Data Processing Agreement
1. INTRODUCTION
1.1 This data processing agreement (hereinafter “DPA”) governs the personal data processing conducted by Creem as a data processor (hereinafter “Processor”) on behalf of the Merchant acting as a data controller (hereinafter “Controller”) within the scope of providing the service (hereinafter “Service”) as defined in and provided under the Merchant Terms, which forms an integral part of the Merchant Terms concluded between the Controller and the Processor (hereinafter “Agreement”).
1.2 The Controller and the Processor are hereinafter individually referred to as the “Party” or collectively as the “Parties”.
1.3 The Parties acknowledge that this DPA and processing activities conducted during fulfilment of the Agreement in relation to the personal data are governed by the Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter the “GDPR”) and other relevant legislative acts governing the processing of personal data (altogether with the GDPR “Legislation”).
1.4 All and every term, unless specifically defined herein, is being used in the meaning of the GDPR or the Agreement. For matters not stipulated in this DPA, the Agreement applies. In the event of a conflict or ambiguity between the Agreement and this DPA, this DPA prevails.
1.5 The Processor’s personal data processing’s subject-matter, nature, types of personal data and categories of data subjects and processing duration are specified in Annex 1 to this DPA.
2. RIGHTS AND OBLIGATIONS OF THE PARTIES
2.1 The Controller shall:
- 2.1.1 ensure that all instructions for the processing of the personal data under the Agreement, this DPA or as otherwise agreed or stipulated shall comply with the Legislation, and such instructions will not in any way cause the Processor to be in breach of the Legislation;
- 2.1.2 comply with the Legislation, including ensure the accuracy, quality and lawfulness of the personal data processed by the Processor and inform the data subjects of the processing operations carried out by the Processor;
- 2.1.3 notify the Processor prior to concluding the Agreement if the Controller requires the Processor to adopt specific procedures, security measures or similar.
2.2 The Processor shall:
- 2.2.1 process the personal data on behalf of the Controller only based on documented (e.g., received via e-mail or any other documented form) instructions given, received and updated (including the ones regulated herein), from time to time, from the Controller and in accordance with the Legislation, unless required to do so by the Legislation to which the Processor is subject. In such case, the Processor shall inform the Controller of that legal requirement before processing, unless the Legislation prohibits this on important grounds of public interest.
- 2.2.2 immediately inform the Controller if, in the Processor’s opinion, instructions given by the Controller infringe data protection provisions set forth in the Legislation;
- 2.2.3 ensure that all of its employees, subcontractors, members of the management board, or other persons to whom the Processor has provided access to the personal data are subject to confidentiality obligation or to an appropriate statutory confidentiality obligation and are aware of their duties and obligations in relation to the personal data processing;
- 2.2.4 take measures required pursuant to Article 32 of the GDPR and the Legislation, including implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk related to the processing of the personal data and avoid alteration, loss or non-authorised processing thereof or access thereto. As a minimum, the Processor undertakes to implement the technical and organisational measures set out in Annex 2 to this DPA;
- 2.2.5 provide assistance to the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligations to respond to the data subjects’ requests for exercising their rights laid down in Chapter III of the GDPR;
- 2.2.6 not communicate to the data subjects nor perform the data subjects’ request directly and independently. The Processor shall forward any requests received from the relevant data subjects for exercising any of their rights to the Controller’s contact person specified in this DPA as soon as reasonably possible, but no later than in five (5) calendar days after the receipt of such a request;
- 2.2.7 assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, while taking into account the nature of processing and the information available to the Processor;
- 2.2.8 notify the Controller in a form reproducible in writing without undue delay, but no later than within twenty-four (24) hours after becoming aware of a personal data breach concerning personal data processed by the Processor, i.e. determining that a potential incident is treated as a data breach. Such notification shall contain at least the information required in Article 33 (3) of the GDPR.
2.3 The Processor acknowledges that according to Article 28 (10) of the GDPR if it infringes the DPA and the Legislation by determining the purposes and means of the processing, the Processor shall be considered a separate controller in respect of that processing.
