Data Processing Agreement
Last updated September 30, 2026
Template — review with your legal adviser before relying on it.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer accepting those Terms ("Customer", the controller) and Your App ("Processor"), and applies whenever the Processor processes personal data on the Customer's behalf as described below. It is accepted electronically at signup, together with the Terms.
1. Subject matter, duration and purpose
The Processor processes personal data on behalf of the Customer for the duration of the Customer's subscription, for the purpose of providing the hosted store platform described in the Terms — in particular, storing and displaying the Customer's product catalogue and processing orders placed by the Customer's own customers.
2. Nature of the processing and data subjects
The processing consists of storage, retrieval, transmission and deletion of data submitted by the Customer or by the Customer's own customers ("Data Subjects") through the Customer's store — typically names, contact details, delivery addresses and order history. No special categories of data are processed unless the Customer chooses to submit them, which the Customer should avoid.
3. Processor obligations (GDPR Art. 28(3))
The Processor shall:
- (a) process personal data only on documented instructions from the Customer, including regarding international transfers, unless required to do otherwise by law;
- (b) ensure persons authorised to process the data are subject to confidentiality;
- (c) take the technical and organisational measures required by Art. 32 GDPR (see Annex 1);
- (d) respect the conditions in this DPA for engaging another processor (sub-processor);
- (e) taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures for responding to requests from Data Subjects;
- (f) assist the Customer in ensuring compliance with Art. 32-36 GDPR, taking into account the information available to the Processor;
- (g) at the Customer's choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless law requires storage;
- (h) make available information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
4. Sub-processors
The Processor may engage the sub-processors listed in Annex 2 (currently: [Sub-processors]). The Processor will inform the Customer of any intended change concerning the addition or replacement of a sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds.
5. International transfers
Where a sub-processor is located outside the European Economic Area, the transfer is protected by an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses.
6. Data breach notification
The Processor shall notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and shall provide reasonably requested information to help the Customer meet its own notification obligations.
7. Deletion or return
At the end of the provision of services, the Processor shall, at the Customer's choice, delete or return all personal data, and delete existing copies, subject to any retention required by law — see the retention periods described in the Privacy Policy.
8. Audits
The Processor will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits conducted by the Customer or an auditor mandated by the Customer, on reasonable notice.
Annex 1 — Technical and organisational measures
- Encryption of data in transit (TLS) and, where applicable, at rest.
- Access control: authenticated, role-based access to production systems, limited to personnel who need it.
- One isolated database per store, so no store's data is stored alongside another's.
- Regular security patching of the platform and its dependencies.
- Logging of security-relevant events for a limited retention period.
- A documented incident-response process.
Annex 2 — Sub-processors
[Sub-processors]
Stripe, Inc. — payment processing.