Log inBook a demo

Retailer Data Processing Addendum

Last updated

This Data Processing Addendum (“DPA”) is entered into in connection with and shall constitute part of the agreement between the retailer using the Services (“Retailer”) and GoVyrl, Inc. (dba Carro) (“Carro”) (the “Agreement”) and sets forth the parties’ obligations with respect to the Processing of Personal Data in connection with Carro’s provision of the Services. This DPA can be modified as described in the Terms and Policies (which also includes this DPA). We encourage you to review them. In the provision of the Services, Retailer acts as a Controller with respect to Personal Data of its customers and other individuals, and Carro acts as a Processor on behalf of Retailer.

This DPA and its Annexes are incorporated into and subject to the Agreement. Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.

1. DEFINITIONS

1.1. “Consumer” means a customer of Retailer who places an order for Products through Retailer's platform, as further described in the Agreement.

1.2. “Controller” means the entity that determines the purposes and means of Processing Personal Data.

1.3. “Data Protection Laws” means all applicable laws and regulations relating to the Processing of Personal Data that apply to a party in connection with this DPA, including where applicable: the EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”); the UK General Data Protection Regulation and UK Data Protection Act 2018 (collectively, “UK GDPR”); the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”); and other applicable U.S. state privacy laws, in each case as amended or replaced from time to time.

1.4. “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.

1.5. “Personal Data” means information relating to an identified or identifiable natural person that Carro Processes as a Processor on behalf of Retailer in connection with the Services, as further described in Annex 1. Personal Data includes “Personal Information” as defined in the Agreement. For clarity, Personal Data does not include: (a) Aggregated Data or Usage Data as defined in the Agreement; or (b) operational or transactional data that does not identify or relate to an identified or identifiable natural person, such as inventory counts, SKU data, product descriptions, pricing information, and logistics routing data.

1.6. “Process” or “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, restriction, erasure, or destruction.

1.7. “Processor” means an entity that Processes Personal Data on behalf of a Controller.

1.8. “Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data.

1.9. “Service Provider” means an entity that processes personal information on behalf of a Business, and includes similar terms under applicable Data Protection Laws such as “Processor.”

1.10. “Sub-processor” means any third-party entity engaged by Carro to Process Personal Data in connection with the Services.

1.11. “Supplier” means a merchant or distributor whose products Carro enables Retailer to offer for sale through the Services.

1.12. CCPA Terms. The terms “Business”, “Sale”, “Sell”, “Share”, and “Commercial Purpose” shall have the meanings ascribed to them under the CCPA/CPRA.

2. PROCESSING OF PERSONAL DATA

2.1. Processing Instructions. Carro will Process Personal Data solely: (a) to perform the Services on Retailer’s behalf in accordance with Retailer’s documented instructions, which include the Agreement and this DPA; and (b) as otherwise required by applicable law. If Carro believes that an instruction from Retailer violates applicable Data Protection Laws, Carro shall promptly notify Retailer. A description of the Processing activities is set forth in Annex 1.

2.2. Prohibited Uses. Carro will not: (a) retain, use, or disclose Personal Data for any purpose other than the specific purpose of providing the Services, or as otherwise permitted under applicable Data Protection Laws; (b) Sell or Share Personal Data; or (c) combine Personal Data with personal data received from or on behalf of another person, or collected from Carro’s own interactions with individuals, except as permitted by Data Protection Laws or as necessary to detect security incidents or protect against fraud. For clarity, Carro’s disclosure of Personal Data to Sub-processors in accordance with Section 8, and to Suppliers in accordance with Section 2.4, does not constitute a Sale or Sharing of Personal Data, because such disclosures are made solely to provide the Services and fulfill orders, and not in exchange for monetary or other valuable consideration for such Personal Data.

