Data Processing Agreement

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and Jiyu Ninja B.V., trading as Stockpilot, registered with the Dutch Chamber of Commerce under number 83679723, Vredenburg 40, 3511 BD Utrecht, the Netherlands ("Stockpilot"). It applies where Stockpilot processes personal data on the Customer's behalf and is accepted when the Customer creates an account.

1. Roles and scope

1.1 The Customer is the controller and Stockpilot is the processor for personal data of the Customer's own customers that is processed through Stockpilot, including order, shipping and return data from the Customer's webshops, marketplaces, carriers and fulfilment partners.

1.2 For personal data relating to the Customer as Stockpilot's own customer, Stockpilot is the controller. That processing falls outside this DPA and is governed by the Privacy Policy.

1.3 Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the categories of personal data and the categories of data subjects.

2. Instructions

2.1 Stockpilot processes personal data only on the Customer's documented instructions, unless required to do otherwise by Union or Member State law. In that case Stockpilot informs the Customer before processing, unless that law prohibits it.

2.2 The Terms of Service, this DPA and the Customer's use of the functionality of the service together constitute the Customer's documented instructions.

2.3 Stockpilot informs the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law.

2.4 Stockpilot does not use the personal data for its own purposes, does not sell it, and does not combine it with data from other customers to build profiles.

3. Confidentiality

Stockpilot ensures that persons authorised to process the personal data are bound by confidentiality, whether by contract or by statutory obligation, and that access is granted only where needed to perform the service.

4. Security

4.1 Stockpilot implements appropriate technical and organisational measures as required by article 32 GDPR. The measures in force are described in Annex 2.

4.2 Stockpilot may update these measures, provided the level of security is not reduced.

5. Subprocessors

5.1 The Customer grants Stockpilot general authorisation to engage subprocessors. The current list is published at stockpilot.com/subprocessors.

5.2 Stockpilot announces the intended addition or replacement of a subprocessor at least 30 days in advance. The Customer may object in writing within that period on reasonable data protection grounds. If the objection cannot be resolved, the Customer may terminate the affected part of the service without penalty.

5.3 Stockpilot imposes on each subprocessor obligations equivalent to those in this DPA and remains fully liable to the Customer for the performance of that subprocessor.

6. Transfers outside the EEA

Where personal data is transferred outside the European Economic Area, the transfer takes place under the European Commission's standard contractual clauses or another valid transfer mechanism. The subprocessor list states where processing takes place per subprocessor.

7. Data subject rights

7.1 Stockpilot assists the Customer, taking into account the nature of the processing, by appropriate technical and organisational measures, in fulfilling the Customer's obligation to respond to requests from data subjects.

7.2 Where a data subject contacts Stockpilot directly about data processed on the Customer's behalf, Stockpilot forwards the request to the Customer without undue delay and does not respond substantively itself, unless the Customer instructs otherwise.

8. Assistance

Stockpilot assists the Customer, taking into account the nature of the processing and the information available to it, in complying with the obligations under articles 32 to 36 GDPR, covering security, breach notification, data protection impact assessments and prior consultation.

9. Personal data breaches

9.1 Stockpilot notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf.

9.2 The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.

9.3 Notification to the Autoriteit Persoonsgegevens and to data subjects is the Customer's responsibility as controller. Stockpilot provides the information reasonably required for that purpose.

10. Return and deletion

10.1 On termination of the service the Customer may choose, in accordance with article 28(3)(g) GDPR, between the return and the deletion of the personal data.

10.2 The Customer can export the personal data from the account at any time during the subscription, and for 14 days after termination, unless the account has been closed for non-payment. In that case Stockpilot makes the export available on written request for 14 days after the outstanding amount has been settled.

10.3 Stockpilot deletes the personal data after that period, unless Union or Member State law requires further retention. Backups are deleted in accordance with the normal backup rotation, with a maximum of 35 days.

10.4 Retention periods imposed by a connected sales channel, including the Amazon Data Protection Policy, prevail where they are shorter than the periods in this article. Personal data originating from Amazon is deleted no later than 30 days after order delivery, except where retention is legally required.

10.5 Stockpilot confirms deletion in writing at the Customer's request, stating the date and the systems concerned.

11. Audits

11.1 Stockpilot makes available to the Customer the information necessary to demonstrate compliance with article 28 GDPR.

11.2 The Customer may audit once per calendar year, at its own expense, after reasonable notice, during business hours and without disproportionate disruption to Stockpilot's operations. Stockpilot may satisfy an audit request by providing an existing certification or third-party assessment report.

12. Liability and term

12.1 The liability provisions of the Terms of Service apply to this DPA.

12.2 This DPA takes effect on acceptance and remains in force for as long as Stockpilot processes personal data on the Customer's behalf.

12.3 Where a provision of this DPA conflicts with the Terms of Service, this DPA prevails for matters concerning the processing of personal data.

13. Governing law

This DPA is governed by Dutch law. Disputes are submitted to the competent court of the Rechtbank Midden-Nederland.

Annex 1, details of the processing

Subject matter: providing the Stockpilot platform for multichannel inventory and order management.

Duration: for as long as the subscription is in force, plus the periods set out in article 10.

Nature and purpose: receiving, processing, fulfilling, shipping and returning orders, keeping stock in sync across sales channels, producing shipping labels, picklists, packing slips and invoices, and providing support.

Categories of personal data: name, delivery and billing address, email address, telephone number, order details, shipping and tracking information, return details, and any other data the Customer's sales channels include in an order.

Categories of data subjects: customers and end customers of the Customer.

Special categories of personal data: none. The Customer does not instruct Stockpilot to process special categories of personal data.

Annex 2, security measures

Encryption of personal data in transit using TLS 1.2 or higher, and at rest using AES-256 or an equivalent standard.

Access control on the principle of least privilege, individually assigned, logged and periodically reviewed, and revoked when no longer needed.

Credentials and API tokens stored encrypted and never logged in readable form.

Segregation of customer data at account level.

Logging and monitoring of system and security events.

Regular backups, stored encrypted, with restore testing.

Documented incident response procedure.

Confidentiality obligations for all personnel with access.

Assessment of subprocessors before deployment and contractual imposition of equivalent obligations.
Aerial view of a calm turquoise ocean under a partly cloudy sky.

Discover what Stockpilot can do
for your business

In 45 minutes, our experts will show you how to manage orders, inventory, and shipping from one platform. For webshops, marketplaces, and everything in between.