Data processing agreement
This agreement forms part of the StoreCalm service terms between the business identified by the account and billing details, as controller, and KP Design, CVR 41134194, Bavnehøjen 5, 4690 Haslev, Denmark, as processor. Contact: contact@storecalm.com. It applies to personal data processed on the customer's behalf through store monitoring.
Scope and instructions
Processing consists of collecting, receiving, storing, analysing, displaying, transmitting authorised alerts, exporting and deleting technical monitoring data for the duration of the service and the applicable deletion period. The purpose is to monitor the customer's authorised stores and help investigate operational failures. The service configuration, these terms and documented support requests are the customer's instructions. We do not use customer monitoring data for advertising or to train general-purpose AI models.
Data can include store URLs, software versions, timestamps, pseudonymous order identifiers, order states, aggregate payment counts, technical diagnostics and masked failure screenshots. Relevant data subjects are the customer's authorised users and, to the limited extent represented by pseudonymous order signals, store customers. Payment card details, names and addresses of store customers, account passwords and special-category data must not be submitted. The customer is responsible for its lawful basis, notices and authority to monitor.
Processor duties
KP Design processes data only on documented instructions, including concerning international transfers, unless applicable law requires otherwise. In that case we notify the customer before processing where legally permitted. We promptly inform the customer if an instruction appears to infringe data protection law. Persons authorised to access customer data are subject to confidentiality obligations, and access is limited to the work required.
Security measures
The service uses TLS, restricted administrative access, workspace membership checks, PostgreSQL row-level isolation, signed connector requests with replay protection, isolated checkout browsers, restricted network destinations, encrypted recovery archives and time-limited diagnostic retention. Monitoring sessions stop before order submission. Screenshots are limited to failure diagnostics and mask form inputs. Operational access and changes are logged. We review and adapt these measures to the risks; the customer remains responsible for its WordPress installation, authorised accounts and local configuration.
Subprocessors and other providers
The customer generally authorises subprocessors necessary to provide the service. Hosting is provided through Contabo, with the StoreCalm application deployed in the EU. Primary encrypted recovery copies are stored on KP Design's separate Synology storage. The processor register and transfer information are provided in the privacy notice. We impose applicable data protection duties on subprocessors and remain responsible for their performance of those duties.
We notify the account contact at least 30 days before adding or replacing a subprocessor for customer monitoring data, except where urgent security or legal circumstances require a shorter notice. The customer may raise a reasonable data protection objection during that period. We work to resolve it; if no reasonable solution is available, the affected service can be terminated and any prepaid unused period refunded.
Stripe also processes payment and billing data under its applicable terms and roles. Google services used on public pages are described separately in the privacy notice. Transfers outside the EEA require an applicable lawful mechanism, such as an adequacy decision or standard contractual clauses with required supplementary measures. Provider terms alone are not a claim that every possible transfer is automatically permitted.
Assistance and incidents
Taking account of the nature of the processing and available information, we assist with data subject requests, security obligations, impact assessments and regulatory consultation. We refer requests concerning customer-controlled data to the customer unless instructed or required otherwise. We notify the customer without undue delay after becoming aware of a personal data breach affecting its data, providing available information about the incident, likely effects, mitigation and a contact point, with further information as it becomes available.
Return, deletion and retention
The customer may export its visible monitoring report and request a fuller export through support. On closure, we return or delete customer monitoring data according to the customer's instruction, unless law requires retention. Detailed results and events normally expire after seven days on Free or 30 days on paid plans. Failure screenshots expire after three or 14 days respectively. Usage and security audit data are retained for 13 months where necessary for service operation, disputes and security. Backups of customer monitoring data expire on a rolling schedule of up to 30 days. Deletion instructions are applied again when restoring older backups.
Account and statutory financial records for which KP Design acts as controller are governed separately by the privacy notice and legal retention duties. Ending the paid plan alone does not close the free workspace; request closure if all workspace data should be deleted.
Evidence and audit
We make information reasonably necessary to demonstrate compliance with these processor obligations available to the customer. We allow and contribute to audits and inspections by the customer or an independent auditor it appoints, subject to reasonable confidentiality, notice and security arrangements that protect other customers. These arrangements do not prevent regulatory access or audits needed following a material incident. The parties coordinate scope and timing and document any corrective actions.
If this agreement conflicts with the service terms on the processing of customer personal data, this agreement takes priority. It does not reduce rights or obligations imposed by the GDPR.