GlamPOS Data Processing Addendum

Version 2026-08-25 · Last updated August 25, 2026

This Data Processing Addendum (“DPA”) forms part of the GlamPOS Terms of Service between GLAMRENO LLC d/b/a GlamPOS (“GlamPOS”) and the Business Owner accepting those Terms (“Merchant”). It applies when GlamPOS processes Personal Data on the Merchant's behalf. Capitalized terms not defined here have the meanings in the Terms or applicable privacy law.

1. Roles and instructions

The Merchant is the controller/business and GlamPOS is the processor/service provider for Merchant Data. GlamPOS will process Merchant Data only to provide, secure, support, and improve the contracted Service; on documented instructions supplied through the Service; or as required by law. GlamPOS will notify the Merchant if an instruction appears unlawful unless prohibited from doing so.

2. Processing details

3. Confidentiality and security

GlamPOS will limit access to authorized personnel bound by confidentiality obligations and maintain reasonable administrative, technical, and organizational safeguards appropriate to the risk, including access controls, encryption in transit, credential protection, tenant authorization, logging, backup controls, and vulnerability and incident management. No security program eliminates all risk.

4. Subprocessors

The Merchant generally authorizes the providers on the current Subprocessor List. GlamPOS will impose written data- protection obligations appropriate to each provider and remain responsible for its processing as required by law. Material new subprocessors will be posted to that list at least 15 days before use where practicable. A Merchant may object on reasonable data-protection grounds by contacting GlamPOS during that period; the parties will work toward a reasonable solution.

5. Requests and compliance assistance

Taking account of the nature of processing, GlamPOS will reasonably assist the Merchant with verified individual-rights requests, security assessments, data- protection impact assessments, and regulator inquiries. If GlamPOS receives a request concerning Merchant-controlled data, it may direct the requester to the Merchant unless law requires a direct response.

6. Security incidents

GlamPOS will notify the Merchant without undue delay after confirming a breach of Merchant Data and provide information reasonably available about the nature, affected data and individuals, likely consequences, mitigation, and remediation. Notification is not an admission of fault. The Merchant remains responsible for notices it must provide as controller unless the parties agree otherwise.

7. Return, deletion, and audits

During the subscription, the Merchant may access or export data through available Service features. At termination, GlamPOS will delete or return Merchant Data under the Privacy Policy's timelines unless law requires retention. On reasonable written request no more than annually, GlamPOS will provide information reasonably necessary to demonstrate compliance. Additional audits must protect other customers, security, and confidentiality and may be subject to reasonable cost reimbursement.

8. Transfers and conflicts

GlamPOS primarily processes data in the United States. If law requires a transfer mechanism for another jurisdiction, the parties will use the applicable standard contractual clauses or other lawful mechanism. If this DPA conflicts with the Terms on processing Merchant Data, this DPA controls; otherwise the Terms, including liability provisions, remain in effect.

Contact

GLAMRENO LLC · 3112 Sunset Ave, Atlantic City, NJ 08401 · contact@glamreno.com

Terms · Privacy · Subprocessors