Data processing agreement
Last updated September 24, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Cambium Group LLC, an Ohio limited liability company (“Cambium Group”, “Processor”), and the customer that accepts the Terms of Service or signs an Order (“Customer”, “Controller”) for the Cambium platform and related services (the “Agreement”). If this DPA and the Agreement conflict on personal data, this DPA controls.
1. Definitions
“Personal Data” means information in Customer Data that relates to an identified or identifiable person. “Processing”, “Controller”, “Processor”, “Data Subject”, and “Personal Data Breach” have the meanings given in applicable data protection law (“Data Protection Law”), including the California Consumer Privacy Act, other U.S. state privacy laws, and, where they apply, the GDPR and the UK GDPR. “Subprocessor” means a third party that Cambium Group engages to process Personal Data.
2. Roles and instructions
Customer is the Controller, and Cambium Group is the Processor (and a “service provider” under the CCPA). Cambium Group processes Personal Data only on Customer’s documented instructions. The Agreement, this DPA, and Customer’s use and configuration of the services are Customer’s complete instructions. Cambium Group will tell Customer if it believes an instruction violates Data Protection Law.
3. Details of the processing (Annex 1)
| Item | Detail |
|---|---|
| Subject matter | Providing the Cambium platform analytics services to Customer |
| Duration | The term of the Agreement, plus the deletion period in section 11 |
| Purpose | Combining Customer’s connected sources; measuring marketing and sales performance; matching orders to customers; producing Customer’s reports, monitoring, and recommendations; when Customer turns it on, sending conversion, profit, and predicted customer-value data to Customer’s own advertising accounts for conversion matching; securing and supporting the services |
| Data Subjects | Customer’s customers and prospective customers; Customer’s users of the platform |
| Categories of Personal Data | Name, email address, phone number, and billing and shipping address on commerce records; order and purchase history; pseudonymous identifiers from Customer’s ad, analytics, and pixel sources (such as device, cookie, and click identifiers); IP address and browser user agent; platform user name and email |
| Sensitive data | None. Cambium Group does not process payment card numbers, government identifiers, health, biometric, or other special-category data |
| Frequency | Continuous, while the services are active |
4. CCPA terms
Cambium Group will not: sell Personal Data, or share it except as Customer directs under this section; retain, use, or disclose it for any purpose other than the business purposes in Annex 1, or outside the direct business relationship with Customer; or combine it with personal information from other sources, except as the CCPA permits for service providers. Cambium Group will comply with the CCPA obligations that apply to it, and will notify Customer if it can no longer meet them. Customer may take reasonable steps to stop unauthorized use of Personal Data.
At Customer’s direction, Cambium Group sends Personal Data to Customer’s own advertising platform accounts for conversion matching, hashed wherever the platform requires it, and only when the consent and opt-out state Cambium Group receives for the Data Subject permits it. Customer controls that disclosure and is responsible for its lawful basis, for its notices and opt-out choices, and for its agreements with those platforms. Those platforms are Customer’s recipients, not Subprocessors.
5. Confidentiality of personnel
Cambium Group limits access to Personal Data to personnel who need it to provide the services, and binds them to confidentiality.
6. Security
Cambium Group implements the measures in Annex 2, which are appropriate to the risk. Cambium Group may update them if the overall level of protection does not decrease.
7. Subprocessors
Customer authorizes the Subprocessors in Annex 3. Cambium Group will give Customer at least 30 days’ notice before a new Subprocessor processes Personal Data. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected services and receive a pro-rata refund of prepaid fees for them, as its sole remedy. Cambium Group imposes data protection terms on each Subprocessor that are no less protective than this DPA, and remains responsible for its Subprocessors’ performance.
8. Data Subject requests
Cambium Group will, taking into account the nature of the processing, help Customer respond to Data Subject requests. If Cambium Group receives a request directly, it will refer the requester to Customer. Cambium Group records each Shopify customer data request, customer redaction request, and shop redaction request, and completes it within 30 days.
9. Personal Data Breach
Cambium Group will notify Customer without undue delay after it becomes aware of a Personal Data Breach that affects Customer’s Personal Data. The notice will describe, as far as known, the nature of the breach, the data and Data Subjects involved, the likely consequences, and the measures taken or proposed. Cambium Group will update the notice as facts are confirmed, and will take reasonable steps to contain and remedy the breach. Notice is not an admission of fault or liability.
10. Assistance and audits
Cambium Group will give Customer the information reasonably needed to show compliance with this DPA and to complete data protection impact assessments. Customer may audit Cambium Group’s compliance once in any 12 months, on at least 30 days’ notice, during business hours, at Customer’s cost, and under confidentiality, by first reviewing Cambium Group’s written answers and documentation. An on-site audit is available only where Data Protection Law requires it or after a Personal Data Breach.
11. Return and deletion
At the end of the Agreement, Cambium Group deletes Customer’s Personal Data within 30 days, unless Customer asks in writing before the end for an export of its data, or law requires Cambium Group to keep it. Backups expire on their normal cycle and are not restored except for recovery.
12. International transfers
Cambium Group processes Personal Data in the United States. Where Data Protection Law requires a transfer mechanism, the parties agree that the standard contractual clauses (and the UK addendum, where it applies) are incorporated by reference, with Customer as exporter and Cambium Group as importer.
13. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
14. Customer obligations
Customer is responsible for having all notices, consents, and legal bases required to provide Personal Data to Cambium Group and to instruct its processing, including any disclosure to advertising platforms that Customer directs, and for the accuracy of the Personal Data it provides.
Annex 2: Security measures
- Encryption in transit (TLS) and at rest, including backups.
- A separate, isolated dataset and service identity for each customer; typed tenant scoping in code and row-level security in the application database.
- Store credentials kept only in a secret manager, referenced by version, never stored in the database.
- Staff access by role and per-customer grant; single sign-on with enforced 2-step verification.
- Automation runs as service accounts, not personal logins.
- Access logging of platform requests and cloud audit logs.
- Read-only access to connected commerce systems.
- Consent checks in the storefront pixel before any event is sent.
- A written security incident response policy.
- Backups with point-in-time recovery for the application database.
Annex 3: Subprocessors
Cloud infrastructure providers that host and operate the Cambium platform (hosting, data storage, and workflow scheduling), in the United States. Cambium Group gives Customer the current list on request, and notifies Customer under section 7 before a new Subprocessor processes Personal Data.