Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") supplements the Terms and Conditions for the use of the Dovail Service (the "Main Agreement") between the Customer (as "Controller") and
slideNbite UG (haftungsbeschränkt)
Frahmredder 37
22393 Hamburg, Germany
Commercial Register: Amtsgericht Hamburg (Hamburg Local Court), HRB 195340
Managing Director: Marten Henke
Email: support.dovail@slidenbite.com
Website: www.dovail.slidenbite.com
(as "Processor", together with the Controller the "Parties").
This DPA reflects the requirements of Art. 28 GDPR for the processing of personal data of the Controller's End Customers carried out by the Processor on the Controller's behalf. It becomes part of the Main Agreement as described in Section 6.2 of the Terms and Conditions. In the event of a conflict between this DPA and the Main Agreement on matters of data protection, this DPA prevails.
1. Subject Matter and Duration
The subject matter of this DPA is the processing of personal data of the Controller's End Customers by the Processor in connection with the back-in-stock waitlist and notification functionality of the Dovail App, as further described in Annex 1.
The term of this DPA follows the term of the Main Agreement. It ends automatically upon termination of the Main Agreement, subject to the post-termination obligations set out in Section 9.
2. Nature and Purpose of Processing
Nature and purpose of the processing are described in Annex 1. In summary, the Processor processes End Customer personal data to operate back-in-stock waitlists, to send transactional Restock Notifications, to provide secure self-service confirmation, management and deletion links, and to measure whether a notification resulted in an order for the Controller's reporting purposes.
3. Type of Personal Data and Categories of Data Subjects
The types of personal data processed and the categories of data subjects affected are described in Annex 1.
4. Rights and Obligations of the Controller
The Controller alone is responsible for assessing the lawfulness of the processing, in particular for obtaining a valid consent (opt-in) from End Customers before their data is submitted to the Service, in accordance with Section 6.1 of the Terms and Conditions. The Controller is entitled to issue instructions to the Processor regarding the type, scope and procedure of the processing, within the functionality made available by the Service. Instructions given through the ordinary configuration options of the Service (e.g. dispatch rules, opt-in text, deletion of individual entries via the dashboard) are deemed documented instructions for the purposes of Art. 28(3)(a) GDPR. Any instruction going beyond the Service's ordinary functionality must be given in text form (email is sufficient) to support.dovail@slidenbite.com.
5. Obligations of the Processor
5.1 Processing on Documented Instructions
The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits this on important grounds of public interest.
5.2 Confidentiality
The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to personal data is limited to those employees and contractors who require it to perform their duties under the Main Agreement.
5.3 Security of Processing
The Processor shall implement the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk within the meaning of Art. 32 GDPR. The Processor may update these measures from time to time, provided the overall level of security is not reduced.
5.4 Sub-Processors
The Controller grants the Processor general written authorisation to engage the sub-processors listed in Annex 3 as of the date of this DPA. The Processor shall inform the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance, by email or via an in-app or dashboard notification. The Controller may object to such a change within this period for good cause related to data protection; in the absence of a timely objection, the change is deemed approved. If the Controller objects for good cause and the Parties cannot resolve the objection, either Party may terminate the Main Agreement with respect to the affected processing.
The Processor shall impose the same data protection obligations set out in this DPA on any sub-processor, by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data protection obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor's obligations.
5.5 Assistance with Data Subject Rights
Taking into account the nature of the processing, the Processor shall assist the Controller, insofar as this is possible, by appropriate technical and organisational measures, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). Where the Processor receives such a request directly from an End Customer, it will, without undue delay, forward the request to the Controller and will not itself respond to the data subject, unless expressly instructed by the Controller.
5.6 Assistance with Controller Obligations
The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR (security of processing, notification of a personal data breach to the supervisory authority, communication of a personal data breach to the data subject, data protection impact assessment, prior consultation), taking into account the nature of processing and the information available to the Processor.
