Data Processing Agreement
Version 1.0 · Effective October 6, 2026
This Data Processing Agreement ("DPA") forms part of our Terms of Service and sets out the terms on which Hongxiu Clothing ("Hongxiu", "we", "us") processes personal data on behalf of the business entity that uses the Services ("Merchant", "you"). It applies where the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR or the Swiss Federal Act on Data Protection ("FADP") applies to that processing, including the transfer of personal data to China for fulfillment. If this DPA conflicts with the Terms of Service with respect to personal data, this DPA prevails.
The Merchant confirms it has a lawful basis for sharing shopper information with Hongxiu for the purposes described below, and remains responsible for its own storefront privacy notices. Hongxiu processes that information only to provide the Services.
1. Roles and scope
The Merchant is the controller of personal data processed for its store, orders and shopper communications. Hongxiu is the processor that processes that personal data on the Merchant's behalf to provide the Partner Portal, the Hongxiu Dropshipping app, connected store integrations and Hongxiu's sourcing, production and fulfillment services (together, the "Services").
Hongxiu's documented instructions are the Terms of Service, the Merchant's configuration and use of the Portal and connected store integrations, and the individual order, stock, shipping and after-sales instructions the Merchant submits. Hongxiu will process personal data only on these documented instructions unless required to do otherwise by law; if an instruction appears to infringe applicable data protection law, we will inform the Merchant without undue delay.
The connected commerce platform (for example, Shopify) is operated under the Merchant's own account and terms. It is not a sub-processor of Hongxiu; personal data received from it is processed under this DPA. Personnel authorized to process personal data are bound by confidentiality obligations.
2. Details of the processing
This section describes the processing as required by Article 28(3) GDPR and serves as Annex I (part A and part B) of the Standard Contractual Clauses referenced in Section 7.
Subject matter and duration
The subject matter is the provision of the Services, including receiving and processing order and stock information, arranging production, packing, shipping and delivery, returning tracking updates, handling after-sales and support, and accounting. The duration is the term of the Terms of Service, followed by the deletion or return described in Section 8.
Nature and purpose of the processing
Receiving, storing, mapping, validating and processing order, stock, shipping and billing information; calculating and recording supplier charges; arranging production and fulfillment; transmitting delivery and tracking information to the Merchant's connected store; handling cancellations, replacements, refunds and support; maintaining records required for accounting and legal compliance.
Types of personal data
Merchant personnel: business and contact names, email addresses, phone numbers and account records. Shoppers/recipients: recipient name, delivery address, contact email and phone where provided, order contents and values, delivery preferences, shipping and tracking records, and correspondence relating to a claim or inquiry. The Services are not designed for special categories of personal data and the Merchant is instructed not to provide them.
Categories of data subjects
Merchant personnel and authorized users; the Merchant's shoppers and delivery recipients.
3. Our obligations as processor
- Process personal data only on the Merchant's documented instructions, as described in Section 1.
- Ensure that personnel processing personal data are subject to confidentiality obligations.
- Implement the technical and organizational measures described in Section 6.
- Engage sub-processors only as described in Section 5, with equivalent data protection obligations.
- Assist the Merchant with responding to requests and obligations as described in Section 4.
- Make available the information reasonably needed to demonstrate compliance, as described in Section 9.
- Return or delete personal data as described in Section 8.
4. Data subjects, breach and impact assessments
Data subject requests. If we receive a request from a data subject relating to personal data we process for the Merchant, we will not respond to it as its own controller and will forward it to the Merchant without undue delay. We will assist the Merchant with the request using the features available in the Services, such as records of orders, account data and the redaction and export tools used for platform data requests.
Personal data breaches. We will notify the Merchant without undue delay after becoming aware of a personal data breach affecting personal data we process for the Merchant, and will provide the information reasonably needed to support the Merchant's notification and remediation obligations, taking into account the nature of the processing and the information available to us.
Impact assessments and consultations. Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance where the Merchant needs information for a data protection impact assessment or a consultation with a supervisory authority relating to the Services.
5. Sub-processors
By accepting the Terms of Service, the Merchant provides general written authorization for Hongxiu to engage the sub-processors listed below, which support the Services. This list is Annex III of the Standard Contractual Clauses referenced in Section 7. We will maintain and update this list before engaging a new sub-processor, and where a change materially affects the processing of the Merchant's data we will provide advance notice by email or in the Portal. The Merchant may object to a new sub-processor on reasonable data protection grounds; if we cannot accommodate the objection, the Merchant may terminate the affected part of the Services.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Hostinger International Ltd. | Cloud hosting and infrastructure for the Portal and the Dropshipping app (virtual private server) | United States |
| Stripe | Payment processing for balances, invoices and card payments | Ireland / United States |
| Zoho Corporation (Zoho Mail / ZeptoMail) | Transactional and operational email delivery | China region |
| Yanwen Logistics and contracted delivery partners | International shipping, labels, customs documentation and delivery | China and destination countries |
Hongxiu's own sourcing, production, quality-control and warehouse operations in China are performed by Hongxiu as the processor. The connected commerce platform (for example, Shopify) is operated by the Merchant and is not a Hongxiu sub-processor.
