GDPR & Data Processing
Last updated: September 15, 2026
This page explains how Pagge Inc. ("Pagge", "we", "us", or "our") complies with the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws, and describes our roles as a data controller and data processor. For information about the personal data we collect and how we use it, please see our Privacy Policy.
1. Our Roles
As a data controller, we process the personal data you provide when you create an account and use the Service, such as your name, email address, and usage information, as described in our Privacy Policy.
As a data processor, we process personal data on behalf of our users (who act as data controllers) when they use Pagge to sell products to their own customers. This includes order details, customer names, and contact information collected through their stores. We process this data only in accordance with our users' instructions and for the purposes of providing the Service.
2. Our Sub-Processors
We engage trusted third parties to help provide the Service. When we act as a data processor, our sub-processors process personal data on our behalf under data processing agreements. Key sub-processors include:
- Paddle — payment processing and Merchant of Record services (paddle.com).
- Lemon Squeezy — payment processing and Merchant of Record services (lemonsqueezy.com).
- Cloud infrastructure providers — hosting and storage of the Service and your content.
- Email and communication providers — delivering transactional and support emails.
- Analytics providers — understanding how the Service is used.
3. Data Processing Agreement (DPA)
Where required, we enter into data processing agreements with our users that include the standard contractual clauses required by applicable law. Our DPA is available on request. To request a copy, please contact us at [email protected].
4. International Transfers
Your data may be processed outside the European Economic Area (EEA) or the United Kingdom. Where data is transferred internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum, to protect your data. You may request a copy of the safeguards in place by contacting us.
5. Your Rights
If you are located in the EEA, the UK, or Switzerland, you have the right to access, rectify, or erase your personal data, to restrict or object to processing, and to data portability. You also have the right to withdraw consent where processing is based on consent, and to lodge a complaint with your local supervisory authority. To exercise these rights, contact us at [email protected].
6. Contact Us
If you have any questions about this page or our data processing practices, please contact us at [email protected].