# Navigating E-Commerce through Uncertainty

## Northbeam + Shipbob + Logical Position 2025 Outlook on Tariffs, TikTok, & Consumer Trends

## Data Processing Addendum.

#### Last modified: **April 17, 2026**

THIS DATA PROCESSING ADDENDUM (“**DPA**”) is entered into and forms part of the Customer Agreement (the “**Agreement**”) between the customer or partner identified under the applicable ordering document (“**Customer**”), and North Beam, Inc., a Delaware corporation (“**Provider**”), together the “**Parties**” and each a “**Party**”.

## 1. Definitions

- **Affiliate**: Any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.
- **Applicable Data Protection Laws**: Privacy, data protection and data security laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including GDPR and CCPA.
- **CCPA**: California Consumer Privacy Act of 2018, amended by the California Privacy Rights Act of 2020 (CPRA).
- **Controller**: Natural or legal person that determines the purposes and means of Processing Personal Data.
- **Customer Personal Data**: Any Personal Data pertaining to users of Customer’s websites or online services that Customer provides to Provider for Processing.
- **Data Subject**: Identified or identifiable natural person to whom Customer Personal Data relates.
- **Personal Data**: Refers to personally identifiable information defined under Applicable Data Protection Laws.
- **Processor**: Natural or legal person that Processes Personal Data on behalf of the Controller.

## 2. Scope of this data processing addendum

1. **2.1** The Parties acknowledge that the details of Provider’s Processing of Customer Personal Data are described in Annex 1 (Data Processing Details).
2. **2.2** Annex 2 applies to Provider’s Processing of Customer Personal Data that is subject to the GDPR.
3. **2.3** Annex 3 applies to Provider’s Processing of Customer Personal Data subject to the CCPA.
4. **2.4** This DPA applies to Provider’s Processing of Customer Personal Data under any requirements of Applicable Data Protection Laws.

## 3. Processing of customer personal data

- **3.1** Provider will Process Customer Personal Data as a Processor only: (i) in accordance with Customer Instructions or (ii) to comply with Provider’s obligations under applicable laws.
- **3.2** “**Customer Instructions**” refers to Processing to provide the Service and other reasonable documented instructions of Customer consistent with the terms of the Agreement.
- **3.3** The Parties acknowledge that Provider’s authorized Processing of Customer Personal Data is integral to the Services and the business relationship between the Parties.

## 4. Vendor personnel

Provider shall ensure that all Provider employees or personnel that Process Customer Personal Data are subject to obligations of confidentiality regarding such data.

## 5. Security

- **5.1** Provider shall implement and maintain measures designed to protect the confidentiality, integrity, and availability of Customer Personal Data.
- **5.2** Customer is responsible for reviewing security information provided by Provider.

## 6. Data subject requests

- **6.1** Provider shall provide Customer with assistance as may be reasonably requested to respond to Data Subject Requests.
- **6.2** Provider will notify Customer promptly if it receives a Data Subject Request.

## 7. Personal Data Breaches

- **7.1** Provider shall notify Customer of a Personal Data Breach without undue delay after becoming aware of it.
- **7.2** If a Personal Data Breach must be notified to any authority, Customer agrees to notify Provider in advance.

## 8. Sub-processing

- **8.1** Customer generally authorizes Provider to appoint Subprocessors.
- **8.2** Provider will enter into written contracts with Subprocessors containing data protection obligations.
- **8.3** Provider’s current list of Subprocessors is available on Northbeam's website.

## 9. Compliance assistance; Audits

- **9.1** Provider shall provide information to help Customer meet its obligations under Applicable Data Protection Laws.
- **9.2** Customer may conduct audits at its own cost, with reasonable advance notice.
- **9.3** Customer must give reasonable advance notice of any audits.

## 10. Return and deletion

- **10.1** Upon termination of the Agreement, Provider shall return or delete Customer Personal Data upon Customer’s request.
- **10.2** Provider may retain Customer Personal Data where required by law.

## 11. Customer Responsibilities

- **11.1** Customer is responsible for its use of the Services.
- **11.2** Customer shall ensure that there is a valid legal basis for Provider’s Processing of Customer Personal Data.

## 12. Precedence

In the event of any conflict, this DPA shall prevail.

## Annex 1 - Data Processing Details  
- **CUSTOMER / ‘DATA EXPORTER’ DETAILS**  
  - **Name**: As set out in the Agreement  
  - **Contact details for data protection**: As set out in the Agreement  
  - **Customer Activities**: Provider of ecommerce websites/services  
  - **Role**: Controller

- **PROVIDER / ‘DATA IMPORTER’ DETAILS**  
  - **Name**: North Beam, Inc.  
  - **Contact details for data protection**: compliance@northbeam.io  
  - **Provider Activities**: Provider of a software-as-a-service analytics platform  
  - **Role**: Processor

- **DETAILS OF PROCESSING**  
  - **Categories of Data Subjects**: Users of Customer’s websites  
  - **Categories of Personal Data**: Personal Data pertaining to user interaction with Customer’s websites  
  - **Nature of the Processing**: Provide ecommerce analytics services  
  - **Purpose of the Processing**: Provide ecommerce analytics services  
  - **Duration of Processing / Retention Period:** Concurrent with term of the Agreement.

## Annex 2 - European Annex

### 1 RESTRICTED TRANSFERS

- **1.1 General.** The Parties acknowledge that Customer’s transmission of Customer Personal Data may involve a Restricted Transfer.

- **1.2 EU Restricted Transfers.** The Parties shall comply with obligations set out in the SCCs as required.

### 2 OPERATIONAL CLARIFICATIONS

- **2.1** Customer agrees to protect Provider’s and its licensors’ trade secrets.

### 3. LIABILITY TO DATA SUBJECTS

Nothing in the Agreement shall limit either party’s liability to Data Subjects under the third party beneficiary provisions of the SCCs.

## Annex 3 - CALIFORNIA ANNEX

- **1.** Capitalized terms used in this California Annex shall have the meanings given in the CCPA.
- **2.** Provider is a Service Provider and shall comply with obligations under the CCPA.
