Ruba
Data Processing Addendum
Last updated July 25, 2026
This Data Processing Addendum (the "Addendum" or "DPA") is between RUBA GLOBAL LLC, a New Jersey limited liability company with its registered office at 99 Green Grove Ave, Keyport, New Jersey 07735 ("Ruba", "we", "us", or "our"), and the person or entity that enters into this Addendum with Ruba ("Seller", "you", or "your").
This Addendum supplements the Seller Services Agreement or another written agreement between Ruba and Seller that identifies this Addendum (the "Agreement"). It takes effect only when Ruba and Seller expressly agree that it applies to an identified feature or service (the "Effective Date").
Ruba is an independent Controller for its ordinary reseller, merchant-of-record, account, payment, tax, fraud, compliance, refund, dispute, recordkeeping, security, and support activities. This Addendum applies only where Ruba Processes Personal Data solely on Seller's documented instructions as a Processor.
Definitions
In this Addendum:
"Applicable Data Protection Law" means privacy, data-protection, and data-security laws that apply to Ruba's Processing of Processor Data under this Addendum.
"Controller" means the person that determines the purposes and means of Processing Personal Data. It includes a "business" where applicable law uses that term.
"Controller Data" means Personal Data that Ruba Processes as an independent Controller.
"Data Subject" means an identified or identifiable individual to whom Personal Data relates. It includes a "consumer" where applicable law uses that term.
"EU GDPR" means Regulation (EU) 2016/679.
"EU SCCs" means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
"Personal Data" means information relating to an identified or identifiable individual and includes "personal information" or a similar term under Applicable Data Protection Law.
"Personal Data Breach" means a security breach resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Processor Data.
"Process", "Processes", "Processed", and "Processing" mean an operation performed on Personal Data, including collection, use, disclosure, storage, or deletion.
"Processor" means a person that Processes Personal Data on behalf of a Controller. It includes a "service provider", "contractor", or comparable term where applicable law uses that term.
"Processor Data" means Personal Data that Ruba Processes solely on Seller's documented instructions for the identified service governed by this Addendum. It excludes Controller Data.
"Sensitive Data" means Personal Data subject to heightened protection under Applicable Data Protection Law.
"Services" means the services governed by the Agreement.
"Subprocessor" means a third party that Ruba engages to Process Processor Data on Ruba's behalf.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner's Office under Section 119A of the Data Protection Act 2018.
"UK GDPR" means the EU GDPR as incorporated into United Kingdom law, together with the United Kingdom Data Protection Act 2018, in each case as amended.
1. Scope and Roles
1.1. This Addendum governs only Processor Data for the identified service. The subject matter, duration, nature, purpose, Personal Data types, Data Subject categories, and applicable schedules are identified in the Agreement or acceptance record and Annexes I through III.
1.2. Ruba acts as an independent Controller for Controller Data. That Processing is governed by the Privacy Notice, the Agreement, and Applicable Data Protection Law, not this Addendum.
1.3. Seller is the Controller of Processor Data. If Seller Processes Processor Data for another Controller, Seller appoints Ruba as a Subprocessor and represents that Seller has authority to give instructions and enter this Addendum for that Controller.
1.4. Nothing in this Addendum makes the parties joint Controllers or changes a role imposed by Applicable Data Protection Law.
1.5. This Addendum controls over the Agreement only for a conflict concerning Ruba's Processor obligations. An applicable EU SCC or UK Addendum controls to the extent required for a transfer it governs.
2. Seller Responsibilities and Instructions
2.1. Seller must comply with Applicable Data Protection Law and is responsible for its instructions; the lawfulness, fairness, accuracy, and quality of Processor Data; its collection and disclosure to Ruba; required notices, legal bases, permissions, and consents; and Data Subject requests within Seller's responsibility.
2.2. Seller's documented instructions consist of this Addendum, the Agreement, Seller's authorized use and configuration of the identified service, and additional written instructions Ruba accepts. Ruba is not required to follow an instruction that violates law, conflicts with the Agreement, changes the Services, or requires material development, cost, or operational changes unless the parties agree otherwise in writing.
