Data Sharing Addendum (Controller-to-Controller)
Platform Operator (HK): LOTOFJEWELRY LIMITED, CR No.: 78809321-000-09-25-8.
Registered Address: RM 5058, 5/F YAU LEE CENTRE, 45 HOI YUEN RD, KWUN TONG, HONG KONG
Operations Center (Thailand): 919/1 Si Lom Rd, Si Lom, Bang Rak, Bangkok 10500, Thailand
Contacts: info@lotofjewelry.com | Phone: +66 80 713 0700
1. Roles & Interpretation
Parties act as independent controllers for personal data exchanged via the Platform for order fulfilment, unless agreed otherwise in writing.
2. Purpose & Lawful Basis
Seller processes data to: fulfil orders; warranty/returns; statutory accounting; respond to lawful requests; prevent fraud. Bases: contract, legal obligation, legitimate interests. Marketing/profiling requires proper legal basis and explicit consent where required.
3. Data Scope
Identity/contact data, shipping/billing addresses, order details, order communications, transaction identifiers (no payment card data if processed by a PSP).
4. Security & Confidentiality
Appropriate TOMs: encryption in transit, MFA & least privilege, logging, backups, secure development and vulnerability management. Personnel under confidentiality and training.
5. Data Subject Rights
Each Party handles rights requests for its processing; Parties reasonably assist each other for shared data requests.
6. Personal Data Breach
Notify the other Party without undue delay (preferably within 48 hours) about any breach affecting shared data with sufficient details for assessment and notifications.
7. International Transfers
Use EU 2021/914 SCCs — Module 1 (Controller↔Controller) and/or UK IDTA/UK Addendum; include transfer impact assessment and supplementary measures as necessary. Incorporated by reference.
8. Retention & Deletion
Retain only as necessary for clause 2 and statutory retention; thereafter delete/anonymize. Delete on Platform request where law permits.
9. Sub-recipients / Processors
As independent controllers, each Party remains responsible for its processors and contracts ensuring GDPR-level protections.
10. Audit & Assurance
On reasonable notice, Seller provides information on TOMs/policies and relevant attestations without exposing trade secrets.
11. Liability & Indemnity
Each Party is liable to data subjects for its processing. Between Parties, liability is governed by the Main B2B Agreement.
12. Term & Signatures
Effective date: [●]
Platform Signature: __________________ Name/Title: __________________ Date: ____
Seller Signature: _____________________ Name/Title: __________________ Date: ____