Try for free Login Home Features Pricing Demo
Platforms

Data Processing Agreement

Last updated: June 5, 2026 · Effective: June 5, 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms & Conditions between you (the "Customer") and Robin Wessels ("StoreLo", also operating as "StoreLoWidget", "we", "us"). It applies whenever you use StoreLo to process personal data on behalf of others — in particular the data of visitors who use a locator you embed. By accepting the Terms, you accept this DPA. A countersigned PDF copy is available on request via info@robinwessels.com.

Contents
  1. Definitions
  2. Roles of the parties
  3. Scope and details of processing
  4. Our obligations as processor
  5. Sub-processors
  6. International data transfers
  7. Assistance with data subject rights
  8. Personal data breaches
  9. Audits and information
  10. Deletion and return of data
  11. Your obligations as controller
  12. Liability and term
  13. Governing law and contact

This DPA reflects the parties' agreement on the processing of personal data in accordance with Article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws.

1. Definitions

"Data protection law" means the GDPR, the UK GDPR, and any other applicable law relating to the processing of personal data. "Controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data that we process on your behalf under the Terms. "Sub-processor" means any third party engaged by us to process Customer Personal Data.

2. Roles of the parties

For Customer Personal Data, you act as the controller (or, where you act on behalf of a third party, as a processor) and we act as your processor. We process Customer Personal Data only on your documented instructions, including those set out in the Terms, this DPA, and your configuration of the service, unless required to act otherwise by law (in which case we will inform you, unless that law prohibits it on important grounds of public interest).

For data where we determine the purposes and means of processing — for example our own account, billing, and marketing-site analytics data — we act as an independent controller, governed by our Privacy Policy, not this DPA.

3. Scope and details of processing

The following describes the processing under this DPA (GDPR Art. 28(3) and Art. 30):

We do not build advertising profiles of end-visitors and we do not sell Customer Personal Data.

4. Our obligations as processor

In line with GDPR Art. 28(3), we will:

5. Sub-processors

You provide general authorisation for us to engage the sub-processors below to process Customer Personal Data. Each is bound by data protection terms no less protective than this DPA. We remain responsible for their performance.

Sub-processorPurposeLocation
Cloudflare, Inc.Edge hosting, CDN, security, rate limitingEU / Global (edge)
Supabase, Inc.Database and authentication hostingEU
Stripe, Inc.Payment and subscription processingEU / US
Sendinblue / Brevo SASTransactional and lead emailEU
Google LLC (Analytics)Marketing-site analytics (consent-based only)US
Meta Platforms Ireland LtdMeta Pixel and Conversions API event forwarding, only for customers who enable it with their own pixel and token (consent-based)EU / US

We will give you reasonable prior notice of any intended addition or replacement of a sub-processor (by updating this page and, on request, by email). If you have a reasonable, data-protection-based objection, contact us within 30 days; we will work in good faith to address it, and if we cannot, you may terminate the affected part of the service.

6. International data transfers

Where Customer Personal Data is transferred outside the EEA or UK, we rely on appropriate safeguards under GDPR Chapter V, including the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum where relevant, and, where applicable, the EU–US Data Privacy Framework. We apply supplementary measures (encryption, pseudonymisation, access controls) where required.

7. Assistance with data subject rights

Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection). Many of these you can fulfil yourself directly from the dashboard, including exporting your data and permanently deleting your account and all associated data. If a data subject contacts us directly about Customer Personal Data, we will, where lawful, refer them to you.

8. Personal data breaches

We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Customer Personal Data, and provide you with information reasonably available to us to help you meet your own notification obligations under GDPR Art. 33–34.

9. Audits and information

We will make available to you information reasonably necessary to demonstrate our compliance with this DPA. Where you reasonably require further assurance, we will respond to a reasonable number of written questions, and — no more than once per year, on reasonable notice and subject to confidentiality — allow an audit of our relevant processing, conducted in a way that does not compromise the security or data of other customers. The party requesting the audit bears its own costs.

10. Deletion and return of data

On termination or expiry of the service, we will, at your choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. Unless you ask us to delete sooner, we retain account data for up to 12 months after cancellation in case you reactivate, after which it is deleted (see Privacy Policy section 13). End-visitor search and analytics events are retained for up to 14 months and cookie-consent records for up to 24 months, then deleted. You can trigger immediate, permanent deletion at any time from the dashboard.

11. Your obligations as controller

You warrant that you have a lawful basis and any required notices or consents to provide Customer Personal Data to us for processing, and that your instructions comply with data protection law. You are responsible for the accuracy and legality of the data you upload, for disclosing the end-visitor processing in your own privacy notice, and for obtaining end-visitor consent at the browser level both for location access and for any analytics or advertising trackers you configure through the service (for example a Meta Pixel), which you load on your own site under your own controllership. Where you enable server-side conversion forwarding (for example the Meta Conversions API), you instruct us to transmit the relevant end-visitor events to your chosen advertising platform using the pixel identifier and access token you supply; you remain the controller for that processing, the platform is your recipient or processor under your own arrangements, and you warrant you have obtained the necessary consent and provided the required notices.

12. Liability and term

This DPA takes effect when you accept the Terms and continues for as long as we process Customer Personal Data on your behalf. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.

13. Governing law and contact

This DPA is governed by the laws of the Netherlands, without prejudice to mandatory data protection law. Questions, objections, or requests for a signed copy: info@robinwessels.com.