(Version 1.0 Effective September 1, 2026)
This Data Processing Addendum (“DPA”) is published by Swiftly Systems, Inc. (“Swiftly”) and is incorporated by reference into the reseller, wholesale-channel, or distribution agreement (the “Channel Agreement”) between Swiftly and an authorized reseller (the “Reseller”). It governs Swiftly’s processing of Personal Information contained in Retailer Data and controls over the body of the Channel Agreement to the extent of any conflict on that subject.
1. Definitions
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person, device, or household, including “personal information,” “personal data,” and “personally identifiable information” as defined under applicable Privacy Laws. Aggregate Data and Deidentified Data are not Personal Information.
“Privacy Laws” means all federal, state, and local laws, rules, and regulations applicable to the collection, use, processing, disclosure, security, or transfer of Personal Information, including the California Consumer Privacy Act as amended and other applicable United States state consumer privacy statutes.
“Retailer Data” means the data and content of the Reseller or a retailer enrolled by the Reseller (each, a “Retailer”) that is processed by the Swiftly Technology, including item, price, and promotion feeds, store lists, circular and advertising history, loyalty and customer-relationship-management data, and transaction logs.
“End User” means a Retailer’s consumers and shoppers and persons authorized to access or use the Swiftly Technology.
“Aggregate Data” means information that relates to a group or category of End Users, or that is presented in aggregate across stores, banners, categories, or periods, from which individual End User identities have been removed and that is not linked or reasonably linkable to any End User or household.
“Deidentified Data” means information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular End User, and for which Swiftly: (i) has implemented technical safeguards that prohibit reidentification of the End User to whom the information pertains; (ii) has implemented business processes that specifically prohibit reidentification of the information; (iii) has implemented business processes to prevent inadvertent release of the information; and (iv) makes no attempt to reidentify the information.
These definitions are the same as those in the Channel Agreement and are to be read consistently with it.
2. Roles of the parties
As among Swiftly, the Reseller, and the Retailers, and with respect to Personal Information contained in Retailer Data:
• the Retailer to which the Personal Information relates is the controlling party, including as a “business” where that term applies;
• the Reseller acts on that Retailer’s behalf in administering the program; and
• Swiftly acts as a service provider or processor, processing that Personal Information on documented instructions received through the Reseller or that Retailer.
Each party will comply with the Privacy Laws applicable to it in connection with the Channel Agreement.
3. Swiftly’s processing obligations
Swiftly will not retain, use, or disclose Personal Information contained in Retailer Data for any purpose other than performing the Services and the purposes expressly permitted by the Channel Agreement, which include creating Aggregate Data and Deidentified Data under Section 10 and the internal use permitted to a service provider under Privacy Laws to build and improve the quality of its services, and will not sell or share that Personal Information. Swiftly will not combine that Personal Information with personal information it receives from another source, except as permitted by Privacy Laws for a service provider.
Swiftly will notify the Reseller if it determines it can no longer meet its obligations under applicable Privacy Laws.
4. Rights and consents
The Reseller will obtain, and grants to Swiftly to the extent within its power to grant, all rights and consents necessary for Swiftly to receive, host, process, store, transmit, and display Retailer Data in order to provide the Services. The Reseller represents that each Retailer Agreement grants it the rights necessary to enable Swiftly’s processing of that Retailer’s data, and that each Retailer has given all notices and obtained all consents required under Privacy Laws for that processing. Where a Retailer transmits Retailer Data to Swiftly directly, the Reseller will cause that Retailer to grant Swiftly the same rights.
5. Individual rights requests
Swiftly will provide reasonable assistance to the Reseller and the applicable Retailer in responding to verified individual rights requests relating to Personal Information processed by Swiftly. If a request is made directly to Swiftly, Swiftly will promptly forward it to the Reseller for routing to the applicable Retailer, and will respond directly only where required by Privacy Laws.
6. Subprocessors
Swiftly may engage subprocessors, including hosting providers and providers of AI systems, to process Personal Information in connection with the Services, provided that Swiftly imposes on each written obligations for confidentiality, data protection, and security no less protective than those in this DPA; permits each to process Personal Information only as necessary to provide the Services; and remains fully responsible and liable for their acts and omissions as though they were Swiftly’s own. Swiftly will provide a current list of subprocessors on written request. The list in effect as at the date of this DPA is set out in Annex 2.
7. Security
Swiftly will implement and maintain the technical and organizational measures described in the Swiftly Security Overview at swiftly.com/trust/security, which is incorporated into this DPA by reference.
8. Security incidents
Swiftly will notify the Reseller of any confirmed Security Incident affecting Retailer Data without undue delay and in any event within seventy-two (72) hours after confirming it, and will cooperate in the investigation and remediation, in each case as set out in the Swiftly Security Overview. As between the parties, the Reseller is responsible for notifying affected Retailers and for any notification required to individuals or regulators.
