Last updated: 2026-06-13
Deposits & Partial Payments: Data Processing Agreement (Art. 28 GDPR)
This Data Processing Agreement (“DPA”) forms part of the agreement between the Controller and the Processor for the use of the Deposits & Partial Payments application (“the App”) and is concluded pursuant to Article 28(3) GDPR.
1. Parties
- Processor: Kainabinoids GmbH, Carabelligasse 5/Haus 56, 1210 Wien, Österreich; FN 607246i, Handelsgericht Wien; UID ATU80796845; contact: hello@sitething.at (“Processor”).
- Controller: the merchant that installs and configures Deposits & Partial Payments on its Wix account (“Controller”). By installing the App, the Controller accepts this DPA.
2. Subject matter, duration, nature and purpose (Art. 28(3))
- Subject matter: processing of data on the Controller’s behalf solely to provide the deposit and balance-collection service.
- Duration: for as long as the App is installed on the Controller’s Wix account; this DPA is co-terminous with that installation and survives only as needed for deletion (§5.8).
- Nature and purpose: calculating a deposit from the Controller’s rule at checkout, tracking the resulting open balance per order, creating Wix Payment Links to collect the balance, and triggering balance reminders on the Controller’s schedule. No other purpose.
- Types of personal data and categories of data subjects: see Annex 1.
3. Controller’s rights and obligations
- The Controller determines the purposes and means of processing and is responsible for the lawfulness of taking deposits from, and collecting balances from, its own customers.
- The Controller may give, amend, and withdraw documented instructions (the installation and the deposit rules and reminder schedule configured in the App are such instructions). Instructions beyond the App’s configuration must be given in writing to hello@sitething.at.
- The Controller has the audit rights in §5.9 and the termination rights in §7.
4. Processor: processing only on instructions (Art. 28(3)(a))
The Processor processes data only on the Controller’s documented instructions, including with regard to transfers, unless required to do so by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such information. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law (Art. 28(3), last paragraph).
5. Processor obligations
- Confidentiality (Art. 28(3)(b)). The Processor ensures that persons authorized to process the data are bound by an obligation of confidentiality that survives the end of their engagement.
- Security (Art. 28(3)(c) / Art. 32). The Processor implements the technical and organizational measures set out in Annex 2, appropriate to the risk.
- Sub-processors (Art. 28(3)(d)). The Controller grants general authorization for the sub-processors listed in Annex 3. The Processor imposes data protection obligations on each sub-processor equivalent to those in this DPA. The Processor will inform the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance (by updating Annex 3 and notifying the merchant), giving the Controller the opportunity to object; if the Controller reasonably objects and the matter cannot be resolved, the Controller may terminate by uninstalling the App.
- Assistance with data subject rights (Art. 28(3)(e)). Taking account of the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures, insofar as possible, in responding to requests under Chapter III GDPR (Art. 15–22). Because the App stores no buyer personal data (Annex 1), most such requests are fulfilled by the Controller directly within Wix; the Processor assists with the order-level ledger data it holds without undue delay.
- Assistance with Art. 32–36 (Art. 28(3)(f)). The Processor assists the Controller in ensuring compliance with the security, breach-notification, DPIA, and prior-consultation obligations, taking into account the nature of processing and information available to it.
- Personal data breach. The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s data, providing the information available (nature, categories and approximate numbers affected, likely consequences, and measures taken or proposed), and assists the Controller with its own notification obligations.
- DPIA. The Processor provides the information reasonably necessary for the Controller’s data protection impact assessment and any prior consultation with the supervisory authority.
- Return or deletion (Art. 28(3)(g)). On termination (uninstallation), the App immediately stops processing and marks the Controller’s stored data for deletion; all stored ledger and configuration data is hard-deleted within 30 days by an automated daily purge, and existing copies are deleted unless Union or Member State law requires their retention. No buyer content is ever retained, so there is nothing to return or delete on that account.
- Audit (Art. 28(3)(h)). The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. The Processor may satisfy this by providing relevant documentation and its sub-processors’ certifications; on reasonable prior notice (at least 30 days) and no more than once per year save for cause, the Controller may request a more detailed audit.
