LEGAL
Data processing agreement
VERSION 1.0 · LAST CHANGED 21 AUG 2026 · APPLIES TO SKUPLY.IO AND THE SERVICE
THESE ARE DRAFTS IN OUR OWN WORDS. THEY NEED A LAWYER BEFORE THEY BIND ANYONE. ANYTHING IN VERMILION IS A NUMBER OR A PERIOD THAT STILL HAS TO BE FIXED.
01
Parties and precedence
This agreement belongs to the terms and applies as soon as you give us access to your shop. You are the controller, we are the processor. Where the terms and this agreement contradict each other about personal data, this agreement wins.
02
What we process and what for
We process only what is needed to fill product fields and keep them filled. Concretely:
KIND OF DATA
DATA SUBJECTS
PURPOSE
Product titles, descriptions, attributes, media
none
deriving and writing fields
Names in free text fields, where present
staff, designers, suppliers
unavoidable consequence of reading the text
Contact details of your app users
your staff
access and the monthly report
Log lines per field
the same staff
being able to roll back and account for it
TO BE COMPLETED ONCE THE FIRST CONNECTION IS MEASURED
03
We act only on your instruction
We process the data only as described here and as you instruct us. If we receive an instruction we believe conflicts with the GDPR, we say so and do not carry it out until it is resolved.
If a law obliges us to a processing not listed here, we report that beforehand, unless that same law forbids it.
04
What we never do with your data
Three things are fixed here, not as a promise but as a prohibition, and they sit that way in our own systems too:
We do not use your catalogue to train models, neither our own nor a third party’s. We do not merge your data with another customer’s. And we do not sell, rent out or publish anything.
That last one covers aggregated and anonymised forms too, because in a product catalogue the line between anonymous and traceable sits lower than people think.
05
Confidentiality
Everyone on our side who can reach your data is bound to confidentiality, and that obligation continues after the contract ends. Access is limited to the people who run the service, and that is a short list we hand over on request.
06
Security
We take appropriate measures within the meaning of article 32 GDPR. What that means concretely:
MEASURE
HOW
STATUS
Access to your shop
API key with product permissions only, no admin login
in place
Storage of keys
encrypted, separated from the rest
in place
Processing and storage
inside the EU
in place
Access on our side
limited to whoever runs the service, with two factor
in place
Traceability
every write action in the log with timestamp and source
in place
[external assessment]
[pentest or certification]
[still to decide]
THE LAST ROW IS A CHOICE THAT STILL HAS TO BE MADE
07
Sub-processors
We may engage sub-processors. The current list sits in the privacy statement and forms part of this agreement. Every sub-processor is put under the same obligations in writing as set out here.
If we want to add or replace one, we give thirty days notice. If you object on reasonable grounds within that period and we cannot resolve it, you may terminate the agreement at no cost for the remaining term.
08
Transfer outside the EU
There is none. Processing and storage happen inside the EU, at our sub-processors too. Should that ever change, it is a change to the sub-processor list and the procedure above applies, with standard contractual clauses as the basis.
09
Assistance with data subject rights
If you receive a request for access, correction or deletion covering data in our systems, we help with it. We never answer such a request ourselves: it is your request and you decide. We deliver what you need within ten working days and charge nothing for it.
10
Data breaches
If we discover a breach, we report it to you without undue delay and at the latest within 24 hours of discovery. That report states what happened, which data it concerns, what the likely consequences are and what we have done about it.
Notifying the supervisory authority and the data subjects is yours to do, because that is the controller’s duty. We supply everything you need for it, and we report even when we are not certain. A breach we do not report because it might have been minor is worse than one report too many.
11
Audit
You may check that we keep to this. Once a year, and beyond that as soon as there is a concrete reason. On request we supply our measures, the log files relating to your data and the sub-processor list.
If you want an on-site audit by an independent party, we cooperate. The cost of that is yours, unless something comes out of it that does not match what is written here.
12
Return and deletion
Everything we wrote into your shop sits there and stays there. That does not need returning, you already have it.
What we hold on our side, the field log and our own namespace, we delete after the contract ends on request within thirty days, and otherwise automatically after ninety days. If you want the log handed over first, we deliver it as a file before we throw it away. Whatever a law obliges us to keep, we keep, and then we say which part that is and for how long.
13
Liability and term
This agreement runs for as long as we process data for you and ends by itself afterwards, except for confidentiality and the deletion duty above. For liability, what is written in the terms applies, with the proviso that fines from the supervisory authority demonstrably resulting from our failure are not covered by it. The cap still has to be fixed.
Questions about this go to hallo@skuply.io and are answered by somebody who builds the service themselves.