Last updated: 2026-06-13

Deposits & Partial Payments: Data Processing Agreement (Art. 28 GDPR)

This Data Processing Agreement (“DPA”) forms part of the agreement between the Controller and the Processor for the use of the Deposits & Partial Payments application (“the App”) and is concluded pursuant to Article 28(3) GDPR.

1. Parties

2. Subject matter, duration, nature and purpose (Art. 28(3))

3. Controller’s rights and obligations

4. Processor: processing only on instructions (Art. 28(3)(a))

The Processor processes data only on the Controller’s documented instructions, including with regard to transfers, unless required to do so by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such information. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law (Art. 28(3), last paragraph).

5. Processor obligations

  1. Confidentiality (Art. 28(3)(b)). The Processor ensures that persons authorized to process the data are bound by an obligation of confidentiality that survives the end of their engagement.
  2. Security (Art. 28(3)(c) / Art. 32). The Processor implements the technical and organizational measures set out in Annex 2, appropriate to the risk.
  3. Sub-processors (Art. 28(3)(d)). The Controller grants general authorization for the sub-processors listed in Annex 3. The Processor imposes data protection obligations on each sub-processor equivalent to those in this DPA. The Processor will inform the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance (by updating Annex 3 and notifying the merchant), giving the Controller the opportunity to object; if the Controller reasonably objects and the matter cannot be resolved, the Controller may terminate by uninstalling the App.
  4. Assistance with data subject rights (Art. 28(3)(e)). Taking account of the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures, insofar as possible, in responding to requests under Chapter III GDPR (Art. 15–22). Because the App stores no buyer personal data (Annex 1), most such requests are fulfilled by the Controller directly within Wix; the Processor assists with the order-level ledger data it holds without undue delay.
  5. Assistance with Art. 32–36 (Art. 28(3)(f)). The Processor assists the Controller in ensuring compliance with the security, breach-notification, DPIA, and prior-consultation obligations, taking into account the nature of processing and information available to it.
  6. Personal data breach. The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s data, providing the information available (nature, categories and approximate numbers affected, likely consequences, and measures taken or proposed), and assists the Controller with its own notification obligations.
  7. DPIA. The Processor provides the information reasonably necessary for the Controller’s data protection impact assessment and any prior consultation with the supervisory authority.
  8. Return or deletion (Art. 28(3)(g)). On termination (uninstallation), the App immediately stops processing and marks the Controller’s stored data for deletion; all stored ledger and configuration data is hard-deleted within 30 days by an automated daily purge, and existing copies are deleted unless Union or Member State law requires their retention. No buyer content is ever retained, so there is nothing to return or delete on that account.
  9. Audit (Art. 28(3)(h)). The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. The Processor may satisfy this by providing relevant documentation and its sub-processors’ certifications; on reasonable prior notice (at least 30 days) and no more than once per year save for cause, the Controller may request a more detailed audit.
  10. Data location / international transfers. The App’s ledger and configuration are stored in Cloudflare D1 in the EU region (EEUR / Zurich); order and customer data otherwise remain in the Controller’s Wix account. The Processor does not transfer the Controller’s data outside the EU/EEA for its own purposes. Cloudflare Inc. is US-headquartered; where access from outside the EEA cannot be excluded, it is governed by Cloudflare’s Data Processing Addendum and the EU Standard Contractual Clauses. Should the transfer position otherwise change, the Processor will first put in place a valid transfer mechanism and inform the Controller.

6. Liability

Each party is liable in accordance with Art. 82 GDPR and the underlying agreement. The Processor is liable for damage caused by processing only where it has not complied with GDPR obligations specifically directed to processors or where it has acted outside or contrary to the Controller’s lawful instructions.

7. Term and termination

This DPA takes effect on installation of the App and ends when the App is uninstalled, subject to the deletion/return obligations in §5.8, which survive termination.

8. Governing law

This DPA is governed by Austrian law, to the extent not overridden by mandatory provisions of the GDPR. Place of jurisdiction is Vienna, Austria, to the extent legally permissible.


Annex 1: Details of processing

ItemDetail
Categories of data subjectsThe Controller’s customers who place an order with a deposit
Types of personal data (stored)None directly identifying a buyer. The App stores order-level ledger data: Wix order id and display number, deposit total, balance owed, currency, due date, status, and Wix Payment-Link references. Order ids are Wix identifiers, not buyer names, emails, or payment details.
Types of data (used transiently, not stored)A buyer’s Wix contact id (a UUID), passed to Wix Automations at reminder time so Wix sends the email; discarded after use
Types of personal data (stored, configuration only)Merchant deposit rules (percentage or fixed, per product or store-wide) and reminder schedule; installation record (instance id, timestamps); webhook dedupe ids and per-order reminder state
Special categories (Art. 9)None processed
Nature of processingCalculating a deposit at checkout; tracking the open balance per order; creating Wix Payment Links; triggering reminders via Wix Automations on a schedule
PurposeLet the merchant take a deposit and reliably collect the remaining balance
DurationFor the duration of the App installation

Annex 2: Technical and organizational measures (Art. 32)

Annex 3: Authorized sub-processors

Sub-processorRoleLocationSafeguards
Cloudflare, Inc.Backend host (Cloudflare Workers), ledger and configuration storage (Cloudflare D1)D1 EU region (EEUR / Zurich); US-headquartered companyISO 27001, SOC 2 Type II, GDPR; own DPA + EU Standard Contractual Clauses. Risk-assessed Low

The App also operates on the Wix platform (Wix.com Ltd.), where the Controller’s order and customer data already reside and where reminder emails (Wix Automations) and balance collection (Wix Payment Links) take place under the Controller’s existing relationship with Wix. Wix is the Controller’s own platform, not a sub-processor introduced by the Processor.

Changes to this list are notified per §5.3.