Data processing addendum
Last updated 8 September 2026
The processor terms that apply when usellit handles personal data on your behalf. Forms part of the Terms of service.
1. Scope and roles
This addendum applies where usellit processes personal data on your behalf, and forms part of the Terms of service. You are the controller; usellit Inc. is the processor. Where you are yourself a processor for someone else, we are the sub-processor and these terms apply accordingly.
2. Subject matter
| Item | Detail |
|---|---|
| Subject matter | Providing point of sale software and ERP synchronisation |
| Duration | The term of the agreement, plus the deletion period below |
| Nature and purpose | Storage, retrieval, synchronisation and display of business records |
| Data subjects | Your staff who use the system, and your customers whose records you sync |
| Categories | Contact details, identifiers, purchase history, role and permission data |
| Special categories | None. Do not put special category data into usellit; it is not built for it |
3. Our obligations
- We process personal data only on your documented instructions, including regarding transfers, unless the law requires otherwise - in which case we tell you first if permitted.
- We ensure people authorized to process it are bound by confidentiality.
- We implement appropriate technical and organizational measures - set out on the security page, which forms part of this addendum.
- We assist you, so far as reasonable, with data subject requests, impact assessments and regulator consultations.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data.
4. Sub-processors
You give general authorization for us to use sub-processors. The current list is published at usellit.ai/sub-processors. We will give at least 30 days' notice before adding one, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may terminate the affected service without penalty.
Each sub-processor is bound by terms no less protective than these, and we remain liable for their performance.
5. International transfers
Our infrastructure runs in the United States. For transfers out of the UK or EEA we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference and completed as follows: module two (controller to processor), with the docking clause applying, and the details in section 2 above populating the annexes.
6. Deletion and return
You may export your data at any time while the agreement is live. On termination we delete it within 90 days unless the law requires us to keep it, and confirm deletion on request. Your ERP is never modified by this.
7. Audit
We will provide the information reasonably needed to demonstrate compliance, and will contribute to audits carried out by you or an auditor you appoint, on reasonable notice, no more than once a year unless a regulator or a breach requires otherwise. Where available we may satisfy this with third-party reports instead - see the security page for what does and does not currently exist.
8. Liability
Liability under this addendum is subject to the limitations in the Terms of service.
9. Conflicts
Where this addendum conflicts with the Terms of service on the processing of personal data, this addendum wins.