Data Processing Agreement (DPA)
Last updated: 2026-07-09
This Data Processing Agreement ("DPA") forms part of the Werklo Terms of Service between Pinkóczi Kornél egyéni vállalkozó (trading as Werklo) ("Processor", "Werklo") and the merchant operating a shop on the Werklo platform ("Controller"), pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"). It applies automatically to every merchant account — no separate signature is required, consistent with how these terms are accepted at registration.
1. Subject matter and duration
The Processor processes personal data on behalf of the Controller for the purpose of operating the Controller’s online shop (order management, payment facilitation, shipping, transactional email, analytics). This DPA applies for the duration of the Controller’s subscription and until deletion of data per Section 10.
2. Nature and purpose of processing
Hosting and storage of shop data; processing of customer orders; transmission of data to payment, shipping, and invoicing providers the Controller connects; sending transactional emails; aggregated visitor analytics.
3. Categories of data subjects
The Controller’s customers (shop buyers) only. The Controller’s own staff/admin account data (login credentials, admin access) is processed by Werklo as controller, not under this DPA — see the Privacy Policy Section 1.
4. Categories of personal data
Customer: name, e-mail address, phone number, shipping and billing address, order history and contents, custom product specifications (e.g. measurements), payment and shipping references, invoices, and support/chat messages sent through the shop.
No special categories of personal data (Article 9 GDPR) are intended to be processed. The Controller must not submit special-category data (e.g. health, biometric, or data revealing racial/ethnic origin, religious belief, or sexual orientation) through the platform unless separately agreed with Werklo in writing.
5. Documented instructions
The Controller’s documented instructions consist of: (a) the Terms of Service and this DPA; (b) the settings the Controller configures in the platform (in particular which checkout and configurator fields are collected, which third-party providers are connected, and which features are enabled); and (c) specific documented requests made through Werklo support from the Controller’s registered account.
The Processor shall inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions, and may suspend the execution of such an instruction until it is confirmed, clarified or withdrawn by the Controller. The Processor may refuse instructions that are manifestly unlawful.
6. Obligations of the Controller
The Controller warrants and undertakes that it: (1) has and maintains a lawful basis under Article 6 GDPR for the processing of its customers’ personal data; (2) provides its customers with the transparency information required by Articles 13-14 GDPR (its own privacy policy, published in its shop); (3) handles data subject requests addressed to it and instructs the Processor where assistance is needed; (4) configures shop fields, forms, uploads and integrations so that only data necessary for operating the shop is collected, and keeps such configuration lawful; (5) does not collect or request special-category data (Section 4) or data of children where prohibited; and (6) uses the third-party providers it connects (payment, invoicing, shipping) under its own contracts with them and in compliance with law.
The Controller is responsible for the lawfulness of the processing it determines. The Processor is not responsible for assessing the lawfulness of the Controller’s business or of the data the Controller chooses to collect, beyond the obligations expressly set out in this DPA.
7. Obligations of the Processor
The Processor shall: (1) process personal data only on documented instructions from the Controller (Section 5), including with regard to transfers to third countries, unless required to do so by Union or Member State law — in which case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this; (2) ensure persons authorised to process the data are bound by confidentiality; (3) implement appropriate technical and organisational measures (Section 9); (4) respect the conditions for engaging sub-processors (Section 8); (5) assist the Controller, taking into account the nature of processing, in responding to data subject requests; (6) assist the Controller with its Articles 32-36 GDPR obligations, taking into account the information available to the Processor; (7) delete or return all personal data after the end of services (Section 10); (8) make available to the Controller all information necessary to demonstrate compliance with this Article and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
Audits are limited to once per calendar year, unless triggered by an actual security incident or requested by a competent supervisory authority. Audits take place during business hours with reasonable advance notice (at least 14 days), are subject to the auditor signing a confidentiality undertaking, and may not access or expose the data of other tenants sharing the platform. Werklo may satisfy an audit request by providing documentation (security policies, this DPA, relevant certifications or reports) in the first instance; an on-site or remote-access audit is a last resort where documentation does not reasonably address the Controller’s request.
8. Sub-processors
The Controller grants general authorisation to the following sub-processors. The Processor will notify Controllers of intended changes at least 30 days in advance via e-mail or the admin panel, during which the Controller may object on reasonable data protection grounds. If an objection is raised, the Processor will make reasonable efforts to address it (e.g. by proposing an alternative sub-processor or safeguard); if the objection cannot be resolved, the Controller may terminate their subscription before the change takes effect, without penalty for the notice period concerned.
The Processor imposes on each sub-processor, by way of a contract or other legal act under Union or Member State law, data protection obligations substantially equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures (Article 28(4) GDPR). Where a sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor’s obligations.
Supabase Inc. (AWS eu-central-1, Frankfurt) — database, authentication, file storage — EU.
Vercel Inc. — application hosting, edge network — EU / US (Standard Contractual Clauses).
Railway Corp. — hosting for Werklo’s self-operated analytics (Umami) and uptime monitoring (Uptime Kuma) instances, and the error tracking (GlitchTip) application itself — EU (Amsterdam). The error-tracking attachment storage bucket (for files attached to error reports) is hosted on Railway’s US West (California) region — US (Standard Contractual Clauses) — since object storage buckets cannot be moved between regions after creation; migrating it is a planned follow-up. Error capture is configured to exclude request bodies and personal data from error reports, and attachments must not and are not used to store personal data.
Resend (Plus Five Five, Inc.) — transactional e-mail delivery — US (SCCs).
Cloudflare, Inc. — DNS, network security — EU / US (SCCs).
Note: where the merchant connects their own Stripe account or invoicing provider (Szamlazz.hu, Billingo, Fakturoid), that provider acts as the merchant’s own processor/controller under its own terms, not as a Werklo sub-processor.
9. Security measures (Article 32)
Encryption in transit (TLS 1.2+) on all endpoints.
Encryption at rest for the database (managed by Supabase/AWS).
Application-level AES-256-GCM encryption for merchant API credentials.
Row-Level Security enforcing tenant data isolation in the shared database.
Access to production infrastructure restricted to authorised personnel on a least-privilege, need-to-know basis, protected by multi-factor authentication.
Security-relevant events (authentication, administrative actions) are logged.
Automated daily database backups with a 35-day retention cycle.
Dependencies and infrastructure are updated regularly, with priority given to known security vulnerabilities; production credentials are rotated on personnel change or suspected exposure.
A documented incident-response process feeding the breach notification duty in Section 11.
Payment card data is never stored on Werklo systems (handled by Stripe, PCI-DSS).
10. Deletion and retention
When a Controller deletes their shop, a 30-day grace period applies before permanent deletion (see the Terms and Privacy Policy) — the Controller can cancel the deletion or export their data within that window.
Once the grace period elapses: customer personal data in orders is anonymised, not deleted, where retention is required by law (8 years, Hungarian Accounting Act / Szamviteli tv. 169. §); all other tenant data (products, settings, integrations, content) is deleted; database backups containing deleted data age out on the standard backup rotation, typically within 35 days of deletion.
Support/complaint records are retained 5 years (Ptk. limitation period).
11. Data breach notification
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, providing the information required by Article 33(3) GDPR to the extent then known, and updating the Controller as more information becomes available.
12. International transfers
Transfers outside the EEA (see Section 8) rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
Contact for data protection matters: privacy@werklo.net.