5.7 Personal Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event no later than 24 hours, after becoming aware of a personal data breach affecting the Controller's End Customer data, in accordance with Section 7 of the Terms and Conditions. The notification shall, to the extent known at the time, describe the nature of the breach, the categories and approximate number of data subjects and personal data records concerned, the likely consequences, and the measures taken or proposed to address the breach. Where information is not available at the time of the initial notification, the Processor shall provide it in phases without further undue delay.
Upon becoming aware of a personal data breach, the Processor shall, at its own cost, take immediate steps to contain and remedy the breach, investigate the incident, take reasonable measures to mitigate anticipated further harm to the Controller and to affected data subjects, and respond without undue delay to questions from the Controller relating to the breach, including regular updates on the progress of its investigation.
The Controller acknowledges that, where the personal data affected constitutes Merchant Data within the meaning of the Shopify API Terms of Service, the Processor is separately obliged to notify Shopify of any actual or suspected breach or compromise of that data no later than 24 hours after becoming aware of it. Such notification to Shopify does not replace, and is made in addition to, the notification to the Controller under this Section 5.7.
5.8 Deletion and Return of Data
Subject to Section 9 of this DPA, the Processor shall, at the choice of the Controller, delete or return all personal data processed on behalf of the Controller after the end of the provision of the Service, and shall delete existing copies unless Union or Member State law requires storage of the personal data.
5.9 Demonstrating Compliance
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to Section 8 of this DPA.
6. No Independent Decision-Making
The Processor shall not use the personal data processed under this DPA for its own purposes, in particular not for marketing purposes towards End Customers, and shall not make personal data available to third parties except as described in Annex 3 or as otherwise agreed in writing with the Controller.
7. Immediate Notification of Infringing Instructions
The Processor shall immediately inform the Controller if, in its opinion, an instruction given by the Controller infringes the GDPR or other applicable data protection provisions.
8. Audits and Inspections
The Controller may verify the Processor's compliance with this DPA by requesting relevant documentation (such as this DPA, the technical and organisational measures described in Annex 2, and, where available, current audit reports, certifications or self-assessments of the Processor's sub-processors). Where such documentation does not reasonably address the Controller's request, the Controller may conduct an on-site or remote audit, including inspections, during normal business hours, subject to at least 30 days' prior written notice and no more than once per calendar year, unless a personal data breach or a binding order of a supervisory authority justifies a shorter notice period or an additional audit. The Controller shall bear its own costs of any such audit; the Processor may charge reasonable costs for the time and resources spent supporting an audit beyond the documentation described above.
9. Term, Termination and Post-Termination Obligations
This DPA remains in effect for as long as the Processor processes personal data on behalf of the Controller under the Main Agreement. Upon termination of the Main Agreement, the Processor shall handle personal data in accordance with the retention and deletion rules set out in Section 6 of the Processor's privacy policy (available at www.dovail.slidenbite.com/legal/privacy) and Section 5 of the Terms and Conditions, unless the Controller requests, prior to termination, that its data be exported instead of deleted, to the extent technically feasible.
10. Liability
Each Party's liability towards the other under or in connection with this DPA is subject to the limitations of liability set out in Section 8 of the Terms and Conditions. This does not affect the Parties' liability towards data subjects and supervisory authorities under Art. 82 and 83 GDPR, which remains governed by the GDPR.
11. Miscellaneous
Should any individual provision of this DPA be or become invalid, this shall not affect the validity of the remaining provisions. This DPA is governed by German law and, to the extent legally permissible, the exclusive venue is Hamburg, consistent with Section 13 of the Terms and Conditions. In the event of any conflict between the annexes of this DPA and its main body, the main body prevails unless the relevant annex explicitly states otherwise.
Annex 1 — Details of Processing
A. Subject Matter
Provision of the Dovail back-in-stock waitlist and Restock Notification functionality, embedded in the Controller's Shopify store.
B. Duration
For the term of the Main Agreement, as set out in Section 9 above.
C. Nature and Purpose of Processing
- Collecting and storing End Customer waitlist sign-ups for out-of-stock products or product variants.
