Personal data processing agreement
What this document is for. If your store holds customers' personal data, you are their controller. Woo Ops processes it on your behalf, and the GDPR requires such a relationship to have a written agreement. This document is that agreement. You do not have to sign it separately: it becomes binding when you connect a store to the app. If your organisation needs a separate, signed copy, write to kontakt@wooops.pl.
- Parties to the agreement
- Subject matter, nature and purpose of the processing
- Where the data actually is
- Types of data and categories of data subjects
- Processing only on documented instructions
- Confidentiality
- Security measures
- Sub-processors
- Transfers outside the EEA
- Assistance with data subjects' rights
- Personal data breaches
- Information and audits
- Ending: return and deletion of data
- The Agency plan and further processing on behalf
- Liability and term
1. Parties to the agreement
You are the controller: the entity that connects a WooCommerce store to the Woo Ops app and decides on the purposes and means of processing the personal data held in that store.
We are the processor:
APTURN Sp. z o.o., ul. Pustola 24/49, 01-129 Warszawa, Poland
NIP 5273142724 (tax identification number) · REGON 540378447 (statistical number) · KRS 0001142653 (National Court Register number)
kontakt@wooops.pl
The agreement is concluded when the first store is connected to the app and applies for as long as you use Woo Ops.
2. Subject matter, nature and purpose of the processing
- Subject matter: the personal data held in your WooCommerce store, in particular in orders, customer records and refunds.
- Nature: providing software that downloads that data from your store to your device, displays it, organises it and lets you carry out operations on it in the store.
- Purpose: running your store's day-to-day operations from a mobile device.
- Duration: the term of the contract for the provision of Woo Ops services.
3. Where the data actually is
This section describes the real architecture, because it has a direct bearing on the scope of our obligations and on your risk.
- The app connects to your store directly. Order and customer data travels from the store into your device's memory without passing through our servers.
- On our servers we do not store orders, buyer details, addresses, phone numbers or email addresses of your store's customers. We keep no copy of your database.
- Data stored in the device's memory stays under your control: it sits on hardware you have at your disposal, and you delete it by disconnecting the store in the app or uninstalling the app.
- There are two exceptions in which personal data from your store may reach our infrastructure or a sub-processor, and we describe them plainly in sections 4 and 8.
The practical consequence for you as the controller. Since the data sits on the device, securing the device itself is your obligation: a screen lock, phone storage encryption, an up-to-date system and the ability to wipe it remotely if the hardware is lost. The measures described in section 7 cover our part; they will not replace securing the phone.
4. Types of data and categories of data subjects
| Category of data subjects | Types of data | Where it is processed |
|---|---|---|
| Your store's customers | First and last name, email address, phone number, billing and delivery address, order contents, amounts, order notes, NIP (tax identification number) if the buyer provided one | Only in your device's memory |
| Your store's customers | The order identifier contained in an event notice, when using the optional Woo Ops Connect plugin | Transiently in the notification service; only the identifier is used, we do not store the contents of the notice |
| Your store's customers | Only the data that you type yourself into the content of a question to the AI feature | Our server and the language model provider. We recommend not putting personal data there |
| You and your staff | Woo Ops account data | Our server, on the terms in the privacy policy, where we are the controller and not the processor |
We do not process on your behalf special categories of personal data within the meaning of Article 9 GDPR, nor data relating to criminal convictions. If your store collects such data, inform us before connecting it.
5. Processing only on documented instructions
- We process the data only on your documented instructions. Using the app's features in line with their intended purpose, this agreement and the terms of service count as such an instruction.
- We do not use the entrusted data for our own purposes, including training models, building profiles or marketing.
- If an obligation to process follows from Union or Member State law, we will inform you of it before processing, unless the law prohibits that on important grounds of public interest.
- We will inform you without delay if, in our view, your instruction infringes the GDPR or other data protection provisions.
6. Confidentiality
We give access to the data only to persons who are authorised to it, have been made familiar with data protection rules and have committed themselves to confidentiality or are under a statutory obligation of secrecy. The confidentiality commitment remains in force also after cooperation with those persons ends.
