Superlister legal
The data-processing terms applying when Superlister acts as a processor.
Data Processing Addendum
Last updated: 8 July 2026
This Data Processing Addendum (the "DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between SUPERLISTER LIMITED ("Superlister", "we", "us", or "our") and the customer that uses our websites, applications, APIs, and related services (the "Customer", "you", or "your").
This DPA applies where Superlister processes Customer Personal Data on behalf of the Customer as a processor under UK data protection law.
This document is a draft agreement and should be reviewed by legal counsel before publication or signature. Replace bracketed placeholders before use.
1. Definitions
In this DPA:
- "Customer Personal Data" means personal data that Superlister processes on behalf of the Customer in connection with the Services.
- "Data Protection Laws" means the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations, and any other UK data protection or privacy laws that apply to the processing.
- "Controller", "processor", "personal data", "personal data breach", "processing", and "data subject" have the meanings given to them in Data Protection Laws.
- "Services" means the services provided by Superlister under the Agreement.
- "Subprocessor" means another processor engaged by Superlister to process Customer Personal Data.
2. Roles Of The Parties
For Customer Personal Data, the Customer is the controller and Superlister is the processor, unless the parties agree otherwise in writing.
The Customer is responsible for determining the purposes and means of processing Customer Personal Data, providing required notices, obtaining required consents, and ensuring that its instructions to Superlister comply with Data Protection Laws.
Superlister will process Customer Personal Data only as described in this DPA, the Agreement, and the Customer's documented lawful instructions, unless required to do otherwise by law.
3. Details Of Processing
The subject matter, duration, nature, purpose, categories of personal data, and categories of data subjects are described in Appendix 1.
The Customer instructs Superlister to process Customer Personal Data as necessary to provide, secure, maintain, support, and improve the Services, and as otherwise permitted by the Agreement and this DPA.
4. Customer Instructions
Superlister will process Customer Personal Data only on documented instructions from the Customer. The Agreement, this DPA, product settings, connected integrations, support requests, and lawful use of the Services constitute the Customer's documented instructions.
If Superlister believes an instruction infringes Data Protection Laws, Superlister will inform the Customer unless prohibited by law.
5. Confidentiality
Superlister will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
6. Security Measures
Superlister will implement appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
These measures may include, as appropriate:
- Access controls and authentication for production systems.
- Role-based access for personnel who need access to provide or support the Services.
- Encryption in transit and, where supported by the relevant infrastructure, encryption at rest.
- Logging, monitoring, and alerting for operational and security events.
- Backup, recovery, and resilience measures.
- Secure development, review, and deployment practices.
- Vendor diligence for relevant Subprocessors.
- Internal policies and procedures for handling security incidents.
7. Subprocessors
The Customer authorises Superlister to engage Subprocessors to provide the Services. Superlister will enter into written agreements with Subprocessors that impose data protection obligations no less protective than those required by this DPA, to the extent applicable to the services provided by the Subprocessor.
A current list of Subprocessors is available on request by contacting privacy@superlister.com. Superlister may also publish a Subprocessor list separately.
Superlister will provide notice of material changes to Subprocessors where required by the Agreement or Data Protection Laws. The Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Superlister in writing within 14 days of receiving notice. The parties will work in good faith to resolve the objection. If the objection cannot be resolved, the Customer may stop using the affected part of the Services.
8. International Transfers
Superlister may process Customer Personal Data outside the United Kingdom where necessary to provide the Services or use authorised Subprocessors.
Where Customer Personal Data is transferred outside the United Kingdom to a country that is not subject to UK adequacy regulations, Superlister will use appropriate safeguards as required by Data Protection Laws. These safeguards may include the UK International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or another lawful transfer mechanism.
9. Personal Data Breach
Superlister will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
The notification will include information reasonably available to Superlister to help the Customer meet its obligations under Data Protection Laws, such as:
- The nature of the breach.
- The categories and approximate number of affected data subjects and records, where known.
