Data Processing Agreement

Vatuno · Last updated: 31 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the merchant installing the app (the "Controller") and the app provider (the "Processor"). It applies where the Processor processes personal data on behalf of the Controller within the meaning of Regulation (EU) 2016/679 ("GDPR"), Article 28.

1. Subject matter and duration

The Processor processes personal data solely to provide EU VAT compliance functionality: recording VAT per order, validating EU VAT identification numbers, generating invoices, producing OSS reports and monitoring the EU distance-selling threshold. Processing lasts for as long as the app is installed, plus the retention periods in section 6.

2. Categories of data subjects and personal data

3. Instructions

The Processor processes personal data only on documented instructions from the Controller, which include installing and configuring the app. The Processor will inform the Controller if, in its opinion, an instruction infringes the GDPR.

4. Confidentiality and security

Personnel authorised to process personal data are bound by confidentiality. The Processor implements measures appropriate to the risk, including: encryption in transit (TLS) and at rest, access restricted to the minimum number of personnel, separation of production and non-production data, and logging of validation activity. See the security overview.

5. Sub-processors

The Controller authorises the following sub-processors:

Sub-processorPurposeLocation
RailwayApplication hosting and databaseEU / US (see hosting region)
European Commission (VIES)VAT number validationEU
ResendReminder emails to the merchant onlyEU / US

The Processor will give the Controller notice before adding or replacing a sub-processor, and the Controller may object on reasonable data-protection grounds.

6. Retention and deletion

Invoices and VAT records are retained to meet EU invoice-retention obligations, which run up to ten years depending on the member state. VAT-number validation logs are retained as evidence of due diligence for the same period, and personal identifiers within them are erased on request. On uninstall or on the Controller's instruction, all data outside those legal obligations is deleted.

7. Data subject rights

The Processor assists the Controller in responding to data subject requests, including via Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact). Where an erasure request conflicts with a legal retention obligation, the obligation prevails under GDPR Article 17(3)(b) and the remaining personal fields are erased or anonymised.

8. Personal data breaches

The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, and provides the information the Controller needs to meet its own notification duties.

9. Audit

The Processor makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, on reasonable notice.

10. International transfers

Where personal data is transferred outside the EEA, the transfer is made under the European Commission's Standard Contractual Clauses or another valid transfer mechanism.

11. Return and deletion on termination

On termination the Processor deletes personal data, except where Union or Member State law requires continued storage, in which case the data remains subject to this DPA.


Questions: busseozgenoglu@gmail.com · Privacy policy · Security overview