7. Security measures
We apply technical and organisational measures appropriate to the risk, within the meaning of Article 32 GDPR:
- encryption of connections in transit (HTTPS/TLS) between the app, your store and our services,
- keeping the application password to your store only in the device's system key store (Keychain, Keystore), without sending it to our servers,
- storing Woo Ops account passwords only as an Argon2id hash,
- limiting the number of failed sign-in attempts and logging them for security purposes,
- limiting access to production systems to authorised persons,
- the minimisation principle: the personal data of your store's customers does not reach our servers, and the scope of data sent to the AI features is limited by a closed list of fields on the server side,
- separation of services: notifications, the account cloud and your store are separate systems.
We provide a current description of the measures on request. We may change them, provided that the level of security is not reduced.
8. Sub-processors
You give general authorisation for us to use further processors. As at the date of this version of the agreement they are:
| Entity | Scope | Location |
|---|---|---|
| The provider of the Woo Ops Cloud server infrastructure | Hosting of the account and notification services | European Union |
| Google Ireland Ltd. / Google LLC | Delivering push notifications. Only a technical message is passed on: the store identifier, the event type, the object identifier and a timestamp | EU / USA |
| Anthropic PBC | Language model. It receives summary numbers and product names, and personal data only if you put it into the content of a question yourself | USA |
- We impose on every such entity data protection obligations no lower than those arising from this agreement.
- We will inform you of an intended change to the list of sub-processors 30 days in advance, to the email address assigned to the account or by a notice in the app.
- You may raise a reasoned objection to the change within 30 days. If we do not find a solution that accommodates your objection, you may terminate the contract for the provision of services with immediate effect, and we will refund a proportional part of the fee for the unused period.
- We are liable to you for the acts and omissions of sub-processors as for our own.
9. Transfers outside the EEA
Using the entities listed in section 8 may involve transferring data to the United States. The transfer takes place on the basis of standard contractual clauses approved by the European Commission or another mechanism from Chapter V of the GDPR, as set out in our agreements with those providers. We provide information about the safeguard applied on request.
If you do not use the AI features, personal data from your store is not transferred outside the EEA at all in connection with that feature.
10. Assistance with data subjects' rights
Taking into account the nature of the processing, we assist you in fulfilling your obligation to respond to requests from data subjects.
In practice: because your store's customer data sits in your store and on your device, you handle a request for access, rectification, erasure or portability yourself on the store side, without our involvement. If you nevertheless need our technical support, we will provide it without delay and free of charge within a reasonable scope. A data subject's request that reaches us directly we will pass on to you without undue delay and will not answer it ourselves.
We also assist you in fulfilling the obligations under Articles 32 to 36 GDPR, including a data protection impact assessment, within the scope of the information we hold.
11. Personal data breaches
We will notify you of a personal data breach concerning the entrusted data without undue delay and no later than within 24 hours of becoming aware of it. The notification will cover the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the remedial measures taken or proposed, and contact details. Reporting the breach to the supervisory authority and notifying the data subjects is up to you as the controller.
12. Information and audits
- We make available to you all information necessary to demonstrate compliance with the obligations under Article 28 GDPR.
- We allow for audits, including inspections, conducted by you or by an auditor you authorise. You announce an audit at least 14 days in advance, conduct it during working hours and in a manner that does not interfere with the security of other clients' data.
- No more than once per calendar year the audit is free of charge, unless the need for it follows from an established breach; in that case it is free of charge regardless of how many there are.
- The persons conducting the audit are bound by confidentiality.
13. Ending: return and deletion of data
After the provision of services ends, depending on your decision, we delete or return the entrusted data and delete existing copies, unless the law requires us to keep them.
In practice it is simple: your store's customer data stays in your store and on your device, so there is nothing for us to return. You delete the copy on the device yourself, by disconnecting the store in the app or uninstalling the app. Data connected with your account we delete on the terms described in the privacy policy.
14. The Agency plan and further processing on behalf
If you use Woo Ops to service your clients' stores, then in relation to the personal data from those stores you are most often a processor yourself, and your client is the controller. In that arrangement we are a sub-processor.
You are then responsible for having a proper data processing agreement with your client and for obtaining their authorisation for us to process the data as a sub-processor. This document applies accordingly and you may rely on it towards your client. On request we will provide the information needed to demonstrate compliance.
15. Liability and term
- The agreement applies for the term of the contract for the provision of Woo Ops services and expires together with it.
- Each party is liable for damage caused by processing that infringes the GDPR on the terms laid down in Article 82 GDPR.
- The liability limitations in the terms of service do not apply to liability towards data subjects, nor to administrative fines.
- In matters not regulated here, the GDPR and Polish law apply.
Woo Ops