Data Processing Agreement
Effective date: July 27, 2026 · Last updated: July 27, 2026
1. Parties and scope
This agreement ("DPA") is between you, the Emberfeed customer ("Controller"), and Daniel Šilha, registered sole trader (IČO 05377595), Letenské náměstí 76/3, 170 00 Prague 7, Czech Republic ("Processor"). It forms part of the Terms of Service and applies automatically whenever product feeds or assets the Controller imports into Emberfeed contain personal data within the meaning of the GDPR. In the event of a conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA prevails. A countersigned copy is available on request at [email protected].
2. Subject matter of the processing
- Subject and purpose: importing, storing, transforming and serving the Controller's product feed data in order to render designed catalog images and serve the resulting feed — nothing else.
- Duration: for as long as the Controller's account exists.
- Types of data: whatever personal data the Controller's feed happens to contain (product feeds normally contain none; incidental examples: a seller's personal name in a brand field, contact details in a description, or images of identifiable individuals appearing in product photography, such as models).
- Data subjects: individuals whose data appears in the Controller's catalog content (e.g. the Controller's staff, suppliers, or individuals depicted in product images). The service is not intended for special categories of personal data (Art. 9 GDPR).
3. Processor obligations
- Process the data only to provide the service and on the Controller's documented instructions, including with regard to transfers of personal data to a third country (the service configuration — feeds, rules, templates — and Sections 5–6 of this DPA constitute those instructions), unless EU or Czech law requires otherwise; in that case we inform the Controller of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
- Immediately inform the Controller if, in our opinion, an instruction infringes the GDPR or other EU or Czech data-protection provisions.
- Ensure that every person authorised to process the data — currently only the Processor personally, a sole trader with no employees — has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.
- Implement the technical and organisational measures in Annex 1 (Art. 32 GDPR) and keep them current.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting their data, with the information needed for the Controller's own Art. 33/34 duties.
- Assist the Controller, to a reasonable extent, with data subject requests and with Art. 32–36 obligations.
- After the end of the services — and earlier on request — at the Controller's choice, return the personal data (an export of stored feed data and uploaded assets in a machine-readable form) and/or delete it within 30 days, unless EU or Czech law requires further storage. Backup snapshots cycle out automatically within a further 7 days.
- Make available the information reasonably necessary to demonstrate compliance (e.g. answering security questionnaires); audits, including inspections, conducted by the Controller or an auditor mandated by the Controller (not a competitor of the Processor), are possible by arrangement, at the Controller's cost, no more than once a year unless a supervisory authority requires one or a breach occurred.
4. Controller obligations
The Controller warrants that it has a valid legal basis for any personal data contained in the feeds and assets it imports, that its instructions to the Processor are lawful, and that it will not instruct processing beyond the purpose described in Section 2. The Controller remains responsible for its own controller duties under the GDPR (including information duties and data-subject requests addressed to it).
5. Subprocessors
The Controller grants a general authorisation for these subprocessors, used strictly for hosting and delivery:
- Hetzner Online GmbH (Germany) — server hosting, EU data centre.
- Cloudflare, Inc. (USA) — CDN, security and bot protection. EU-US Data Privacy Framework and standard contractual clauses.
- Google Ireland Limited / Google LLC (EU/USA) — e-mail infrastructure (Google Workspace). US transfers are covered by Google LLC's EU-US Data Privacy Framework certification.
We engage each subprocessor under a written contract imposing data-protection obligations no less protective than those in this DPA, and we remain fully liable to the Controller for the subprocessor's performance. Changes to this list are announced on this page and notified by e-mail to registered account addresses at least 14 days before a new subprocessor handles Controller data; if the Controller objects on reasonable data-protection grounds, it may terminate before the change takes effect.
6. International transfers
Data is stored in the EU. Where a subprocessor operates from outside the EU/EEA, transfers rely on an adequacy decision (EU-US Data Privacy Framework) or standard contractual clauses. A copy of the applicable safeguards is available on request.
7. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits a data subject's rights or either party's liability towards data subjects under Art. 82 GDPR.
Annex 1 — Technical and organisational measures
- TLS encryption for all traffic; HTTPS-only cookies.
- Passwords stored as salted Argon2id hashes; API keys stored hashed.
- Single-operator access model: production access restricted to the Processor personally via key-based SSH over a private network.
- Per-account data isolation enforced at the application layer.
- Daily consistent database snapshots with automatic 7-day rotation, stored on the EU server; the hosting provider's nightly server backup adds a second EU-resident copy.
- Security monitoring: uptime checks, nightly integrity checks, rate limiting and bot protection.
- Regular review of the effectiveness of these measures: automated nightly integrity checks, a tested backup-restore procedure, and periodic review of access and dependencies.
- EU-hosted infrastructure (Hetzner, Germany).
Questions or a signed copy? [email protected]. Back to Emberfeed.