinafter defined as “Services”). This DPA is applicable to the extent Leap Processes Brand Personal Data on behalf of the Brand (as those terms are defined below), and effective on the date the Main Agreement is entered into (the “DPA Effective Date”). Any conflict shall be resolved by giving effect to such in the following order of precedence, unless otherwise expressly set forth in this DPA: (1) Data Protection Law; (2) this DPA; and (3) the Main Agreement.
1. Definitions.
Capitalized terms used in this DPA that are not otherwise defined herein will have the same meaning ascribed to them as set forth in the Main Agreement or in Data Protection Laws.
1.1. “California Consumer Privacy Act of 2018” or “CCPA” means the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., and its implementing regulations, and any amendments, modifications, or successors thereto.
1.2. “Brand Personal Data” means any electronic data that is provided to, collected by, stored, maintained, or otherwise Processed by, Leap in connection with the Services that is Personal Data.
1.3. “Data Protection Law(s)” means any statute, law, rule, regulation, or order by any governmental body, either currently in effect or which becomes effective during the term of the Main Agreement, in so far as those laws and regulations apply to the processing of Brand Personal Data in connection with this DPA or the Main Agreement, such as, but not limited to: (i) the EU and UK Data Protection Laws; and (ii) the CCPA.
1.4. “Data Subject” means: (i) an identified or identifiable natural person who is in the European Economic Area (EEA) or whose rights are protected by the GDPR; (ii) a “Consumer” as the term is defined in the CCPA; or (iii) as defined under applicable Data Protection Laws.
1.5. “Enforcement Agency” means: (i) a Supervising Authority under the GDPR; (ii) the Attorney General of the State of California; or (iii) any government or any agency, bureau, commission, court, department, official, political subdivision, tribunal, board or other instrumentality of any administrative, judicial, legislative, executive, regulatory, police or taxing authority of any government, whether federal, state, regional, provincial, local, domestic or foreign, with jurisdiction over the enforcement of Data Protection Laws.
1.6. “EU and UK Data Protection Laws” means (i) Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“General Data Protection Regulation” or “GDPR”), as transposed into domestic legislation of each Member State and the laws implementing the GDPR; and (ii) the GDPR as implemented or adopted under the laws of the United Kingdom (“UK GDPR”).
1.8. “Personal Data” means any data that: (i) relates to an identified or identifiable individual, and includes, but is not limited to, addresses, phone numbers, passport numbers, driver’s license numbers, user names, passwords, credit or debit card numbers, bank account numbers, other financial account numbers, personal identification numbers, dates of birth, Social Security Numbers, or other unique identification information; (ii) is considered “personal information” or “personal data” under applicable Data Protection Laws.
1.9. “Personnel” means any natural person acting under the authority of a Party.
1.10 “Process” or “Processing” means any operation or set of operations performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure, or destruction.
1.11. “Security Breach” means, in connection with the Services, the loss, misuse, inadvertent, unauthorized, and/or unlawful disclosure, Processing, alteration, corruption, sale, rental, or destruction of Brand Personal Data as defined under applicable Data Protection Laws or other applicable laws.
1.12 “Standard Contractual Clauses” means where the GDPR applies, the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council; or where the UK GDPR applies, the applicable standard data protection clauses adopted pursuant to Article 46(2)(c) or (d) of the UK GDPR.
2. Roles
2.1. Brand and Leap acknowledge and agree that in circumstances where Brand is providing Brand Personal Data to Leap on its own behalf for Processing, Brand is a “Controller” or “Business”, and appoints Leap as a “Processor” or “Service Provider” under applicable Data Protection Laws to Process such Brand Personal Data.
2.3. The Parties acknowledge and agree that in other circumstances Brand may be a Processor, in which case Brand appoints Leap as another processor (or as a Subprocessor to Brand), which shall not change the obligations of either Brand or Leap under this DPA, as Leap will remain a Processor with respect to the Brand in such circumstances.
3. Processing of Brand Personal Data
3.1. Where required under Data Protection Laws, the subject matter, nature and limited specific purpose of the Processing, the types of Brand Personal Data and categories of Data Subjects may be set out in Schedule 1, which is an integral part of this DPA.
3.2. If Leap is a Processor, Leap, at all times, shall Process Brand Personal Data for the purposes set forth in this DPA and only in accordance with the lawful, documented instructions of Brand, and in the context of a Leap’s ongoing business relationship with the Brand, except where otherwise required by applicable law. This DPA and the Main Agreement sets out Brand’s complete instructions to Leap in relation to the Processing of Brand Personal Data.
3.3. Brand: (i) shall be solely responsible for, and represents and warrants that, any documented instructions it provides hereunder shall comply with Data Protection Laws; and (ii) acknowledges and agrees that Brand (and not Leap) controls the nature and contents of Brand Personal Data.
3.4 Brand represents and warrants that on the DPA Effective Date and during the term of this DPA: (i) Brand Personal Data has been and will be collected and Processed by Brand in accordance with applicable Data Protection Laws; (ii) that it has the full authority under Data Protection Law to provide such data to Leap for the Processing contemplated by this DPA, and the Processing of Brand Personal Data in accordance with this DPA by Leap will not violate applicable Data Protection Laws; (iii) Brand will take all steps necessary to ensure it achieves the foregoing, including without limitation, by providing Data Subjects with appropriate privacy notices, obtaining any required consent, and ensuring that there is a lawful basis for Leap to Process Brand Personal Data; and (iv) Brand shall provide Data Subjects with appropriate opt-outs where applicable under the Data Protection Laws, and shall inform Leap of any exercise of such rights by a Data Subject.
3.5. Any Processing required outside of the scope of the rights and obligations set forth under this DPA will require prior written agreement of the Parties, and Brand may issue additional instructions to Leap as it deems necessary to comply with Data Protection Law. Additional instructions must be set forth in a written instrument mutually agreed to by the Parties. Brand shall be responsible for any additional fees, or costs arising from any such additional instructions.
3.6. Leap, as a Processor or Service Provider, is prohibited from: (i) Selling or Sharing Brand Personal Data; (ii) Processing, retaining, using, or disclosing Brand Personal Data for a commercial purpose other than providing the Services or for any purpose other than those listed on Schedule 1, unless otherwise permitted by the Data Protection Laws; (iii) Processing, retaining, using, or disclosing the Brand Personal Data outside of the direct business relationship between Leap and Brand; and (iv) combining Brand’s Personal Data subject to the CCPA from another Processor customer, unless permitted by the CCPA.
3.7. Leap understands the prohibitions outlined in Section 3.6, and certifies that it understands and shall comply with the same. Leap shall notify Brand no later than ten business days after its determination that it can no longer meet its obligations under the CCPA; and hereby grants Brand the right, upon notice, to take reasonable and appropriate steps to stop and remediate any of Leap’s use of Brand Personal Data.
4. Subprocessing
4.1. Brand authorizes and instructs Leap to appoint Subprocessors (and permits each Subprocessor to appoint additional Subprocessors) in accordance with this Section 4.
4.2. As of the DPA Effective Date, Brand hereby authorizes and instructs Leap to engage those Subprocessors set out at https://trust.leapinc.com/subprocessors (the “Subprocessor List”). The Subprocessor List may be updated from time to time. The Subprocessor List shall include the name and location of, and a brief description of the Processing undertaken by, each current Leap Subprocessor.
4.3. Brand acknowledges and agrees that Leap may engage additional Subprocessors. In accordance with the Data Protection Laws, Leap shall enter into a written contract or other legally binding agreement with such Subprocessors imposing the same obligations set forth in this DPA, upon such Subprocessors. At least ten (10) calendar days prior to Leap engaging any new Subprocessor(s), Leap shall provide notice to Brand of such change(s), and Brand shall have five (5) days from such notice to object to such change(s) by providing objective, justifiable grounds related to the ability of such Subprocessor(s) to adequately protect Brand Personal Data in accordance with this DPA. Leap will have the right to cure the objection through any options in its sole discretion.
4.4. If any Subprocessor fails to fulfill its obligations under Data Protection Laws, or this DPA, Leap will be fully liable to Brand for the performance of such obligations.
5. International Data Transfers and SCCs
5.1 Brand authorizes Leap to transfer and process any Brand Personal Data subject to the GDPR or UK GDPR outside of the European Economic Area (“EEA”) or the United Kingdom, as applicable, in order to provide the Services pursuant to the Main Agreement and for Leap’s other legitimate interests, provided that Leap has taken appropriate measures designed to ensure the transfer and resulting processing is in compliance with Data Protection Laws.
5.2 If, in the performance of the Main Agreement, Brand Personal Data subject to the GDPR or UK GDPR is transferred to any third party located in a country outside the EEA and/or the UK that the applicable authorities have not recognized as providing an adequate level of protection or Brand Personal Data, then the Standard Contractual Clauses shall apply. To the extent (and where required) pursuant to the Data Protection Laws, Brand is considered a data exporter and Leap is considered a data importer.
5.3 In relation to transfers of Brand Personal Data protected by GDPR, the Standard Contractual Clauses shall apply, completed as follows:
a) Modules One, Two, or Three will apply (as applicable);
b) In Clause 7, the optional docking clause will not apply;
c) In Clause 9(a), Option 2 will apply, and the time period for prior notice of Subprocessor changes shall be set out in Section 4.3 of this DPA;
d) In Clause 11, the optional language will not apply;
e) In Clause 17, Option 2 will apply, and the Standard Contractual Clauses shall be governed by Irish law;
f) In Clause 18(b), disputes shall be resolved before the courts of Ireland;
g) Annex I of the Standard Contractual Clauses shall be deemed completed with the information set out in Schedule 1 to this DPA, as applicable;
h) Annex II of the Standard Contractual Clauses shall be deemed completed with the information set out in Section 6 of this DPA.
i) Annex III of the Standard Contractual Clauses shall be deemed completed with the information set out in the Subprocessor List.
5.4 In relation to transfers of Brand Personal Data protected by the UK GDPR, the Standard Contractual Clauses shall apply along with the International Data Transfer Addendum (“IDTA”), completed as follows:
a) In Table 1 of the IDTA, the parties’ details and key contact information are located in Annex 1(A) of Schedule 1 of this DPA;
b) In Table 2 of the IDTA, information about the version of the Standard Contractual Clauses, modules and selected clauses which this UK International Data Transfer Agreement is appended to is located in Section 5.3 of this DPA; and
c) In Table 3 of the IDTA: The list of Parties is located in Annex I(A) of Schedule 1. The description of the transfer is set forth in Annex I(B) (Nature and Purpose of the Processing) of Schedule 1 (Description of the Processing/Transfer). Annex II is located in Section 6 of this DPA. The list of sub-processors is located in the Subprocessor List.
6. Security
6.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Leap shall implement technical and organizational measures to ensure a level of security appropriate to the risks presented by the Processing (collectively, the “Technical and Organizational Security Measures”), including the measures listed at Trust Center - Leap.
7. Security Breach
7.1. Leap will notify Brand without undue delay, and in any case, within seventy-two (72) hours, upon Leap becoming aware of a Security Breach. Leap’s notification of or response to a Security Breach under this Section 7 will not be construed as an acknowledgement by Leap of any fault or liability with respect to the Security Breach.
7.2. Any notification in accordance to Section 7.1, shall, to the extent known within the notification window: (i) describe the nature of the Security Breach, including, where possible, the categories and approximate number of affected data subjects, and the categories and approximate number of personal data records concerned; (ii) the name and contact details of a contact person at Leap who can provide additional information; (iii) describe, to the extent known, the likely consequences of such Security Breach; and (iv) describe proposed mitigation efforts, as applicable.
7.3. Leap will make commercially reasonable efforts, in accordance with its security incident management policies and procedures, to identify the cause of such Security Breach, and provide Brand with sufficient information to allow Brand to meet its obligations under Data Protection Laws to report or inform Data Subjects of the Security Breach.
