Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms & Conditions between you (the "Customer") and Robin Wessels ("StoreLo", also operating as "StoreLoWidget", "we", "us"). It applies whenever you use StoreLo to process personal data on behalf of others — in particular the data of visitors who use a locator you embed. By accepting the Terms, you accept this DPA. A countersigned PDF copy is available on request via info@robinwessels.com.
- Definitions
- Roles of the parties
- Scope and details of processing
- Our obligations as processor
- Sub-processors
- International data transfers
- Assistance with data subject rights
- Personal data breaches
- Audits and information
- Deletion and return of data
- Your obligations as controller
- Liability and term
- Governing law and contact
This DPA reflects the parties' agreement on the processing of personal data in accordance with Article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection laws.
1. Definitions
"Data protection law" means the GDPR, the UK GDPR, and any other applicable law relating to the processing of personal data. "Controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data that we process on your behalf under the Terms. "Sub-processor" means any third party engaged by us to process Customer Personal Data.
2. Roles of the parties
For Customer Personal Data, you act as the controller (or, where you act on behalf of a third party, as a processor) and we act as your processor. We process Customer Personal Data only on your documented instructions, including those set out in the Terms, this DPA, and your configuration of the service, unless required to act otherwise by law (in which case we will inform you, unless that law prohibits it on important grounds of public interest).
For data where we determine the purposes and means of processing — for example our own account, billing, and marketing-site analytics data — we act as an independent controller, governed by our Privacy Policy, not this DPA.
3. Scope and details of processing
The following describes the processing under this DPA (GDPR Art. 28(3) and Art. 30):
- Subject matter: provision of the hosted store-locator service.
- Duration: for the term of the Terms, plus the retention period in section 10.
- Nature and purpose: hosting, storing, and serving the store locations you upload, and processing end-visitor search and approximate-location data to return nearby results and basic analytics, on your behalf.
- Types of personal data: (a) your account data (name, email); (b) data you place in your locator (which may include store contact emails, phone numbers, addresses); (c) end-visitor data (search queries, approximate GPS location only where the visitor grants browser permission, and anonymised/technical event data).
- Categories of data subjects: you and your staff; contacts you include in your locator; visitors to sites that embed your locator.
We do not build advertising profiles of end-visitors and we do not sell Customer Personal Data.
4. Our obligations as processor
In line with GDPR Art. 28(3), we will:
- process Customer Personal Data only on your documented instructions;
- ensure that persons authorised to process Customer Personal Data are bound by confidentiality;
- implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (GDPR Art. 32), including encryption in transit and at rest, access controls, row-level isolation between customers, and least-privilege key management;
- respect the conditions in section 5 for engaging sub-processors;
- assist you, taking into account the nature of processing, in fulfilling your obligations to respond to data subject requests (section 7);
- assist you in ensuring compliance with GDPR Art. 32–36 (security, breach notification, and data protection impact assessments), taking into account the information available to us;
- at your choice, delete or return Customer Personal Data at the end of the service (section 10); and
- make available to you the information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits (section 9).
5. Sub-processors
You provide general authorisation for us to engage the sub-processors below to process Customer Personal Data. Each is bound by data protection terms no less protective than this DPA. We remain responsible for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Edge hosting, CDN, security, rate limiting | EU / Global (edge) |
| Supabase, Inc. | Database and authentication hosting | EU |
| Stripe, Inc. | Payment and subscription processing | EU / US |
| Sendinblue / Brevo SAS | Transactional and lead email | EU |
| Google LLC (Analytics) | Marketing-site analytics (consent-based only) | US |
| Meta Platforms Ireland Ltd | Meta Pixel and Conversions API event forwarding, only for customers who enable it with their own pixel and token (consent-based) | EU / US |
We will give you reasonable prior notice of any intended addition or replacement of a sub-processor (by updating this page and, on request, by email). If you have a reasonable, data-protection-based objection, contact us within 30 days; we will work in good faith to address it, and if we cannot, you may terminate the affected part of the service.
6. International data transfers
Where Customer Personal Data is transferred outside the EEA or UK, we rely on appropriate safeguards under GDPR Chapter V, including the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum where relevant, and, where applicable, the EU–US Data Privacy Framework. We apply supplementary measures (encryption, pseudonymisation, access controls) where required.
7. Assistance with data subject rights
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection). Many of these you can fulfil yourself directly from the dashboard, including exporting your data and permanently deleting your account and all associated data. If a data subject contacts us directly about Customer Personal Data, we will, where lawful, refer them to you.
8. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Customer Personal Data, and provide you with information reasonably available to us to help you meet your own notification obligations under GDPR Art. 33–34.
9. Audits and information
We will make available to you information reasonably necessary to demonstrate our compliance with this DPA. Where you reasonably require further assurance, we will respond to a reasonable number of written questions, and — no more than once per year, on reasonable notice and subject to confidentiality — allow an audit of our relevant processing, conducted in a way that does not compromise the security or data of other customers. The party requesting the audit bears its own costs.
10. Deletion and return of data
On termination or expiry of the service, we will, at your choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. Unless you ask us to delete sooner, we retain account data for up to 12 months after cancellation in case you reactivate, after which it is deleted (see Privacy Policy section 13). End-visitor search and analytics events are retained for up to 14 months and cookie-consent records for up to 24 months, then deleted. You can trigger immediate, permanent deletion at any time from the dashboard.
11. Your obligations as controller
You warrant that you have a lawful basis and any required notices or consents to provide Customer Personal Data to us for processing, and that your instructions comply with data protection law. You are responsible for the accuracy and legality of the data you upload, for disclosing the end-visitor processing in your own privacy notice, and for obtaining end-visitor consent at the browser level both for location access and for any analytics or advertising trackers you configure through the service (for example a Meta Pixel), which you load on your own site under your own controllership. Where you enable server-side conversion forwarding (for example the Meta Conversions API), you instruct us to transmit the relevant end-visitor events to your chosen advertising platform using the pixel identifier and access token you supply; you remain the controller for that processing, the platform is your recipient or processor under your own arrangements, and you warrant you have obtained the necessary consent and provided the required notices.
12. Liability and term
This DPA takes effect when you accept the Terms and continues for as long as we process Customer Personal Data on your behalf. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.
13. Governing law and contact
This DPA is governed by the laws of the Netherlands, without prejudice to mandatory data protection law. Questions, objections, or requests for a signed copy: info@robinwessels.com.