werklo

Data Processing Agreement (DPA)

Last updated: 2026-09-27

This Data Processing Agreement ("DPA") forms part of the Werklo Terms of Service between Pinkóczi Kornél egyéni vállalkozó (trading as Werklo) ("Processor", "Werklo") and the merchant operating a shop on the Werklo platform ("Controller"), pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR"). It applies automatically to every merchant account. No separate signature is required, consistent with how these terms are accepted at registration.

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller for the purpose of operating the Controller’s online shop (order management, payment facilitation, shipping, transactional email, analytics). This DPA applies for the duration of the Controller’s subscription and until deletion of data per Section 10.

2. Nature and purpose of processing

Hosting and storage of shop data; processing of customer orders; transmission of data to the payment and invoicing providers the Controller connects; transmission of delivery data to the shipping provider Werklo holds the account with, where the Controller buys a label through the platform (Section 8); sending transactional emails; aggregated visitor analytics.

3. Categories of data subjects

The Controller’s customers (shop buyers), and, depending on the features the Controller uses: holders of buyer accounts in the shop, newsletter subscribers, authors of product reviews, people who contact the shop through its contact forms or live chat, people who send a withdrawal statement through the shop’s withdrawal form, and visitors of the shop (aggregated visit statistics only). The Controller’s own staff/admin account data (login credentials, admin access) is processed by Werklo as controller, not under this DPA. See the Privacy Policy Section 1.

4. Categories of personal data

Customer: name, e-mail address, phone number, shipping and billing address, order history and contents, custom product specifications (e.g. measurements), payment and shipping references, invoices, and support/chat messages sent through the shop.

Depending on the features used: buyer account data (sign-in sessions, saved addresses, measurement profiles), loyalty point balances, newsletter sign-ups with the record of consent, product reviews (name, e-mail address, rating, text), contact-form messages, withdrawal statements (name, e-mail address, order number given, note, time received), files a buyer uploads for a custom piece, and aggregated visit statistics. One-way hashes of IP addresses are used for rate limiting on public forms; sign-in rate-limit records are deleted after one day.

No special categories of personal data (Article 9 GDPR) are intended to be processed. The Controller must not submit special-category data (e.g. health, biometric, or data revealing racial/ethnic origin, religious belief, or sexual orientation) through the platform unless separately agreed with Werklo in writing.

5. Documented instructions

The Controller’s documented instructions consist of: (a) the Terms of Service and this DPA; (b) the settings the Controller configures in the platform (in particular which checkout and configurator fields are collected, which third-party providers are connected, and which features are enabled); and (c) specific documented requests made through Werklo support from the Controller’s registered account.

The Processor shall inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions, and may suspend the execution of such an instruction until it is confirmed, clarified or withdrawn by the Controller. The Processor may refuse instructions that are manifestly unlawful.

6. Obligations of the Controller

The Controller warrants and undertakes that it: (1) has and maintains a lawful basis under Article 6 GDPR for the processing of its customers’ personal data; (2) provides its customers with the transparency information required by Articles 13-14 GDPR (its own privacy policy, published in its shop); (3) handles data subject requests addressed to it and instructs the Processor where assistance is needed; (4) configures shop fields, forms, uploads and integrations so that only data necessary for operating the shop is collected, and keeps such configuration lawful; (5) does not collect or request special-category data (Section 4) or data of children where prohibited; and (6) uses the third-party providers it connects (payment, invoicing, shipping) under its own contracts with them and in compliance with law.

The Controller is responsible for the lawfulness of the processing it determines. The Processor is not responsible for assessing the lawfulness of the Controller’s business or of the data the Controller chooses to collect, beyond the obligations expressly set out in this DPA.

7. Obligations of the Processor

The Processor shall: (1) process personal data only on documented instructions from the Controller (Section 5), including with regard to transfers to third countries, unless required to do so by Union or Member State law, in which case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits this; (2) ensure persons authorised to process the data are bound by confidentiality; (3) implement appropriate technical and organisational measures (Section 9); (4) respect the conditions for engaging sub-processors (Section 8); (5) assist the Controller, taking into account the nature of processing, in responding to data subject requests; (6) assist the Controller with its Articles 32-36 GDPR obligations, taking into account the information available to the Processor; (7) delete or return all personal data after the end of services (Section 10); (8) make available to the Controller all information necessary to demonstrate compliance with this Article and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

Audits are limited to once per calendar year, unless triggered by an actual security incident or requested by a competent supervisory authority. Audits take place during business hours with reasonable advance notice (at least 14 days), are subject to the auditor signing a confidentiality undertaking, and may not access or expose the data of other tenants sharing the platform. Werklo may satisfy an audit request by providing documentation (security policies, this DPA, relevant certifications or reports) in the first instance; an on-site or remote-access audit is a last resort where documentation does not reasonably address the Controller’s request.

8. Sub-processors

The Controller grants general authorisation to the following sub-processors. The Processor will notify Controllers of intended changes at least 30 days in advance via e-mail or the admin panel, during which the Controller may object on reasonable data protection grounds. If an objection is raised, the Processor will make reasonable efforts to address it (e.g. by proposing an alternative sub-processor or safeguard); if the objection cannot be resolved, the Controller may terminate their subscription before the change takes effect, without penalty for the notice period concerned.

The Processor imposes on each sub-processor, by way of a contract or other legal act under Union or Member State law, data protection obligations substantially equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures (Article 28(4) GDPR). Where a sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor’s obligations.

Supabase Inc. (AWS eu-west-1, Ireland), database, authentication, file storage. Data stored in the EU; remote operational access by the provider from outside the EEA under the Standard Contractual Clauses in its Data Processing Addendum.