2.3. Aggregated Data. Nothing in this DPA restricts Carro’s right to derive, generate, compile, retain, use, or disclose Aggregated Data or Usage Data (as defined in the Agreement) for any lawful business purpose, including product improvement, analytics, benchmarking, and reporting, provided that such data does not identify Retailer or any individual Data Subject and such use complies with applicable Data Protection Laws. Retailer shall have no ownership interest in Aggregated Data or Usage Data. For the avoidance of doubt, the deletion and return obligations in Section 5 do not apply to Aggregated Data or Usage Data.

2.4. Supplier Data Flows. Retailer acknowledges and agrees that Carro’s provision of the Services inherently involves transmitting certain order, fulfillment, and related Personal Data (such as Consumer name, shipping address, order items, and order ID, together with, where enabled by Retailer as described below, Consumer email address and phone number) to Suppliers for the purpose of fulfilling orders placed by Consumers. Such Personal Data may be transmitted through the Carro platform, e-commerce integrations, secure file transfer, or other methods made available through the Services. Upon receipt, each Supplier processes such Personal Data as an independent party in the transaction chain for its own fulfillment purposes, and not on behalf of or at the direction of Carro. Suppliers are solely responsible for their own handling of Personal Data after receipt, including compliance with applicable Data Protection Laws. Carro’s standard platform terms require Suppliers to use Consumer Personal Data solely for order fulfillment and to refrain from selling, sharing, or using such data for marketing or advertising purposes. Disclosure of a Consumer’s email address and phone number to a Supplier is governed by a Retailer-level setting that is disabled by default; Retailer controls whether such sharing is enabled for its Suppliers. Retailer acknowledges that Suppliers are not Sub-processors of Carro for purposes of Section 8 of this DPA, and Carro is not liable for a Supplier’s processing of Personal Data after transmission. Retailer authorizes Carro to disclose such Personal Data to Suppliers as described in this Section 2.4, regardless of how Retailer's relationship with the applicable Supplier was established. Carro's disclosures of Personal Data to Suppliers under this Section 2.4 are made in reliance on the foregoing authorization.

2.5. CCPA. To the extent the CCPA/CPRA applies, Retailer is the Business and Carro is the Service Provider with respect to Personal Data. Carro shall provide the same level of privacy protection as required under the CCPA/CPRA. Carro shall notify Retailer if it determines it can no longer meet its obligations under applicable Data Protection Laws. Upon notice to Carro, Retailer shall have the right to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data.

2.6. Sensitive Personal Data. Retailer shall not submit Sensitive Personal Data (including special categories of personal data under GDPR, and sensitive personal information under CCPA/CPRA) to the Services unless expressly agreed in writing by Carro with additional safeguards in place. Carro shall have no liability for Sensitive Personal Data submitted to the Services without such prior written agreement.

2.7. Retailer Obligations. Retailer represents, warrants, and covenants that: (a) its Processing instructions are and will remain lawful; (b) it has provided all required privacy notices and has a lawful basis for Processing Personal Data; (c) it is responsible for the accuracy, quality, and legality of Personal Data submitted to the Services; and (d) it will comply with all applicable Data Protection Laws in connection with its use of the Services.

3. CONFIDENTIALITY. Carro shall treat Personal Data as confidential information and shall ensure that personnel authorized to Process Personal Data are subject to appropriate confidentiality obligations. The confidentiality provisions of the Agreement apply to Personal Data.

4. DATA SUBJECT RIGHTS

4.1. Assistance. Carro shall provide reasonable cooperation and assistance to Retailer in responding to Data Subject rights requests under applicable Data Protection Laws, taking into account the nature of the Processing and the information available to Carro. Carro’s assistance obligations under this Section are limited to what is reasonably practicable given the nature of the Services.

4.2. Direct Requests. If Carro receives a Data Subject rights request directly, Carro will promptly notify Retailer and will not respond to the request unless authorized by Retailer or required by law.

4.3. Regulatory Inquiries. If Carro receives a complaint or inquiry from a supervisory authority relating to Personal Data, Carro will notify Retailer without undue delay to the extent permitted by law.

