Private betainstoor is currently open to invited beta testers only. Request beta access →
logo
brand
Legal · Data processing agreement

Your customers’ data, on your terms.

How we handle the data of the people who buy, book and subscribe in your store. Required by GDPR, part of every instoor account.

VERSION1.0
EFFECTIVE2026-10-01
BASISArt. 28 GDPR
Request a signed copy
01 / Parties and roles

Parties and roles

In short

You, the merchant, decide what happens with your customers’ data. We process it only to run your store.

Controller

The merchant

The business that holds an instoor account and accepts the Terms of service.

Processor

instoor

Villaratio BV, Oude Kapellestraat 14, 8700 Tielt, Belgium, BE 0728.924.019.

1.1This Data Processing Agreement ("DPA") forms part of the Terms of service and applies whenever instoor processes personal data on behalf of the merchant, as required by Article 28 of the General Data Protection Regulation (GDPR).

1.2Words such as "personal data", "processing", "controller", "processor" and "data breach" have the meaning given in the GDPR.

02 / Subject and duration

Subject and duration

In short

This agreement runs as long as your account does, and ends when your data has been returned or deleted.

2.1instoor processes personal data only to provide the Services described in the Terms of service.

2.2This DPA starts when the merchant creates an account and ends when instoor has deleted or returned all personal data under section 12.

03 / What we process

What we process

In short

Your customers’ contact details, orders, bookings and subscriptions, to run your store and nothing else.

Data subjectsCustomers and visitors of the merchant’s store, people who book an appointment or slot, subscribers.
Categories of dataName, email, phone number, delivery and billing address, order and booking history, subscription status, messages to the store, notes added by the merchant.
Special categoriesNot intended. If a merchant collects them (for example health information for a dental appointment), the merchant is responsible for a valid legal basis. See 3.2.
PurposeHosting the store, handling orders, reservations and subscriptions, sending transactional messages, customer support.
Payment dataCard details are handled by Mollie under the merchant’s own agreement with Mollie. instoor only receives the payment status.

3.2The merchant should not collect special categories of personal data through custom fields unless it has a valid legal basis and has informed its customers.

04 / Acting on your instructions

Acting on your instructions

In short

We only do what you tell us through the platform and this agreement. If an instruction seems unlawful, we let you know.

4.1instoor processes personal data only on the documented instructions of the merchant. Using the settings and features of the platform counts as such an instruction.

4.2If instoor believes an instruction breaks the GDPR or other data protection law, it informs the merchant without delay.

4.3The merchant remains responsible for the lawfulness of the processing, including informing its customers and obtaining consent where needed.

05 / Confidentiality

Confidentiality

In short

Everyone at instoor who can access data is bound to keep it confidential.

5.1instoor ensures that people authorised to process personal data have committed to confidentiality or are under a legal duty of confidentiality.

5.2Access is limited to team members who need it for support, operations or security.

06 / Security measures

Security measures

In short

Encryption, limited access, backups and monitoring. The full list is in Annex 2.

Encryption

TLS in transit, encryption at rest for databases and backups.

Access control

Role-based access, two-factor login for staff, access logging.

Backups

Daily backups, stored in the EU, with tested restores.

Monitoring

Alerts for unusual activity and regular security updates.

Separation

Data of each store is logically separated from other stores.

Testing

Regular reviews and {{PEN_TEST_FREQUENCY}} external security tests.

6.1instoor takes appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the costs and the risks for data subjects.

07 / Sub-processors

Sub-processors

In short

We use a short list of providers to run instoor. We tell you 30 days before we add a new one.

  • Hosting · Hetzner Online GmbH (Germany) Germany
  • Transactional email · Mailjet SAS (France) EU
  • SMS reminders · {{SMS_PROVIDER}} EU
  • Error monitoring · {{MONITORING_PROVIDER}} EU

7.1The merchant gives general authorisation for instoor to use sub-processors. The current list is in Annex 3.

7.2instoor informs the merchant by email at least thirty (30) days before adding or replacing a sub-processor. The merchant may object on reasonable grounds. If no solution is found, the merchant may cancel without penalty.

7.3instoor binds each sub-processor to the same data protection obligations as in this DPA and stays responsible for their work.

08 / Transfers outside the EU

Transfers outside the EU

In short

Data stays in the EU. If that ever changes, strict legal safeguards apply.

8.1instoor stores personal data within the European Economic Area. A transfer outside the EEA only takes place on the basis of an adequacy decision or the European Commission’s Standard Contractual Clauses, with additional measures where needed.

09 / Helping you with requests

Helping you with requests

In short

If a customer asks to see or delete their data, the tools are in your dashboard. If you need more, we help.

9.1The platform lets the merchant view, export, correct and delete customer data. instoor assists the merchant with requests from data subjects that cannot be handled through these tools.

9.2If a data subject contacts instoor directly, instoor forwards the request to the merchant and does not answer it on the merchant’s behalf unless instructed.

9.3instoor also assists with data protection impact assessments and prior consultations where reasonably required, taking into account the information available to it.

10 / Data breaches

Data breaches

In short

If something goes wrong, we tell you quickly, so you can meet your own 72-hour deadline.

  1. Step 1
    Detect

    We investigate and contain the incident.

  2. Step 2
    Notify you

    Within {{BREACH_NOTICE_HOURS}} hours of becoming aware, with what we know.

  3. Step 3
    Follow up

    Updates as we learn more, and the measures taken.

10.1instoor notifies the merchant without undue delay after becoming aware of a personal data breach, and in any case within {{BREACH_NOTICE_HOURS}} hours.

10.2The notification describes the nature of the breach, the categories and approximate number of data subjects, the likely consequences and the measures taken or proposed.

10.3Notifying the supervisory authority and data subjects remains the responsibility of the merchant as controller. instoor provides the information needed to do so.

11 / Audits

Audits

In short

You can ask how we protect data. We share reports first, and allow an audit if that isn’t enough.

11.1On request, instoor provides the information needed to show compliance with this DPA, such as security summaries or certifications.

11.2If that information is not sufficient, the merchant may have an audit carried out by an independent auditor bound by confidentiality, at most once per year, with at least thirty (30) days’ notice. The merchant bears the costs unless the audit reveals a material breach by instoor.

12 / Return and deletion

Return and deletion

In short

When you leave, you can export everything. After that, we delete it.

12.1After the account ends, the merchant can export its data for 30 days.

12.2After that period, instoor deletes the personal data, including copies, within {{DELETION_DAYS}} days, unless EU or Belgian law requires it to be kept. Backups are overwritten in their normal cycle.

13 / Liability and precedence

Liability and precedence

In short

The liability rules of the Terms apply. If this DPA and the Terms conflict on data protection, this DPA wins.

13.1The limitation of liability in the Terms of service applies to this DPA, to the extent permitted by the GDPR.

13.2In case of conflict between this DPA and the Terms of service on the processing of personal data, this DPA prevails.

13.3This DPA is governed by Belgian law. The competent courts of the judicial district in which the registered office of Villaratio BV is located have jurisdiction.

14 / Annexes

Annexes

In short

The details that change more often live in separate annexes.

  • Annex 1Description of the processing See section 03
  • Annex 2Technical and organisational measures {{ANNEX_2_LINK}}
  • Annex 3List of sub-processors {{ANNEX_3_LINK}}