Legal and trust
Data Processing Agreement
How Billions+ processes personal data on behalf of businesses using the platform to operate customer workflows and automated business systems.
Last updated:

- PROCESSOR DUTIES
- Roles, instructions, and assistance commitments are surfaced.
- SUB-PROCESSORS
- Provider use, transfer mechanisms, and notices are scannable.
- AUDIT TRAIL
- Breach, deletion, and evidence expectations are easy to review.
Plain-language summary
This DPA sets out how Billions+ processes customer personal data for business customers, including roles, instructions, security measures, sub-processors, breach support, deletion, and compliance assistance.
Purpose and Scope
This Data Processing Agreement describes how Billions+ processes personal data on behalf of a business customer when providing the platform, storefront tools, connected-channel workflows, order operations, automations, AI-assisted sales features, support, security, and related services.
This DPA applies where Billions+ processes personal data for which the customer determines the purposes and means of processing. It is intended to supplement the Terms of Service and any order form or written agreement between the parties.
Roles of the Parties
2.1 Controller
The customer is the controller of personal data it collects, imports, configures, or receives through its workspace, storefronts, connected channels, and customer workflows. The customer decides what data is collected, why it is collected, how long it should be kept, and which lawful basis or legal authority applies.
2.2 Processor
Billions+ acts as processor for customer personal data and processes it only to provide the service, follow documented instructions, maintain security, support the platform, comply with applicable law, and perform obligations under the agreement.
Categories of Data
Customer personal data may include contact identifiers, names, phone numbers, email addresses, delivery details, order history, purchase intent, support requests, customer messages, product interests, channel identifiers, team-member details, business instructions, operational notes, payment-status metadata, and technical logs.
The exact categories depend on how the customer configures Billions+, what integrations are connected, which channels are used, what data customers provide, and which workflows are enabled.
Processing Instructions
The customer instructs Billions+ to process personal data as necessary to provide and secure the service. Instructions include configuration choices made in the product, use of APIs or integrations, support requests, order forms, written instructions, and the ordinary operation of enabled features.
If Billions+ believes an instruction violates applicable data-protection law, we may notify the customer and suspend the affected processing where necessary until the issue is resolved.
Nature and Purpose of Processing
Processing may include collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, disclosure to configured integrations, alignment, restriction, deletion, and return of personal data.
The purpose of processing is to operate the customer’s business workflows, manage storefront and catalog activity, route customer conversations, support orders, provide automation, enable AI-assisted workflows, maintain security, troubleshoot issues, and provide support.
Security Measures
Billions+ maintains technical and organizational measures designed to protect personal data from unauthorized access, accidental or unlawful destruction, loss, alteration, disclosure, or misuse. Measures may include encryption in transit, authentication controls, access restrictions, audit logging, monitoring, network controls, internal policies, and secure development practices.
Security measures are reviewed and updated over time to reflect changes in the service, processing risk, infrastructure, and available safeguards. The customer is responsible for configuring workspace permissions, managing users, protecting credentials, and using the platform securely.
Sub-processors
Billions+ may use sub-processors to provide hosting, storage, messaging, email, analytics, payment, monitoring, support, and other operational services. Sub-processors are authorized only to process personal data as needed to provide their services to Billions+ and must be bound by contractual obligations designed to protect personal data.
Billions+ remains responsible for sub-processor performance to the extent required by applicable law and the agreement. Where required, customers may receive notice of material sub-processor changes and may object according to the applicable process.
Data Subject Requests
If a data subject asks to access, correct, delete, restrict, export, or object to processing of personal data controlled by the customer, the customer is responsible for responding to that request. Billions+ will provide reasonable assistance where the request requires action on systems controlled by Billions+.
If Billions+ receives a request directly from a customer’s end user, we may redirect the requester to the customer unless applicable law requires a different response.
Personal Data Breach
If Billions+ becomes aware of a personal data breach affecting customer personal data, we will notify the customer without undue delay and provide information reasonably available to help the customer meet its own notification obligations.
The notice may include the nature of the incident, affected systems or data categories where known, likely consequences where reasonably assessable, remediation measures taken or planned, and a contact point for follow-up.
International Transfers
Billions+ and its sub-processors may process personal data in countries where infrastructure, support, or operational providers are located. Where data-protection law requires a transfer mechanism, the parties will rely on appropriate safeguards such as standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms.
Return and Deletion
After termination or upon documented request, Billions+ will delete or return customer personal data according to the agreement, product capabilities, legal requirements, and backup-retention cycles. Data may be retained where required by law, security, fraud prevention, dispute resolution, or financial recordkeeping obligations.
Deletion from backups and disaster-recovery systems may occur on a delayed cycle according to normal retention processes, provided the data is protected and not actively processed except for recovery, security, or legal purposes.
Audit and Compliance Assistance
Billions+ will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, operational, and commercial restrictions. Where required, audits or assessments must be scoped, reasonable, non-disruptive, and limited to systems relevant to processing customer personal data.
Billions+ may respond to compliance requests through documentation, security summaries, questionnaires, attestations, third-party reports, or other appropriate evidence rather than unrestricted system access.
Trust appendix
An auditable processing appendix for business buyers.
Businesses need precise processor commitments before connecting channels, customers, orders, and AI workflows.
Legal review required
Subprocessor register
Named subprocessors, purpose, location, objection process, and material-change notice period.
Transfer mechanism
International transfer mechanism, SCC or equivalent reference, and hosting/support regions.
Breach timing
Concrete notification target, contents of notice, and customer cooperation obligations.
Deletion and audit
Return/deletion SLA, backup retention, audit scope, report cadence, and evidence format.
Questions about this page? Contact [email protected]
Email us