Data Processing Agreement
This Data Processing Agreement ("DPA") applies where Shopiza processes personal data relating to your customers and store visitors ("Customer Personal Data") on your behalf when you use the Service. For personal data where Shopiza is itself the controller (your merchant account and site-visitor data), the Privacy Policy applies instead. In case of conflict on the subject of data protection, this DPA prevails over the Terms of Service.
1. Definitions
1.1 "GDPR" means Regulation (EU) 2016/679 and, where applicable, the UK GDPR and any other applicable data-protection law. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Sub-processor" have the meanings given in the GDPR.
1.2 Capitalised terms not defined here have the meaning given in the Terms of Service.
2. Roles and scope
2.1 The parties agree that, for Customer Personal Data, you are the Controller and Shopiza is the Processor.
2.2 You are responsible for the lawfulness of the Customer Personal Data and of your instructions, for having a valid legal basis, and for providing all required notices to and honouring the rights of your customers. You warrant that your instructions and your use of the Service comply with applicable data-protection law.
3. Processing on documented instructions
3.1 Shopiza will process Customer Personal Data only on your documented instructions, including as set out in this DPA, the Terms of Service, and your configuration and use of the Service, unless required to do otherwise by EU or Member State law (in which case we will inform you, unless that law prohibits it on important grounds of public interest).
3.2 Shopiza will inform you if, in its opinion, an instruction infringes applicable data-protection law. Shopiza has no obligation to monitor the legality of your instructions beyond this.
3.3 The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.
4. Confidentiality
4.1 Shopiza ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality and process the data only as necessary to provide the Service.
5. Security (GDPR Art. 32)
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, Shopiza implements appropriate technical and organisational measures, as described in Annex 2. You acknowledge the Service's development status (see the Terms of Service) and remain responsible for assessing whether those measures meet your requirements.
6. Sub-processors
6.1 You give Shopiza general authorisation to engage Sub-processors to process Customer Personal Data. A current list is in Annex 3.
6.2 Shopiza will impose data-protection obligations on each Sub-processor that are, in substance, no less protective than those in this DPA, and remains responsible to you for the performance of its Sub-processors' obligations.
6.3 Shopiza will give you reasonable notice of any intended addition or replacement of a Sub-processor and a means to object on reasonable data-protection grounds. If you object and we cannot reasonably accommodate the objection, you may terminate the affected part of the Service.
7. Assistance with Data Subject rights
7.1 Taking into account the nature of the processing, Shopiza will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights. If a Data Subject sends a request directly to Shopiza about a store, we will forward it to you and will not respond directly except to confirm it should be directed to the store owner.
8. Assistance with security, breaches, and impact assessments
8.1 Taking into account the nature of processing and the information available to Shopiza, we will provide reasonable assistance to help you comply with your obligations under GDPR Articles 32 to 36 (security, breach notification, data-protection impact assessments, and prior consultation).
9. Personal Data Breach notification
9.1 Shopiza will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the information reasonably available to help you meet your notification obligations. You are responsible for notifying supervisory authorities and Data Subjects where the law requires.
10. International transfers
10.1 Shopiza will not transfer Customer Personal Data outside the EEA except in compliance with Chapter V of the GDPR, relying on an adequacy decision (including the EU-US Data Privacy Framework for certified recipients) and/or the European Commission's Standard Contractual Clauses with appropriate safeguards, which are incorporated by reference where a transfer requires them.
11. Deletion or return of data
11.1 On termination of the Service, and at your choice, Shopiza will delete or return Customer Personal Data and delete existing copies within a reasonable period, unless EU or Member State law requires storage. Data in routine backups is deleted in the ordinary course of backup rotation.
12. Audits and information
12.1 Shopiza will make available to you information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits must be on reasonable prior notice, no more than once per year (unless required by a supervisory authority or following a Personal Data Breach), during business hours, subject to confidentiality, and must not compromise the security or data of other customers. Where available, Shopiza may satisfy this obligation by providing existing reports or documentation.
13. Liability
13.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except to the extent those limitations are not permitted by applicable data-protection law. Nothing in this DPA affects a Data Subject's statutory rights or a supervisory authority's powers.
14. Term
14.1 This DPA takes effect when you accept the Terms of Service and continues for as long as Shopiza processes Customer Personal Data on your behalf.
15. Language
15.1 This DPA is drafted in English, which is the authoritative version. Any translation is provided for convenience only; in case of any discrepancy or conflict, the English version prevails.
Annex 1, Details of the processing
- Subject matter: provision of the Shopiza e-commerce service to the Controller.
- Duration: the term of the Terms of Service, plus any legally required retention.
- Nature and purpose: hosting an online store and processing orders, payments (via the payment provider), delivery, customer accounts, communications, and analytics, so the Controller can sell to its customers.
- Types of Personal Data: identifiers and contact details (name, email, phone), billing and shipping addresses, order and transaction data, account credentials for customer accounts, communications, and technical data such as IP address and device information.
- Categories of Data Subjects: the Controller's customers, prospective customers, and store visitors.
- Special-category data: not intended or required; the Controller must not use the Service to process special categories of data unless separately agreed with appropriate safeguards.
Annex 2, Technical and organisational measures
- Encryption in transit (HTTPS/TLS) and encryption at rest of designated sensitive personal-data fields.
- Hashed and salted storage of passwords; no storage of full payment-card data (handled by the payment provider).
- Role-based access controls and the principle of least privilege for staff access.
- Rate limiting, bot protection, audit logging of security-relevant events, and account lockout on repeated failed logins.
- Network and origin protection via a security proxy (Cloudflare), including a web application firewall.
- Regular software updates and backups.
- Given the development status of the Service, measures are kept under review and improved over time.
Annex 3, Approved Sub-processors
- Stripe (United States), payment processing.
- Google (United States), sign-in (OAuth) for merchant accounts.
- Cloudflare (United States), security, CDN, and inbound email routing.
- Hetzner (Germany, EU), server and database hosting.
- Resend (United States), outbound transactional and marketing email.
Data-protection questions: [email protected].