Preamble and parties
This Data Processing Agreement (“DPA”) applies between the seller as controller (“controller”) and Philippe Ramón Hamerla, 8220 Chlorakas, Paphos, Cyprus as processor (“processor”) for all personal data that the processor processes on behalf of the controller in the course of providing the merchavio platform.
The DPA takes effect when a seller account is created and the platform features are used, and supplements the Seller Terms. In the event of conflict on data protection matters, this DPA prevails.
1. Subject matter, nature and purpose of processing
The subject matter is the processing of personal data arising from the use of the platform (in particular running the storefront and community, also under an own domain connected by the controller (“custom domain”), order/customer management, delivery of digital products, livestreams and voice rooms, and communication).
Also covered are: (a) the finance and bookkeeping module, including the incoming receipts and invoices uploaded by the controller, their categorisation, the evaluations generated from them (including revenue, cash flow, VAT and cash-basis profit overviews) and the exports; and (b) the management of the controller’s team access with role-based permissions.
Nature and purpose: storage, organisation, display, transmission and deletion of this data exclusively to provide the contractually agreed platform features to the controller.
2. Duration
Processing takes place for the term of the user relationship. After it ends, the provisions on return and deletion (section 10) apply.
3. Types of data and categories of data subjects
- Types of data: master data (name, email, where applicable address), contract/order data, payment status (without full payment details), communication and usage data, and content provided by the controller.
- Additionally in the finance and bookkeeping module: receipt and invoice data uploaded or recorded by the controller, including the information about third parties contained therein, in particular name/company, address, contact details, tax or VAT identification number, bank details, invoice number, amount, tax rate and description of services of the respective issuer, as well as the related categories, notes and evaluations.
- Additionally for team access: name, email address, invitation and sign-in status, and assigned role and permissions.
- Data subjects: the controller’s customers, prospects, community members, the controller’s team members, and issuers, suppliers and other business partners of the controller whose data is contained in uploaded receipts.
4. Instructions
The processor processes the data only on documented instructions from the controller, including with regard to transfers to third countries, unless required to process otherwise by Union or Member State law. Using the platform features counts as an instruction. If the processor considers an instruction to be unlawful, it informs the controller.
5. Confidentiality
The processor only uses persons for processing who are committed to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b), Art. 29, Art. 32(4) GDPR).
6. Technical and organisational measures (Art. 32 GDPR)
The processor takes appropriate technical and organisational measures to protect the data; details are described in the “TOM” annex (see below). The measures may be developed further as technology evolves, provided the level of protection is not reduced.
7. Sub-processors
The controller gives general authorisation for the use of the following sub-processors. The processor contractually binds them to a level of data protection equivalent to this DPA (Art. 28(4) GDPR).
- Hetzner Online GmbH (Germany): hosting/server operation.
- Cloudflare, Inc. (USA): object storage (Cloudflare R2, region EU) for uploaded files, receipts from the finance and bookkeeping module and backups; also name resolution (DNS) for the domain.
- Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (USA): payment processing.
- PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg): payment processing and subscription billing where PayPal is chosen as the payment method. If the seller connects their own PayPal business account, the seller is the controller for this PayPal merchant relationship; we technically create the subscriptions/payments with the seller’s credentials in the seller’s name.
- Google Ireland Limited / Google LLC (USA): optional sign-in via Google sign-in.
- Brevo (Sendinblue GmbH, Cologne / Brevo SAS, France, EU): sending of transactional emails and, only where consent has been given, marketing emails.
- Zoho Corporation (USA): mailboxes for contact and support enquiries (data centre USA).
- LiveKit, Inc. (USA): real-time audio/video infrastructure for livestreams, voice rooms and video communities (“LiveKit Cloud”).
- BunnyWay d.o.o. (Slovenia, EU): delivery of uploaded course and product videos via a content delivery network (“Bunny Stream”).
This list is identical to the list in section 7 of the Privacy Policy and is only changed together with it. Recipients acting as independent controllers (in particular sellers, app providers under “Works with Merchavio” and the push service of the respective browser) are not sub-processors.
The processor informs the controller of intended changes (addition/replacement); the controller may object for an important data protection reason. In the event of an objection, features may be restricted or the user relationship may be terminated.
8. Assistance to the controller
- Data subject rights: the processor assists the controller with appropriate technical and organisational measures in responding to requests from data subjects (Art. 12–23 GDPR). If data subjects contact us directly, we refer them to the controller.
- Security, notification obligations, data protection impact assessment: the processor assists the controller in complying with the obligations under Art. 32–36 GDPR, within reason and taking into account the information available to it.
9. Notification of personal data breaches
The processor informs the controller without undue delay after becoming aware of a personal data breach affecting the controller’s data and provides the information required for notification under Art. 33/34 GDPR.
10. Return and deletion
After the user relationship ends, the processor makes the controller’s data available on request in a common format (export) and then deletes or anonymises the data, unless a statutory retention obligation applies.
11. Evidence and audits
The processor provides the controller with the information required to demonstrate compliance with the obligations under Art. 28 GDPR and allows audits (e.g. through self-assessments, evidence/certificates or, after reasonable prior notice and with due regard to operations and confidentiality interests, on-site inspections).
12. Transfers to third countries
Transfers to third countries only take place on the basis of an adequacy decision (e.g. EU-U.S. Data Privacy Framework) or appropriate safeguards under Art. 46 GDPR (in particular EU standard contractual clauses) together with any necessary supplementary measures (see section 7).
13. Liability and final provisions
The liability provisions of the Terms/Seller Terms and Art. 82 GDPR apply. Amendments require text form. The law specified in the Seller Terms applies; mandatory requirements of the GDPR remain unaffected.
Annex: Technical and organisational measures (TOM)
- Confidentiality. Physical access: data centres of the processors (Hetzner/EU) with physical access controls. System access: individual user accounts, server-side password storage only as bcrypt hashes, SSH key-based server access, principle of least privilege.
- Integrity. Transfer: transport encryption (TLS/HTTPS) for all connections; API access via signed tokens (JWT). Stored credentials/API secrets of connected services (e.g. the seller’s PayPal API credentials) are stored encrypted (encryption at rest, AES-256-GCM). Input: logging of security-relevant events.
- Availability and resilience: automated backups several times a day to separate storage in the EU, with tested restoration; operation in an EU data centre; server firewall, automatic security updates and blocking of repeated failed logins.
- Data minimisation: no access logs containing IP addresses; service logs are limited in size and automatically overwritten.
- Separation: data stored separately per account (tenant separation); separate processing for different purposes.
- Processor control: careful selection and contractual obligation of sub-processors; bound by instructions.
- Recoverability and review: procedures for restoring from backups; regular review and updating of the measures.