Data processing agreement (DRAFT)
Recommended basis: the EU standard contractual clauses between controllers and processors, Commission Implementing Decision (EU) 2021/915, Annex ("SCC 2021/915"). Use the official text unchanged, and fill in its annexes with the data below. This file holds the content for those annexes.
Controller: the customer. Processor: [Company].
Annex I — Parties
- Controller: [customer name, address, contact].
- Processor: [Company], [Address], [Email].
Annex II — Description of the processing
- Categories of data subjects: the shop's customers, newsletter subscribers, shop visitors, the controller's employees who use the shop admin.
- Categories of personal data: names, addresses, email addresses, phone numbers, order data, customer accounts (password hashes), IP addresses in log files, any other data the controller stores in the shop.
- Sensitive data: none expected. The controller must not store special categories of data without a separate agreement.
- Nature of the processing: hosting, storage, backup, restore, monitoring and support of the controller's Shopware shop.
- Purpose: to provide the managed hosting service under the Terms.
- Duration: the term of the contract, plus the backup retention (at most 30 days) after the end.
Annex III — Technical and organisational measures (summary)
- Each shop runs in separate containers, with its own database user, cache and storage; other shops cannot read its data.
- Encryption in transit (HTTPS) and of backups (restic, client-side encryption).
- Backups at a second provider, in write-once (Object Lock) storage.
- Hardened servers (SSH keys only, automatic security updates, firewall), administrative access over a VPN.
- Access only for named operators, with a log of operations.
- Monitoring and alerts; incident runbooks; regular restore tests.
- Log files with IP addresses are kept at most 30 days.
Annex IV — Subprocessors
See subprocessors.md. The controller gives general authorisation. We tell the controller about a new subprocessor at least 30 days before we use it; the controller can object.
Breach notification
We tell the controller about a personal data breach without undue delay, and in any case within 48 hours after we find it, so that the controller can meet its 72-hour duty to the authority.