2.3. Seller must not submit Sensitive Data unless the identified service expressly permits it or Ruba approves it in writing.
2.4. Seller must protect systems, credentials, and accounts within Seller's control and promptly notify Ruba of suspected compromise or unlawful submission, access, or disclosure of Processor Data.
3. Ruba's Processor Obligations
3.1. Ruba will Process Processor Data only on Seller's documented instructions, including instructions concerning transfers, unless law applicable to Ruba requires otherwise. Where legally permitted, Ruba will inform Seller of that requirement before Processing.
3.2. Ruba will inform Seller if, in Ruba's reasonable opinion, an instruction violates Applicable Data Protection Law and may suspend the affected instruction or Processing pending resolution.
3.3. Ruba will limit access to Processor Data to persons who require access for the identified service and are subject to confidentiality obligations.
3.4. Ruba will comply with obligations Applicable Data Protection Law imposes directly on Ruba as a Processor. If Ruba determines it can no longer satisfy a material obligation, Ruba will inform Seller and take the action required by applicable law.
3.5. Ruba may use information that has been aggregated or de-identified so that applicable law no longer treats it as Personal Data, subject to restrictions imposed by applicable law.
3.6. If Ruba receives a binding government demand for Processor Data, Ruba will disclose only information it reasonably determines is legally required and, where legally permitted, notify Seller. Ruba is not required to challenge the demand unless an applicable transfer instrument or law requires it.
4. United States Processor Terms
4.1. To the extent Ruba is a Processor, service provider, or contractor under applicable United States state privacy law, Seller discloses Processor Data only for the limited purposes identified in this Addendum.
4.2. Except as applicable law permits to provide the identified service or comply with law, Ruba will not sell or share Processor Data; use or disclose it outside the limited purposes or direct business relationship stated in this Addendum; or combine it with Personal Data from another source where the applicable law prohibits that combination.
4.3. Seller may take legally required, reasonable, and appropriate steps to help ensure Ruba uses Processor Data consistently with applicable law, subject to Section 9. If Ruba notifies Seller that Ruba can no longer comply, Seller may take legally required, reasonable, and appropriate steps to stop and remediate unauthorized use.
5. Security and Personal Data Breaches
5.1. Ruba will maintain measures designed to provide security appropriate to the risk, taking into account the factors required by Applicable Data Protection Law. The applicable measures are identified in Annex II.
5.2. Ruba will notify Seller without undue delay after becoming aware of a Personal Data Breach and will provide information available to Ruba that applicable law requires for Seller's response.
5.3. Ruba will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach. Notice or cooperation is not an admission of fault or liability.
5.4. Seller is responsible for determining and making notifications within Seller's legal responsibility, except where applicable law assigns an obligation directly to Ruba.
6. Data Subject and Compliance Assistance
6.1. If Ruba receives a Data Subject request concerning Processor Data, Ruba will notify Seller, direct the requester to Seller, or respond as Seller authorizes or law requires. Ruba handles requests concerning Controller Data under the Privacy Notice.
6.2. Taking into account the Processing and information available to Ruba, Ruba will provide assistance required by Applicable Data Protection Law concerning Data Subject rights, security, Personal Data Breaches, legally required assessments, and legally required regulatory consultation.
6.3. Ruba may provide assistance through generally available functionality or documentation and may charge reasonable fees for assistance beyond its legal or included Service obligations, unless the need results from Ruba's material breach or applicable law prohibits charging.
7. Subprocessors
7.1. Seller gives Ruba general written authorization to engage the Subprocessors identified in the applicable Subprocessor schedule supplied to Seller before the Effective Date. That schedule forms part of Annex III.