3. AUDITING RIGHTS
3.1 Upon the Controller’s request in a form reproducible in writing, the Processor shall provide the Controller with all information necessary (which may be redacted to remove confidential commercial information not relevant to the requirements to the fulfilment of this DPA) to demonstrate compliance with the obligations laid down in the DPA and the Legislation, within fifteen (15) calendar days of the receipt of such request.
3.2 Where, in the opinion of the Controller, such information is not sufficient to verify the Processor’s compliance with the DPA and the Legislation, the Controller may, upon thirty (30) calendar days prior notice in a form reproducible in writing to the Processor, conduct an audit by the Controller or another auditor mandated by the Controller. The notification shall contain a proposal for an auditing plan. Any costs for conducting the audit shall be borne by each Party themselves.
3.3 The notice periods specified in this Section 3 are not applicable in case there is an extraordinary event (e.g. there are reasonable grounds to believe that a personal data breach has occurred, a personal data breach has occurred, a request or investigation by a supervisory authority, a request from a data subject, a violation of the Legislation etc.).
3.4 Any audit shall be performed during the Processor’s regular business hours and the performance of the audit must not interrupt the Processor’s business activities.
3.5 The Processor shall remedy any deficits found during the audit at its own expense within a reasonable period determined by the Controller. Failure to do so shall be considered as material breach.
4. USE OF SUB-PROCESSORS
4.1 The Processor is permitted to engage another processor (hereinafter “Sub-processor”) for the performance of the DPA under the Controller’s general authorisation provided hereby. The Controller acknowledges and agrees, that the Processor has engaged the Sub-processors listed in Annex 3 to this DPA.
4.2 Should the Processor wish to engage a new Sub-processor or replace a current Sub-processor with a new Sub-processor, then the Processor is obliged to inform the Controller in a form reproducible in writing. Upon having reasonable grounds, the Controller may object, in a form reproducible in writing, to any such additions, changes or replacements within thirty (30) calendar days as of the Processor informing the Controller. If the Controller does not object during such time period, the addition, change or replacement shall be deemed accepted.
4.3 In case the Controller exercises, pursuant to Section 4.2 of the DPA, its opportunity to object to the addition or replacement of a Sub-processor and the Processor does not, under reasonable grounds, agree with such objections, both Parties have the right to terminate the Agreement, together with the DPA by notifying the other Party thirty (30) calendar days in advance.
4.4 In the event the Processor engages or replaces a current Sub-processor, the Processor shall engage such Sub-processor under an agreement at least in a form reproducible in writing containing the same obligations as those set out in this DPA and remain fully liable to the Controller for the performance of each Sub-processor’s obligations.
5. DATA TRANSFERS OUTSIDE THE EU/EEA
5.1 The Controller allows the Processor to transfer the personal data outside of the European Union / European Economic Area (hereinafter “EU/EEA”), including engage any Sub-processors located outside the EU/EEA, if the Processor transfers personal data to countries in relation to which the European Commission has issued an adequacy decision or if the Processor uses other appropriate safeguards set out in Chapter V of the GDPR (e.g., standard contractual clauses adopted by the European Commission).
5.2 Before transferring personal data outside the EU/EEA to the country in relation to which the European Commission has not issued an adequacy decision, the Processor must carry out a data transfer impact assessment to ensure that the laws of the country to which the personal data are to be transferred provide an essentially equivalent level of protection as those in the EU/EEA.
5.3 The Controller is entitled to request information from the Processor regarding the countries to which the personal data is transferred to and of the existence or absence of an adequacy decision by the European Commission, or reference to the appropriate safeguards, as well as, if applicable, a copy of the data transfer impact assessment referred to in Section 5.2 of the DPA.
5.4 In the event that any of the measures referred to in Section 5.1 of the DPA are no longer sufficient to satisfy the requirements of the Legislation applicable to the processing of personal data under the DPA to legalise the transfer of personal data outside the EU/EEA, the Processor shall implement either an alternative transfer mechanism which satisfies the requirements of the Legislation in order to legalise the transfer of personal data outside the EU/EEA or cease with such transfer.
6. LIABILITY
6.1 Notwithstanding any other provisions in the Agreement with regard to the Processor’s liability and indemnity obligations, the Processor shall be liable, without any limitation, for any claims, damages, fines, penalties, costs and expenses caused to the Controller by the Processor as a result of the Processor’s breach of its obligations under the DPA, Agreement and/or Legislation.
7. TERMINATION
7.1 Without prejudice to the Legislation, in the event that the Processor is in breach of its obligations under this DPA, the Controller may instruct the Processor to suspend the processing of personal data until the latter complies with this DPA or the DPA is terminated. The Processor shall promptly inform the Controller in case it is unable to comply with this DPA, for whatever reason.
7.2 The Controller shall be entitled to terminate the DPA extraordinarily without notice if:
- 7.2.1 the processing of personal data by the Processor has been suspended by the Controller pursuant to Section 7.1 and if compliance with this DPA is not restored within a reasonable time and in any event within fourteen (14) days following suspension;
- 7.2.2 the Processor is in substantial or persistent breach of this DPA or its obligations under the Legislation;
- 7.2.3 the Processor fails to comply with a binding decision of a competent court or the competent supervisory authority/ies regarding its obligations pursuant to this DPA and/or the Legislation.
7.3 Termination of the DPA causes automatic termination of the Agreement and vice versa. Termination of this DPA does not exempt the Parties from fulfilling their obligations as specified in the Legislation.
8. DELETION OR RETURN OF PERSONAL DATA
8.1 Upon termination of this DPA and the Agreement, the Processor shall permanently delete from its systems, including backup systems, all of the personal data processed under this DPA within ten (10) calendar days as of termination of the DPA and the Agreement, unless storage of any personal data is required by the Legislation, processing is carried out in public interest or there is another lawful ground for the processing.
9. MISCELLANEOUS
9.1 This DPA becomes effective upon entering into the Agreement by the Parties and is valid until the termination of the Agreement.
9.2 In all other aspects, including governing law, and jurisdiction, the provisions of the Agreement shall apply.
10. ANNEXES
10.1 Annex 1 – details of data processing.
10.2 Annex 2 – technical and organisational measures.
10.3 Annex 3 – sub-processors.
Annex 1 – Details of Data Processing
1. SUBJECT-MATTER AND PURPOSE OF PROCESSING
1.1 The Processor will process the personal data as necessary to provide the Service according to the Agreement.
2. NATURE OF THE PROCESSING
2.1 The Processor may conduct the following processing activities: receiving data, including collection, accessing, retrieval, recording and data entry; using data, including analysing by provision of the Service; returning data to the Controller; erasing data, including destruction and deletion.
3. CATEGORIES OF DATA SUBJECTS AND TYPES OF PERSONAL DATA
3.1 Merchant’s sub-account users: name, email address, login information and other properties received from third-party authentication providers.
3.2 For the purpose of generating AI-based statistics, the following personal data of Buyers (as defined in the Agreement) shall be processed: name, email address, and IP address.
4. DURATION OF PROCESSING
4.1 The Processor will process the personal data as long it is necessary for the provision of the Service.
Annex 2 – Technical and Organisational Measures
To ensure the minimum level of security of the personal data processed, the Processor is required to implement at least the following technical and organisational measures:
1. ACCESS REGULATION
1.1 Access to the personal data and Controller’s systems is restricted only to persons who have been authorised to do so by the Processor.
1.2 The authentication information (username, password, proof of identity, etc.) must be kept confidential and may not be disclosed without authorisation.
1.3 The authentication information received is intended for one user only. Sharing authentication information (username/password) with other persons is prohibited.
2. IT SECURITY
2.1 Access to the Controller’s system and personal data is only permitted from properly secured IT devices; the requirements include, but are not limited to:
2.1.1 the operating system must have vendor support (i.e., the vendor issues security patches for it). The use of unsupported operating systems (e.g. Windows XP) is prohibited;
2.1.2 the hardware, operating system, and software (including browsers) security patches must be installed regularly at the scheduled time;
2.1.3 IT devices must be protected against malicious software by anti-virus programs and local firewalls;
2.1.4 user privileges on the operating system must be restricted. Use of the Controller’s IT system/personal data (access, transmission, processing and storage) with administrator privileges is prohibited;
2.1.5 security logging must be enabled and configured according to the operating system manufacturer's instructions. Security logs must be retained for six months. The time of the IT device must be kept synchronised with the external accurate time display;
2.1.6 IT devices shall be configured according to the security recommendations of the manufacturer or other trusted source. After 15 minutes of inactivity, the computer shall automatically lock;
2.1.7 access to the IT device must be protected by a secure (complex) password or double authentication, if possible;
2.1.8 personal data (including electronic documents and temporary files) must be stored in encrypted form;
2.1.9 when IT device is decommissioned and re-used, established procedures, measures and rules must be followed to ensure that all personal data is securely deleted;
2.1.10 the Controller may use dedicated methods and software to automatically detect the security level of devices accessing the system/personal data and to restrict access.
3. NETWORK SECURITY
3.1 Access to the Controller system and personal data is only permitted over properly secured networks; the requirements include, but are not limited to:
3.1.1 connection over unsecured networks (not managed or regulated by the Processor, e.g. public WiFi networks) is prohibited;
3.1.2 the Internet connection must be protected by a firewall;
3.1.3 where WiFi networks are used for network connection, they must be securely encrypted and protected by a secure authentication method.
4. MANAGEMENT OF PERSONAL DATA
4.1 Electronic data or documents may not be stored for longer than is necessary for the purposes of the Agreement or the DPA.
4.2 After the data has been returned to the Controller, it must be securely deleted from the Processor's infrastructure (including computers, networks and email systems).
4.3 Personal data may only be transmitted over the network after reliable identification of the external party and must be encrypted.
5. PHYSICAL SECURITY
5.1 IT devices and documents containing personal data must be protected from unauthorised physical access - access to premises must be restricted and controlled, and equipment and documents not in use must be kept locked.
6. USER RESTRICTIONS
6.1 Testing, scanning, evaluating, attempting to circumvent or undermine the security measures of the Controller’s IT system to which the Processor has access, if any, is prohibited.
6.2 It is forbidden to disclose technical information about the Controller’s information systems, including information about the system name, manufacturer, platform, architecture, authentication methods, security measures and techniques.
6.3 Information obtained from a Controller’s system may not be copied (including photocopied).
7. MAINTENANCE OF THE DEVICES
7.1 Before granting access to computers (or other devices containing personal data) for maintenance/support purposes (i.e. access rights to IT technicians), it is necessary to ensure that maintenance staff comply with the requirements of personal data protection.
8. AWARENESS
8.1 Security awareness training shall be provided to all staff with access to personal data to ensure that they are able to use the internet and email securely and are aware of information security risks and safeguards.
Annex 3 – Sub-processors
The Processor uses the following Sub-processors:
| Name of the Sub-processor | Subcontracted tasks/activities | Country where personal data is processed |
|---|---|---|
| OpenAI | AI API | Ireland and USA |
| FeatureBase | Customer Support | Estonia |
| AWS/Amazon | Server infrastructure | Germany |
| SupaBase | Database infrastructure | USA |
| Sentry | Observability & error tracking | USA |
| Github | Code Infrastructure | Estonia |
| Papertrail/Solarwinds | Observability & logs tracking | USA |
| BetterStack | Incident management & logs tracking | USA |
| Authentication, Email & Workspace | USA | |
| Resend | Email Infrastructure | USA |
| Slack | Team communication | EU and USA |
| Discord | Team communication & Community | Netherlands |
| Posthog | Product analytics & feature flagging | USA |
| Vercel | Client & Server infrastructure | USA |
Related documents
- Data Processing Agreement (V1.0)
The previous version of this Data Processing Agreement, in effect from 11.11.2025 until 03.08.2026.
Have questions about our data processing practices?
Contact Us