Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR – Stockaro

Deutsch  |  English

This is a translation provided for your convenience. The German version of this agreement is the authoritative one; in the event of any discrepancy, the German text prevails. Use the language switch above to read it.

Parties

Processor: Manuel Heithus, Im Mühlengarten 12a, 33428 Harsewinkel
Controller: The merchant who installed the app via the Shopify App Store.

By installing and using the app, the merchant accepts this agreement.

Subject matter and duration

The processor provides a warehouse management app (WMS) for Shopify merchants and, in doing so, processes order data, product data and inventory data on behalf of the merchant.

Duration: Processing begins when the app is installed and continues until it is uninstalled. Data is then deleted in accordance with the section „Deletion and return".

Categories of data subjects: The merchant's end customers (from their Shopify order data) and the individuals acting for the merchant (support and notification contact).

Data processed

  • Order number, customer name (first/last), delivery address, order line items (SKU, title, quantity), order status, optional order note
  • Product data (SKU, title, variant IDs)
  • Inventory movements (quantity, timestamp, source)
  • Shop access token (stored encrypted)
  • Support and feedback data from the merchant (reply email address, subject, message, ticket number, technical context and optionally selected error-log excerpts)

Purpose of end-customer data (name + delivery address): picking list, packing workflow, delivery note.

Not stored from Shopify end-customer data: email addresses, phone numbers, billing addresses, payment data. Merchant email addresses may be processed for notifications and support replies.

Obligations of the processor

  • Processing only on documented instructions from the controller (Art. 28(3)(a) GDPR); this agreement, the terms of service and the merchant's use of the app constitute such instructions
  • Confidentiality of all persons authorised to process the data (Art. 28(3)(b) GDPR)
  • Technical and organisational measures pursuant to Art. 32 GDPR — set out in detail in the TOM annex
  • Assistance with data subject rights (Art. 28(3)(e) GDPR) and with security, breach notification and data protection impact assessments (lit. f)
  • Notification of personal data breaches to the controller without undue delay, at the latest within 48 hours of becoming aware (Art. 33(2) GDPR). The 72-hour deadline towards the supervisory authority (Art. 33(1) GDPR) applies to the controller; the processor supplies the information required for it in good time
  • Deletion or return after the end of processing, at the controller's choice (Art. 28(3)(g) GDPR)

Sub-processors

Railway Corp. (hosting, database) — SOC 2 Type II, Railway DPA. Region EU-West (Amsterdam, Netherlands); hosting of application and database data takes place within the EU/EEA, no third-country transfer is envisaged for hosting.
Resend, Inc. (transactional emails and support ticket notifications, USA) — transfer based on the EU Standard Contractual Clauses (SCC) pursuant to the Resend DPA.
Full list: sub-processor list

The controller grants general authorisation for engaging these sub-processors (Art. 28(2) GDPR). The controller is informed of intended changes in advance in accordance with the sub-processor list and may object to them. The processor imposes substantially the same data protection obligations on every sub-processor and remains fully liable to the controller for their performance (Art. 28(4) GDPR).

Deletion and return

After the end of processing, all personal data is deleted or returned at the controller's choice (Art. 28(3)(g) GDPR). Return is provided via the machine-readable CSV export, which can be requested before deletion.

Procedure: On uninstallation, the app is deactivated immediately and the access token is revoked. Full deletion of the shop's data is triggered by the Shopify webhook shop/redact and takes place without undue delay after that webhook is received. The timing of the webhook is determined by Shopify — it is typically sent around 48 hours after uninstallation. Database backups are overwritten in the hosting provider's regular cycle; the longest retention is one month.

Data subject to a statutory retention obligation is excluded from deletion; its processing is restricted instead.

Evidence and audit rights

The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for reviews, including inspections (Art. 28(3)(h) GDPR).

Reviews are to be carried out with reasonable notice (at least 10 working days) and at the controller's expense. The processor may instead provide equivalent evidence — such as the TOM annex, the sub-processor list, or certifications held by the sub-processors engaged.

Contact / data protection enquiries

info@stockaro.de

Annexes: Technical and organisational measures · Sub-processors


Last updated: 2026-08-12

← Legal notice  |  Privacy policy  |  Terms  |  Help