7.2. Where Applicable Data Protection Law requires it, Ruba will give Seller at least 15 calendar days' written notice of an intended addition or replacement and an opportunity to object before the Subprocessor begins Processing Processor Data. A shorter period may apply where reasonably necessary to address an emergency, security risk, legal requirement, or provider replacement outside Ruba's reasonable control, in which case Ruba will give notice as soon as reasonably practicable.
7.3. An objection must be timely, written, and based on documented grounds relating specifically to protection of Processor Data. Ruba may provide information or an available measure to address it.
7.4. If the parties cannot resolve an objection, Ruba may decline to use the Subprocessor for Seller, suspend or discontinue the affected service, or allow Seller to terminate only the affected service. That termination is Seller's exclusive contractual remedy, except where Applicable Data Protection Law requires otherwise.
7.5. Ruba will impose written data-protection obligations on each Subprocessor as required by Applicable Data Protection Law and remains responsible for a Subprocessor to the extent required by that law and the Agreement.
7.6. If Applicable Data Protection Law requires Ruba to provide information concerning a Subprocessor or its agreement, Ruba may withhold or redact information the law does not require, including commercial terms, security-sensitive information, Personal Data, privileged material, and other confidential information.
8. Return, Deletion, and Retention
8.1. When the identified service ends, Ruba will, at Seller's choice, return or delete Processor Data as required by Applicable Data Protection Law. Seller must use generally available export functionality where available and request any return before the service ends or within 30 days afterward.
8.2. Ruba may retain Processor Data to the extent and for the period law requires. Retained Processor Data remains subject to this Addendum and will not be actively Processed for another purpose.
8.3. Subject to Applicable Data Protection Law and an applicable transfer instrument, Processor Data may remain in protected backups until deleted through Ruba's ordinary cycle.
8.4. This Section does not govern Controller Data.
8.5. Ruba may charge reasonable fees for a custom return, migration, restoration, or deletion process not included in generally available functionality, unless required because of Ruba's material breach or prohibited by law.
9. Information and Audits
9.1. On reasonable written request, and only to the extent required by Applicable Data Protection Law, Ruba will provide information reasonably necessary to demonstrate compliance with this Addendum. Ruba may satisfy the request through appropriate documentation or an available independent report or certification.
9.2. Only if Section 9.1 is legally insufficient may Seller use a qualified independent auditor that is not Ruba's competitor and is bound by written confidentiality obligations. Seller itself may conduct an audit only where non-waivable law, an applicable transfer instrument, or a competent supervisory authority expressly requires Ruba to permit it. Unless a supervisory authority requires otherwise or credible evidence indicates material noncompliance:
- an audit may occur no more than once in a 12-month period;
- Seller must give at least 30 days' written notice and a detailed proposed scope;
- a remote documentary review must be used before any on-site inspection;
- the audit must be limited to Ruba's Processing of Processor Data under this Addendum, occur during normal business hours, and avoid unreasonable disruption; and
- the audit must not access another person's information, compromise security, or require disclosure of privileged information, trade secrets, or information Ruba is legally or contractually prohibited from disclosing.
Nothing in this Section grants a general right to investigate Ruba or access Ruba's source code, credentials, cryptographic keys, production systems, financial or corporate records, provider contracts, premises, or information unrelated to the Processing governed by this Addendum. Any access expressly required by non-waivable law or a competent supervisory authority remains subject to lawful scope, confidentiality, security, and data-minimization restrictions to the maximum extent permitted.
9.3. Seller bears its audit costs and Ruba's reasonable support costs unless the audit establishes Ruba's material breach, in which case Ruba will bear its reasonable internal support costs.
9.4. Ruba will cooperate with a competent supervisory authority only to the extent Applicable Data Protection Law requires.
10. International Transfers
10.1. Seller authorizes Ruba and its Subprocessors to Process Processor Data in the United States and other countries identified in the applicable schedules, subject to Applicable Data Protection Law. Seller is responsible for determining whether its disclosure is a restricted transfer and for exporter obligations. Ruba will provide reasonably available information that applicable law requires, without granting access to information outside the lawful scope of that obligation.