4.4. Assistance with DPIAs. Taking into account the nature of the Processing and the information available to Carro, Carro shall provide reasonable assistance to Retailer with any data protection impact assessments and prior consultations with supervisory authorities that Retailer is required to undertake under applicable Data Protection Laws in connection with the Services.

5. DELETION AND RETURN OF PERSONAL DATA

5.1. During Term. Retailer may request deletion of specific Personal Data during the term of the Agreement. Carro shall use commercially reasonable efforts to comply within thirty (30) days, except where retention is required by applicable law or necessary to provide the Services.

5.2. Upon Termination. Upon written request following termination or expiration of the Agreement, and unless retention is required by applicable law, Carro shall within thirty (30) days, at Retailer’s election: (a) return Personal Data in a CSV or JSON format (or another commercially reasonable format); or (b) securely delete Personal Data (including copies held by Sub-processors), to the extent technically feasible. Carro is not required to delete Personal Data that resides solely in backup archival systems prior to the ordinary rotation of such systems, provided that such archived Personal Data remains subject to this DPA until deleted. Where full deletion of Personal Data within the timeframe described above is not technically supported by the system in which such Personal Data resides, Carro shall delete such Personal Data as soon as reasonably practicable and shall notify Retailer of the applicable timeline upon request.

6. SECURITY

6.1. Security Measures. Carro shall maintain reasonable technical and organizational measures designed to protect Personal Data against a Security Incident, consistent with the nature and scope of the Processing. Carro may update its security measures from time to time, provided that such updates do not materially reduce the overall level of protection for Personal Data.

6.2. Security Incident Notification. Upon becoming aware of a confirmed Security Incident, Carro shall notify Retailer without undue delay and shall provide, to the extent known, the following: (a) the nature of the Security Incident, including the categories and approximate number of Data Subjects affected; (b) the likely consequences of the Security Incident; and (c) the measures taken or proposed to be taken to address the Security Incident and mitigate its effects. Carro shall provide reasonable assistance to support Retailer’s investigation and mitigation obligations under applicable Data Protection Laws. The timing, content, and manner of any notification to Data Subjects or supervisory authorities shall be Retailer’s responsibility as Controller.

6.3. No Guarantee. Carro does not guarantee that its security measures will prevent all Security Incidents. Retailer is responsible for implementing appropriate security controls on its own systems and for ensuring the secure transmission of Personal Data to the Services.

7. AUDIT RIGHTS

7.1. Information to Demonstrate Compliance. Upon Retailer’s reasonable written request, Carro will make available to Retailer information reasonably necessary to demonstrate its compliance with this DPA, which may include responses to a reasonable security questionnaire and/or a copy or summary of Carro’s then-current third-party audit report(s) or certifications, if any, subject to the confidentiality provisions of the Agreement. Provision of such information shall satisfy Retailer’s audit rights under this Section 7, unless it is materially insufficient to verify Carro’s compliance with this DPA.

7.2. Audits and Inspections. Where the information made available under Section 7.1 is materially insufficient to verify Carro’s compliance with this DPA, or where required by applicable Data Protection Laws, Carro shall allow for and contribute to audits, including inspections, conducted by Retailer or an independent third-party auditor mandated by Retailer. Any such review shall be: (a) conducted by a mutually agreed independent third party bound by confidentiality obligations; (b) conducted during normal business hours with at least thirty (30) days’ prior written notice; (c) limited in scope to matters directly relevant to Carro’s obligations under this DPA; and (d) conducted at Retailer’s cost and expense.

7.3. Frequency. Retailer shall not exercise audit rights under Section 7.2 more than once per calendar year, unless Retailer has reasonable grounds to believe a material Security Incident or breach of this DPA has occurred.

7.4. Confidentiality of Audit. All information provided by Carro in connection with any audit, and all audit findings and reports, shall be treated as Confidential Information under the Agreement.

8. SUB-PROCESSORS

8.1. General Authorization. Retailer provides Carro with general written authorization to engage Sub-processors to Process Personal Data in connection with the Services. A list of Carro’s current Sub-processors may be provided upon reasonable request.

