This Data Processing Agreement ("DPA") forms part of the agreement between Vangelder Solutions BV, enterprise number BE 0802.046.676, Pastorijstraat 27, 9100 Nieuwkerken-Waas, Belgium ("Processor", "we"); and the merchant that installs and uses the EU E-Invoicing Connector app ("Controller", "you"), each a "Party". It governs the processing of personal data by the Processor on behalf of the Controller under Regulation (EU) 2016/679 ("GDPR"). If it conflicts with the main terms of service, this DPA prevails for data-protection matters.
1. Roles and scope
The Controller determines the purposes and means of processing the personal data contained in its Shopify orders, customers and companies. The Processor processes that personal data solely to provide the App (generating and transmitting Peppol e-invoices and, if enabled, forwarding accountant copies) and only on the Controller's documented instructions, including those given through the App's configuration.
2. Processor obligations (GDPR Art. 28(3))
The Processor shall:
- Instructions — process personal data only on the Controller's documented instructions, including for international transfers, unless required by EU/Member-State law.
- Confidentiality — ensure persons authorised to process the data are bound by confidentiality.
- Security — implement the technical and organisational measures in Annex B (Art. 32).
- Sub-processors — engage sub-processors only under Section 4.
- Data subject requests — assist the Controller to respond to requests to exercise data subject rights (Chapter III).
- Assistance — assist the Controller with security, breach notification, DPIAs and prior consultation (Arts. 32–36).
- Deletion/return — at the Controller's choice, delete or return all personal data at the end of the services and delete existing copies, unless retention is required by law (see Section 6).
- Audit — make available information necessary to demonstrate compliance and allow for and contribute to audits under Section 7.
- Notify — immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data-protection law.
3. Personal data breach
The Processor shall notify the Controller without undue delay and no later than 48 hours after becoming aware of a personal data breach affecting the Controller's data, providing the information the Controller reasonably needs to meet its own notification obligations (Arts. 33–34). Contact for breach notifications: support@vangeldersolutions.be.
4. Sub-processors
- The Controller provides general authorisation for the Processor to engage the sub-processors listed in Annex C.
- The Processor will impose equivalent data-protection obligations on each sub-processor and remains liable for their performance.
- The Processor will inform the Controller of any intended addition or replacement of a sub-processor, with at least 30 days' notice and an opportunity to object on reasonable data-protection grounds.
5. International transfers
Processing takes place within the EEA. The Processor will not transfer the Controller's personal data outside the EEA without an appropriate transfer mechanism under Chapter V GDPR (e.g. an adequacy decision or Standard Contractual Clauses).
6. Duration, deletion and return
This DPA applies for as long as the Processor processes personal data on the Controller's behalf. On termination or uninstall, the Processor deletes the Controller's data from the App database in line with Annex A (triggered by Shopify's shop/redact request ≈48 hours after uninstall). The legal e-invoice retained at the Peppol Access Point is kept to satisfy the statutory Belgian VAT/accounting retention obligation and is not deleted by this process.
7. Audit
The Processor will make available, on reasonable request and no more than once per year (or following a personal data breach), the information necessary to demonstrate compliance, and will allow audits by the Controller or a mandated independent auditor, subject to reasonable confidentiality and security conditions.
8. Liability
Liability under this DPA is subject to the limitations agreed in the main Terms of Service.
Annex A — Details of the processing
- Subject matter: provision of the EU E-Invoicing Connector app.
- Duration: for the term of the Controller's use of the App.
- Nature and purpose: reading order/customer/company data from Shopify, generating an EN 16931 UBL e-invoice, transmitting it over Peppol via an Access Point, writing status metafields back to Shopify, and optionally forwarding an invoice copy (UBL + PDF) to the Controller's accountant.
- Types of personal data: business-customer company and contact name, billing/shipping address, VAT/enterprise number, order/line-item and payment details; the Controller's own configuration data; identifiers of the installing user.
- Categories of data subjects: the Controller's business customers (and their contacts) on B2B orders; the Controller's own staff/administrators.
- Special categories: none intended or required.
Annex B — Technical and organisational measures (Art. 32)
- Encryption at rest: provider credentials encrypted with AES-256-GCM; master key in Azure Key Vault (never in the database), accessed via a managed identity; documented key-rotation procedure.
- Encryption in transit: all traffic over TLS/HTTPS; the inbound A-Cube delivery webhook is cryptographically signature-verified.
- Data minimisation: buyer personal data is processed transiently and not persisted; only non-identifying metadata is stored.
- Tenant isolation: data is scoped per shop; deletion routines are shop-scoped.
- Hosting: Microsoft Azure (EU — Ireland) with certified physical, network and access controls.
- Access control: production access limited to authorised personnel on a need-to-know basis.
- Deletion: automated shop-scoped deletion on Shopify
shop/redact. - Resilience & logging: managed database backups and operational logging by the hosting platform.
Annex C — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify International Ltd. | Source platform providing order/customer data | EU / global |
| Peppol Access Point provider(s) — e.g. A-Cube S.r.l. (Italy) or another certified provider selected by the Controller | Peppol Access Point — transmits and retains the legal e-invoice | EEA (or, where a provider operates outside the EEA, under an appropriate Chapter V safeguard) |
| Microsoft Ireland Operations Ltd. (Azure) | Hosting, database and transactional email | EU (Ireland) |