Data Processing Agreement
Where you (the merchant) are the controller and Datadir is the processor of the store and customer data our apps handle for you.
Last updated: 23 September 2026
This DPA is incorporated into the Terms of Service and applies whenever a Tendor App processes personal data on your behalf. You are the controller; datadir s. r. o. is the processor.
1. Subject matter and duration
We process personal data only to provide the Apps you've installed, for as long as they're installed, plus the short wind-down period in section 7.
2. Nature and purpose
Reading and writing store data (products, inventory, prices, orders and metadata) and, where a feature needs it, limited shopper data — solely to deliver that App's function, as a reversible, audited change set.
3. Categories of data and data subjects
- Data subjects: the merchant's staff, their store's shoppers, and — where a feature involves them — the merchant's suppliers.
- Data: store configuration and catalogue data; supplier contact details the merchant enters (name, email, phone) where an App emails purchase orders; and, per feature, shopper identifiers such as an email address (back-in-stock alerts) or saved items (wishlists). We minimise this to what the feature requires.
4. Our obligations
- Process personal data only on your documented instructions (installing and configuring an App is such an instruction), including as regards transfers to a third country, unless required to process by Union or Member-State law — in which case we will inform you of that legal requirement before processing, unless the law forbids it on important grounds of public interest. We will tell you promptly if, in our opinion, an instruction infringes the GDPR or other applicable data-protection law.
- Ensure personnel authorised to process the data have committed to confidentiality or are under an appropriate statutory duty of confidentiality.
- Apply appropriate technical and organisational security measures (section 6).
- Assist you, taking into account the nature of processing and insofar as possible, with data-subject requests and with your security, breach-notification, data-protection-impact-assessment, and prior-consultation obligations (Articles 32–36 GDPR).
- Treat this DPA and your App configuration as your complete and final documented instructions for processing; any additional or different instruction requires our written agreement.
- Notify you without undue delay (and in any event within 48 hours) after becoming aware of a personal-data breach, providing the information in Article 33(3) GDPR (nature of the breach; categories and approximate numbers affected; likely consequences; measures taken) as it becomes available.
5. Sub-processors
You grant general written authorisation for the sub-processors below. We will give you at least 30 days' prior notice (by email and by updating this list) of any intended addition or replacement, during which you may object on reasonable data-protection grounds; if you object and we cannot offer a commercially reasonable alternative, you may terminate the affected App and receive a pro-rata refund of prepaid fees. We impose on every sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and we remain fully liable to you for any sub-processor's failure to meet them.
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify Inc. | The platform your store runs on; source of the store & shopper data | Per Shopify's DPA |
| Hetzner Online GmbH | Application hosting and database | Germany (EU) |
| Scaleway SAS | Encrypted, off-site database backups | France (EU) |
| BunnyWay d.o.o. (Bunny.net) | Authoritative DNS, and CDN for our website | Slovenia (EU); global anycast edge |
| Transactional email relay (EU / EEA) | Sending transactional emails for apps that send mail (e.g. back-in-stock alerts); not used by apps that send no mail | EU / EEA |
6. Security measures
- Tenant isolation enforced at the database level (row-level security), so no store can read another's data.
- Tamper-evident audit log — every change is recorded in a hash-chained, per-store log.
- Reversibility — changes are stored as change sets that can be rolled back to their recorded prior state.
- Encryption in transit, and encryption at rest for off-site backups; access on least-privilege; EU data residency.
- We periodically review these measures, and maintain the ability to restore data from backups.
7. Return and deletion
On uninstall, or on your request, we delete or return the personal data we process for you, except where the law requires retention. In practice: access tokens are deleted immediately on uninstall; store data is erased within 30 days of uninstall, and in any event on Shopify's shop/redact (~48 hours after uninstall); encrypted backups containing your data roll off on a 30-day cycle, after which residual copies are purged. We honour Shopify's shop/redact and customers/redact requests on the platform's schedule.
8. International transfers
All personal data processed under this DPA is stored in the EU/EEA (hosting and database in Germany; encrypted backups in France). We do not transfer it to a third country except to Shopify, which processes under its own DPA relying on an adequacy decision and/or EU Standard Contractual Clauses. Should we introduce any further third-country transfer, we will implement Article 46 safeguards (Standard Contractual Clauses) and update the list above beforehand.
9. Audits
On reasonable prior notice — and no more than once a year, absent a personal-data breach or a regulator's request — we will make available the information needed to demonstrate compliance with Article 28 GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to confidentiality and reasonable coordination to avoid service disruption. We may satisfy an audit request in the first instance with a completed security questionnaire (and any third-party reports or certifications we may hold at the time).
Questions about this DPA, or to request a countersigned copy for your records: hello@datadir.co. Company details: Legal notice.