Data Processing Agreement (Art. 28 GDPR)
Version: 1.0 · Last updated: 2026-10-08 · Effective from: 8 October 2026
This Data Processing Agreement ("DPA") forms part of the Lektoro Terms of Service ("Terms") between:
- the Merchant using one or more Lektoro apps (the "Controller"), and
- Maciej Kaczmarczyk (Lektoro), ul. Warszawska 87/16, 66-400 Gorzów Wielkopolski, Poland, a natural person conducting unregistered activity (Art. 5 of the Polish Entrepreneurs' Law; no entry in CEIDG, no NIP or REGON; identified by name and address), not registered for VAT, e-mail legal@lektoro.pl (the "Processor").
It is concluded when the Merchant accepts the Terms by installing an app. On request, the Processor will provide a copy of this DPA for signature (including electronic signature). Terms not defined here have the meaning given in Regulation (EU) 2016/679 ("GDPR").
1. Subject matter and duration
1.1 The Processor processes personal data on behalf of the Controller only to provide the apps listed in Annex I (the "Services").
1.2 The DPA applies for as long as the Processor processes personal data for the Controller, i.e. from installation of an app until deletion of the data under section 10.
2. Nature, purpose, data and data subjects
The nature and purpose of processing, the types of personal data and the categories of data subjects for each app are described in Annex I. The Controller will not upload or enter into the apps special categories of data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR), and will not enter personal data in fields not intended for it (e.g. incident descriptions, notes).
3. Instructions
3.1 The Processor processes personal data only on documented instructions of the Controller, including with regard to transfers to third countries, unless required to do so by EU or Member State law; in that case the Processor will inform the Controller before processing, unless the law prohibits it.
3.2 The Terms, this DPA, the configuration of the apps by the Controller (settings, enabled features, integrations, granted permissions) and the Controller's actions in the apps constitute the Controller's documented instructions. Further instructions must be in writing (e-mail is sufficient) and within the scope of the Services.
3.3 The Processor will inform the Controller immediately if, in its opinion, an instruction infringes the GDPR or other data protection law.
4. Confidentiality
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. At present only the Processor himself has access to production systems.
5. Security
5.1 The Processor implements the technical and organisational measures described in Annex II (Art. 32 GDPR).
5.2 The Processor may update the measures as technology develops, provided the overall level of security is not reduced.
6. Subprocessors
6.1 The Controller gives a general authorisation to engage subprocessors. The current list is in Annex III and at https://lektoro.pl/legal/subprocessors/.
6.2 The Processor will inform the Controller of any intended addition or replacement of subprocessors at least 30 days in advance by updating the list and by e-mail to the shop's contact address. The Controller may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the affected Services by uninstalling the app; fees already paid for the current billing period are not refunded (fees are charged and refunded by Shopify under its rules).
6.3 The Processor imposes on each subprocessor, by contract, data protection obligations providing the same level of protection as this DPA, and remains liable to the Controller for the performance of the subprocessor's obligations.
6.4 Not subprocessors. Shopify (the platform the Controller uses and on which the apps run) and the services the Controller chooses to connect (e.g. Google Merchant Center, Slack, eBay, the Controller's 3PL or own webhook endpoint) are not subprocessors of the Processor. Data sent to them on the Controller's instruction is the Controller's disclosure.
7. International transfers
7.1 The Processor stores the personal data within the EEA (SEOHOST Sp. z o.o., servers in Poland).
7.2 Transfers to a third country by the Processor or a subprocessor take place only if the conditions of Chapter V GDPR are met, in particular on the basis of an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 3 for processor-to-subprocessor transfers), together with supplementary measures where necessary.
8. Assistance to the Controller
8.1 Data subject requests. Taking into account the nature of processing, the Processor assists the Controller by
appropriate technical and organisational measures in responding to requests under Arts. 12–22 GDPR. The apps
implement Shopify's customers/data_request and customers/redact webhooks as described in Annex I. Where an app
holds data linked to the customer or the listed orders (3PL Case-Pack Picker, DRS Deposit & Returns, EPR Packaging
Report), a customers/data_request is stored (identifiers only) and the Controller is shown a notice in the app with
a CSV/JSON download of the matching records, for the Controller to answer the data subject; the other apps hold no
customer data and only acknowledge and log the request. If a data
subject contacts the Processor directly, the Processor will forward the request to the Controller without undue
delay and will not respond itself unless instructed.
8.2 Other assistance. The Processor assists the Controller in ensuring compliance with Arts. 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and the information available to the Processor.
9. Personal data breaches
9.1 The Processor notifies the Controller of a personal data breach affecting the Controller's data without undue delay and where feasible within 48 hours after becoming aware of it, by e-mail to the shop's contact address.
9.2 The notification includes, as far as available: the nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed, and a contact point. The Processor's contact point is legal@lektoro.pl. Information may be provided in phases.
