Data processing agreement
Know what is used, why it is needed and how to stay in control.
Who operates WakeMyCart?
- Legal entity
- A.M.E.X. Internet Marketing ltd
- Business address
- Makariou III, No.9, Larnaca, 7530, Cyprus
- Country of establishment
- Cyprus
- Registration and VAT details
- Company registration HE 377934. VAT registration 10377934Z.
- Support
- support@wakemycart.com
- Privacy contact
- support@wakemycart.com
- Data protection contact
- For privacy enquiries, email support@wakemycart.com or write to the company address above. Include WakeMyCart in your subject.
Agreement status and acceptance
Draft for operator and merchant review. It is not an executed agreement. Complete the parties, provider register, security arrangements and retention/exit details before processing personal data within this agreement’s scope.
Before processing, identify the merchant’s legal entity and authorised contact in the completed agreement and link it to the account and connected stores. The store configuration records local operational instructions. Review whether a processor relationship applies to each actual service; installing local software does not itself transfer shopper records to the operator. An agency must confirm whether it is the controller or acts as a processor for a client, and supply the client’s authorisation and instructions before using the service.
1. Parties, scope and instructions
The merchant identified in its service account is the controller of its shoppers’ recovery information. The operator identified in the legal notice acts as processor only where it actually processes merchant-controlled personal data, such as retained legacy recovery records, requested migration assistance or support material. Current Free and Pro run recovery processing on the merchant’s WordPress installation and send messages directly through the merchant’s chosen email provider. Those providers require the merchant’s own applicable arrangements. The operator separately controls account administration and security as described in the privacy notice. This agreement covers the processing actually ordered for the duration of that processing and the agreed return/deletion period. The processor acts only on documented merchant instructions, including configuration and lawful instructions about international transfers, unless law requires otherwise. It informs the merchant of a conflicting legal requirement where legally permitted and immediately flags an instruction it considers unlawful.
2. Processing details
For existing cloud-engine stores, the transitional scope is secure return of historical recovery data, reconciliation of sending state, a temporary relay for previously issued links and delivery feedback, and reviewed deletion of former cloud copies. Where specifically requested, support may include merchant-supplied records. Data may include shopper email, name, cart/product details, consent, message history, orders/refunds and recovery identifiers. In the normal local engine these records, rules, tokens and experiments remain in WordPress; connecting an account is optional for Free. Connected installations send store/installation details, licence and update requests, software versions and basic health status to the account service. Current Free and Pro plugins do not report aggregate contact usage. The merchant’s mail provider receives recipient and message contents directly. Special-category data is not requested; avoid unnecessary sensitive descriptions and checkout fields.
3. Confidentiality and security
The processor limits access to authorised people bound by confidentiality and maintains measures appropriate to risk. The security annex includes HTTPS transport, signed store requests with replay checks, scoped access, hashed passwords and session tokens, encrypted connection secrets and MFA material, and revocable sessions. Hosting access, encrypted backups, restoration tests, monitoring, patching and staff procedures must be confirmed for the deployed service in the operator’s security record. No certification or absolute security guarantee is implied.
4. Subprocessors and transfers
The merchant gives general written authorisation to the completed subprocessor register incorporated into this agreement. The processor gives at least 30 days’ prior written notice of an intended addition or replacement, with an opportunity to object on data-protection grounds before use. The parties seek a workable alternative; if none is available, the merchant may stop the affected service and obtain return/deletion of its data. Equivalent written protections bind each subprocessor; the processor remains responsible for its obligations. Transfers outside the EEA require an applicable lawful mechanism and any necessary assessment and supplementary safeguards, recorded in the register. This agreement is not itself a transfer mechanism.
5. Rights and assessment assistance
Taking account of the processing and information available, the processor assists the merchant with access, correction, erasure, restriction, objection, portability and applicable automated-decision requests. It forwards shopper requests received directly to the relevant merchant without deciding them independently, except as instructed or legally required. It also assists with security obligations, impact assessments and prior consultation where required.
6. Personal data breaches
The processor notifies the merchant without undue delay after becoming aware of a personal data breach. Available information includes what happened, affected data and people, likely consequences, response measures and a contact point; updates follow as facts emerge. The processor preserves relevant evidence and assists the merchant’s notification assessment. The merchant remains responsible for its controller decisions and statutory deadlines.
7. Return, deletion and retention
At the merchant’s choice on ending the service, the processor returns or deletes personal data and deletes existing copies unless applicable law requires retention. The parties record the return format, timing, backup expiry and any lawful retention before termination. The published retention inventory governs routine processing; it does not override a valid earlier erasure instruction. The operator coordinates deletion of its own copies and contracted-provider copies within this scope. The merchant separately manages WordPress records, backups and its chosen sending provider; deleting an account registration does not delete that local database. Any necessary suppression or legal-hold exception is explained and minimised.
8. Evidence, audit and changes
The processor makes information needed to demonstrate these obligations available to the merchant and contributes to audits and inspections by the merchant or its appointed auditor, with proportionate arrangements protecting other customers’ data. No arrangement removes a supervisory authority’s powers or blocks an urgent justified audit. Material changes are notified to the merchant and recorded in an updated agreement. For conflicts about processing obligations, this agreement takes precedence over the general service terms.
Operational annexes
Subprocessor register and transfer arrangements · Data and retention inventory · Application security measures · Rights and deletion procedure
Backup and return/deletion arrangements: To be confirmed by the service operator before public launch.
Privacy and incident contact: support@wakemycart.com
Governing law: To be confirmed by the service operator before public launch. Mandatory data-protection rights and regulator powers remain unaffected.