1. Parties
This Data Processing Agreement (“DPA”) is entered into between the merchant entity that has accepted the Unauth Terms of Service (“Data Controller”) and Unauth Ltd, a company incorporated in England and Wales (“Processor” or “Unauth”). The Controller provides order, support, claim, and related commerce data to the Unauth platform; Unauth processes that data solely as directed by the Controller.
2. Subject matter and duration of processing
Unauth processes personal data provided by the Controller for the purposes set out in section 3 below. Processing commences on the date the Controller first provides data to the platform and continues for the duration of the active subscription, plus any retention period specified in section 7. Either party may terminate processing by providing 30 days written notice.
3. Nature and purpose of processing
Unauth processes order, support, claim, outcome, and transaction data to provide support payout case review, evidence packaging, merchant-owned rule recommendations, recovery workflow, and payout/recovery reporting. Processing activities include normalisation of case records, linking tickets to orders, compiling evidence checklists, recording agent decisions, and tracking recovery outcomes. Plaintext customer identifiers remain within the Controller’s own data silo.
4. Type of personal data
The following categories of personal data may be processed: order identifiers and values; customer name, email address, delivery address, and phone number (as provided by the Controller); device identifiers and IP addresses (where present in the provided data); refund and chargeback history. No special-category data within the meaning of Article 9 UK GDPR is knowingly processed.
5. Obligations of the Processor (Unauth)
Unauth shall: process personal data only on documented instructions from the Controller; ensure that persons authorised to process the personal data are bound by appropriate confidentiality obligations; implement the security measures described in section 8; assist the Controller in fulfilling its obligations regarding data subject rights; delete or return all personal data at the end of the processing term unless storage is required by applicable law; and provide all information necessary to demonstrate compliance with this DPA.
6. Sub-processors
Unauth uses the following sub-processors: Supabase Inc. (database infrastructure and storage, hosted in the EU); Vercel Inc. (application hosting and edge functions, hosted in the EU and US). Controllers are notified of any addition or replacement of sub-processors at least 30 days in advance via email, with the right to object within that period.
We use Amplitude analytics software to track feature usage within the Unauth application. No personal customer data is sent to Amplitude - only anonymised merchant behaviour events.
7. Data subject rights and deletion
Unauth will assist the Controller in responding to data subject access, erasure, and portability requests within the Controller’s statutory timeframe. Controllers may request deletion of all personal data associated with their account via the Settings page or by contacting dpa@unauth.co. Pseudonymous network-graph contributions (hashed identifiers and aggregate counts) are retained for 24 months from last contribution date; all other personal data is deleted within 30 days of account closure.
8. Security measures
Unauth implements the following technical and organisational measures: encryption of data at rest (AES-256) and in transit (TLS 1.3); row-level security enforced at the database layer preventing any cross-tenant data access; HMAC-SHA256 hashing of customer identifiers before network contribution; access controls limiting Unauth staff to aggregated metrics only; regular penetration testing; incident response procedures with 72-hour notification to affected Controllers.
9. Data transfers
Where personal data is transferred outside the UK or EEA, Unauth relies on the International Data Transfer Agreement (IDTA) for transfers to the United States via sub-processors (Supabase and Vercel). Standard Contractual Clauses (Module 2, Processor to Processor) are executed with all relevant sub-processors. Copies are available on request to dpa@unauth.co.
10. Contact
For all data protection and DPA enquiries: dpa@unauth.co