- The likely consequences of the breach, where known.
- Measures taken or proposed to address the breach and mitigate possible adverse effects.
Superlister's notification of, or response to, a personal data breach is not an admission of fault or liability.
10. Assistance To The Customer
Taking into account the nature of the processing and information available to Superlister, Superlister will provide reasonable assistance to the Customer in meeting the Customer's obligations under Data Protection Laws, including obligations relating to:
- Data subject rights requests.
- Security of processing.
- Personal data breach notifications.
- Data protection impact assessments.
- Prior consultation with the Information Commissioner's Office, where required.
Superlister may charge reasonable fees for assistance that is outside the standard functionality of the Services, unless the assistance is required because of Superlister's breach of this DPA.
11. Data Subject Requests
If Superlister receives a request from a data subject relating to Customer Personal Data, Superlister will, where reasonably practicable, direct the data subject to contact the Customer or notify the Customer.
Superlister will not respond to the request except on the Customer's documented instructions or where required by law.
12. Deletion And Return
At the end of the provision of Services, or on the Customer's written request, Superlister will delete or return Customer Personal Data, unless retention is required by law or permitted under the Agreement.
Deletion may be subject to technical limitations, backup retention schedules, security requirements, fraud prevention, dispute resolution, accounting obligations, and legal obligations.
13. Audit And Information
Superlister will make available information reasonably necessary to demonstrate compliance with this DPA.
The Customer may request an audit no more than once in any 12-month period, unless required by a supervisory authority or following a personal data breach affecting Customer Personal Data. Audits must be conducted during normal business hours, on reasonable written notice, in a manner that does not disrupt Superlister's operations or compromise the security or confidentiality of other customers, systems, or data.
Superlister may satisfy audit requests by providing relevant summaries, policies, security documentation, third-party reports, certifications, or written responses, where appropriate.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by Data Protection Laws.
15. Order Of Precedence
If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA will control to the extent of the conflict.
16. Contact
For questions about this DPA, contact:
SUPERLISTER LIMITED
71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
privacy@superlister.com
Appendix 1: Details Of Processing
Subject Matter
Superlister's processing of Customer Personal Data to provide, secure, maintain, support, and improve the Services.
Duration
For the term of the Agreement and any period during which Superlister processes Customer Personal Data in connection with the Services, subject to deletion, backup, legal, security, and retention requirements.
Nature And Purpose Of Processing
Superlister may process Customer Personal Data to:
- Create, manage, authenticate, and support user accounts.
- Capture, upload, store, process, transform, and display product information, images, videos, and listing content.
- Generate, classify, enrich, verify, revise, and submit marketplace listings.
- Connect to third-party marketplace, payment, email, notification, AI, analytics, and infrastructure services.
- Provide billing, subscription, support, notification, and administrative functions.
- Monitor, debug, secure, audit, and improve the Services.
- Comply with legal obligations and enforce the Agreement.
Categories Of Data Subjects
Customer Personal Data may relate to:
- Customer personnel and authorised users.
- Customer contractors, agents, or representatives.
- Marketplace account holders and operational contacts.
- End customers, buyers, or message senders whose data appears in marketplace or order workflows.
- Individuals shown or referenced in uploaded content, if any.
Categories Of Personal Data
Customer Personal Data may include:
- Names, email addresses, business names, roles, account identifiers, and authentication metadata.
- Billing, subscription, invoice, and payment processor metadata.
- Marketplace account identifiers, OAuth tokens, listing settings, listing status, order metadata, and integration data.
- Product descriptions, item attributes, product images, videos, listing drafts, generated content, prompts, outputs, and quality-control metadata.
- Communications, support requests, messages, notes, and feedback.
- IP addresses, device and browser metadata, log data, diagnostic events, and usage data.
Sensitive Data
The Services are not intended for processing special category data under UK GDPR or criminal offence data. The Customer must not upload or submit such data unless expressly agreed in writing with Superlister.
Processing Operations
Processing operations may include collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction.