Parties and roles
You, the merchant, decide what happens with your customers’ data. We process it only to run your store.
The merchant
The business that holds an instoor account and accepts the Terms of service.
instoor
Villaratio BV, Oude Kapellestraat 14, 8700 Tielt, Belgium, BE 0728.924.019.
1.1This Data Processing Agreement ("DPA") forms part of the Terms of service and applies whenever instoor processes personal data on behalf of the merchant, as required by Article 28 of the General Data Protection Regulation (GDPR).
1.2Words such as "personal data", "processing", "controller", "processor" and "data breach" have the meaning given in the GDPR.
Subject and duration
This agreement runs as long as your account does, and ends when your data has been returned or deleted.
2.1instoor processes personal data only to provide the Services described in the Terms of service.
2.2This DPA starts when the merchant creates an account and ends when instoor has deleted or returned all personal data under section 12.
What we process
Your customers’ contact details, orders, bookings and subscriptions, to run your store and nothing else.
| Data subjects | Customers and visitors of the merchant’s store, people who book an appointment or slot, subscribers. |
|---|---|
| Categories of data | Name, email, phone number, delivery and billing address, order and booking history, subscription status, messages to the store, notes added by the merchant. |
| Special categories | Not intended. If a merchant collects them (for example health information for a dental appointment), the merchant is responsible for a valid legal basis. See 3.2. |
| Purpose | Hosting the store, handling orders, reservations and subscriptions, sending transactional messages, customer support. |
| Payment data | Card details are handled by Mollie under the merchant’s own agreement with Mollie. instoor only receives the payment status. |
3.2The merchant should not collect special categories of personal data through custom fields unless it has a valid legal basis and has informed its customers.
Acting on your instructions
We only do what you tell us through the platform and this agreement. If an instruction seems unlawful, we let you know.
4.1instoor processes personal data only on the documented instructions of the merchant. Using the settings and features of the platform counts as such an instruction.
4.2If instoor believes an instruction breaks the GDPR or other data protection law, it informs the merchant without delay.
4.3The merchant remains responsible for the lawfulness of the processing, including informing its customers and obtaining consent where needed.
Confidentiality
Everyone at instoor who can access data is bound to keep it confidential.
5.1instoor ensures that people authorised to process personal data have committed to confidentiality or are under a legal duty of confidentiality.
5.2Access is limited to team members who need it for support, operations or security.
Security measures
Encryption, limited access, backups and monitoring. The full list is in Annex 2.
TLS in transit, encryption at rest for databases and backups.
Role-based access, two-factor login for staff, access logging.
Daily backups, stored in the EU, with tested restores.
Alerts for unusual activity and regular security updates.
Data of each store is logically separated from other stores.
Regular reviews and {{PEN_TEST_FREQUENCY}} external security tests.
6.1instoor takes appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the costs and the risks for data subjects.
Sub-processors
We use a short list of providers to run instoor. We tell you 30 days before we add a new one.
- Hosting · Hetzner Online GmbH (Germany) Germany
- Transactional email · Mailjet SAS (France) EU
- SMS reminders · {{SMS_PROVIDER}} EU
- Error monitoring · {{MONITORING_PROVIDER}} EU
7.1The merchant gives general authorisation for instoor to use sub-processors. The current list is in Annex 3.
7.2instoor informs the merchant by email at least thirty (30) days before adding or replacing a sub-processor. The merchant may object on reasonable grounds. If no solution is found, the merchant may cancel without penalty.
7.3instoor binds each sub-processor to the same data protection obligations as in this DPA and stays responsible for their work.
Transfers outside the EU
Data stays in the EU. If that ever changes, strict legal safeguards apply.
8.1instoor stores personal data within the European Economic Area. A transfer outside the EEA only takes place on the basis of an adequacy decision or the European Commission’s Standard Contractual Clauses, with additional measures where needed.
Helping you with requests
If a customer asks to see or delete their data, the tools are in your dashboard. If you need more, we help.
9.1The platform lets the merchant view, export, correct and delete customer data. instoor assists the merchant with requests from data subjects that cannot be handled through these tools.
9.2If a data subject contacts instoor directly, instoor forwards the request to the merchant and does not answer it on the merchant’s behalf unless instructed.
9.3instoor also assists with data protection impact assessments and prior consultations where reasonably required, taking into account the information available to it.
Data breaches
If something goes wrong, we tell you quickly, so you can meet your own 72-hour deadline.
-
Step 1Detect
We investigate and contain the incident.
-
Step 2Notify you
Within {{BREACH_NOTICE_HOURS}} hours of becoming aware, with what we know.
-
Step 3Follow up
Updates as we learn more, and the measures taken.
10.1instoor notifies the merchant without undue delay after becoming aware of a personal data breach, and in any case within {{BREACH_NOTICE_HOURS}} hours.
10.2The notification describes the nature of the breach, the categories and approximate number of data subjects, the likely consequences and the measures taken or proposed.
10.3Notifying the supervisory authority and data subjects remains the responsibility of the merchant as controller. instoor provides the information needed to do so.
Audits
You can ask how we protect data. We share reports first, and allow an audit if that isn’t enough.
11.1On request, instoor provides the information needed to show compliance with this DPA, such as security summaries or certifications.
11.2If that information is not sufficient, the merchant may have an audit carried out by an independent auditor bound by confidentiality, at most once per year, with at least thirty (30) days’ notice. The merchant bears the costs unless the audit reveals a material breach by instoor.
Return and deletion
When you leave, you can export everything. After that, we delete it.
12.1After the account ends, the merchant can export its data for 30 days.
12.2After that period, instoor deletes the personal data, including copies, within {{DELETION_DAYS}} days, unless EU or Belgian law requires it to be kept. Backups are overwritten in their normal cycle.
Liability and precedence
The liability rules of the Terms apply. If this DPA and the Terms conflict on data protection, this DPA wins.
13.1The limitation of liability in the Terms of service applies to this DPA, to the extent permitted by the GDPR.
13.2In case of conflict between this DPA and the Terms of service on the processing of personal data, this DPA prevails.
13.3This DPA is governed by Belgian law. The competent courts of the judicial district in which the registered office of Villaratio BV is located have jurisdiction.
Annexes
The details that change more often live in separate annexes.
- Annex 1Description of the processing See section 03
- Annex 2Technical and organisational measures {{ANNEX_2_LINK}}
- Annex 3List of sub-processors {{ANNEX_3_LINK}}