Liquor OS Data Processing Addendum
Last updated: October 3, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service (or any written agreement) between you, the customer ("Customer"), and InStoreAdvisor Inc. ("Liquor OS", "we") for the Liquor OS service. It applies whenever we process personal data on Customer's behalf. It needs no signature; if your organization needs a countersigned copy, email support@get-creative.co.
1. Definitions
"Data protection law" means every privacy and data protection law that applies to the processing, including the EU and UK General Data Protection Regulations (GDPR), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act (CCPA) and other US state privacy laws. "Customer personal data" means personal data that Customer or its users put into Liquor OS, or that Liquor OS collects for Customer from Customer's own customers. "Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings given in the GDPR; "service provider" and "business" have the meanings given in the CCPA.
2. Roles
Customer is the controller (or "business") of Customer personal data, and we are its processor (or "service provider"). We process Customer personal data only to provide, support and secure Liquor OS for Customer, on Customer's documented instructions. The Terms of Service, Customer's configuration of Liquor OS and this DPA are those instructions. We tell Customer if we believe an instruction breaks data protection law.
3. What we process
| Subject matter and duration | Providing Liquor OS, for as long as Customer uses it and the return or deletion period after |
| Nature and purpose | Hosting, storing, organizing, analyzing and transmitting data, including with AI features, to deliver the service Customer configures |
| Data subjects | The store's owners and staff; people who text, call, chat with or email the store; people who review the store |
| Personal data | Names people give, phone numbers, email addresses, message and call content, call recordings, public reviews and replies, opt-out records |
| Special categories | Not intended. Customer will not put special category data, government ID numbers or payment card numbers into Liquor OS except through the payment provider's own forms |
4. Our commitments
We will:
- process Customer personal data only for the purposes in section 3, and never sell it, share it for cross-context behavioral advertising, or combine it with personal data from other sources except as data protection law allows a service provider to;
- make sure everyone who can access it is bound to confidentiality;
- apply the security measures in section 9;
- help Customer answer data subjects' requests, through the features of Liquor OS and, where they aren't enough, by assisting on request;
- help Customer with data protection impact assessments and consultations with regulators where they relate to Liquor OS;
- tell Customer without undue delay, and within 72 hours, after we become aware of a personal data breach affecting Customer personal data, with the information Customer needs to meet its own obligations;
- at the end of the service, delete Customer personal data within 30 days after the export window in the Terms of Service, unless the law requires us to keep it (encrypted backups are covered in our Privacy Policy);
- make available the information needed to show we comply with this DPA, and allow audits as described in section 8.
5. Customer's commitments
Customer is responsible for having a lawful basis for the processing, for giving people the notices and obtaining the consents the law requires (including consent to receive texts and calls), and for the accuracy of the data it provides.
6. Subprocessors
Customer authorizes us to use the subprocessors listed in Service Providers and Subprocessors. We bind each one by contract to data protection terms that protect Customer personal data at least as well as this DPA, and we remain responsible for them. We will give at least 30 days' notice of a new subprocessor by updating that page and, for customers who ask to be notified, by email. Customer may object on reasonable data protection grounds; if we cannot address the objection, Customer may end the affected service and receive a refund of prepaid fees for it.
7. International transfers
Customer personal data may be processed in the United States and Germany, and by subprocessors in the countries listed. Where data protection law requires a transfer safeguard for data from the European Economic Area, the UK or Switzerland, the parties agree to the European Commission's Standard Contractual Clauses (Module 2, controller to processor, or Module 3 where Customer is itself a processor), with the UK International Data Transfer Addendum and Swiss amendments where they apply. For those clauses: Customer is the data exporter, we are the data importer, the optional docking clause applies, the supervisory authority is the one competent for Customer, the governing law and courts are those of Ireland, and Annexes I to III are completed by sections 3, 6 and 9 of this DPA.
8. Audits
Once a year, or after a breach, Customer may ask us written questions about our compliance, and we will answer them. If those answers are not enough, Customer may audit, at its own cost, with at least 30 days' notice, during business hours, under confidentiality and in a way that does not reveal other customers' data.
9. Security measures
- Encryption: data is encrypted in transit over HTTPS. Backups are encrypted.
- Separation: each customer's data is kept apart by access rules enforced in the database.
- Access: our team's access is limited to the people who need it, uses individual accounts, and access to sensitive records is logged.
- Resilience: daily backups are stored in a separate cloud provider, and restores are tested monthly.
- Monitoring: errors and unusual activity are monitored, and security issues are tracked to resolution.
- AI safeguards: information sent to AI model providers is limited to what a feature needs, and the providers process it to return the result.
- People: team members are bound to confidentiality.
10. Order of precedence and liability
If this DPA conflicts with the Terms of Service about personal data, this DPA governs. Liability under this DPA is subject to the limits in the Terms of Service, except where data protection law does not allow it.
Contact
- Email: support@get-creative.co
- Mail: InStoreAdvisor Inc., Attn: Privacy, 4465 E Genesee St., Syracuse, New York 13214, United States
We answer every message, normally within a few working days.