8.2. New Sub-processors. Carro will provide at least thirty (30) days’ prior notice of any new Sub-processor that will Process Personal Data. Carro may provide such notice by email, in-app notification, or other reasonable means.

8.3. Objection. Retailer may object to a new Sub-processor within thirty (30) days of notice, provided that such objection is based on reasonable, documented grounds relating to data protection. If Retailer does not object within this period, the Sub-processor is deemed approved. Retailer acknowledges that certain Sub-processors are essential to the provision of the Services, and that objection may prevent Carro from providing all or part of the Services.

8.4. Resolution. If Retailer reasonably objects and Carro cannot provide a commercially reasonable alternative, either party may terminate the affected Services upon written notice, without liability to the other party in respect of such termination.

8.5. Sub-processor Obligations. Carro shall impose data protection obligations on its Sub-processors that are substantially equivalent to those in this DPA, to the extent applicable to the Sub-processor’s activities. Carro shall remain responsible to Retailer for the performance of Sub-processors’ obligations to the extent caused by Sub-processor acts or omissions.

9. INTERNATIONAL DATA TRANSFERS

9.1. General. Carro processes Personal Data primarily in the United States. Carro's Sub-processors may process Personal Data in other locations. To the extent Retailer (or its affiliates) transfers Personal Data from the European Economic Area (“EEA”), the United Kingdom, or Switzerland to Carro in the United States, the provisions of Annex 4 shall apply.

9.2. Activation. The international transfer provisions in Annex 4 apply only to the extent that Retailer’s use of the Services involves the transfer of Personal Data of individuals located in the EEA, United Kingdom, or Switzerland. Retailer is responsible for notifying Carro if such transfers apply to its use of the Services.

9.3. Alternative Mechanisms. If any transfer mechanism ceases to be valid under applicable law and the parties cannot agree on an alternative, either party may terminate the affected Services upon thirty (30) days’ written notice.

10. LIABILITY

10.1. Agreement Terms Apply. The parties’ respective liabilities under or in connection with this DPA, including any breach of Data Protection Laws, shall be subject to the limitations of liability, exclusions, and disclaimers set forth in the Agreement. Nothing in this DPA increases either Party’s liability beyond the caps set forth in the Agreement.

11. MISCELLANEOUS

11.1. Precedence. In the event of a conflict between this DPA and the Agreement, this DPA shall control solely with respect to the Processing of Personal Data. In the event of a conflict between this DPA and the EU SCCs or UK Addendum (each as defined in Annex 4), the EU SCCs or UK Addendum (as applicable) shall prevail.

11.2. Amendment. Carro may update this DPA from time to time to reflect changes in Data Protection Laws or Carro’s practices, with reasonable notice to Retailer. Material reductions in data protection obligations shall require Retailer’s consent.

11.3. Governing Law. Without prejudice to the mandatory provisions of the EU SCCs or UK Addendum, this DPA shall be governed by the laws and jurisdiction provisions set forth in the Agreement.

11.4. Entire Agreement. This DPA, together with its Annexes and the Agreement, constitutes the entire agreement between the parties with respect to the Processing of Personal Data and supersedes all prior agreements relating to the same subject matter.

11.5. Survival. The obligations in this DPA that by their nature survive termination shall survive expiration or termination of the Agreement.

ANNEX 1: DETAILS OF PROCESSING

A. Roles of the Parties

Data Exporter (Controller): Retailer, as identified in the applicable Order Form or, where none, in Retailer's account.

Data Importer (Processor): GoVyrl, Inc. (dba Carro), 8605 Santa Monica Blvd #379929, West Hollywood, CA 90069-4109. Privacy contact: privacy@getcarro.com.

Activities: Provision of the Services as described in the Agreement, including marketplace enablement, order processing, inventory sync, fulfillment coordination, and platform fee billing.

B. Processing and Transfer Details

Categories of Data Subjects: Retailer's customers (“Consumers”) who place orders through Retailer's platform; Retailer's authorized users and employees who use the Services.

