Data Processing Addendum

Article 28 processing terms

Version 1.0 · 1 September 2026

These terms apply with the ComeSeeBuy B2B service agreement whenever a customer entrusts personal data to ComeSeeBuy for processing on its behalf.

1. Parties and roles

The merchant is the controller and ComeSeeBuy is the processor, operated by UAB „Verslo titanas“, for merchant-buyer and other merchant-instructed data. ComeSeeBuy remains a separate controller for its own account, security, billing and legal records.

2. Processing details

Processing lasts for the service term and the limited deletion or lawful-retention period that follows. Its purpose is to receive supported comment events from an authorised Facebook Business Page, recognise a product code, prevent duplicates, create a reservation and cart, provide support and secure the service. Data subjects may include merchant representatives, personnel, buyers and Page visitors. Data may include platform identifiers, supported comment content, reservation and cart records, voluntarily provided contact details and necessary security logs. Special-category data is not requested.

3. ComeSeeBuy obligations

  • process data only on documented lawful instructions and promptly flag an instruction we believe infringes applicable law;
  • bind authorised personnel to confidentiality and apply risk-appropriate technical and organisational measures;
  • assist with data-subject requests, security incidents, impact assessments and supervisory-authority enquiries;
  • notify the merchant without undue delay after confirming a personal-data breach;
  • at the end of service, return or delete eligible data at the merchant’s choice, except records that law requires us to retain;
  • provide reasonably necessary compliance information and permit proportionate audits.

4. Subprocessors

The merchant gives general authorisation for providers listed on the public subprocessor page. We will give advance notice of a material new subprocessor where practicable, and the merchant may reasonably object on data-protection grounds. Subprocessors receive substantially equivalent protection obligations.

5. International transfers

Data is transferred outside the EEA only under a lawful transfer mechanism and the merchant’s instructions. Where no adequacy decision applies, European Commission Standard Contractual Clauses and any necessary supplementary measures are used.

6. Merchant obligations

The merchant ensures a lawful basis, transparent buyer notice, accurate instructions, authority to connect the Page and appropriate access control for its users. The merchant must not submit data that the service does not need.

7. Priority and contact

If these terms conflict with the main agreement on personal-data processing, these terms control. Privacy and DPA questions: info@comeseebuy.com.