Legal
Data Processing Agreement (DPA)
Last updated: 1 July 2026
The Data Processing Agreement (DPA) is a legal addendum that governs the processing of personal data between Takka Store and its customers, ensuring full compliance with GDPR standards. It is an integral part of the Terms & Conditions and the Privacy Policy.
About the agreement
- A binding document that governs how the personal data provided by the merchant to run their store is processed.
- Its clauses are designed to comply with Article 28 of the EU General Data Protection Regulation.
- It represents a contract between the customer (data controller) and the Takka Store platform (the technical processor).
- It applies to all services that involve collecting, storing or processing individuals' data in the store.
Legal and technical definitions
- Personal data: any information relating to the data subject such as name, email and location.
- Controller: the customer/merchant who determines the purposes and means of processing.
- Processor: the Takka Store platform, which processes the data on the controller's behalf.
- Sub-processor: any third party, such as analytics tools, engaged to assist with execution.
- Data subject: the end customer to whom the processed data relates.
- Processing: any operation on data such as collection, organization, storage, modification and deletion.
Responsibilities of the parties
- Customer responsibility: ensures they have the legal basis to collect and process their customers' data.
- Takka Store commitment: performing technical operations only within the scope of delivering the service and protecting the infrastructure.
- Sub-processing: subject to contractual terms that guarantee the same level of protection as this agreement.
Data-processing controls
- We process data only based on clear written or programmatic instructions from the controller.
- Processing includes cloud storage, statistical analysis, and facilitating shipping and payment.
- Purposes are limited to e-commerce services, technical support and performance improvement.
- It continues throughout the subscription period and ends upon an account-deletion request or service cancellation.
Security commitments
- Data encryption: advanced protocols (AES-256) for data at rest and in transit.
- Anonymization: processing that ensures data cannot be linked to its owner without separate additional information.
- Confidentiality and integrity: no access to data except within the scope of running the service and preventing tampering.
- Backup: organized periodic backups to restore data immediately in emergencies.
- Disaster recovery: disaster-recovery protocols for business continuity.
- Security testing: periodic penetration tests and comprehensive assessments to detect vulnerabilities.
Confidentiality and staff training
- All staff sign binding non-disclosure agreements that remain in force after their employment ends.
- Periodic courses for the engineering team on the latest information-security methods.
- Applying a least-privilege policy — only authorized personnel can access the data.
Sub-processors
- An updated list of technical partners is available within the security and data-protection page.
- Notifying the controller in advance before adding or changing any sub-processor.
- The merchant's right to object to any new sub-processor when there are documented concerns.
- Imposing strict protection terms on all sub-processors, matching this agreement.
Protecting data-subject rights
- We help merchants fulfill their customers' privacy requests (access, correction, deletion, portability).
- We provide the tools needed to exercise these legal rights flexibly.
Contact
- For data-processing requests and inquiries: privacy@takkastore.com.
Related links: Privacy Policy · Terms & Conditions · Contact us