Legal

Data Processing Agreement

Version 28 September 2026. In force from that date.

This Data Processing Agreement applies when 5wire Networks Ltd, trading as Ottom ("Ottom", "we") handles personal data on behalf of a customer ("you") while providing Ottom. It forms part of the Terms of Service and applies automatically, without a signature. It sets out the terms UK data protection law requires between a controller and its processor.

1. Scope and roles

This agreement covers Customer Personal Data: personal data that you give us, or that we collect on your behalf, in order to provide Ottom to you. Annex 1 describes it. For Customer Personal Data you are the controller and we are your processor. If you use Ottom for a client, for example as an agency, you may be acting as a processor yourself, and we are then your subprocessor on the same terms.

It does not cover personal data we handle for our own purposes, such as your account, billing, security records, marketing and our benchmark study. We are the controller of that, and our Privacy Policy describes it.

Data Protection Law means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations and, where it applies to you, the EU GDPR. Words such as controller, processor, personal data breach and data subject have the meanings those laws give them.

2. Your instructions

We process Customer Personal Data only on your documented instructions. Those are the Terms of Service, this agreement, the way you configure and use Ottom, and any other written instruction we agree. We will tell you if we think an instruction breaks Data Protection Law. If the law requires us to process the data some other way, we will tell you first unless the law forbids it.

You are responsible for having a lawful basis for the processing you ask us to do, and for the notices you give the people concerned.

3. Confidentiality

Everyone we authorise to process Customer Personal Data is bound to keep it confidential, and has access only as far as their work requires.

4. Security

We maintain the technical and organisational measures in Annex 2, which are designed to give a level of security appropriate to the risk. We may improve them over time but will not reduce the overall level of protection.

5. Subprocessors

You give us general authorisation to use the subprocessors on our subprocessors page. We put each one under written terms that protect Customer Personal Data at least as well as this agreement, and we remain responsible to you for what they do.

We email the owners of paying accounts at least 30 days before a new subprocessor starts processing Customer Personal Data. If you object on reasonable data protection grounds, write to [email protected] before the change. If we cannot resolve it, you may end the affected plan before the change and we will refund what you prepaid for time after it ends.

6. Transfers outside the UK

We host Customer Personal Data in the United Kingdom. Some subprocessors process it elsewhere, as the subprocessors page shows. Every such transfer relies on UK adequacy regulations, the UK Extension to the EU US Data Privacy Framework, or the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, together with any further measures the transfer needs.

If the EU GDPR applies to your transfer of Customer Personal Data to us, it relies on the European Commission's adequacy decision for the United Kingdom while one is in force, and otherwise on the standard contractual clauses, which we will enter into on request.

7. Helping you meet your obligations

  • If a person asks us directly to exercise their rights over Customer Personal Data, we pass the request to you and do not answer it ourselves unless you ask us to.
  • Taking into account what Ottom does, we help you answer such requests. Much of it you can do yourself: remove a member, cancel an invitation, change who receives alerts and reports, delete stores, and download or delete your account.
  • We give you the information you reasonably need for a data protection impact assessment or a consultation with a regulator about Ottom.

8. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will tell you without undue delay and in any case within 48 hours. We will describe what happened, the data and people likely to be affected, the likely consequences and what we are doing about it, as far as we know at the time, and keep you updated as we learn more. We send the notice to the owner of your account. Telling you is not an admission of fault.

9. Deleting or returning data

You can download your data at any time from your account settings. When our contract ends, or when you delete your account, we delete or anonymise Customer Personal Data within 30 days, unless the law requires us to keep it. Copies in our backups are deleted as the backups expire, on the schedule in Annex 2.

10. Information and audits

We make available the information you reasonably need to show that we meet this agreement. Once a year, on request, we answer a reasonable security questionnaire and provide a summary of our security measures.

An inspection, by you or by an independent auditor bound to confidentiality, is available to customers on an enterprise contract, on at least 30 days written notice, during business hours, no more than once a year and at your cost. It is available to any customer when a regulator requires it or after a personal data breach affecting your data. An audit must not give access to other customers’ data.

11. Liability and precedence

Each party’s liability under this agreement is subject to the limits in the Terms of Service. For Customer Personal Data, this agreement takes precedence over the Terms of Service; an enterprise order form takes precedence over both. It lasts for as long as we process Customer Personal Data.

12. Annex 1: details of the processing

ItemDetails
Subject matterProviding Ottom to you under the Terms of Service
DurationThe term of the contract, plus the time it takes to delete or anonymise the data afterwards
Nature of the processingStoring, organising, retrieving, displaying and sending data; visiting your storefront with automated agents and recording what they see; sending reports and alerts
PurposeTo scan and monitor your storefronts, produce reports, run your workspaces and deliver reports and alerts where you direct
People the data is aboutYour staff and contractors; people you invite to a workspace; people you share reports with or send alerts to; people who appear on your own storefront pages, such as reviewers or staff
Kinds of personal dataNames, email addresses and workspace roles; alert destinations; passwords for protected storefronts you give us; and any personal data that appears in screenshots and page recordings of your storefront
Special category dataNone is intended. Do not put special category data on the pages we scan for you, or send it to us

13. Annex 2: security measures

Hosting and network

  • Servers in the United Kingdom, run by us.
  • Web traffic reaches our servers only through Cloudflare; the firewall refuses every other inbound connection. Administrative access to servers is only over an encrypted private network, never exposed to the internet.
  • All traffic to and from the website is encrypted with TLS.

Access

  • Our staff tools sit behind Cloudflare Access, which requires multi-factor sign-in, and an allowlist of staff addresses.
  • Every action staff take in those tools, including viewing an account as its owner sees it, is written to an audit log that cannot be edited.
  • Customers can protect their accounts with an authenticator app or a passkey. Workspace roles limit who can invite people, manage stores and change billing.

Data

  • Passwords are hashed with scrypt; sign-in links, sessions and API tokens are stored only as hashes.
  • Storefront passwords and Shopify access tokens are encrypted with AES-256-GCM.
  • Error reports have request bodies, cookies, email and IP addresses removed before they leave our servers.
  • Page recordings are deleted after 60 days (365 on an enterprise contract), and other data on the schedule in the Privacy Policy.

Resilience

  • The database is backed up daily. Backups are encrypted and held off-site in the United Kingdom for 30 days, and restoring from them is tested.
  • We monitor the service and are alerted to failures, and publish incidents on our status page.

14. Annex 3: subprocessors

The subprocessors authorised under this agreement are those on our subprocessors page at any given time, with the dated record of changes kept there.

Version history

  • 28 September 2026 (in force): Held: do not publish until the off-site backup that Annex 2 describes has been tested (ROADMAP, 22 Sep 2026, item 14).