Skip to content
CommerVue

Data Processing Agreement (DPA)

Last updated: August 27, 2026 · processing agreement under Art. 28(3) GDPR

1. Parties and acceptance

This data processing agreement is concluded between the CommerVue user who connects their store (the "controller" — determining the purposes and means of processing their customers’ data) and Webology s.r.o., Company ID (IČO): 55 257 224, with its registered office at Mieru 960/25, 028 01 Trstená, Slovakia (the "processor" — processing data on behalf of the controller).

The agreement is accepted upon account registration and is a condition of using the service. We record the time of acceptance.

2. Subject matter, nature, purpose, and duration of processing

The subject matter is the processing of data about the orders, products, and customers of the controller’s store, which the service automatically synchronizes from the connected platform (WooCommerce, FiskalPRO, or other). The purpose is exclusively to provide the analytical and monitoring functions of the CommerVue service to the controller. Processing lasts for as long as the store is connected to the service.

3. Categories of data subjects and types of data

Data subjects: customers of the controller’s store.

Types of data (deliberately minimized): customer name, a cryptographic hash of the email address (SHA-256; the email itself is not stored), city/region/country from the billing or shipping address (street, phone number, and payment details are not stored), and order history (items, amounts, statuses, timestamps).

4. Controller’s instructions

The processor processes data exclusively on the basis of the controller’s documented instructions — namely this agreement, the configuration of the service (connecting/disconnecting a store), and actions performed in the application. The processor never uses the data for its own purposes, does not sell it, and does not share it with third parties for marketing.

5. Confidentiality and security (Art. 32 GDPR)

Persons authorized to process the data are bound by a duty of confidentiality. The technical and organizational measures adopted include, in particular: encryption in transit (HTTPS, HMAC-signed webhooks), pseudonymization of email addresses (SHA-256 hash), minimization of addresses to the city level, strict data isolation between stores (tenant isolation enforced at the API level), access control, and secure storage of credentials.

6. Sub-processors

The controller grants a general authorization for engaging sub-processors necessary for operating the service: the hosting/infrastructure provider Hetzner Online GmbH (Germany, EU) and the email service provider Websupport s.r.o. (Slovakia). We will give advance notice of intended changes to sub-processors; the controller has the right to object.

7. Assistance with data subject rights

The processor assists the controller in fulfilling its obligations towards data subjects (Arts. 12 to 23 GDPR) and in securing the processing (Arts. 32 to 36 GDPR). To exercise the right to erasure, the application provides a "Delete customer data" function — it irreversibly anonymizes the customer’s identity, including the locations of their orders; anonymous statistics remain. The controller must also delete the customer at the source (in their own store).

The processor will notify the controller of any personal data breach without undue delay after becoming aware of it.

8. Deletion after the end of processing

After a store is disconnected or the account is closed, the processor deletes all of the store’s data. Before disconnecting, the controller can export the data (CSV) directly in the application.

9. Audits and demonstrating compliance

The processor will provide the controller with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and will allow for reasonable audits. Direct any requests to info@webology.sk.

Data Processing Agreement (DPA) | CommerVue