Data Processing Addendum
This Data Processing Addendum ("DPA") governs the processing of personal data that NEXT BASKET carries out on behalf of merchants who use the NEXT BASKET platform to run their online stores. For that data, the merchant is the controller (GDPR) or business (CCPA), and NEXT BASKET is the processor or service provider. This DPA implements Article 28 of the EU General Data Protection Regulation and the CCPA’s service-provider requirements.
Effective date: 23 July 2026
Document version: Version 1.0 — effective 23 July 2026
1. Parties, roles, and relationship to the main agreement
This DPA forms part of the Master Subscription Agreement (Platform Terms) and the applicable Order Form (together, the "main agreement") under which Next Basket Platform B.V. (trading as NEXT BASKET AI; "NEXT BASKET", "we") provides the NEXT BASKET platform and related services to the merchant identified in that agreement ("Merchant", "you"). This DPA is incorporated into the main agreement by reference when the Merchant accepts it at clickwrap checkout, and may also be signed electronically for negotiated customers. A negotiated, signed DPA prevails over this published version for the same processing.
Roles. For personal data of the Merchant’s shoppers and other end users processed on the Merchant’s store ("Shopper Data"), the Merchant is the controller under the GDPR and the business under the CCPA, and NEXT BASKET is the Merchant’s processor under Article 28 GDPR and service provider under the CCPA. For the Merchant’s own account and billing data, NEXT BASKET acts as an independent controller, as described in our Privacy Policy — that processing is outside this DPA.
Each party will comply with the data protection laws applicable to it in its role, including the GDPR and applicable US state privacy laws.
2. Details of processing (subject matter, duration, nature, purpose)
- Subject matter
- Hosting and operation of the Merchant’s online store on the NEXT BASKET platform, including storefront delivery, order and customer management, and the platform features the Merchant enables.
- Duration
- The term of the main agreement, plus the post-termination return/deletion window in Section 11.
- Nature and purpose
- Collection, storage, structuring, use, disclosure by transmission, and deletion of Shopper Data as necessary to provide the platform services to the Merchant — and for no other purpose.
- Categories of data subjects
- Shoppers and visitors of the Merchant’s store; the Merchant’s staff users who operate the store.
- Categories of personal data
- Identification and contact data (name, email, phone, addresses), order and transaction data, account data, customer-service communications, and technical data (IP address, device/browser metadata). Payment card data is processed by the payment provider, not stored by NEXT BASKET.
- Special categories of data
- Not intended to be processed. The platform is not designed for special-category (Art. 9 GDPR) or otherwise sensitive data, and the Merchant must not submit it unless NEXT BASKET has given prior written approval and appropriate controls and an addendum are in place. Child-directed stores and regulated health or biometric use are not accepted by default.
3. Processing on documented instructions (Art. 28(3)(a))
NEXT BASKET will process Shopper Data only on the Merchant’s documented instructions — including with regard to transfers of personal data to a third country or an international organisation — unless required to do otherwise by EU or Member State law, in which case NEXT BASKET will inform the Merchant of that legal requirement before processing (unless the law prohibits that on important grounds of public interest).
The main agreement, this DPA, and the Merchant’s configuration and use of the platform (the features it enables, the data it submits) constitute the Merchant’s complete documented instructions. Additional instructions require written agreement.
NEXT BASKET will immediately inform the Merchant if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection provisions.
4. Confidentiality (Art. 28(3)(b))
NEXT BASKET ensures that persons authorised to process Shopper Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to Shopper Data is limited to personnel who need it to provide the services.
5. Security measures (Art. 28(3)(c), Art. 32)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons, NEXT BASKET implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR) — including encryption of data in transit, access controls, and measures to ensure ongoing confidentiality, integrity, availability, and resilience of the processing systems.
The technical and organisational measures NEXT BASKET currently maintains are described at a high level in Annex II to this DPA (Section 14). These are verified, high-level measures; NEXT BASKET does not claim encryption of data at rest, any named security certification, or specific recovery-point or recovery-time objectives in this DPA, and will state such measures only once engineering evidence supports them.
6. Sub-processors (Art. 28(2), 28(4))
The Merchant gives NEXT BASKET general written authorisation to engage sub-processors to provide parts of the services. The current list of sub-processors is published on our Subprocessor List page (/subprocessors/), which identifies each sub-processor, the service it provides, and its processing location.
NEXT BASKET will notify the Merchant by email to the account administrator, and will update the Subprocessor List page (/subprocessors/), at least 30 days before a new or replacement sub-processor begins material processing of Shopper Data — except for emergency or security-driven replacements, where notice follows as soon as practicable. The Merchant may object on reasonable data-protection grounds within 15 days of the notice.
Where NEXT BASKET engages a sub-processor, it imposes data-protection obligations by contract that are materially equivalent to those in this DPA, and remains fully liable to the Merchant for the performance of the sub-processor’s obligations (Art. 28(4)).
7. International transfers (SCC Modules 2 and 3)
NEXT BASKET will not transfer Shopper Data outside the European Economic Area (or another jurisdiction with equivalent transfer restrictions) except with a valid transfer mechanism under Chapter V GDPR.
Sub-processors located in the EEA process Shopper Data under Article 28 terms. For transfers of Shopper Data outside the EEA, the parties rely on the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), with completed annexes and appropriate supplementary measures: Module 2 (controller to processor) for transfers from the Merchant to NEXT BASKET where applicable, and Module 3 (processor to processor) for onward transfers from NEXT BASKET to its sub-processors.