9. Restrictions on AI training
Swiftly will not use Personal Information contained in Retailer Data to train, fine-tune, or otherwise develop any AI system except in Aggregate or Deidentified Data form, or to the extent necessary to configure, tune, and operate a Solution for the Reseller and the applicable Retailer. Swiftly will not permit any third-party AI provider to use that Personal Information to train, fine-tune, or improve any model or service made available to third parties.
10. Aggregate and Deidentified Data
Swiftly may create Aggregate Data and Deidentified Data from Retailer Data and may use it to operate, secure, support, improve, and develop its products and services, including to build and maintain baselines, benchmarks, models, category and peer-group comparisons, and recommendations, and to make those comparisons and recommendations available to the Reseller, to Retailers, and to Swiftly’s other customers. In using and disclosing Aggregate Data and Deidentified Data, Swiftly will not identify the Reseller, any Retailer, or any store as the source; will not disclose the individual results of a Reseller, Retailer, or store to any other customer, or present data in a manner from which those individual results can readily be derived; and will not attempt to reidentify any individual. This paragraph is a covenant of Swiftly and does not qualify or condition the definitions in Section 1 or the rights granted above.
Nothing in this DPA limits Swiftly’s rights in Aggregate Data and Deidentified Data under the Channel Agreement. Where this DPA and the Channel Agreement differ on those rights, the Channel Agreement governs, notwithstanding the order of precedence stated at the top of this DPA.
Aggregate Data and Deidentified Data are not Personal Information, and Swiftly’s rights in them, and in the baselines, benchmarks, models, and reporting derived from them, are perpetual. They survive expiration or termination of the Channel Agreement, the cessation of any Retailer’s enrollment, and any return or deletion of Retailer Data under Section 12, and Swiftly is not required to re-compute, unwind, or remove any baseline, benchmark, model, or report that incorporates data contributed before that time.
11. Prohibited categories
The Reseller will not, and will cause each Retailer not to, submit to the Solutions any protected health information subject to HIPAA, payment card data subject to PCI DSS, government-issued identification numbers, biometric identifiers, precise geolocation of individuals, or information concerning any individual known to be under the age of sixteen.
12. Return and deletion
Within thirty (30) days after a Retailer ceases to be enrolled, after expiration or termination of the applicable Services Schedule, or on the Reseller’s earlier written request, Swiftly will, at the Reseller’s election, return that Retailer’s Retailer Data to the Reseller or to the Retailer, or delete it, except to the extent retention is required by law, is necessary to document performance, or is contained in routine backups maintained in the ordinary course. Data in routine backups remains subject to this DPA until deleted in the ordinary course. Swiftly’s rights in Aggregate Data and Deidentified Data under Section 10 are unaffected by this Section 12.
13. Changes to this DPA
Swiftly may update this DPA from time to time and will give the Reseller at least thirty (30) days’ written notice before a change takes effect. Swiftly will not make a change that materially reduces its data-protection commitments during the then-current term without the Reseller’s written consent.
Annex 1: Details of processing
Item | Detail |
Subject matter | Provision of the Swiftly Solutions, including AI generation of retail circular and promotional content and related analytics. |
Duration | The term of the Channel Agreement, plus the return and deletion period in Section 12. |
Nature and purpose | Hosting, processing, storing, transmitting, and displaying Retailer Data in order to generate Output and provide reporting and analytics. |
Types of Personal Information | A pseudonymous household or loyalty identifier; the loyalty or customer-relationship-management records associated with it; and itemized point-of-sale transaction records associated with it, in each case to the extent these contain Personal Information. Direct identifiers may be hashed or tokenized before transmission. Names and contact details of Reseller and Retailer personnel administering the program. |
Categories of data subjects | Consumers and shoppers of the Retailers. Personnel of the Reseller and the Retailers, in respect of program administration contact details only. |
Frequency | Transaction logs daily; loyalty and customer files at least monthly; item, price, and promotion feeds on the recurring cadence required to generate each circular. |
Retention | Transaction and loyalty data for a rolling period of up to twenty-four (24) months to support baselines and period-over-period comparison, and otherwise for the duration above, then returned or deleted under Section 12. Routine backups are retained for Thirty (30) Days and then deleted in the ordinary course. |
Annex 2: Subprocessors
The subprocessors engaged by Swiftly as at the effective date of this DPA are:
Subprocessor | Processing performed | Location |
[NAME] | Cloud hosting and storage of Retailer Data | [UNITED STATES] |
[NAME] | Provision of the AI systems used to generate Output | [UNITED STATES] |
[NAME] | [Data integration / loyalty data ingestion] | [UNITED STATES] |
Swiftly maintains the current list and provides it on request under Section 6.