On this page
- 1. INTRODUCTION
- 2. DATA SUBJECTS AND CATEGORIES OF DATA
- 3. PRINCIPLES OF DATA PROCESSING BY THE PARTIES
- 4. SECURITY
- 5. DATA RETENTION
- 6. INVOLVEMENT OF PROCESSORS AND DATA TRANSFERS OUTSIDE THE EEA
- 7. DATA SUBJECTS’ RIGHTS
- 8. DATA BREACHES
- 9. COOPERATION WITH SUPERVISORY AUTHORITIES
- 10. DATA SUBJECT COMPLAINTS
- 11. FINAL PROVISIONS
1. INTRODUCTION
1.1 This data sharing agreement (hereinafter “DSA”) governs the personal data sharing from Creem to the Merchant both acting as data controllers within the scope of providing the service (hereinafter “Service”) as defined in and provided under the Merchant Terms, which forms an integral part of the Merchant Terms concluded between Creem and the Merchant (hereinafter “Agreement”).
1.2 The Creem and the Merchant are hereinafter individually referred to as the “Party” or collectively as the “Parties”.
1.3 The Parties acknowledge that this DSA and processing activities conducted during fulfilment of the Agreement in relation to the personal data are governed by the Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter the “GDPR”) and other relevant legislative acts governing the processing of personal data (altogether with the GDPR “Legislation”).
1.4 All and every term, unless specifically defined herein, is being used in the meaning of the GDPR or the Agreement. For matters not stipulated in this DSA, the Agreement applies. In the event of a conflict or ambiguity between the Agreement and this DSA, this DSA prevails.
2. DATA SUBJECTS AND CATEGORIES OF DATA
2.1 The Parties agree that personal data to be shared from Creem to the Merchant under this DSA relates to the following:
- 2.1.1 Categories of data subjects: Buyers
- 2.1.2 Types of personal data:
- checkout_id: the ID of the checkout session created for the payment;
- order_id: the ID of the order created after successful payment;
- customer_id: the customer ID, based on the email that executed the successful payment;
- subscription_id: the subscription ID of the product;
- product_id: the product ID that the payment is related to;
- request_id (optional): the request ID Merchant provided when creating the checkout session;
- signature: all previous parameters signed by Creem using Merchant’s API-key, verifiable by Merchant;
- customer’s (Buyer’s) name, country and email address;
- any additional data relating to the Buyer, as specified by the Merchant on the checkout page.
2.2 Special categories of personal data are not shared from Creem to the Merchant pursuant to this DSA.
3. PRINCIPLES OF DATA PROCESSING BY THE PARTIES
3.1 The Merchant shall comply with the Legislation, and in particular with principles relating to processing of personal data arising from the GDPR, when processing personal data received from Creem and shall be responsible for fulfilling its own obligations arising therefrom.
3.2 The Merchant shall ensure that the processing of personal data received under this DSA has a specific purpose and a corresponding lawful basis under the Legislation.
3.3 Each Party shall ensure that sufficient information regarding the processing of personal data is provided to data subjects in the privacy notice or a similar document made publicly available in a transparent and easily accessible manner, as well as upon receipt of a data subject request.
4. SECURITY
4.1 Each Party undertakes to implement appropriate technical and organisational security measures as required under Article 32 of the GDPR. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, each Party shall ensure a level of security appropriate to the risk, including, inter alia, as appropriate:
- 4.1.1 the pseudonymisation and encryption of personal data;
- 4.1.2 the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
- 4.1.3 the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
- 4.1.4 a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of processing.
5. DATA RETENTION
5.1 The Merchant shall retain personal data only for as long as necessary to fulfil the purposes of the processing, including for the period and in accordance with any legal obligations to retain certain data (e.g., under accounting laws or anti-money laundering laws).
5.2 Upon expiry of the retention period, the Merchant shall delete the personal data or render it anonymous, with the aim of transforming the personal data into a form in which the data subject can no longer be identified.
6. INVOLVEMENT OF PROCESSORS AND DATA TRANSFERS OUTSIDE THE EEA
6.1 The Merchant undertakes to ensure that, where processors are engaged in the processing of personal data, a data processing agreement is concluded with such processors in accordance with Article 28 of the GDPR.
6.2 Personal data shall not be transferred outside the European Economic Area (“EEA”) unless adequate safeguards are in place in accordance with Chapter V of the GDPR. The Merchant shall ensure the implementation of the necessary safeguards and shall be responsible for the personal data transfers it carries out.
7. DATA SUBJECTS’ RIGHTS
7.1 Each Party shall be responsible for enabling data subjects to exercise their rights under the GDPR in respect of the personal data processed by that Party.
7.2 The Parties will provide reasonable assistance to each other in fulfilling such requests where necessary.
8. DATA BREACHES
8.1 If either Party becomes aware of a personal data breach concerning personal data shared under this DSA, it shall notify the other Party without undue delay, but not later than within 24 hours after determining that a potential incident is treated as a data breach.
8.2 The Parties shall cooperate and provide each other with all reasonable assistance required to investigate and remedy the breach, and to comply with any related obligations, including notifying the competent data protection supervisory authority and, where relevant, the data subjects. The Parties shall also assist each other, where necessary, in documenting the breach for their internal accountability purposes.
9. COOPERATION WITH SUPERVISORY AUTHORITIES
9.1 Each Party shall, without undue delay, inform the other Party if it becomes the subject of any inquiry, investigation, or other proceeding by a data protection supervisory authority in relation to the personal data shared under this DSA.
9.2 The Parties shall provide each other with reasonable assistance and cooperation in responding to supervisory authorities, to the extent permitted by applicable law.
10. DATA SUBJECT COMPLAINTS
10.1 Each Party shall without undue delay inform the other Party of any complaint received from a data subject concerning personal data shared under this DSA.
10.2 The Parties shall provide each other with reasonable assistance and cooperation in handling data subject complaints, to the extent permitted by applicable law.
11. FINAL PROVISIONS
11.1 This DSA shall apply for the duration of the Agreement between the Parties.
11.2 In all other aspects, including liability, governing law, and jurisdiction, the provisions of the Agreement shall apply.
Related documents
- Data Sharing Agreement (V1.0)
The previous version of this Data Sharing Agreement, in effect from 11.11.2025 until 03.08.2026.
Have questions about data sharing?
Our team answers legal and privacy questions at support@creem.io.