Data Processing Addendum
Last updated: 9 July 2026
Scope
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Sello SARL ("Processor") and the merchant ("Controller") and applies where the Controller uses Sello to process personal data on behalf of end customers.
Subject matter and duration
Processor processes personal data for the duration of the Controller's use of Sello, for the purpose of providing the review service described in the Terms.
Nature and purpose of processing
Localization, HS code suggestion, and compliance review of product listings. Where the Controller provides end-customer data, Processor stores and processes it only as instructed by the Controller.
Categories of data subjects
End customers of the Controller, where such data is included in materials the Controller sends to Sello.
Categories of personal data
Where applicable: customer names, contact details, addresses, order references. Sello does not require end-customer personal data to function.
Sub-processors
- OpenAI (LLM inference) — under OpenAI's API data usage policy, no training on inputs.
- Supabase (database and edge functions) — hosted in the European Union.
- Stripe (payment processing) — billing only.
Processor will notify Controllers of any new or replaced sub-processor at least 30 days in advance.
Security
Encryption in transit (TLS) and at rest. Access controls and logging on production systems.
Data subject rights
Processor will assist the Controller in responding to data subject requests within a reasonable time.
Breach notification
Processor will notify the Controller within 72 hours of becoming aware of a personal data breach affecting the Controller's data.
International transfers
Where personal data is transferred outside the EU/EEA to a sub-processor, standard contractual clauses apply.
Deletion
On termination, Processor will delete or return Controller data within 90 days, except where retention is required by law.
Contact
Sello SARL — hello@sello.company