b2bcraft

Data processing agreement (DRAFT)

Recommended basis: the EU standard contractual clauses between controllers and processors, Commission Implementing Decision (EU) 2021/915, Annex ("SCC 2021/915"). Use the official text unchanged, and fill in its annexes with the data below. This file holds the content for those annexes.

Controller: the customer. Processor: [Company].

Annex I — Parties

  • Controller: [customer name, address, contact].
  • Processor: [Company], [Address], [Email].

Annex II — Description of the processing

  • Categories of data subjects: the shop's customers, newsletter subscribers, shop visitors, the controller's employees who use the shop admin.
  • Categories of personal data: names, addresses, email addresses, phone numbers, order data, customer accounts (password hashes), IP addresses in log files, any other data the controller stores in the shop.
  • Sensitive data: none expected. The controller must not store special categories of data without a separate agreement.
  • Nature of the processing: hosting, storage, backup, restore, monitoring and support of the controller's Shopware shop.
  • Purpose: to provide the managed hosting service under the Terms.
  • Duration: the term of the contract, plus the backup retention (at most 30 days) after the end.

Annex III — Technical and organisational measures (summary)

  • Each shop runs in separate containers, with its own database user, cache and storage; other shops cannot read its data.
  • Encryption in transit (HTTPS) and of backups (restic, client-side encryption).
  • Backups at a second provider, in write-once (Object Lock) storage.
  • Hardened servers (SSH keys only, automatic security updates, firewall), administrative access over a VPN.
  • Access only for named operators, with a log of operations.
  • Monitoring and alerts; incident runbooks; regular restore tests.
  • Log files with IP addresses are kept at most 30 days.

Annex IV — Subprocessors

See subprocessors.md. The controller gives general authorisation. We tell the controller about a new subprocessor at least 30 days before we use it; the controller can object.

Breach notification

We tell the controller about a personal data breach without undue delay, and in any case within 48 hours after we find it, so that the controller can meet its 72-hour duty to the authority.