IziStoreIziStore
    HomeDashboardSign in

    Legal documents

    OverviewTerms of ServicePrivacy PolicyRefund PolicyCookie PolicyData Processing Agreement (DPA)Acceptable Use PolicySub-processors and third-party services

    Need help?

    Support: [email protected]

    WeKrea LLC
    30 North Gould Street, STE R, Sheridan, WY 82801, United States

    IziStore

    © 2026 WeKrea LLC — All rights reserved.

    Terms of ServicePrivacy PolicyRefund PolicyCookie PolicyData Processing Agreement (DPA)Acceptable Use PolicySub-processors and third-party services
    IziStore

    Data Processing Agreement (DPA)

    The agreement governing IziStore’s processing of personal data you control: instructions, security, sub-processors, transfers, breaches and deletion.

    Last updated :
    August 5, 2026
    In force since :
    August 5, 2026
    Published by :
    WeKrea LLC

    In short

    • You are the controller; we are the processor for your customers’ data.
    • We process that data only on your documented instructions and never for our own purposes.
    • This agreement applies automatically when you use the service — no separate signature is required.
    • The EU Standard Contractual Clauses apply to transfers out of the EEA, UK and Switzerland.

    Contents

    1. 1. Parties and incorporation
    2. 2. Subject matter and roles
    3. 3. Documented instructions
    4. 4. Annex I — Details of processing
    5. 5. Annex II — Technical and organisational measures
    6. 6. Confidentiality and personnel
    7. 7. Sub-processors
    8. 8. International transfers
    9. 9. Assistance to the Controller
    10. 10. Personal-data breach
    11. 11. Deletion and return
    12. 12. Audit
    13. 13. California law (CCPA/CPRA)
    14. 14. Liability and term

    1. Parties and incorporation

    This agreement (the "DPA") is entered into between you, as controller ("Controller"), and WeKrea LLC, 30 North Gould Street, STE R, Sheridan, WY 82801, United States, as processor ("Processor").

    It forms part of the Terms of Service and applies from account creation. No separate signature is needed; if your organisation requires a countersigned copy, write to [email protected].

    In case of conflict, this DPA prevails over the Terms of Service for anything concerning the processing of personal data.

    2. Subject matter and roles

    The Processor processes personal data on behalf of the Controller for the sole purpose of providing the service described in the Terms of Service.

    For data about the Controller’s own account (identification, billing, security, support) the Processor acts as an independent controller, as described in the Privacy Policy.

    3. Documented instructions

    • The Processor processes data only on the Controller’s documented instructions: the Terms of Service, this DPA, the account configuration and the use of features constitute those instructions.
    • The Processor informs the Controller if it considers an instruction to infringe the GDPR or another applicable rule.
    • Where a legal obligation requires further processing, the Processor informs the Controller beforehand unless legally prohibited.

    4. Annex I — Details of processing

    ItemDescription
    Subject matterProvision of an e-commerce, order-management, messaging and automation platform
    DurationThe life of the account, plus the deletion periods in section 11
    NatureCollection, storage, structuring, consultation, transmission, erasure
    PurposeRunning the features enabled by the Controller (store, orders, messages, campaigns, AI, analytics)
    Data subjectsShoppers, prospects, contacts, the Controller’s team members, message recipients
    Data categoriesIdentity, contact details (phone, email, address), order and payment data (excluding card numbers), message content, technical and browsing data
    Special categoriesNone are required by the service; the Controller undertakes not to introduce any
    FrequencyContinuous, for the duration of the contract

    5. Annex II — Technical and organisational measures

    • TLS 1.2+ for all communications; encryption at rest for databases and backups.
    • Logical multi-tenant isolation: every query is scoped by user and store identifier.
    • Role-based access control, least privilege, secrets kept outside the source tree and rotated after an incident.
    • Signed-session authentication with expiry and revocation; rate limiting on sensitive API endpoints.
    • Logging of administrative access and sensitive operations; monitoring of errors and outages.
    • Encrypted, tested backups retained for 35 days; documented restore procedure.
    • Confidentiality undertakings for every person authorised to access data.
    • Dependency review and security patching prioritised by severity.

    6. Confidentiality and personnel

    The Processor limits access to staff who need it to perform the contract, binds them to confidentiality, and trains them on data protection.

    7. Sub-processors

    The Controller gives general authorisation for the sub-processors listed at /legal/subprocessors.

    The Processor imposes on each of them protection obligations equivalent to this DPA and remains liable for their failures.

    Any addition or replacement is published on that page with thirty (30) days notice. The Controller may object on reasonable data-protection grounds; failing agreement, it may terminate the affected part of the service without penalty.

    8. International transfers

    For transfers from the EEA, the UK or Switzerland to a country without an adequacy decision, the European Commission Standard Contractual Clauses (Decision 2021/914) are deemed incorporated into this DPA: module 2 (controller to processor) or module 3 (processor to sub-processor), together with the UK IDTA addendum and the Swiss annex.

    The Clauses’ annexes are populated by sections 4, 5 and 7 of this DPA, and the competent supervisory authority is that of the Controller’s member state.

    9. Assistance to the Controller

    • The Processor provides export, correction and deletion features enabling the Controller to answer data-subject requests.
    • If a request reaches the Processor directly, it forwards it to the Controller without answering itself, unless instructed otherwise.
    • The Processor reasonably assists with data-protection impact assessments, prior consultations and security of processing.

    10. Personal-data breach

    The Processor notifies the Controller without undue delay and at the latest 72 hours after becoming aware of a personal-data breach, stating the nature of the breach, the categories and approximate volume of data affected, the likely consequences and the measures taken.

    The Processor does not notify authorities or data subjects on the Controller’s behalf, absent its own legal obligation.

    11. Deletion and return

    At the end of the contract the Controller has thirty (30) days to export its data. After that period, the Processor deletes or anonymises the data, including in backups according to their rotation cycle (35 days), unless retention is legally required.

    12. Audit

    On written request, the Processor makes available the information needed to demonstrate compliance with this DPA.

    An on-site audit or detailed questionnaire may be requested at most once per twelve-month period, on thirty (30) days notice, during business hours, without disrupting operations and subject to confidentiality. Reasonable costs are borne by the Controller unless the audit reveals a material failure.

    13. California law (CCPA/CPRA)

    For data subject to the CCPA/CPRA, the Processor acts as a "service provider". It does not sell or share personal information, retains, uses and discloses it only to perform the contract, and does not combine it with data from other sources outside the permitted exceptions.

    14. Liability and term

    Each party’s liability under this DPA is subject to the limitations set out in the Terms of Service, to the extent permitted by law.

    This DPA remains in force for as long as the Processor processes personal data on behalf of the Controller.

    Contact: [email protected].

    WeKrea LLC — 30 North Gould Street, STE R, Sheridan, WY 82801, United States — [email protected]