- Sending transactional email notifications to End Customers when a requested product or variant becomes available again.
- Providing secure, token-based self-service links for End Customers to confirm, manage or withdraw their waitlist entry.
- Determining delivery availability for a requested destination and quantity via the Shopify Storefront API.
- Issuing single-use discount codes to End Customers on completion of a waitlist sign-up and on reconfirmation of an existing waitlist entry, and recording their redemption status.
- Measuring, on a limited and aggregated basis, whether a notified waitlist request resulted in an order, for reporting to the Controller.
D. Categories of Data Subjects
End Customers of the Controller who sign up for a Restock Notification through the Service.
E. Categories of Personal Data
- First and last name, where provided
- Email address
- Delivery address (street, postal code, city, country and, where applicable, province)
- Company name, where voluntarily provided for a business delivery
- Requested quantity and product or product variant of interest
- Preferred language
- Consent text, consent source and consent timestamp
- Confirmation, withdrawal and unsubscription status and timestamps
- Technical identifiers and access tokens used for secure self-service links
- Notification and transactional email delivery status
- Single-use discount codes issued in connection with the waitlist entry, including their issue date and redemption status
- Limited order data used to calculate whether a notified request resulted in an order
Annex 2 — Technical and Organisational Measures
The measures set out below describe the technical and organisational measures implemented by the Processor pursuant to Art. 32 GDPR. The Processor may update these measures from time to time, provided the overall level of security is not reduced.
1. Confidentiality
- Access control (premises): The Processor does not operate its own data centre. Physical access control to servers is provided by the sub-processors listed in Annex 3 (Supabase, STRATO) under their own published technical and organisational measures.
- System access control: Access to production systems requires individual, named user accounts. Multi-factor authentication is enforced for the Supabase, Shopify and Postmark accounts used for production access, as well as for SSH access to the production server. Shared or generic accounts are not used.
- Data access control: Access to production systems and personal data is restricted to authorised personnel and limited to what is necessary for business operations. Production access is currently held by two named individuals.
- Separation control: Controller data is logically separated by shop/tenant at the database level so that one Merchant's End Customer data cannot be accessed through another Merchant's account.
- Pseudonymisation: Each waitlist entry is addressed through its own cryptographically random, non-guessable and unique token. Each End Customer additionally receives a separate cryptographically random token for managing and deleting their own profile. Tokens are scoped to a single purpose and cannot be derived from one another or from the personal data they relate to.
2. Integrity
- Transmission control: All data in transit is encrypted via TLS/HTTPS.
- Input and access control: Access to personal data is logged. Access logs are retained for no longer than 90 days, consistent with Section 6 of the Privacy Policy, and are then deleted.
3. Availability and Resilience
- Backups: The Supabase production database is backed up daily. Backups are encrypted and retained for seven days.
- Incident response: A documented incident response process is in place. Responsibility for the process is assigned to two named individuals, who are also the contact points for notifications under Section 5.7 of this DPA.
4. Procedures for Regular Review
- These technical and organisational measures are reviewed at least annually, and additionally whenever the Service undergoes a material change affecting the processing of personal data. The review is documented and assigned to a named individual.
Annex 3 — Authorised Sub-Processors
Shopify International Ltd. is listed below solely for the delivery availability check described in Annex 1.C, in which the End Customer's delivery address, requested quantity and product variant are submitted to a Shopify API for this specific purpose. For its separate role as platform, billing and OAuth infrastructure provider for the Controller's store, Shopify acts as an independent controller and is not covered by this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database hosting (storage of waitlist data and app configuration) | EU (Frankfurt region) |
| Postmark (AC PM LLC, an ActiveCampaign company) | Transactional email delivery | United States (SCCs in place) |
| STRATO GmbH | Hosting of the public website, application server and domain infrastructure | Germany / EU |
| Shopify International Ltd. | Delivery availability check only — submission of End Customer delivery address, requested quantity and product variant via a Shopify API | Ireland (EU) |