9.3 The Processor documents breaches and takes reasonable steps to contain them and mitigate their effects.
10. Deletion and return of data
10.1 During the contract the Controller can export its data using the export functions of each app (CSV, JSON, printable reports) and delete data in the apps where the apps provide this.
10.2 After uninstallation the Processor deletes the Shopify access tokens immediately and keeps the remaining
data for 48 hours (to allow recovery from accidental uninstallation). On receipt of Shopify's shop/redact webhook
(sent 48 hours after uninstallation) the Processor deletes all personal data of the Controller from the app
databases. Backups are overwritten within 30 days. If the shop/redact webhook is not received, the Processor
deletes the data automatically once 90 days have passed since uninstallation (the apps record the uninstallation
date; a daily clean-up runs with each app's scheduled jobs or, in apps without scheduled jobs, with the app's
regular activity), unless the app has been reinstalled in the meantime.
10.3 The obligation to delete does not apply to data the Processor must keep under EU or Member State law.
10.4 On request, the Processor confirms deletion in writing.
11. Information and audits
11.1 The Processor makes available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR, primarily through this DPA, its annexes, the Privacy Policy and written answers to reasonable questionnaires.
11.2 Where this is not sufficient, the Controller (or an independent auditor bound by confidentiality, who is not a competitor of the Processor) may carry out an audit, including an inspection, with at least 30 days' written notice, during business hours, not more than once per 12 months unless required by a supervisory authority or following a breach. The Controller bears its own costs . Audits of subprocessors are carried out by relying on their certifications and reports.
12. Liability
Liability under this DPA is governed by Art. 82 GDPR and, between the parties, by the liability provisions of the Terms, to the extent permitted by law .
13. Final provisions
13.1 In case of conflict, this DPA prevails over the Terms with regard to data protection.
13.2 This DPA is governed by Polish law. The courts named in the Terms have jurisdiction.
13.3 The Processor may amend this DPA to reflect changes in law, Shopify requirements or the Services, with notice as provided in the Terms; amendments must not reduce the level of protection.
Annex I – Description of processing per app
Common to all apps
- Nature of processing: collection through the Shopify Admin API, webhooks and app extensions; storage; organisation; analysis and calculation; display in Shopify admin; export at the Controller's request; deletion.
- Data subjects common to all apps: the Controller's staff members who use the apps (only a Shopify user ID is recorded where stated below; the apps use offline access tokens and do not receive staff names or e-mails from Shopify ).
- Duration: while the app is installed, then until deletion under section 10 (48 hours after uninstallation, at
the latest 90 days if
shop/redactis not received; backups up to 30 days). Shorter periods are stated per app. - Privacy webhooks:
shop/redactdeletes all data of the shop in every app.customers/data_request: 3PL Case-Pack Picker, DRS Deposit & Returns and EPR Packaging Report store the request (customer ID, order IDs, request ID – no e-mail or phone) and offer the Controller a CSV/JSON download of the matching records (pick plans of the listed orders; store-credit payouts of the customer and POS sales of the listed orders; ledger entries of the listed orders); the stored request is deleted oncustomers/redactfor that customer and with the shop's data. The other apps hold no customer data.
| App | Data subjects | Personal data processed | Purpose | Retention specifics | customers/redact |
|---|---|---|---|---|---|
| 3PL Case-Pack Picker | Customers of the Controller (indirectly, via orders) | Fulfillment order ID, order name, status, hold reason, assigned location name, line SKUs and quantities (no name, address, e-mail, phone); data in order CSVs uploaded by the Controller (only order, SKU, quantity used) | Pick plans, export to the Controller's 3PL, reconciliation | Pick plans deleted after the Controller's retention setting (default 90 days) | Deletes pick plans of the listed orders and stored data requests of the customer |
| DRS Deposit & Returns | Customers of the Controller; POS staff | Shopify customer ID (only for store-credit payouts), payout amount; Shopify staff user ID for POS transactions and returns; POS location ID | Deposit ledger, payouts, limits, reporting | Until shop/redact | Removes the customer ID from payout records; deletes stored data requests of the customer |
| Accessibility Audit | – (none expected) | Theme code may incidentally contain personal data typed into it by the Controller | Accessibility scan and patches | Scan history 3/30/200 scans by plan | No customer data |
| EPR Packaging Report | Customers of the Controller (indirectly); staff | Order ID and name, destination country code, order source, line SKUs and quantities, refunds; Shopify user ID or "admin" in audit log; data in uploaded CSVs (only listed columns used, other personal data discarded) | EPR packaging ledger and reports | Until shop/redact | Removes links between ledger entries and the customer's orders; deletes stored data requests of the customer |
