This DPA forms part of the contract between the business customer as Controller and Juchi Europe GmbH as Processor where Kommerzdock processes personal data on the customer's behalf.
1. Subject, purpose and duration
Processing is limited to contracted order, inventory, shipping, integration, support and customer-initiated AI transmission functions for the service term plus deletion periods. Customer configuration and authorised actions are documented instructions.
2. People and data
Data subjects include merchant staff and users, consumers/recipients, suppliers and carrier contacts. Data may include accounts, order number, name, address, email, phone, products, price, payment status without credentials, inventory, carrier, tracking and support data.
3. Instructions, confidentiality and security
Processing occurs only on documented instructions or mandatory law; apparently unlawful instructions are reported. Personnel are bound to confidentiality. Measures include access control, server-side tenant isolation/RLS, transport encryption, credential protection, backup/recovery, security logging, vulnerability and incident management; the final TOM schedule requires production evidence.
4. Assistance and incidents
The Processor assists with data-subject requests, breach duties, DPIAs and consultations, and notifies the Controller without undue delay after becoming aware of a breach affecting Controller data.
5. Subprocessors and BYOK
The Controller generally authorises the published list; changes receive reasonable advance notice and may be opposed on reasonable data-protection grounds. A customer-selected provider contracted directly using BYOK is not automatically a Kommerzdock-selected subprocessor; changed contractual or purpose roles require reassessment.
6. International transfers
Transfers outside the EEA require a Chapter V GDPR mechanism. Customers assess providers they select and contract directly.
7. Return, deletion and audit
At termination, data is returned or deleted at the Controller's choice unless law requires retention. Online data is deleted within 30 days and backups expire within the 90-day rolling target. Necessary evidence and proportionate audits are supported while protecting other customers and security.