Data Processing Agreement (DPA)
The agreement governing IziStore’s processing of personal data you control: instructions, security, sub-processors, transfers, breaches and deletion.
- Last updated :
- August 5, 2026
- In force since :
- August 5, 2026
- Published by :
- WeKrea LLC
In short
- You are the controller; we are the processor for your customers’ data.
- We process that data only on your documented instructions and never for our own purposes.
- This agreement applies automatically when you use the service — no separate signature is required.
- The EU Standard Contractual Clauses apply to transfers out of the EEA, UK and Switzerland.
1. Parties and incorporation
This agreement (the "DPA") is entered into between you, as controller ("Controller"), and WeKrea LLC, 30 North Gould Street, STE R, Sheridan, WY 82801, United States, as processor ("Processor").
It forms part of the Terms of Service and applies from account creation. No separate signature is needed; if your organisation requires a countersigned copy, write to [email protected].
In case of conflict, this DPA prevails over the Terms of Service for anything concerning the processing of personal data.
2. Subject matter and roles
The Processor processes personal data on behalf of the Controller for the sole purpose of providing the service described in the Terms of Service.
For data about the Controller’s own account (identification, billing, security, support) the Processor acts as an independent controller, as described in the Privacy Policy.
3. Documented instructions
- The Processor processes data only on the Controller’s documented instructions: the Terms of Service, this DPA, the account configuration and the use of features constitute those instructions.
- The Processor informs the Controller if it considers an instruction to infringe the GDPR or another applicable rule.
- Where a legal obligation requires further processing, the Processor informs the Controller beforehand unless legally prohibited.
4. Annex I — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of an e-commerce, order-management, messaging and automation platform |
| Duration | The life of the account, plus the deletion periods in section 11 |
| Nature | Collection, storage, structuring, consultation, transmission, erasure |
| Purpose | Running the features enabled by the Controller (store, orders, messages, campaigns, AI, analytics) |
| Data subjects | Shoppers, prospects, contacts, the Controller’s team members, message recipients |
| Data categories | Identity, contact details (phone, email, address), order and payment data (excluding card numbers), message content, technical and browsing data |
| Special categories | None are required by the service; the Controller undertakes not to introduce any |
| Frequency | Continuous, for the duration of the contract |
5. Annex II — Technical and organisational measures
- TLS 1.2+ for all communications; encryption at rest for databases and backups.
- Logical multi-tenant isolation: every query is scoped by user and store identifier.
- Role-based access control, least privilege, secrets kept outside the source tree and rotated after an incident.
- Signed-session authentication with expiry and revocation; rate limiting on sensitive API endpoints.
- Logging of administrative access and sensitive operations; monitoring of errors and outages.
- Encrypted, tested backups retained for 35 days; documented restore procedure.
- Confidentiality undertakings for every person authorised to access data.
- Dependency review and security patching prioritised by severity.
6. Confidentiality and personnel
The Processor limits access to staff who need it to perform the contract, binds them to confidentiality, and trains them on data protection.
7. Sub-processors
The Controller gives general authorisation for the sub-processors listed at /legal/subprocessors.
The Processor imposes on each of them protection obligations equivalent to this DPA and remains liable for their failures.
Any addition or replacement is published on that page with thirty (30) days notice. The Controller may object on reasonable data-protection grounds; failing agreement, it may terminate the affected part of the service without penalty.
8. International transfers
For transfers from the EEA, the UK or Switzerland to a country without an adequacy decision, the European Commission Standard Contractual Clauses (Decision 2021/914) are deemed incorporated into this DPA: module 2 (controller to processor) or module 3 (processor to sub-processor), together with the UK IDTA addendum and the Swiss annex.
The Clauses’ annexes are populated by sections 4, 5 and 7 of this DPA, and the competent supervisory authority is that of the Controller’s member state.
9. Assistance to the Controller
- The Processor provides export, correction and deletion features enabling the Controller to answer data-subject requests.
- If a request reaches the Processor directly, it forwards it to the Controller without answering itself, unless instructed otherwise.
- The Processor reasonably assists with data-protection impact assessments, prior consultations and security of processing.
10. Personal-data breach
The Processor notifies the Controller without undue delay and at the latest 72 hours after becoming aware of a personal-data breach, stating the nature of the breach, the categories and approximate volume of data affected, the likely consequences and the measures taken.
The Processor does not notify authorities or data subjects on the Controller’s behalf, absent its own legal obligation.
11. Deletion and return
At the end of the contract the Controller has thirty (30) days to export its data. After that period, the Processor deletes or anonymises the data, including in backups according to their rotation cycle (35 days), unless retention is legally required.
12. Audit
On written request, the Processor makes available the information needed to demonstrate compliance with this DPA.
An on-site audit or detailed questionnaire may be requested at most once per twelve-month period, on thirty (30) days notice, during business hours, without disrupting operations and subject to confidentiality. Reasonable costs are borne by the Controller unless the audit reveals a material failure.
13. California law (CCPA/CPRA)
For data subject to the CCPA/CPRA, the Processor acts as a "service provider". It does not sell or share personal information, retains, uses and discloses it only to perform the contract, and does not combine it with data from other sources outside the permitted exceptions.
14. Liability and term
Each party’s liability under this DPA is subject to the limitations set out in the Terms of Service, to the extent permitted by law.
This DPA remains in force for as long as the Processor processes personal data on behalf of the Controller.
Contact: [email protected].