8. Assistance
8.1. Taking into account the nature of the Processing, Leap may reasonably assist Brand, by implementing appropriate technical and organizational measures, for fulfilment of Brand’s own obligations under Data Protection Laws, including:
a) complying with Data Subjects’ requests to exercise Data Subject Rights;
b) replying to inquiries or complaints from Data Subjects; and
c) replying to investigations and inquiries from Enforcement Agencies.
8.2. Unless prohibited by Data Protection Laws, Leap shall inform Brand without undue delay if Leap:
a) receives a request, complaint or other inquiry regarding the Processing of Brand Personal Data from a Data Subject or Enforcement Agency;
b) receives a binding or non-binding request to disclose Brand Personal Data from law enforcement, courts or any government body;
c) is subject to a legal obligation that requires Leap to Process Brand Personal Data in contravention of Brand’s instructions; or
d) is otherwise unable to comply with Data Protection Law or this DPA.
8.3. Unless prohibited by applicable law, Leap shall obtain Brand’s written authorization before responding to, or complying with any requests, orders, or legal obligations referred to in Section 8.2.
9. Accountability
9.1. Leap shall maintain records of all Processing of Brand Personal Data, including at a minimum the categories of information required under Data Protection Law, and must provide a copy of such records to an Enforcement Agency upon request and without undue delay.
9.2. Leap shall not be responsible for assessing any instruction or verifying the lawfulness of any instructions from Brand for the Processing of Brand Personal Data. Leap may inform Brand if Leap believes that an instruction of Brand violates Data Protection Law. Leap may suspend Processing in its discretion, until Brand has modified or confirmed the lawfulness of the instructions in writing.
10. Data Protection Impact Assessment and Prior Consultation
At Brand’s request, Leap shall provide reasonable assistance to Brand with any data protection impact assessments and prior consultations with Supervisory Authorities or other competent data privacy authorities, as required by applicable Data Protection Laws, and in each case solely in relation to Processing of Brand Personal Data by, and taking into account the nature of the Processing and information available to, the Parties.
11. Audit
11.1. To the extent required under applicable Data Protection Laws, Leap will:
a) make available to Brand on request information that is reasonably necessary to demonstrate compliance with this DPA and applicable Data Protection Laws;
b) allow for and contribute to audits, including inspections, by an auditor mandated by Brand in relation to the Processing of the Brand Personal Data by Leap.
11.2. Information and audit rights of Brand only arise under this Section 11 to the extent: a) Leap Processes Brand Personal Data; and b) this DPA, and the Main Agreement do not otherwise give Brand information and audit rights meeting the relevant requirements of applicable Data Protection Laws (including, where applicable, Article 28(3)(h) of the GDPR).
11.3. Brand may only mandate an auditor for the purposes of this Section 11 if the auditor is approved by Leap in writing, such approval not to be unreasonably withheld.
11.4. Brand shall give Leap reasonable notice of any audit or inspection to be conducted under Section 11 and shall make (and ensure that each of its mandated auditors makes) reasonable endeavors to avoid causing any damage, injury, or disruption to Leap’s premises, equipment, Personnel, and business while its Personnel are on those premises in the course of such an audit or inspection.
11.5. Any audits conducted in accordance with Section 11.1 – 11.4 shall be conducted during Leap’s normal business hours, upon reasonable prior notice, and no more frequently than once per year during the term of the Main Agreement, unless in response to a Security Breach or as may be required by a Supervisory Authority.
12. Termination and Return of Brand Personal Data
12.1. This DPA shall be in force from the DPA Effective Date, and shall remain in force until termination or expiration of this DPA or the Main Agreement, whichever is earlier (the “Termination Date”).
12.2. Subject to Section 12.3, Leap shall without undue delay, and in any event no later than thirty (30) days after Brand ceases use of any data integration method used to provide Brand Personal Data to Leap in connection with the Brand’s use of the Services, including without limitation, the Leap App or SFTP data feed, whether by uninstall, disconnection, or discontinuation of automated data transfer(“Disconnection Date”), render unrecoverable or return Brand Personal Data in accordance with Leap’s security practices.