Categories of Personal Data: Consumer data includes name, shipping and billing address, email address, phone number, order details (items, quantities, amounts), order and transaction IDs, and IP address. Retailer user data includes name, email address, job title, company name, account credentials, IP address, one-time passcode and session/refresh tokens, per-company API key, SFTP username and client SSH version, and usage and activity data within the Services. Personal Data may also be processed in connection with customer support interactions, which can include Consumer or Retailer contact information submitted in support communications.

Sensitive Personal Data: None.

Nature of Processing: Automated processing to facilitate order intake, inventory and product data synchronization, order routing to Suppliers, fulfillment tracking, payment processing, and related platform operations as directed by Retailer.

Purposes of Processing: To provide the Services, including enabling Retailer to source products from Suppliers and automate order fulfillment on behalf of Consumers.

Permitted Recipients: Suppliers engaged through the Carro platform receive the Consumer Personal Data reasonably necessary to fulfill orders (such as name, shipping address, order items, and order ID, and, only where Retailer has enabled such sharing as described in Section 2.4, email address and phone number), solely for the purpose of fulfilling orders. Suppliers are not Sub-processors of Carro; see Section 2.4 of this DPA.

Duration of Processing: For the duration of the Agreement, and as required to complete pending order fulfillments.

Retention Period: Personal Data is retained for so long as necessary to provide the Services and to complete any pending order fulfillments. Following termination or expiration, Personal Data is deleted or returned in accordance with Section 5 of this DPA. Live platform data is anonymized after 12 months. Personal Data residing solely in backup archival systems (including MongoDB backups) is retained for up to 12 months, after which it is securely deleted in the ordinary course of backup rotation, subject to the protections of this DPA until deleted.

Location of Processing: United States.

Frequency of Transfer: Continuous and ongoing for the duration of the Agreement.

Transfer Mechanism (EEA/UK/Switzerland): Standard Contractual Clauses (EU) Module 2 (Controller to Processor) and UK Addendum, as set forth in Annex 4. Applies only where Retailer's use of the Services involves Personal Data of individuals in the EEA, UK, or Switzerland.

C. Competent Supervisory Authority

Where the EU SCCs apply, the competent supervisory authority shall be the supervisory authority of the EEA member state in which Retailer (as data exporter) is established, or such other authority as determined in accordance with Clause 13 of the EU SCCs. Where the UK Addendum applies, the Information Commissioner's Office (ICO) shall be the relevant supervisory authority.

ANNEX 2: TECHNICAL AND ORGANIZATIONAL MEASURES

Carro maintains an information security program designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction. Taking into account the nature, scope, context, and purposes of Processing and the sensitivity of the Personal Data, Carro implements and maintains the following technical and organizational measures:

Encryption: Personal Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 encryption across Carro's primary data stores (MongoDB Atlas) and cloud infrastructure (Google Cloud Platform). Account credentials are stored using industry-standard one-way hashing and are never stored in plaintext.

Access Controls: Access to Personal Data is restricted to authorized personnel on a least-privilege, per-company scoped basis. Administrative access to Carro's infrastructure and SFTP access to customer file transfer directories are authenticated through dedicated credentialing and secrets-management systems.

Monitoring and Logging: Carro maintains audit logging of authenticated platform activity and application-level logging across its infrastructure, retained for up to 365 days, to support security monitoring and incident investigation.

Backup and Resilience: Carro's primary data stores and cloud storage operate on multi-region, provider-managed infrastructure with built-in redundancy.

Incident Response: Carro maintains a process for detecting, investigating, and responding to Security Incidents, as further described in Section 6.2 of this DPA.

Sub-processor Oversight: Carro requires its Sub-processors to maintain data protection obligations substantially equivalent to those in this DPA, as further described in Section 8.5.

