Data Processing Agreement
Effective: September 1, 2026
This Data Processing Agreement ("DPA") is incorporated into the Terms of Service between Channel3, Inc. ("Processor", "we", "us") and the entity agreeing to these terms ("Controller", "you") for the use of Channel3's platform, APIs, and related services (the "Services"). If you and Channel3 have signed additional written terms, this DPA forms part of that agreement as well.
Channel3 is a processor (or service provider) only for personal data the Controller submits to the Services, such as queries, uploads, catalog feeds, and end-user data the Controller sends through the APIs. Channel3 is a controller of account, billing, and website data as described in our Privacy Policy. This DPA applies where Channel3 processes personal data on behalf of the Controller and that processing is subject to applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Channel3 on behalf of the Controller in connection with the Services.
- "Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Channel3 under this DPA.
- "Sub-Processor" means any third party engaged by Channel3 to process Personal Data on behalf of the Controller.
- "Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the GDPR, UK GDPR, and the California Consumer Privacy Act (CCPA).
2. Scope and purpose of processing
Channel3 processes Personal Data solely for the purpose of providing the Services as described in the Terms of Service and as further instructed by the Controller. The categories of data subjects, Personal Data, and processing activities are determined by the Controller's use of the Services.
Typical categories include:
- Data subjects: End users, developers, and business contacts of the Controller
- Categories of data: Names, email addresses, organization information, IP addresses, device identifiers, usage data, and commerce interaction data
- Processing activities: Providing platform access, processing API requests, analytics, authentication, and customer support
3. Obligations of the Processor
Channel3 shall:
- Process Personal Data only on documented instructions from the Controller, unless required by applicable law. Channel3 will not use Personal Data processed under this DPA to train its internal models
- Ensure that persons authorized to process Personal Data are subject to confidentiality obligations
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption in transit and at rest, access controls, and regular security assessments
- Taking into account the nature of the processing and the information reasonably available to Channel3, provide reasonable assistance to the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, and objection) and in meeting obligations related to security, breach notification, data protection impact assessments, and prior consultation. Channel3 may charge the Controller for its reasonable costs of assistance that is extensive or repeated beyond what Data Protection Laws require
- At the Controller's choice, delete or return all Personal Data upon termination of the Services as described in Section 8, unless retention is required by applicable law
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 7
4. Sub-Processors
The Controller provides general authorization for Channel3 to engage Sub-Processors. A current list of Sub-Processors is available at our Sub-Processors page.
Channel3 will give the Controller reasonable advance notice of any intended changes to its Sub-Processors, giving the Controller the opportunity to object on reasonable grounds. If the parties cannot resolve a timely objection, the Controller's sole remedy is to terminate the Services affected by that Sub-Processor. Channel3 will impose data protection obligations on each Sub-Processor that are no less protective than those in this DPA.
5. Data breach notification
Channel3 will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach affecting the Controller's data. The notification will include, to the extent known at the time, the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
6. International data transfers
Channel3 is based in the United States. Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States or other countries without an adequacy decision, Channel3 will ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Audit rights
No more than once in any twelve-month period, unless required by a regulator or in response to a confirmed Personal Data Breach, Channel3 will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Channel3 may satisfy an audit request by providing a recent third-party security certification or audit report (such as SOC 2 or ISO 27001) covering the relevant period, where available. Audits require at least 30 days' written notice, are conducted during normal business hours in a manner that minimizes disruption to Channel3's operations, and are subject to the confidentiality obligations in the Terms of Service. The Controller bears its own costs of an audit; Channel3 may charge its reasonable costs for any audit beyond one in a twelve-month period.
8. Term and termination
This DPA shall remain in effect for the duration of Channel3's processing of Personal Data on behalf of the Controller. Upon termination or expiry of the Services, Channel3 will, at the Controller's election, delete or return all Personal Data within a reasonable timeframe, unless retention is required by applicable law. Channel3 may retain Personal Data contained in encrypted backups until those backups are deleted or overwritten in the ordinary course of its backup cycle, subject to the confidentiality and security obligations of this DPA.
9. Liability
Each party's liability arising out of or relating to this DPA, including any liability arising under Data Protection Laws, is subject to the limitations and exclusions of liability set out in the Terms of Service, to the fullest extent permitted by applicable law.
10. Governing law
This DPA shall be governed by the laws of the State of Delaware, USA, without regard to conflict of laws principles, except where Data Protection Laws require otherwise.
Contact us
Channel3, Inc., 169 Madison Ave STE 38212, New York, NY 10016. For questions about this DPA or to exercise any rights, contact us at support@trychannel3.com.