Hongxiu Partner PortalContact us

Data Processing Agreement

Version 1.0 · Effective October 6, 2026

This Data Processing Agreement ("DPA") forms part of our Terms of Service and sets out the terms on which Hongxiu Clothing ("Hongxiu", "we", "us") processes personal data on behalf of the business entity that uses the Services ("Merchant", "you"). It applies where the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR or the Swiss Federal Act on Data Protection ("FADP") applies to that processing, including the transfer of personal data to China for fulfillment. If this DPA conflicts with the Terms of Service with respect to personal data, this DPA prevails.

The Merchant confirms it has a lawful basis for sharing shopper information with Hongxiu for the purposes described below, and remains responsible for its own storefront privacy notices. Hongxiu processes that information only to provide the Services.

1. Roles and scope

The Merchant is the controller of personal data processed for its store, orders and shopper communications. Hongxiu is the processor that processes that personal data on the Merchant's behalf to provide the Partner Portal, the Hongxiu Dropshipping app, connected store integrations and Hongxiu's sourcing, production and fulfillment services (together, the "Services").

Hongxiu's documented instructions are the Terms of Service, the Merchant's configuration and use of the Portal and connected store integrations, and the individual order, stock, shipping and after-sales instructions the Merchant submits. Hongxiu will process personal data only on these documented instructions unless required to do otherwise by law; if an instruction appears to infringe applicable data protection law, we will inform the Merchant without undue delay.

The connected commerce platform (for example, Shopify) is operated under the Merchant's own account and terms. It is not a sub-processor of Hongxiu; personal data received from it is processed under this DPA. Personnel authorized to process personal data are bound by confidentiality obligations.

2. Details of the processing

This section describes the processing as required by Article 28(3) GDPR and serves as Annex I (part A and part B) of the Standard Contractual Clauses referenced in Section 7.

Subject matter and duration

The subject matter is the provision of the Services, including receiving and processing order and stock information, arranging production, packing, shipping and delivery, returning tracking updates, handling after-sales and support, and accounting. The duration is the term of the Terms of Service, followed by the deletion or return described in Section 8.

Nature and purpose of the processing

Receiving, storing, mapping, validating and processing order, stock, shipping and billing information; calculating and recording supplier charges; arranging production and fulfillment; transmitting delivery and tracking information to the Merchant's connected store; handling cancellations, replacements, refunds and support; maintaining records required for accounting and legal compliance.

Types of personal data

Merchant personnel: business and contact names, email addresses, phone numbers and account records. Shoppers/recipients: recipient name, delivery address, contact email and phone where provided, order contents and values, delivery preferences, shipping and tracking records, and correspondence relating to a claim or inquiry. The Services are not designed for special categories of personal data and the Merchant is instructed not to provide them.

Categories of data subjects

Merchant personnel and authorized users; the Merchant's shoppers and delivery recipients.

3. Our obligations as processor

4. Data subjects, breach and impact assessments

Data subject requests. If we receive a request from a data subject relating to personal data we process for the Merchant, we will not respond to it as its own controller and will forward it to the Merchant without undue delay. We will assist the Merchant with the request using the features available in the Services, such as records of orders, account data and the redaction and export tools used for platform data requests.

Personal data breaches. We will notify the Merchant without undue delay after becoming aware of a personal data breach affecting personal data we process for the Merchant, and will provide the information reasonably needed to support the Merchant's notification and remediation obligations, taking into account the nature of the processing and the information available to us.

Impact assessments and consultations. Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance where the Merchant needs information for a data protection impact assessment or a consultation with a supervisory authority relating to the Services.

5. Sub-processors

By accepting the Terms of Service, the Merchant provides general written authorization for Hongxiu to engage the sub-processors listed below, which support the Services. This list is Annex III of the Standard Contractual Clauses referenced in Section 7. We will maintain and update this list before engaging a new sub-processor, and where a change materially affects the processing of the Merchant's data we will provide advance notice by email or in the Portal. The Merchant may object to a new sub-processor on reasonable data protection grounds; if we cannot accommodate the objection, the Merchant may terminate the affected part of the Services.