Internal Engineering Tooling: As an exception to the per-company scoping described under Access Controls, Carro's internal job-processing and queue-management systems may temporarily hold order-related job data in unmasked form, which can include Consumer name, shipping address, and email address. This data is stored within Carro's cloud infrastructure and encrypted at rest as described above. Access to the associated dashboards is limited to Carro engineering personnel who need it to operate and maintain the Services, is authenticated through Carro's credentialing systems, and is subject to confidentiality obligations. Data for successfully completed jobs is removed on completion; data for failed jobs is retained only until the job is resolved or cleared.

ANNEX 3: AUTHORIZED SUB-PROCESSORS

Retailer hereby authorizes Carro to engage the following Sub-processors to Process Personal Data in connection with the Services.

Sub-processorPurpose / ActivityCategories of Personal DataData Subject(s)Location of ProcessingHomepage / DPA (informational)
Google Cloud PlatformCloud infrastructure hosting and database servicesUploaded documents and EDI files (may include end-customer ship-to details); background job dataEnd customer; Business contactUnited StatesHomepage · DPA
Google WorkspaceIdentity provider; internal email and collaboration toolsInternal Carro personnel data onlyNone under this DPA (Carro internal personnel only)United StatesHomepage · DPA
StripeRetailer platform fee billing and Supplier order invoicing. Stripe acts as a Processor for the payment transaction itself, and as an independent Controller for its own fraud prevention, sanctions/KYC, and regulatory reporting obligations.Company name, billing contact email, phone, and addressBusiness contactManaged by StripeHomepage · DPA
SlackInternal team communication and platform alertsEmail addresses, company names and URLs referenced in internal operational notificationsPlatform userManaged by SlackHomepage · DPA
AttioCRM — Retailer business contacts, opportunities, and communicationsBusiness contact names, emails, and company detailsBusiness contactManaged by AttioHomepage · DPA
EasyPostShipping label generation and trackingFull ship-to name, address, and phone number; customs signer name for international shipmentsEnd customer; Business contactManaged by EasyPostHomepage · Legal Center
MailgunTransactional email deliveryRecipient name and email address; packing slip contents (end-customer name and shipping address)End customer; Platform user; Business contactManaged by Mailgun (US region)Homepage · DPA
FrontCustomer support platformRetailer contact name, email, and company name; order-related details submitted in support communications, which can include the Consumer's name and, in some instances, shipping address or contact informationEnd customer; Business contactManaged by FrontHomepage · DPA
MongoDBDatabase servicesCore platform data, including account and company details, order records (name, address, phone, email), invoices, returns, and session dataEnd customer; Platform user; Business contactUnited StatesHomepage · DPA
BalancePayment operationsCompany billing and contact data; buyer billing address; Supplier (vendor) KYB information (beneficial owner identity, tax ID, bank details) — which may include an individual’s personal address where the Supplier is a sole proprietorship or individually-owned businessRetailers and Suppliers, including their personnel, beneficial owners, and sole proprietorsManaged by BalanceHomepage · DPA (on file, not publicly posted)
SegmentProduct analyticsUser identity data (name, email); business contact details submitted during Supplier onboardingPlatform user; Business contactManaged by SegmentHomepage · DPA
SentryError tracking and session replayName, email address, shipping address, and billing details for historical records (retained, not deleted; exports of historical data are masked); Personal Data captured going forward is masked client-side prior to transmission to SentryEnd customer; Platform user; Business contactManaged by SentryHomepage · DPA

Note: Suppliers receive only the Personal Data necessary to fulfill individual orders (e.g., Consumer shipping address and order details, together with, where enabled by the Retailer, email address and phone number) and are independently responsible for their own data protection compliance. Suppliers are not Sub-processors of Carro for purposes of this DPA. Each Supplier is bound by a data protection addendum with Carro that limits its use of this Personal Data to order fulfillment and requires its deletion once no longer needed.

Note: While Front is used primarily for support communications involving Retailer business contacts, Consumer Personal Data may also reach Front where order details are included in support communications. The categories of Personal Data above reflect this.