NEXT BASKET does not rely on the EU–US Data Privacy Framework as the transfer mechanism unless a sub-processor’s current certification for the exact contracting entity is verified in the official Data Privacy Framework registry; where it is relied on, it is recorded for that specific provider rather than asserted generically. The mechanism actually relied on for each sub-processor is identified in connection with the Subprocessor List.
8. Assistance with data subject rights and compliance (Art. 28(3)(e), (f))
- Taking into account the nature of the processing, NEXT BASKET will assist the Merchant by appropriate technical and organisational measures, insofar as possible, in fulfilling the Merchant’s obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection) concerning Shopper Data.
- If a shopper contacts NEXT BASKET directly with a request concerning the Merchant’s store, NEXT BASKET will redirect the request to the Merchant without undue delay and will not respond on the merits except on the Merchant’s documented instruction or where required by law.
- NEXT BASKET will assist the Merchant in ensuring compliance with the Merchant’s obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to NEXT BASKET.
9. Personal data breach notification
NEXT BASKET will notify the Merchant after becoming aware of a personal data breach affecting Shopper Data, and will provide the information reasonably available to it about the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
NEXT BASKET will provide this notification without undue delay and, where reasonably possible, within 48 hours after it confirms a personal data breach affecting Shopper Data. An initial notification may be incomplete and will be supplemented by updates as further information becomes available.
NEXT BASKET’s notification is not an acknowledgement of fault or liability. The Merchant is responsible for its own notifications to supervisory authorities and data subjects (Art. 33, 34 GDPR).
10. Audits and information (Art. 28(3)(h))
NEXT BASKET will make available to the Merchant all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor mandated by the Merchant.
Audit mechanics: the Merchant may exercise this right once in any 12-month period, satisfied first through NEXT BASKET’s current documentation and completed questionnaires, on at least 30 days’ prior written notice. An on-site audit takes place only where legally required or where that documentation is insufficient, subject to confidentiality, without disrupting NEXT BASKET’s operations, and without endangering the security or confidentiality of other merchants’ data. The Merchant bears the costs of an audit unless it reveals a material non-compliance. NEXT BASKET does not claim any SOC 2 or ISO/IEC 27001 attestation, and will offer one only where current evidence supports it.
11. Return and deletion at the end of services (Art. 28(3)(g))
Upon termination or expiry of the services, NEXT BASKET will, at the Merchant’s choice, delete or return all Shopper Data to the Merchant, and delete existing copies, unless EU or Member State law requires storage of the personal data.
The Merchant has an export window of 30 days after termination to retrieve Shopper Data. NEXT BASKET deletes or anonymises active copies within 90 days, subject to legal holds, and backup copies expire through NEXT BASKET’s normal backup cycle no later than 180 days, unless law or a security incident requires longer retention. These periods are consistent with the data-export terms of the Master Subscription Agreement and NEXT BASKET’s offboarding procedures.
12. CCPA service-provider terms
To the extent Shopper Data includes personal information of California residents and the CCPA applies to the Merchant, NEXT BASKET acts as the Merchant’s "service provider" (Cal. Civ. Code § 1798.140), and the parties agree that:
- NEXT BASKET will not sell or share Shopper Data (as "sell" and "share" are defined in the CCPA).
- NEXT BASKET will not retain, use, or disclose Shopper Data for any purpose other than the business purposes specified in this DPA and the main agreement — including not retaining, using, or disclosing it outside the direct business relationship with the Merchant or for any commercial purpose of its own.
- NEXT BASKET will not combine Shopper Data with personal information it receives from other sources, except as permitted for service providers by the CCPA and its regulations.
- NEXT BASKET certifies that it understands these restrictions and will comply with them, will notify the Merchant if it determines it can no longer meet its obligations under the CCPA, and grants the Merchant the right, upon notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Shopper Data.
- NEXT BASKET will reasonably assist the Merchant in responding to verifiable consumer requests under the CCPA concerning Shopper Data.
13. Order of precedence and liability
In case of conflict between this DPA and the main agreement concerning the processing of Shopper Data, this DPA prevails; where the Standard Contractual Clauses apply, they prevail over both to the extent of the conflict.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Master Subscription Agreement, except that the 2× super-cap for data-protection obligations set out in that agreement applies to liability arising under this DPA. Liability for fraud, wilful misconduct, and any liability that cannot lawfully be limited remains uncapped. A negotiated DPA may specify a different cap.
Contact for this DPA: Next Basket Platform B.V., Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands, email office@nextbasket.com.
Annex II — Technical and organisational measures
NEXT BASKET maintains the following verified, high-level technical and organisational measures for the processing of Shopper Data under this DPA:
- Encryption of data in transit using TLS.
- Role-based, least-privilege access controls.
- Logical separation of each tenant’s data (tenant isolation).
- Secrets management for credentials and keys.
- Secure development practices and change review.
- Dependency, static, and security scanning.
- Logging and monitoring of the processing systems.
- Vulnerability handling and remediation.
- Backup and recovery procedures.
- Incident response processes.
- Personnel confidentiality obligations.
- Sub-processor diligence.
This Annex describes measures at a high level. NEXT BASKET does not claim encryption of data at rest, a named security certification (such as SOC 2 or ISO/IEC 27001), or specific recovery-point or recovery-time objectives until engineering evidence supports them; any such measures will be added to this Annex only with that evidence.