The Data Processing Agreement (DPA) is a legal addendum that governs the processing of personal data between Takka Store and its customers, ensuring full compliance with GDPR standards. It is an integral part of the Terms & Conditions and the Privacy Policy.

About the agreement

  • A binding document that governs how the personal data provided by the merchant to run their store is processed.
  • Its clauses are designed to comply with Article 28 of the EU General Data Protection Regulation.
  • It represents a contract between the customer (data controller) and the Takka Store platform (the technical processor).
  • It applies to all services that involve collecting, storing or processing individuals' data in the store.

Legal and technical definitions

  • Personal data: any information relating to the data subject such as name, email and location.
  • Controller: the customer/merchant who determines the purposes and means of processing.
  • Processor: the Takka Store platform, which processes the data on the controller's behalf.
  • Sub-processor: any third party, such as analytics tools, engaged to assist with execution.
  • Data subject: the end customer to whom the processed data relates.
  • Processing: any operation on data such as collection, organization, storage, modification and deletion.

Responsibilities of the parties

  • Customer responsibility: ensures they have the legal basis to collect and process their customers' data.
  • Takka Store commitment: performing technical operations only within the scope of delivering the service and protecting the infrastructure.
  • Sub-processing: subject to contractual terms that guarantee the same level of protection as this agreement.

Data-processing controls

  • We process data only based on clear written or programmatic instructions from the controller.
  • Processing includes cloud storage, statistical analysis, and facilitating shipping and payment.
  • Purposes are limited to e-commerce services, technical support and performance improvement.
  • It continues throughout the subscription period and ends upon an account-deletion request or service cancellation.

Security commitments

  • Data encryption: advanced protocols (AES-256) for data at rest and in transit.
  • Anonymization: processing that ensures data cannot be linked to its owner without separate additional information.
  • Confidentiality and integrity: no access to data except within the scope of running the service and preventing tampering.
  • Backup: organized periodic backups to restore data immediately in emergencies.
  • Disaster recovery: disaster-recovery protocols for business continuity.
  • Security testing: periodic penetration tests and comprehensive assessments to detect vulnerabilities.

Confidentiality and staff training

  • All staff sign binding non-disclosure agreements that remain in force after their employment ends.
  • Periodic courses for the engineering team on the latest information-security methods.
  • Applying a least-privilege policy — only authorized personnel can access the data.

Sub-processors

  • An updated list of technical partners is available within the security and data-protection page.
  • Notifying the controller in advance before adding or changing any sub-processor.
  • The merchant's right to object to any new sub-processor when there are documented concerns.
  • Imposing strict protection terms on all sub-processors, matching this agreement.

Protecting data-subject rights

  • We help merchants fulfill their customers' privacy requests (access, correction, deletion, portability).
  • We provide the tools needed to exercise these legal rights flexibly.

Contact


Related links: Privacy Policy · Terms & Conditions · Contact us