LEGAL

Data processing agreement

VERSION 1.0 · LAST CHANGED 21 AUG 2026 · APPLIES TO SKUPLY.IO AND THE SERVICE

THESE ARE DRAFTS IN OUR OWN WORDS. THEY NEED A LAWYER BEFORE THEY BIND ANYONE. ANYTHING IN VERMILION IS A NUMBER OR A PERIOD THAT STILL HAS TO BE FIXED.

01

Parties and precedence

This agreement belongs to the terms and applies as soon as you give us access to your shop. You are the controller, we are the processor. Where the terms and this agreement contradict each other about personal data, this agreement wins.

02

What we process and what for

We process only what is needed to fill product fields and keep them filled. Concretely:

KIND OF DATA

DATA SUBJECTS

PURPOSE

Product titles, descriptions, attributes, media

none

deriving and writing fields

Names in free text fields, where present

staff, designers, suppliers

unavoidable consequence of reading the text

Contact details of your app users

your staff

access and the monthly report

Log lines per field

the same staff

being able to roll back and account for it

TO BE COMPLETED ONCE THE FIRST CONNECTION IS MEASURED

03

We act only on your instruction

We process the data only as described here and as you instruct us. If we receive an instruction we believe conflicts with the GDPR, we say so and do not carry it out until it is resolved.

If a law obliges us to a processing not listed here, we report that beforehand, unless that same law forbids it.

04

What we never do with your data

Three things are fixed here, not as a promise but as a prohibition, and they sit that way in our own systems too:

We do not use your catalogue to train models, neither our own nor a third party’s. We do not merge your data with another customer’s. And we do not sell, rent out or publish anything.

That last one covers aggregated and anonymised forms too, because in a product catalogue the line between anonymous and traceable sits lower than people think.

05

Confidentiality

Everyone on our side who can reach your data is bound to confidentiality, and that obligation continues after the contract ends. Access is limited to the people who run the service, and that is a short list we hand over on request.

06

Security

We take appropriate measures within the meaning of article 32 GDPR. What that means concretely:

MEASURE

HOW

STATUS

Access to your shop

API key with product permissions only, no admin login

in place

Storage of keys

encrypted, separated from the rest

in place

Processing and storage

inside the EU

in place

Access on our side

limited to whoever runs the service, with two factor

in place

Traceability

every write action in the log with timestamp and source

in place

[external assessment]

[pentest or certification]

[still to decide]

THE LAST ROW IS A CHOICE THAT STILL HAS TO BE MADE

07

Sub-processors

We may engage sub-processors. The current list sits in the privacy statement and forms part of this agreement. Every sub-processor is put under the same obligations in writing as set out here.

If we want to add or replace one, we give thirty days notice. If you object on reasonable grounds within that period and we cannot resolve it, you may terminate the agreement at no cost for the remaining term.

08

Transfer outside the EU

There is none. Processing and storage happen inside the EU, at our sub-processors too. Should that ever change, it is a change to the sub-processor list and the procedure above applies, with standard contractual clauses as the basis.

09

Assistance with data subject rights

If you receive a request for access, correction or deletion covering data in our systems, we help with it. We never answer such a request ourselves: it is your request and you decide. We deliver what you need within ten working days and charge nothing for it.

10

Data breaches

If we discover a breach, we report it to you without undue delay and at the latest within 24 hours of discovery. That report states what happened, which data it concerns, what the likely consequences are and what we have done about it.

Notifying the supervisory authority and the data subjects is yours to do, because that is the controller’s duty. We supply everything you need for it, and we report even when we are not certain. A breach we do not report because it might have been minor is worse than one report too many.

11

Audit

You may check that we keep to this. Once a year, and beyond that as soon as there is a concrete reason. On request we supply our measures, the log files relating to your data and the sub-processor list.

If you want an on-site audit by an independent party, we cooperate. The cost of that is yours, unless something comes out of it that does not match what is written here.

12

Return and deletion

Everything we wrote into your shop sits there and stays there. That does not need returning, you already have it.

What we hold on our side, the field log and our own namespace, we delete after the contract ends on request within thirty days, and otherwise automatically after ninety days. If you want the log handed over first, we deliver it as a file before we throw it away. Whatever a law obliges us to keep, we keep, and then we say which part that is and for how long.

13

Liability and term

This agreement runs for as long as we process data for you and ends by itself afterwards, except for confidentiality and the deletion duty above. For liability, what is written in the terms applies, with the proviso that fines from the supervisory authority demonstrably resulting from our failure are not covered by it. The cap still has to be fixed.

Questions about this go to hallo@skuply.io and are answered by somebody who builds the service themselves.