Where a sub-processor processes personal data, we impose data protection obligations equivalent to those in this DPA. We remain liable to the Merchant for the performance of our sub-processors to the extent required by applicable law.
6. Technical and organizational measures
This section is Annex II of the Standard Contractual Clauses referenced in Section 7. We use measures including:
- transport encryption (HTTPS/TLS) for the Portal and for data exchanged with the Dropshipping app and connected stores;
- HMAC-SHA256 signed server-to-server requests with timestamp validation and replay protection;
- password hashing (scrypt) and opaque, revocable, HTTP-only session cookies;
- role-based access control and per-merchant data segregation in the Portal and administration tools;
- least-privilege staff access, with administrative actions recorded in the Portal;
- data minimization: only the information needed for the relevant service step is requested and shared; card details are entered on payment-provider hosted pages and are not stored by us;
- dedicated data-subject-request tooling, including redaction of recipient details in historical order snapshots and export of the data held for a request;
- logging, monitoring and controlled deployment processes for the Services.
No method of storage or transmission is completely secure. We review and update these measures as the Services and the risks evolve.
7. International transfers and safeguards
Fulfillment for the Merchant is performed in China. Personal data provided for fulfillment is therefore transferred to and processed in China, and may also be processed in the other locations described in Section 5.
Standard Contractual Clauses. Where the GDPR applies, the parties agree that the Standard Contractual Clauses approved by the European Commission in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference and apply to transfers of personal data from the European Economic Area to Hongxiu in China, and to onward transfers to the sub-processors described in Section 5. The Annexes are completed as follows: Annex I by Sections 1 and 2 of this DPA; Annex II by Section 6; Annex III by Section 5. Where the UK GDPR applies, the UK Addendum to the Standard Contractual Clauses issued by the UK Information Commissioner applies in the same way. Where the Swiss FADP applies, the Standard Contractual Clauses apply with the adjustments required for Switzerland.
Transfer assessment and supplementary measures. We have assessed the transfers described in this DPA and rely on the Standard Contractual Clauses together with the security, minimization and access-control measures described in Section 6. We will reasonably cooperate with the Merchant's own transfer assessments and will inform the Merchant if we can no longer comply with the Standard Contractual Clauses.
Signed copies. If the Merchant needs a countersigned copy of this DPA or of the Standard Contractual Clauses with completed annexes, we will provide one on request using the contact address in Section 11.
8. Deletion and return of data
At the end of the provision of the Services, and at the Merchant's choice, we will delete or return the personal data we process for the Merchant, except where we are required by law to retain it or need it for records relating to orders, reserved inventory, balances or disputes. Retained records are limited to what is required for those purposes and remain protected by the measures in Section 6 and the confidentiality obligations of this DPA.
We also honor deletion and redaction requests submitted through the applicable platform data-request process or through the contact address in Section 11, including redaction of recipient details from historical order records where the record itself must be retained for accounting purposes.
9. Audit and information
We will provide the Merchant with the information reasonably necessary to demonstrate compliance with this DPA, starting with written responses, documentation and, where the Merchant remains entitled to an audit under applicable law, allowing one audit per year on at least 30 days' written notice. Audits are bound by confidentiality, must be conducted during business hours in a way that does not disrupt the Services, and may be satisfied by a shared report or remote review where that is sufficient.
10. Term, liability and governing law
This DPA takes effect when the Merchant accepts the Terms of Service and continues for as long as Hongxiu processes personal data for the Merchant, followed by the obligations in Sections 8 and 10. Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing in this DPA limits rights or liability that cannot be limited under applicable data protection law. This DPA is governed by the law and dispute provisions of the Terms of Service, without prejudice to mandatory provisions of the GDPR, UK GDPR or FADP and the rights of data subjects.
11. Contact and signed copies
Questions about this DPA, requests for a countersigned copy, notifications of objections to sub-processors, and privacy requests can be sent to service@wearhongxiu.com. This page shows the current version and effective date; we may update it as the Services or the law changes, and material changes will be published here before they take effect.