Data processing agreement
Last updated: October 2, 2026
This data processing agreement (“DPA”) is made between:
- the business that installs EU Shop Kit on its Wix site (the “Controller”), and
- Synexco Digital, B-13-06 Sunway Geo Residence, Bandar Sunway, 47500 Subang Jaya, Selangor, Malaysia, registered with the Companies Commission of Malaysia (SSM) under no. 202603052366 (SA0649630-T) (the “Processor”).
It is part of the EU Shop Kit Terms of service (“Terms”) and applies to all personal data the Processor processes on behalf of the Controller when providing EU Shop Kit (the “Service”). It takes effect when the Controller installs the Service. Terms such as “personal data”, “processing” and “personal data breach” have the meaning given in the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Subject matter and duration
- The Processor processes personal data on behalf of the Controller to provide the Service under the Terms.
- This DPA applies for as long as the Processor processes personal data on behalf of the Controller: from installation until the data is deleted after the Service ends (section 11).
2. Nature and purpose of the processing
The processing serves the following purposes:
- receiving the withdrawal statements that shoppers submit through the online withdrawal function on the Controller’s shop, including checking the order number and email address against the Controller’s orders in Wix;
- documenting withdrawals and storing them as proof for the retention period set by the Controller;
- sending shoppers the acknowledgement of receipt, and sending the Controller notifications about new withdrawals;
- giving the Controller access to withdrawals in the dashboard, including status changes, notes and exports;
- displaying product safety information, including the contact details of manufacturers and responsible persons, on the Controller’s product pages;
- protecting the Service against abuse, and providing hosting, backups and support.
The processing consists of collecting, recording, storing, retrieving, consulting, using, disclosing by transmission (sending emails), comparing, restricting and erasing personal data.
The Processor does not track shoppers, does not build profiles, does not use the data for advertising and does not sell it.
3. Types of personal data
- Shoppers: name; email address; order number; ordered items concerned (names and quantities); the withdrawal statement, including the trader details and dates it contains; the optional message; order details entered by the shopper; date and time of receipt; language; order date and shipping or estimated delivery date; IP address, stored only as a keyed hash; delivery status of emails; technical data in server logs.
- Order data retrieved from Wix for the order check: order number, buyer name, buyer email address and ordered items.
- Controller’s staff and contacts: names and contact details in the business details, email addresses that receive notifications, and Wix user IDs recorded in the activity log.
- Manufacturers and responsible persons, where they are natural persons: names and contact details entered in product safety profiles.
No special categories of personal data (Art. 9 GDPR) are intended to be processed.
4. Categories of data subjects
- the Controller’s customers who use the withdrawal function;
- the Controller’s staff and contact persons;
- contact persons of manufacturers and responsible persons.
5. Instructions
- The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless EU or Member State law requires otherwise. In that case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits it.
- The Terms, this DPA and the Controller’s settings and actions in the Service are the Controller’s documented instructions. The Controller can give further instructions in writing, for example by email to privacy@eushopkit.com, if they are compatible with the Service.
- The Processor informs the Controller immediately if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection law.
6. Controller’s responsibilities
The Controller is responsible for the lawfulness of the processing, for informing data subjects, including in its own privacy policy, and for the lawfulness of its instructions.
7. Confidentiality
The Processor ensures that everyone authorised to process the personal data is bound by confidentiality, by contract or by law.
8. Security
- The Processor takes the technical and organisational measures required by Art. 32 GDPR. They are described in Annex 1.
- The Processor may update the measures as technology develops, provided that the overall level of protection doesn’t decrease.
9. Sub-processors
- The Controller gives the Processor general authorisation to engage sub-processors. The current list is published at /legal/subprocessors/ and in Annex 2.
- The Processor announces any intended addition or replacement of a sub-processor at least 30 days in advance, on the sub-processors page and by email to the Controller.
- The Controller may object to a change on reasonable data protection grounds within those 30 days, by email to privacy@eushopkit.com. If the parties can’t resolve the objection, the Controller may end the use of the Service by uninstalling it before the change takes effect.
- The Processor imposes the same data protection obligations as in this DPA on each sub-processor by contract, in particular sufficient guarantees for appropriate technical and organisational measures. The Processor remains liable to the Controller for its sub-processors’ performance of their obligations.
10. Assistance
- Data subject requests. Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organisational measures in responding to requests from data subjects under Chapter III GDPR. The dashboard shows all data stored for each withdrawal, and exports are available on paid plans. The Processor forwards to the Controller, without undue delay, any request it receives from a data subject about the Controller’s data, and doesn’t answer it itself except to refer the data subject to the Controller.
- Other obligations. The Processor assists the Controller in meeting its obligations under Art. 32 to 36 GDPR (security, notification of personal data breaches, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to the Processor.
11. Deletion and return at the end of the Service
- While the Service is installed, the Controller can export its withdrawal records and product safety data on paid plans. Withdrawal records are deleted automatically at the end of the retention period set by the Controller.
- When the Controller uninstalls the Service, the Processor deletes all personal data processed on the Controller’s behalf 30 days after uninstallation, unless EU or Member State law requires it to be stored. If the Controller reinstalls the Service within those 30 days, the data is restored.
