Data processing agreement
This applies when you sell on NodeShop and your customers' personal data passes through our systems. You are the controller of that data. [Legal entity name] is your processor.
effective [Effective date]
01Roles
You decide why and how your customers’ personal data is processed. We process it only on your documented instructions — which, in the ordinary course, means operating the portal, the storefront, the billing and the support desk you have configured.
Using the platform as intended constitutes those instructions. Anything beyond it needs to be agreed in writing.
02What we process on your behalf
| Category | What it is | How long |
|---|---|---|
| Account | Email address, display name, and the portal it belongs to | For as long as the account exists |
| Sessions | IP address and browser user agent at sign-in | Until the session expires or is revoked |
| Billing | Billing email, country and tax identifier where supplied | As long as tax law requires the record |
| Usage | Aggregated request counts, bandwidth and connection counts per key | Rolled up; raw samples are not retained indefinitely |
| Availability | Probe results against endpoints we serve | 90 days, then deleted automatically |
| Support | Ticket contents and correspondence | For as long as the account exists |
Data subjects are your customers and the people they invite into their workspaces.
03Our undertakings
We will process your customers’ data only for you; keep it confidential and ensure everyone with access is bound to do the same; apply the security measures described in our privacy policy; help you respond to data subject requests; and tell you without undue delay if there is a personal data breach affecting it.
We will not use your customers’ data for our own purposes, will not contact your customers except as necessary to operate the service you asked for, and will not sell it.
04Sub-processors
You authorise the providers below. We will give notice before adding a new one, and you may object on reasonable data-protection grounds.
| Provider | What they do | What they receive |
|---|---|---|
| eeze | Checkout, payment processing and merchant of record | Order and billing details, billing email, country, tax identifier |
| Resend | Transactional email — sign-in codes, receipts, alerts | Email address, message content |
| Cloudflare | Authoritative DNS for platform and operator domains | Domain names only; no customer records |
| Let's Encrypt | TLS certificate issuance | Hostnames only |
| OpenRouter | The in-product help assistant, when an operator enables it | The question asked and the page context it was asked from |
| TeraSwitch (Frankfurt, Germany) | Application and database hosting | All service data, at rest in the EU |
05Isolation between operators
Every row belonging to your store is scoped to your portal and that scope is enforced by the database, not by application code. Another operator on this platform cannot read your customers’ data, and neither can a query of ours that forgets to filter.
06Return and deletion
On termination we will, at your choice, return your customers’ data in a portable form or delete it, except where we are required to keep a record — billing and tax records in particular. [Counsel: set the deletion window and confirm the retention exceptions.]
07Audit, transfers and law
[Counsel: this section needs drafting. It should cover audit rights and how they are satisfied, the international transfer mechanism, the liability position between controller and processor, and how this agreement interacts with the terms of service.]
[Legal entity name], [Registered address]. [privacy@nodeshop.app — confirm this address exists]. Governed by [Governing law and courts].