12.3. After the Disconnection Date, Leap has no obligation to retain, and will render unrecoverable, such data in accordance with Leap’s security practices.
12.4. Leap and each Subprocessor may retain Brand Personal Data to the extent required by applicable laws and only to the extent and for such period as required by applicable laws.
12.5. At Brand’s reasonable request, Leap shall provide written certification to Brand that it has fully complied with this Section 12.
13. General Terms
13.1. Governing Law and Jurisdiction. This DPA is governed by the law designated in the Main Agreement. The Parties hereby submit to the choice of jurisdiction stipulated in the Main Agreement with respect to any disputes or claims arising under this DPA, including disputes regarding its existence, validity, or termination or the consequences of its nullity.
13.2. Changes to Data Protection Laws; Severance. If any variation is required to this DPA as a result of changes to Data Protection Laws, then either Party may provide written notice to the other Party of such change in law and the Parties will discuss and negotiate in good faith any necessary variations to this DPA to address such changes. If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision does not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.
14. Indemnification; Liability
14.1. Each Party is fully liable to the other Party for any infringements of Data Protection Laws or this DPA, including any acts or omissions by the respective Parties’ Personnel.
14.2. A Party (the “Indemnifying Party”) shall defend, indemnify, and hold harmless the other Party, its affiliates, and each of their partners, officers, directors, employees, customers, contractors, and agents from and against any and all third party claims, expenses, costs (including reasonable attorneys’ fees), penalties, settlements, and damages arising out of or related to Indemnifying Party’s breach of its obligations set forth in this DPA, or Indemnifying Party’s violation of the Data Protection Laws.
14.3. For the avoidance of doubt, as between the Parties, each Party’s liability and remedies under this DPA are subject to the aggregate liability limitations and damages exclusions set forth in the Main Agreement.15. Modifications15.1. This DPA may only be modified by a written amendment signed by both Brand and Leap.16. For the avoidance of doubt, this DPA does not apply when both Brand and Leap are Controllers of Personal Data related to the Services, for example when Personal Data within Operations Data as defined in the Main Agreement is provided to both Parties by Leap’s point of sale system vendor(s) (e.g., Shopify). In such cases, each Party shall comply with applicable Data Protection Laws with respect to their receipt, collection, use and other Processing of such Personal Data. Any other obligations with respect to such Operations Data are in the Main Agreement.
Schedule 1
1. LIST OF PARTIES
(a) Data exporter.
Name: See Main Agreement
Address: See Main Agreement
Contact person’s name, position and contact details: See Main Agreement.
Activities relevant to the data transferred under these Clauses: Receipt of services provided by the data importer in accordance with the Main Agreement.
Signature and date: See Main Agreement
Role (controller/processor): Controller
(b) Data importer.
Name: Leap
Address: 99 Hudson Street, 7th Floor, New York, NY 10013
Contact person’s name, position and contact details: Gabriel Levine, Senior Director of Engineering, legalnotices@leapinc.co
Activities relevant to the data transferred under these Clauses: The data importer provides the Services to the data exporter in accordance with the Agreement.
Signature and date: See Main Agreement
Role (controller/processor): Processor
2. DESCRIPTION OF TRANSFER
Categories of data subjects whose personal data is transferred
Brand employees and Brand customers.
Categories of personal data transferred
Contact information, including name, shipping address, and email address, as applicable; purchase history
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
None.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Ongoing.
Nature of the processing
As needed to for the performance of the services by Leap as set forth in the Main Agreement.
Purpose(s) of the data transfer and further processing
The performance of the services by Leap as set forth in the Main Agreement.The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
The personal data will be retained for as long as necessary for the purpose of the processing and taking into account applicable laws.
For transfers to (sub) processors, also specify subject matter, nature and duration of the processing
See Subprocessor List.
3. COMPETENT SUPERVISORY AUTHORITY
Ireland.