- If the Controller asks during those 30 days, the Processor returns a copy of the withdrawal records before deleting them.
- Deleted data remains in encrypted backups for up to 7 days and is then overwritten.
12. Information and audits
- The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR, including this DPA and its annexes.
- The Processor allows for and contributes to audits, including inspections, by the Controller or an auditor mandated by the Controller. The Controller gives at least 30 days’ notice, unless a personal data breach or a supervisory authority requires a shorter period. Audits take place during business hours, at most once a year unless there is a specific reason, and without disproportionate disruption. The auditor must be bound by confidentiality. Each party bears its own costs.
- The Processor may first answer audit requests with documentation, for example the certifications and audit reports of its hosting provider.
13. Personal data breaches
- The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller’s data.
- The notification includes, as far as available, the information listed in Art. 33(3) GDPR. Information that isn’t yet available is provided in phases, without undue further delay.
- The Processor takes reasonable measures to contain the breach and mitigate its possible adverse effects, and supports the Controller in notifying the supervisory authority and data subjects where required.
14. International transfers
- The Processor hosts all personal data in the European Union, with Amazon Web Services in Frankfurt, Germany.
- The Processor is established in Malaysia, for which the European Commission has not adopted an adequacy decision, and may access personal data from there for support and operations. For this transfer, the parties agree to the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) (the “Clauses”), which are incorporated into this DPA by reference. The Controller is the data exporter and the Processor the data importer. For the Clauses:
- the optional Clause 7 (docking clause) applies;
- under Clause 9, Option 2 (general written authorisation) applies, with the notice period in section 9 of this DPA;
- the option in Clause 11 doesn’t apply;
- under Clause 17, Option 2 applies; where the law of the Member State in which the data exporter is established doesn’t allow for third-party beneficiary rights, the law of Ireland applies;
- under Clause 18, the courts of the Member State in which the data exporter is established have jurisdiction;
- Annex I is completed by the introduction and sections 1 to 4 of this DPA, with the competent supervisory authority determined under Clause 13; Annex II by Annex 1; and Annex III by Annex 2.
- The Processor transfers personal data to other third countries only on the Controller’s instructions and in accordance with Chapter V GDPR.
15. Liability and precedence
- Liability is governed by Art. 82 GDPR and by the Terms.
- In case of conflict, this DPA takes precedence over the Terms in matters of data protection. Where Standard Contractual Clauses apply, they take precedence over both.
Annex 1: Technical and organisational measures
Hosting and location
- All servers, the database and email delivery run on Amazon Web Services in the eu-central-1 region (Frankfurt, Germany).
Encryption
- Encryption in transit: connections to the Service use TLS (HTTPS), and email delivery requires TLS.
- Encryption at rest: the managed database is encrypted.
- Field-level encryption: shoppers’ personal data, such as names, email addresses, withdrawal statements, messages and the recipients of emails, is additionally encrypted with AES-256-GCM. Each encrypted value is bound to its shop and field, so it can’t be decrypted in the context of another shop.
Pseudonymisation and data minimisation
- Keyed HMAC hashes are used instead of plain email addresses for lookups, and instead of plain IP addresses for abuse protection.
- Only the data needed for the withdrawal statement is collected. The storefront elements use no cookies and no tracking.
Separation of shops
- Each shop’s data is isolated by PostgreSQL row-level security. The application runs with least-privileged database roles, which are not superusers and cannot bypass row-level security.
Integrity and traceability
- Withdrawal records are append-only for the application: it can change only their status and internal notes, and it can’t delete them. They are deleted only by the automatic retention process or when the shop’s data is erased.
- A fingerprint (SHA-256 hash) of each acknowledgement email sent is stored as proof of its content.
- An audit log records security-relevant actions, such as changes to settings, status changes and exports.
Logging
- Application logs are redacted: names, email addresses, tokens and other secrets are removed, request bodies are not logged, and request logs contain no client IP addresses.
Access control
- Access to production systems is limited to the operator and protected by multi-factor authentication.
- The merchant dashboard can only be used with a context signed by Wix, which the server verifies before it issues a short-lived session token.
Availability and recovery
- The database is backed up daily. Backups are encrypted, kept for 7 days and allow point-in-time recovery.
Secure development and operations
- Automated dependency scanning and secret scanning.
- Rate limiting on public endpoints.
- Verification of signed webhooks from Wix and of signed email delivery events.
Deletion
- Withdrawal records are deleted automatically when the retention period set by the Controller ends.
- All of a shop’s data is deleted 30 days after the shop uninstalls the Service.
Annex 2: Sub-processors
The current list of sub-processors is published at /legal/subprocessors/. At the date of this DPA:
| Sub-processor | Service | Location of processing |
|---|---|---|
| Amazon Web Services EMEA SARL, Luxembourg | Hosting, database and email delivery (Amazon SES) | Frankfurt, Germany (EU) |
| Cloudflare, Inc., USA | Content delivery and protection against attacks for the website and the app, including the storefront elements; email forwarding for support requests | Cloudflare’s global network |