| Feed & Pixel Guard | Recipients of alerts; storefront visitors (aggregated only) | Alert e-mail address (may identify a person), Slack webhook URL; Google Merchant Center account ID; storefront visitor IP address processed transiently in memory for rate limiting (not stored); aggregated hourly event counts (not personal data) | Feed and pixel monitoring, alerts | Check history 7/90/365 days by plan | No customer data |
| GPSR Safety Info | Contact persons of economic operators (manufacturers, EU responsible persons, importers), staff | Name, postal address, e-mail, phone and contact URL of operators (where a natural person); Shopify user ID in activity log and versions | GPSR information management and publication on the storefront (public by law, Art. 19 GPSR) | Until shop/redact | No customer data |
| Green Claims Checker | Staff; authors named in store content | Shopify user ID or name entered by staff as decision maker; short excerpts of store texts (may contain names) | Claim detection, evidence and audit log | Until shop/redact | No customer data |
| HS Codes & Customs | – (none expected) | No personal data expected (product and customs data only) | Customs data audit and fixes | Until shop/redact | No customer data |
| Oversell & Sync Watch | Recipients of alerts; the Controller's eBay account holder | Shop contact e-mail, alert recipient e-mails, Slack/webhook URLs; eBay user ID, eBay account reference (EIAS), encrypted eBay tokens (only if the connector is enabled) | Inventory sync monitoring, alerts, eBay comparison | Issue history 7/30/90 days by plan | No customer data |
| MOQ Purchase Orders | Contact persons of the Controller's suppliers | Supplier contact name, e-mail, phone, notes | Supplier management, purchase orders | Daily demand 400 days; last 5 reorder runs; rest until shop/redact | No customer data |
| Currency Rounding | – (none expected) | No personal data expected (prices and markets only) | Price rounding | Until shop/redact | No customer data |
| Textile Passport DPP | Contact persons of suppliers and of the economic operator; staff; visitors of public passport pages | Supplier contact name and e-mail; operator name, address, e-mail; supplier portal token hash, last use; data and evidence files submitted by suppliers (may contain personal data); actor in audit log; visitor and supplier IP addresses processed transiently in memory for rate limiting (not stored); customer ID parameter appended by Shopify App Proxy (received but not used or stored) | Product passports, supplier data collection, public passport pages | Until shop/redact; published versions cannot be deleted while installed | No customer data |
Annex II – Technical and organisational measures (Art. 32 GDPR)
Measures implemented in the code (verified 2026-10-05).
1. Encryption and pseudonymisation
- TLS (HTTPS) for all connections to the apps, Shopify and third-party APIs; outbound webhooks and integrations accept HTTPS only.
- Encryption at the application level (AES-256-GCM) of stored third-party credentials: storefront password and Google refresh token (Feed & Pixel Guard), marketplace OAuth tokens (Oversell & Sync Watch), 3PL webhook signing secret (3PL Case-Pack Picker). Keys are held in environment variables, separate from the database.
- Supplier portal links (Textile Passport DPP) are stored only as SHA-256 hashes.
2. Access control
- Shopify OAuth with offline tokens; every admin request is authenticated with a Shopify session token; webhooks and App Proxy requests are verified by HMAC signature.
- Least privilege: each app requests only the scopes it needs; write scopes are optional and requested at the time of use; the Controller can revoke optional scopes in the app.
- Strict separation of data by shop in every database query.
- Public endpoints (pixel ingest, supplier portal, App Proxy pages, eBay deletion notifications) are rate-limited and validate input; cron endpoints require a secret.
- Administrative access to production: only the Processor.
3. Integrity and input validation
- Validation and size limits for uploads and forms (e.g. file type by magic bytes, 5 MB per evidence file); CSV exports protected against formula injection.
- Protection against server-side request forgery for outbound requests (HTTPS only, no redirects, blocking of private/reserved IP ranges, connection pinned to the checked address).
- Signed outbound webhooks (HMAC-SHA256) where the Controller configures them.
- Audit logs of changes in apps that keep compliance records (EPR, GPSR, Green Claims, Textile DPP, deposit ledger).
4. Availability and resilience
- Daily database backups retained for 30 days, stored in the EU (SEOHOST, Poland).
- Idempotent processing of webhooks and payments-like operations (store credit, stock receipts); recovery of interrupted background jobs.
5. Data minimisation and retention
- No app reads customer names, e-mails, phone numbers or addresses; order-based apps read only the fields listed in Annex I.
- Plan-based history limits and automatic deletion as listed in Annex I; deletion on
shop/redact. - Personal data in uploaded CSV files outside the needed columns is not stored.
Annex III – Subprocessors
See subprocessors.md / https://lektoro.pl/legal/subprocessors/. Current list:
| Subprocessor | Purpose | Apps | Location / transfer mechanism |
|---|---|---|---|
| SEOHOST Sp. z o.o., ul. Obornicka 330, 60-689 Poznań, Poland (KRS 0000939910, NIP 9721323212) | Application hosting, database, backups, logs | All | Poland (EU); no transfer outside the EEA |
| Resend, Inc. | Delivery of alert and summary e-mails | Feed & Pixel Guard | USA; Standard Contractual Clauses |
| SEOHOST Sp. z o.o. (as above) – mail server (SMTP), sender alerts@lektoro.pl | Delivery of alert and summary e-mails | Oversell & Sync Watch | Poland (EU); no transfer outside the EEA |