Data Processing Agreement

Last updated September 30, 2026

Template — review with your legal adviser before relying on it.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer accepting those Terms ("Customer", the controller) and Your App ("Processor"), and applies whenever the Processor processes personal data on the Customer's behalf as described below. It is accepted electronically at signup, together with the Terms.

1. Subject matter, duration and purpose

The Processor processes personal data on behalf of the Customer for the duration of the Customer's subscription, for the purpose of providing the hosted store platform described in the Terms — in particular, storing and displaying the Customer's product catalogue and processing orders placed by the Customer's own customers.

2. Nature of the processing and data subjects

The processing consists of storage, retrieval, transmission and deletion of data submitted by the Customer or by the Customer's own customers ("Data Subjects") through the Customer's store — typically names, contact details, delivery addresses and order history. No special categories of data are processed unless the Customer chooses to submit them, which the Customer should avoid.

3. Processor obligations (GDPR Art. 28(3))

The Processor shall:

4. Sub-processors

The Processor may engage the sub-processors listed in Annex 2 (currently: [Sub-processors]). The Processor will inform the Customer of any intended change concerning the addition or replacement of a sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds.

5. International transfers

Where a sub-processor is located outside the European Economic Area, the transfer is protected by an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses.

6. Data breach notification

The Processor shall notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and shall provide reasonably requested information to help the Customer meet its own notification obligations.

7. Deletion or return

At the end of the provision of services, the Processor shall, at the Customer's choice, delete or return all personal data, and delete existing copies, subject to any retention required by law — see the retention periods described in the Privacy Policy.

8. Audits

The Processor will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits conducted by the Customer or an auditor mandated by the Customer, on reasonable notice.

Annex 1 — Technical and organisational measures

Annex 2 — Sub-processors

[Sub-processors]

Stripe, Inc. — payment processing.