Data Processing Agreement
Last updated: 7 October 2026
This agreement is part of the Terms of Service between the merchant (“Controller”) and [COMPANY NAME], [STREET AND NUMBER], [POSTCODE] [CITY], The Netherlands(“Processor”). It applies to the personal data of the Controller's customers that the Processor handles when providing kaas, and meets the requirements of Article 28 of the GDPR.
1. Subject and duration
The Processor processes personal data only to provide the checkout and related features the Controller uses, for as long as the Terms of Service run, plus the export period after they end.
2. Data and people concerned
- People: the Controller's customers and visitors of its checkout.
- Data: name, email address, phone number, shipping and billing address, order contents and amounts, payment status and method (never full card numbers), marketing consent, survey answers, IP address, browser and device information, and checkout behaviour (such as steps completed).
3. Instructions
The Processor processes the data only on the Controller's documented instructions — the Terms of Service, this agreement and the settings the Controller chooses in the dashboard — unless EU or Dutch law requires otherwise, in which case the Processor informs the Controller first where the law allows.
4. Confidentiality and security
Everyone with access to the data is bound to confidentiality. The Processor takes appropriate technical and organisational measures, including encryption in transit, encrypted storage of access credentials, access limited to what's needed, logging, and keeping software up to date.
5. Sub-processors
The Controller gives general permission for the following sub-processors:
- Vercel Inc. — application hosting.
- Neon Inc. — database hosting, United States (AWS us-east-1).
Services the Controller connects itself (Shopify, Mollie, Whop, Meta) receive data under the Controller's own agreements with them. The Processor informs the Controller at least 30 days before adding or replacing a sub-processor; the Controller may object and, if no solution is found, end the agreement. Sub-processors are bound to the same obligations as in this agreement.
6. Transfers outside the EU
Data is transferred outside the European Economic Area only with appropriate safeguards: an adequacy decision such as the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses.
7. Help with rights and obligations
The Processor helps the Controller, as far as reasonable, to answer requests from people exercising their rights, and with security, data protection impact assessments and consultations with supervisory authorities. Requests the Processor receives directly are passed on to the Controller.
8. Data breaches
The Processor informs the Controller without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach, with the information the Controller needs to meet its own notification obligations.
9. Audits
The Processor makes available the information needed to show compliance with this agreement. The Controller may have an audit carried out once a year, at its own cost, with at least 30 days' notice, by an independent auditor bound to confidentiality.
10. End of processing
When the agreement ends, the Controller can export its data for 30 days. After that the Processor deletes the personal data, unless the law requires it to be kept.
11. Liability
The liability limits of the Terms of Service apply to this agreement.
Contact for data protection matters: [CONTACT EMAIL].