- Data location / international transfers. The App’s ledger and configuration are stored in Cloudflare D1 in the EU region (EEUR / Zurich); order and customer data otherwise remain in the Controller’s Wix account. The Processor does not transfer the Controller’s data outside the EU/EEA for its own purposes. Cloudflare Inc. is US-headquartered; where access from outside the EEA cannot be excluded, it is governed by Cloudflare’s Data Processing Addendum and the EU Standard Contractual Clauses. Should the transfer position otherwise change, the Processor will first put in place a valid transfer mechanism and inform the Controller.
6. Liability
Each party is liable in accordance with Art. 82 GDPR and the underlying agreement. The Processor is liable for damage caused by processing only where it has not complied with GDPR obligations specifically directed to processors or where it has acted outside or contrary to the Controller’s lawful instructions.
7. Term and termination
This DPA takes effect on installation of the App and ends when the App is uninstalled, subject to the deletion/return obligations in §5.8, which survive termination.
8. Governing law
This DPA is governed by Austrian law, to the extent not overridden by mandatory provisions of the GDPR. Place of jurisdiction is Vienna, Austria, to the extent legally permissible.
Annex 1: Details of processing
| Item | Detail |
|---|---|
| Categories of data subjects | The Controller’s customers who place an order with a deposit |
| Types of personal data (stored) | None directly identifying a buyer. The App stores order-level ledger data: Wix order id and display number, deposit total, balance owed, currency, due date, status, and Wix Payment-Link references. Order ids are Wix identifiers, not buyer names, emails, or payment details. |
| Types of data (used transiently, not stored) | A buyer’s Wix contact id (a UUID), passed to Wix Automations at reminder time so Wix sends the email; discarded after use |
| Types of personal data (stored, configuration only) | Merchant deposit rules (percentage or fixed, per product or store-wide) and reminder schedule; installation record (instance id, timestamps); webhook dedupe ids and per-order reminder state |
| Special categories (Art. 9) | None processed |
| Nature of processing | Calculating a deposit at checkout; tracking the open balance per order; creating Wix Payment Links; triggering reminders via Wix Automations on a schedule |
| Purpose | Let the merchant take a deposit and reliably collect the remaining balance |
| Duration | For the duration of the App installation |
Annex 2: Technical and organizational measures (Art. 32)
- Data minimization / no buyer content. The App stores no buyer name, email address, or payment data. It stores only order-level ledger data (order ids, amounts, due dates, status, payment-link references) and merchant configuration. The buyer’s email and name stay in Wix; only a Wix contact id is used transiently at reminder time.
- Per-merchant isolation. Every stored row is partitioned by the Wix installation id (
instanceId); a token is minted per installation (OAuth client-credentials, instance-scoped) so one merchant’s data is never reachable under another’s token. - Webhook authentication. Incoming Wix webhooks are signature-verified first (RS256) and rejected if unverified; duplicate events are ignored by event-id dedupe.
- Endpoint protection. Configuration and balance endpoints are guarded by a constant-time shared secret that fails closed if the secret is unset, and reject the request before any database access.
- Encryption in transit. TLS to the Wix API, to Cloudflare, and for all balance-collection links.
- Secrets management. App credentials, the Wix public verification key, and the route secret are held in Cloudflare’s encrypted secret storage, never in source code.
- Least privilege. Access to Wix data is limited to the minimum eCommerce scopes required; no “Manage Stores” scope is requested.
- Deletion. On uninstall, the App marks the merchant’s data for deletion immediately and an automated daily purge hard-deletes it within 30 days.
- Confidentiality / integrity / availability. Processing runs on Cloudflare Workers + D1 (EU region); the Processor relies on Cloudflare’s and Wix’s certified controls (see Annex 3).
Annex 3: Authorized sub-processors
| Sub-processor | Role | Location | Safeguards |
|---|---|---|---|
| Cloudflare, Inc. | Backend host (Cloudflare Workers), ledger and configuration storage (Cloudflare D1) | D1 EU region (EEUR / Zurich); US-headquartered company | ISO 27001, SOC 2 Type II, GDPR; own DPA + EU Standard Contractual Clauses. Risk-assessed Low |
The App also operates on the Wix platform (Wix.com Ltd.), where the Controller’s order and customer data already reside and where reminder emails (Wix Automations) and balance collection (Wix Payment Links) take place under the Controller’s existing relationship with Wix. Wix is the Controller’s own platform, not a sub-processor introduced by the Processor.
Changes to this list are notified per §5.3.