Vercel Inc., application hosting (Dublin, Ireland region) and global edge network, EU / US (Standard Contractual Clauses).

Railway Corp., hosting for Werklo’s self-operated analytics (Umami) and uptime monitoring (Uptime Kuma) instances, and the error tracking (GlitchTip) application itself. EU (Amsterdam). The error-tracking attachment storage bucket (for files attached to error reports) is hosted on Railway’s US West (California) region, US (Standard Contractual Clauses), since object storage buckets cannot be moved between regions after creation; migrating it is a planned follow-up. Error capture is configured to exclude request bodies and personal data from error reports, and attachments must not and are not used to store personal data.

Resend (Plus Five Five, Inc.), transactional e-mail delivery, US (SCCs).

Cloudflare, Inc., DNS, network security, EU / US (SCCs).

Eurosender SARL, 5 Place de la Gare, L-1616 Luxembourg (Luxembourg register B230321), shipping labels. Where the Controller buys a shipping label through the platform, the Processor buys it on its own Eurosender account (Terms Section 13) and transmits the buyer’s name, delivery address, e-mail address, phone number and any delivery note for the parcel concerned. EU (Luxembourg); no transfer outside the EEA. Unlike the payment, invoicing, e-mail marketing and social providers below, this one runs on the Processor’s credential rather than the Controller’s, which is why it is a sub-processor.

TypeSafe AI, Inc., 255 California St, Suite 1300, San Francisco, CA 94117, US, AI matching of spreadsheet columns when the Controller imports its own product or stock file. It receives column headings and up to five example values per column; columns recognised as contact details travel as a heading only. It is named here, and not only in the Privacy Policy, because that recognition does not extend to personal names, so a file the Controller uploads may incidentally contain buyer data. US, Standard Contractual Clauses (Module 3, processor to processor) under the provider’s published Data Processing Addendum.

This table lists the sub-processors that can process the Controller’s buyer data. Providers that only process Werklo’s own controller data (platform subscription billing via Stripe Payments Europe Ltd., Werklo’s own invoicing via Szamlazz.hu, and the AI drafting and translation of merchant-written text via OpenAI Ireland Limited) are listed in the Privacy Policy at https://www.werklo.net/privacy instead. The two lists are maintained together.

Note: where the merchant connects their own Stripe account, invoicing provider (Szamlazz.hu, Fakturoid), e-mail marketing provider (e.g. Mailchimp) or social account for publishing posts (Pinterest, Instagram, Facebook, Threads), that provider acts as the merchant’s own processor/controller under its own terms and under the account the merchant holds with it, not as a Werklo sub-processor. The Processor transmits data to such a provider only on the Controller’s instruction, given by connecting it, and the Controller is responsible for the terms and privacy notice governing that provider’s own processing.

Card payments in the Controller’s shop run through Stripe Connect: buyers pay into the Controller’s own Stripe account, and the Processor, as the Connect platform, creates those payments on the Controller’s instructions and receives their status (paid, refunded, disputed) for the order screens. Stripe processes the payments under its own terms with the Controller and is not a sub-processor of Werklo.

9. Security measures (Article 32)

Encryption in transit (TLS 1.2+) on all endpoints.

Encryption at rest for the database (managed by Supabase/AWS).

Application-level AES-256-GCM encryption for merchant API credentials.

Row-Level Security enforcing tenant data isolation in the shared database.

Access to production infrastructure restricted to authorised personnel on a least-privilege, need-to-know basis, protected by multi-factor authentication.

Security-relevant events (authentication, administrative actions) are logged.

Automated daily database backups with a 35-day retention cycle.

Dependencies and infrastructure are updated regularly, with priority given to known security vulnerabilities; production credentials are rotated on personnel change or suspected exposure.

A documented incident-response process feeding the breach notification duty in Section 11.

Payment card data is never stored on Werklo systems (handled by Stripe, PCI-DSS).

10. Deletion and retention

When a Controller deletes their shop, a 30-day grace period applies before permanent deletion (see the Terms and Privacy Policy). The Controller can cancel the deletion or export their data within that window.

Return of data: the Controller can download all of its data at any time, including during the grace period and while a feature is restricted, under Settings > Export your data in the admin panel: one CSV file per kind of record (products, orders, order lines, customers, saved addresses, loyalty points, reviews, withdrawal statements, newsletter subscribers, coupons, enquiries, blog posts), complete and unfiltered except for credentials and Werklo-internal hashes. Product photos remain reachable at the addresses given in the product file until permanent deletion.

Once the grace period elapses: customer personal data in orders is anonymised, not deleted, where retention is required by law (8 years, Hungarian Accounting Act / Szamviteli tv. 169. §); all other tenant data (products, settings, integrations, content) is deleted; database backups containing deleted data age out on the standard backup rotation, typically within 35 days of deletion. Uploaded files (product images, theme images, buyer file uploads) are deleted from our file storage at the same time. Issued invoices are the exception in both directions: the invoice is an accounting document and is retained intact -- not anonymised -- for 8 years, with the buyer’s name and address on it (Számviteli tv. 169. § (2); for electronic invoices, in electronic form, Áfa tv. 179. § (2)), and stored invoice PDFs are therefore excluded from the file deletion above.

Support/complaint records are retained 5 years (Ptk. limitation period).

11. Data breach notification

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, providing the information required by Article 33(3) GDPR to the extent then known, and updating the Controller as more information becomes available.

12. International transfers

Transfers outside the EEA (see Section 8) rely on the European Commission’s Standard Contractual Clauses, which are the mechanism the Processor invokes in each case. Where a recipient is additionally certified under the EU-US Data Privacy Framework, that adequacy decision applies alongside the Clauses; the Processor does not rely on it on its own for any recipient.

Contact for data protection matters: privacy@werklo.net.