Sub-processorPurposeProcessing location
Hostinger International Ltd.Cloud hosting and infrastructure for the Portal and the Dropshipping app (virtual private server)United States
StripePayment processing for balances, invoices and card paymentsIreland / United States
Zoho Corporation (Zoho Mail / ZeptoMail)Transactional and operational email deliveryChina region
Yanwen Logistics and contracted delivery partnersInternational shipping, labels, customs documentation and deliveryChina and destination countries

Hongxiu's own sourcing, production, quality-control and warehouse operations in China are performed by Hongxiu as the processor. The connected commerce platform (for example, Shopify) is operated by the Merchant and is not a Hongxiu sub-processor.

Where a sub-processor processes personal data, we impose data protection obligations equivalent to those in this DPA. We remain liable to the Merchant for the performance of our sub-processors to the extent required by applicable law.

6. Technical and organizational measures

This section is Annex II of the Standard Contractual Clauses referenced in Section 7. We use measures including:

No method of storage or transmission is completely secure. We review and update these measures as the Services and the risks evolve.

7. International transfers and safeguards

Fulfillment for the Merchant is performed in China. Personal data provided for fulfillment is therefore transferred to and processed in China, and may also be processed in the other locations described in Section 5.

Standard Contractual Clauses. Where the GDPR applies, the parties agree that the Standard Contractual Clauses approved by the European Commission in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference and apply to transfers of personal data from the European Economic Area to Hongxiu in China, and to onward transfers to the sub-processors described in Section 5. The Annexes are completed as follows: Annex I by Sections 1 and 2 of this DPA; Annex II by Section 6; Annex III by Section 5. Where the UK GDPR applies, the UK Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner applies in the same way. Where the Swiss FADP applies, the Standard Contractual Clauses apply with the adjustments required for Switzerland.

Transfer assessment and supplementary measures. We have assessed the transfers described in this DPA and rely on the Standard Contractual Clauses together with the security, minimization and access-control measures described in Section 6. We will reasonably cooperate with the Merchant's own transfer assessments and will inform the Merchant if we can no longer comply with the Standard Contractual Clauses.

Signed copies. If the Merchant needs a countersigned copy of this DPA or of the Standard Contractual Clauses with completed annexes, we will provide one on request using the contact address in Section 11.

8. Deletion and return of data

At the end of the provision of the Services, and at the Merchant's choice, we will delete or return the personal data we process for the Merchant, except where we are required by law to retain it or need it for records relating to orders, reserved inventory, balances or disputes. Retained records are limited to what is required for those purposes and remain protected by the measures in Section 6 and the confidentiality obligations of this DPA.

We also honor deletion and redaction requests submitted through the applicable platform data-request process or through the contact address in Section 11, including redaction of recipient details from historical order records where the record itself must be retained for accounting purposes.

9. Audit and information

We will provide the Merchant with the information reasonably necessary to demonstrate compliance with this DPA, starting with written responses, documentation and, where the Merchant remains entitled to an audit under applicable law, allowing one audit per year on at least 30 days' written notice. Audits are bound by confidentiality, must be conducted during business hours in a way that does not disrupt the Services, and may be satisfied by a shared report or remote review where that is sufficient.

10. Term, liability and governing law

This DPA takes effect when the Merchant accepts the Terms of Service and continues for as long as Hongxiu processes personal data for the Merchant, followed by the obligations in Sections 8 and 10. Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing in this DPA limits rights or liability that cannot be limited under applicable data protection law. This DPA is governed by the law and dispute provisions of the Terms of Service, without prejudice to mandatory provisions of the GDPR, UK GDPR or FADP and the rights of data subjects.

11. Contact and signed copies

Questions about this DPA, requests for a countersigned copy, notifications of objections to sub-processors, and privacy requests can be sent to service@wearhongxiu.com. This page shows the current version and effective date; we may update it as the Services or the law changes, and material changes will be published here before they take effect.