This page summarizes Queeble's standard data processing commitments for merchants and partners evaluating the platform for customer-data workflows.
1. Scope
•This Data Processing Addendum applies when Queeble processes personal data on behalf of a merchant or business customer in connection with the Queeble services.
•For that customer data, the merchant is the controller or business and Queeble acts as a processor or service provider except where applicable law states otherwise.
2. Processing Instructions
•Queeble processes personal data only on documented instructions from the merchant, including instructions reflected in the product configuration, support requests, and applicable service documentation.
•Queeble will not process merchant customer data for unrelated advertising or for sale to third parties.
3. Categories of Data
•Depending on enabled features, Queeble may process names, email addresses, phone numbers, shipping or billing addresses, order records, support conversation content, store data, channel metadata, and associated operational records.
•The categories of data subjects may include merchant staff, store customers, leads, prospects, and end users interacting with enabled channels.
4. Security Measures
•Queeble maintains technical and organizational safeguards designed to protect personal data, including access controls, authentication controls, encryption for sensitive data flows and secrets, audit logging, and service monitoring.
•Access to production data is limited to authorized personnel with a legitimate business need.
5. Subprocessors
•Queeble may use subprocessors for hosting, cloud infrastructure, communication delivery, analytics, support, security, and payment operations.
•Queeble requires subprocessors to protect personal data through written obligations appropriate to the services they provide.
6. Data Subject Requests
•Queeble provides features and reasonable assistance to help merchants respond to access, deletion, correction, export, or restriction requests where required by law.
•If Queeble receives a request directly about merchant-controlled data, Queeble may direct the requester to the relevant merchant unless legally required to respond otherwise.
7. Incident Notification
•If Queeble confirms a security incident affecting merchant customer data, Queeble will investigate, contain, and remediate the issue and notify the affected merchant without undue delay, subject to legal and operational constraints.
•Notifications may include the nature of the incident, affected data categories, known impact, and available remediation steps.
8. International Transfers
•Where cross-border transfers occur, Queeble applies safeguards available under applicable law, including contractual protections where appropriate.
9. Return and Deletion
•Upon termination or deletion of the services, Queeble will delete or return personal data in accordance with the service terms, retention schedule, merchant instructions, and legal obligations.
•Backup, security, billing, and compliance records may be retained for limited periods where required for legitimate business or legal purposes.
10. Contact
•For DPA execution requests or vendor reviews, contact legal@queeble.com.