We use cookies to make your experience better. To comply with the new e-Privacy directive, we need to ask for your consent to set the cookies. Learn more.
Data Processing Agreement
Last updated: 12 September 2026
This Data Processing Agreement (DPA) governs our processing of personal data on your behalf when we provide the Service, and forms part of our Terms of Service. Terms like "personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings in the EU General Data Protection Regulation (GDPR) and, where it applies, the UK GDPR ("Data Protection Law").
1. Roles
1.1 For the personal data in your Store and processed through the Service (the "Customer Personal Data" — e.g. your Shoppers' account, order, and contact details), you are the controller and we are the processor. Where you're yourself a processor for someone else, we act as sub-processor and this DPA applies accordingly.
1.2 We process Customer Personal Data only on your documented instructions — which are: this DPA, the Terms of Service, your configuration and use of the Service through the Portal, and any further lawful written instructions you give. If we believe an instruction breaches Data Protection Law, we'll tell you. If we're required by law to process otherwise, we'll inform you unless the law prohibits it.
1.3 You're responsible for the lawfulness of the Customer Personal Data and for having a legal basis to collect it and have us process it — including providing privacy notices to, and obtaining any needed consents from, your Shoppers (including for any AI features you enable).
1.4 Details of the processing (subject matter, duration, nature and purpose, types of personal data, categories of data subjects) are in Annex I.
2. Our obligations as processor
We will:
- 2.1 process Customer Personal Data only as described in §1.2;
- 2.2 ensure people authorised to process it are under a duty of confidentiality;
- 2.3 implement appropriate technical and organisational security measures (Article 32) as described in Annex II, and use reasonable and appropriate measures designed to protect the data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access;
- 2.4 respect the conditions in §3 for engaging sub-processors;
- 2.5 taking into account the nature of the processing, assist you with reasonable technical and organisational measures, so far as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). The Portal's tools (including data export and deletion) are the primary way this assistance is provided;
- 2.6 assist you in ensuring compliance with Articles 32–36 (security, breach notification, data-protection impact assessments, prior consultation), taking into account the information available to us;
- 2.7 at your choice, delete or return all Customer Personal Data after the end of the Service, and delete existing copies, except where law requires us to keep it. This aligns with the account grace-period and deletion process in the Service Specific Terms;
- 2.8 make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits — satisfied first through our documentation, certifications, and reports, with on-site audits reserved for where those are insufficient, on reasonable notice and subject to confidentiality (details in §6).
3. Sub-processors
3.1 You give general authorisation for us to engage sub-processors to help provide the Service. We'll impose data-protection obligations on them that are substantially the same as ours under this DPA, and we remain responsible for their performance.
3.2 Our current sub-processors are listed in Annex III. We'll give you advance notice of any intended addition or replacement (e.g. by email or a posted list you can subscribe to) so you have the chance to object on reasonable data-protection grounds. If you object and we can't reasonably accommodate it, you may terminate the affected Service as your remedy.
4. International transfers
4.1 We process Customer Personal Data within the EU/EEA where the Service is provided. Where any transfer of Customer Personal Data outside the EEA/UK occurs (including via a sub-processor), we'll ensure an appropriate safeguard under Data Protection Law is in place — such as an adequacy decision or the applicable Standard Contractual Clauses (and the UK Addendum where relevant), which are incorporated by reference where used.
5. Personal data breaches
5.1 We'll notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably available to help you meet your own notification obligations. We'll take reasonable steps to contain and remediate. Our notice isn't an admission of fault.
6. Audits
6.1 We'll respond to reasonable audit requests through documentation and any third-party certifications or reports we hold. On-site audits are limited to what those can't address, must be on reasonable prior notice, no more than once a year (except where required by a supervisory authority or after a breach), conducted so as not to disrupt the Service or other customers, and subject to confidentiality.
7. Liability
7.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by Data Protection Law.
8. Precedence and term
8.1 If there's a conflict between this DPA and the rest of the agreement on the processing of personal data, this DPA prevails. This DPA lasts for as long as we process Customer Personal Data.
Annex I — Details of processing
Subject matter. Our provision of the managed Magento / Adobe Commerce hosting Service to you.
Duration. For the term of the agreement, plus the grace period after the account ends and until deletion (see the Service Specific Terms).
Nature and purpose. Hosting, operating, securing, backing up, restoring, and supporting your Store and the features you enable — including serving your storefront, sending transactional email on your behalf, custom domains, data import/export, and any AI assistant features.
Frequency. Continuous, for as long as the Service is provided.
Types of personal data. The personal data you and your Shoppers put into or through your Store, which typically includes:
- Shopper data — names; contact details (email address, phone number); billing and shipping addresses; order and transaction history; account login details (passwords are stored hashed); IP addresses and device/browser data; messages and support communications.
- Store user data — names and login details of the people you allow to administer your Store.
Payment card data. Full card details are handled by the payment processor (Stripe) and are not stored by us on your behalf.
Special categories of data. The Service is not intended for special categories of personal data (Article 9 GDPR) or criminal-offence data. You are responsible for not submitting such data unless you have a valid legal basis and have configured the Service appropriately; if you do, you remain the controller and this DPA applies to it.
Categories of data subjects.
- Your Shoppers / customers and visitors to your Store.
- Your own staff and users who administer the Store through the Portal.
Annex II — Technical and organisational security measures
We maintain a documented information-security programme with measures appropriate to the risk, including the following. These measures may evolve as the Service develops, but we will not materially reduce their overall level of protection during the term.
- Encryption in transit. Traffic to and from the Service and your Store is encrypted using current TLS.
- Encryption at rest. Backups of your Store are encrypted, and secrets and sensitive credentials are protected using a managed key-management service.
- Tenant isolation. Each customer's Store, storage, and media are logically and operationally separated from other customers' Stores.
- Access control and least privilege. Access to systems is restricted to authorised personnel on a need-to-know basis, using individual accounts and short-lived, scoped credentials rather than shared long-lived keys. Administrative access uses key-based authentication.
- Network security. The Service sits behind an edge security and content-delivery layer providing TLS, filtering, and bot/abuse protection; administrative interfaces are restricted.
- Backups and recovery. We take regular automated backups of your Store and provide restore tools, as described in the Service Specific Terms.
- Logging and monitoring. We log and monitor platform activity to detect and investigate operational and security issues; logs are handled so as to limit exposure of sensitive data.
- Vulnerability and patch management. We maintain and update the underlying platform images and components, and provide tools for you to keep your Store patched.
- Personnel. Staff with access to personal data are bound by confidentiality obligations and receive appropriate security guidance.
- Incident response. We maintain an incident-response process and will notify you of a personal data breach affecting Customer Personal Data without undue delay (see §5).
- Sub-processor assurance. We impose data-protection and security obligations on our sub-processors that are substantially equivalent to those in this DPA (see Annex III).
Annex III — Sub-processors
We currently engage the following sub-processors:
| Sub-processor | Role | Location / transfer safeguard |
|---|---|---|
| Amazon Web Services (AWS) | Hosting of Stores and backups; sending of Store email | Ireland / EU; AWS DPA and Standard Contractual Clauses where any transfer occurs |
| Cloudflare | Content delivery, custom domains, edge security | Global edge; Cloudflare DPA and EU Standard Contractual Clauses / EU–US Data Privacy Framework |
| Stripe | Billing, subscriptions, payment processing | EU (Stripe Payments Europe, Ltd.), with Standard Contractual Clauses / Data Privacy Framework for any US transfer |