Note: Balance acts as Carro's Sub-processor only with respect to the invoicing and payout processing activities identified above. Balance separately acts as an independent Controller with respect to processing it undertakes for its own purposes, including Supplier and Retailer onboarding, underwriting, KYC/KYB, AML, risk management, regulatory compliance, and decisions regarding whether to approve or provide Balance services to a Supplier or Retailer. Business information processed in connection with such activities may constitute Personal Data, including where a Supplier is a sole proprietor or individually-owned business. No Consumer/end-customer order data is transmitted to Balance in connection with the invoicing and payout processing described above.

Note: Homepage and DPA links above are provided for Retailer's convenience and reference only. They are not incorporated by reference into this DPA, and Carro's obligations to Retailer with respect to each Sub-processor are governed by Section 8.5 of this DPA regardless of the specific terms of a Sub-processor's own publicly posted DPA. Links reflect information available as of August 2026 and may change without notice.

ANNEX 4: INTERNATIONAL DATA TRANSFERS

A. Application

This Annex 4 applies where Retailer (or its affiliates) transfers Personal Data from the European Economic Area, United Kingdom, or Switzerland to Carro in the United States (each, a “Restricted Transfer”). The provisions of this Annex 4 are modular and are activated only to the extent that Retailer’s use of the Services involves such Restricted Transfers. Retailer is responsible for notifying Carro if Restricted Transfers apply.

B. EU Standard Contractual Clauses

Where Restricted Transfers from the EEA are subject to the GDPR, the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (Commission Implementing Decision 2021/914) (“EU SCCs”) are incorporated by reference into this DPA on the following terms:

ProvisionSelection / Detail
ModuleModule 2 (Controller to Processor) applies. Retailer is the Controller and Carro is the Processor.
Clause 7 (Docking Clause)The optional docking clause shall apply.
Clause 9 (Sub-processors)Option 2 (General written authorization) applies. The notice period for new Sub-processors is as set out in Section 8.2 of this DPA.
Clause 11 (Redress)The optional provision shall not apply.
Clause 13 (Supervisory Authority)The supervisory authority identified in Annex 1, Section C of this DPA shall apply.
Clause 17 (Governing Law)Option 1 applies. The EU SCCs shall be governed by the law of the Republic of Ireland.
Clause 18 (Jurisdiction)The courts of the Republic of Ireland shall have jurisdiction.
Annex ICompleted by reference to Annex 1 of this DPA.
Annex II (TOMs)Completed by reference to Annex 2 of this DPA.
Annex III (Sub-processors)Completed by reference to Annex 3 of this DPA.

C. UK Addendum

Where Restricted Transfers from the United Kingdom are subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner’s Office under S119A(1) of the Data Protection Act 2018 (“UK Addendum”) is incorporated by reference into this DPA on the following terms:

Table / ProvisionSelection
Table 1 (Start Date)The effective date of the Agreement.
Table 1 (Parties)As identified in Annex 1 of this DPA.
Table 2 (EU SCCs)The EU SCCs incorporated in Section B above, with the module and clause selections set out therein.
Table 3 (Appendix Information)As set out in Annexes 1, 2, and 3 of this DPA.
Table 4 (Ending the Addendum)Either party may end the UK Addendum as set out in Section 19 of the UK Addendum.

D. Swiss Transfers

Where Restricted Transfers from Switzerland are subject to the Swiss Federal Act on Data Protection (FADP), the EU SCCs shall apply as modified in accordance with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC), including references to ‘GDPR’ being read as references to the FADP, and the competent supervisory authority being the FDPIC.

E. Conflict

In the event of any conflict between this DPA and the EU SCCs or UK Addendum, the EU SCCs or UK Addendum (as applicable) shall prevail to the extent of that conflict.

F. Alternative Transfer Mechanism

If Carro adopts an alternative data transfer mechanism recognized under applicable Data Protection Laws (such as adequacy decisions or binding corporate rules), that mechanism shall apply in place of the EU SCCs and UK Addendum, and Carro shall notify Retailer accordingly.