10.2. If Seller transfers Processor Data subject to the EU GDPR to Ruba in a country not covered by an applicable adequacy decision and no other lawful mechanism applies, the parties enter the EU SCCs by reference as follows:
- Seller is the data exporter and Ruba is the data importer.
- Module 2 applies where Seller is a Controller, and Module 3 applies where Seller is a Processor.
- Clause 7 does not apply.
- In Clause 9, Option 2 applies with the notice period stated in Section 7.2.
- The optional language in Clause 11 does not apply.
- In Clause 17, Option 1 applies and the EU SCCs are governed by Irish law.
- Under Clause 18, the courts of Ireland are the chosen courts.
- Annexes I through III of this Addendum complete the corresponding EU SCC annexes.
10.3. If Seller makes a restricted transfer governed by the UK GDPR and no other lawful mechanism applies, the official UK Addendum applies to the EU SCCs in Section 10.2. Seller is the exporter, Ruba is the importer, both parties may end the UK Addendum as its Mandatory Clauses permit, and Annexes I through III provide the required Appendix Information.
10.4. If a restricted transfer is governed by Swiss data-protection law, the EU SCCs apply with adaptations required by that law. References to the EU GDPR include the Swiss Federal Act on Data Protection where applicable; Switzerland is included as a Member State for Clause 18(c); and the Swiss Federal Data Protection and Information Commissioner is the competent authority for Processing governed by Swiss law.
10.5. If a transfer mechanism becomes invalid or unavailable, the parties will implement another lawful mechanism or Ruba may suspend the affected transfer or service.
11. Liability and General Terms
11.1. The Agreement's disclaimers, indemnification provisions, exclusions of damages, and limitations of liability apply to this Addendum. This Addendum creates no separate liability cap or indemnification obligation. Nothing limits rights or liability where an applicable transfer instrument or law prohibits the limitation.
11.2. This Addendum remains effective while Ruba Processes Processor Data for the identified service. Provisions that must continue to fulfill their purpose survive, including confidentiality, deletion and retention, audits relating to the term, transfers, liability, and interpretation.
11.3. Changes are governed by the Agreement. No change modifies an applicable EU SCC or UK Addendum except as that instrument permits.
11.4. Legal notices must be sent as provided in the Agreement. Privacy and data-protection requests may be sent to privacy@getruba.com.
11.5. Except for rights an applicable transfer instrument or law expressly grants to Data Subjects, this Addendum creates no third-party-beneficiary rights.
Annex I — Processing Schedule
The written or electronic acceptance record for the identified service must state or incorporate:
- the subject matter, duration, nature, and purpose of the Processing;
- the categories of Data Subjects and Personal Data;
- whether Seller is a Controller or Processor;
- the frequency of Processing;
- any approved Sensitive Data; and
- the competent supervisory authority where an applicable transfer instrument requires it.
The acceptance record forms part of this Annex. Ruba will not Process Sensitive Data unless the applicable service expressly permits it or the parties approve it in writing with appropriate safeguards.
Annex II — Security Schedule
Before the Effective Date, Ruba will supply or identify the security schedule applicable to the identified service. That schedule forms part of this Annex and will describe the technical and organizational measures required by Applicable Data Protection Law for the Processing, including applicable access, confidentiality, security, availability, recovery, review, incident-response, and provider controls.
Nothing in the schedule grants Seller operational access to Ruba's systems or requires public disclosure of security-sensitive information.
Annex III — Subprocessor Schedule
The Subprocessors authorized for the identified service are those listed in the Subprocessor schedule supplied to Seller before the Effective Date. The schedule forms part of this Annex and will include information required by Applicable Data Protection Law for Seller's authorization. Changes are governed by Section 7.
Contact
RUBA GLOBAL LLC
99 Green Grove Ave
Keyport, New Jersey 07735
Privacy and data-protection questions: privacy@getruba.com
Legal notices and Addendum questions: legal@getruba.com