Data Processing Addendum
Last updated: April 17, 2026
In plain English
This DPA attaches to the Terms of Service. It explains the roles of the parties, lists our sub-processors, and commits Weedus to industry-standard security. Sign and return a countersigned copy by emailing us.
1. Roles of the parties
For any personal information contained in Customer Data, Customer is the “controller” and Weedus is the “processor” (as those terms are defined under applicable data protection laws such as the GDPR, the UK GDPR, and the California Consumer Privacy Act). Weedus processes personal information solely to provide the service and on Customer's documented instructions.
2. Scope and duration
This DPA applies for as long as Weedus processes personal information on Customer's behalf under the Terms of Service. It automatically terminates when the underlying agreement terminates.
3. Categories of data and data subjects
Categories of data subjects: Customer's employees and contractors who are authorized users of the Weedus platform, and Customer's trading partners (vendors or retailers) whose business-contact information appears in orders, deliveries, or invoices.
Categories of personal information: name, business email address, business phone number, work location, team role and permissions, authentication metadata, and service telemetry (IP/user-agent).
4. Sub-processors
Customer authorizes Weedus to engage the sub-processors listed below. We will notify Customer at least 30 days before engaging a new sub-processor by posting to this page. Customer may object in writing; if we cannot reasonably accommodate the objection, either party may terminate the affected portion of the service.
Current sub-processors:
- Stripe, Inc. - payments and billing (United States).
- SendGrid (Twilio, Inc.) - transactional and marketing email (United States).
- Google Cloud Storage - file and image storage (United States).
- DigitalOcean, LLC - application and database hosting (United States).
- POSaBIT, Inc. - only when Customer has enabled inventory sync (United States).
5. Security measures
Weedus implements technical and organizational measures consistent with industry practice for B2B SaaS, including: TLS 1.2+ in transit; AES-256 at rest; role-based access controls for the engineering team; separation of production and non-production environments; encrypted backups; incident-response runbooks; annual internal security review.
6. Incident notification
Weedus will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, the likely impact, and the steps taken or proposed.
7. Cross-border transfers
Customer Data is stored and processed primarily in the United States. To the extent Weedus transfers personal information from the EEA, the UK, or Switzerland to a jurisdiction that is not the subject of an adequacy decision, the Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum) apply and are incorporated by reference into this DPA.
8. Audits
Weedus will make available to Customer, on reasonable written request, the information necessary to demonstrate compliance with this DPA. Where a formal audit is legally required, the parties will agree on scope, timing, and a commercially reasonable cost allocation in advance.
9. Return or deletion
On termination of the underlying agreement, Weedus will make Customer Data available for export for 30 days and, unless legally required to retain it, delete or anonymize it thereafter.
10. Countersigning
Customers who need a countersigned DPA on file can email hello@weedus.app and we will return a signed copy within 2 business days.