Acuerdo de tratamiento de datos
Version 1.0.0 · Last updated: September 5, 2026
This Data Processing Agreement (the DPA) forms part of the Terms of Service between the merchant that holds a Composerie account (the Merchant or Controller) and Composerie (the Processor). It governs the personal data that Composerie processes on the Merchant's behalf under Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR. It is accepted electronically when the Merchant accepts the Terms; no signature is required. A countersigned copy is available on request.
1. Parties and Scope
Processor
Composerie
Registered with the Dutch Chamber of Commerce (KvK) under number 80513573
Markerkant 13-11, 1314 AL Almere, Flevoland
VAT: NL003449094B70
The Netherlands
Privacy contact: support@composerie.com
The Controller is the legal entity that registered the Composerie organization, as recorded in the account settings. This DPA applies to all Merchant Personal Data (defined below) that Composerie processes while providing the Service, in every environment and through every connected platform.
This DPA does not apply to data for which Composerie is itself the controller (such as the Merchant's own account, billing and support data). That processing is described in our Privacy Policy.
2. Definitions
- Merchant Personal Data — personal data of the Merchant's shoppers, order recipients, staff and other data subjects that Composerie processes on the Merchant's instructions, as described in Section 4.
- Sub-processor — a third party engaged by Composerie to process Merchant Personal Data on Composerie's behalf.
- Data Protection Law — the GDPR, the UK GDPR, the Dutch GDPR Implementation Act (UAVG) and any other data protection law that applies to the processing.
- Service, Terms and Content have the meaning given in the Terms of Service. Other capitalized terms have the meaning given in the GDPR.
3. Roles of the Parties
The Merchant is the controller of Merchant Personal Data and Composerie is its processor. The Merchant warrants that it has a lawful basis for the processing, that it has provided the notices required by Data Protection Law to its shoppers, and that its instructions comply with Data Protection Law. Composerie processes Merchant Personal Data only on the Merchant's documented instructions; these Terms, this DPA and the Merchant's use of the Service's features (including the integrations the Merchant connects) constitute the complete set of instructions.
4. Details of the Processing
5. Composerie's Obligations
Composerie shall:
- process Merchant Personal Data only on the Merchant's documented instructions, unless required to do otherwise by law, in which case Composerie informs the Merchant before processing unless the law prohibits it;
- immediately inform the Merchant if, in Composerie's opinion, an instruction infringes Data Protection Law;
- ensure that persons authorized to process Merchant Personal Data have committed themselves to confidentiality;
- implement the technical and organizational measures in Annex 2 and keep them appropriate to the risk;
- engage sub-processors only in accordance with Section 8;
- assist the Merchant with data-subject requests, data protection impact assessments and prior consultations as set out in Section 10;
- delete or return Merchant Personal Data at the end of the Service as set out in Section 13;
- make available the information necessary to demonstrate compliance and allow audits as set out in Section 12.
6. Security of Processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, Composerie implements the technical and organizational measures described in Annex 2. Composerie may update those measures from time to time, provided the updates do not materially lower the overall level of protection.
7. Confidentiality and Personnel
Access to Merchant Personal Data is limited to personnel who need it to operate, support or secure the Service. Such personnel are bound by written confidentiality obligations and receive data-protection instructions. Support staff access a Merchant's data only for the purpose of resolving that Merchant's request, and such access is logged.
8. Sub-processors
The Merchant grants Composerie general authorization to engage the sub-processors listed in Annex 1. Composerie imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains fully liable to the Merchant for the sub-processor's performance.
Composerie announces any intended addition or replacement of a sub-processor at least 30 days in advance by updating Annex 1 (published at composerie.com/dpa) and, for material changes, by email to the organization owners. The Merchant may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, the Merchant may terminate the affected part of the Service with immediate effect and receive a pro-rata refund of prepaid fees for the remaining period.
Parties that receive Merchant Personal Data because the Merchant connected them (its e-commerce platform, its fulfillment partners and the AI provider accounts it connects) act on the Merchant's own instructions and agreements; they are listed in Annex 1 for transparency but are not Composerie's sub-processors.
9. International Transfers
Merchant Personal Data is stored and processed in the European Economic Area. Where a sub-processor processes data outside the EEA, Composerie relies on a European Commission adequacy decision (including the EU-US Data Privacy Framework for certified providers) or on the Standard Contractual Clauses (Commission Decision 2021/914) together with the supplementary measures required under Data Protection Law, and the UK Addendum where the UK GDPR applies. Annex 1 records the safeguard used per sub-processor.
10. Assistance with Data-Subject Requests and Assessments
- Data-subject requests. If a data subject contacts Composerie directly about Merchant Personal Data, Composerie refers the request to the Merchant without undue delay and does not respond substantively unless instructed. Composerie provides the tools and assistance the Merchant reasonably needs to answer access, rectification, erasure, restriction, portability and objection requests, including erasure of a shopper's personalization content and order identifiers on request.
- Shopify privacy webhooks. For Shopify stores, Composerie answers Shopify's customers/data_request, customers/redact and shop/redact webhooks automatically: it exports the stored data for the customer, erases or anonymizes the customer's order data, personalization content and email logs, and purges all data of an uninstalled store after Shopify's mandatory waiting period.
- Impact assessments. Composerie provides the information about its processing reasonably needed for the Merchant's data protection impact assessments and prior consultations with a supervisory authority.
11. Personal Data Breach
Composerie notifies the Merchant without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Merchant Personal Data. The notification describes, as far as known at that time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Composerie provides further information in phases as it becomes available and cooperates with the Merchant's own notification duties. Notification of, or response to, a breach is not an acknowledgement of fault.
12. Information and Audits
Composerie makes available to the Merchant the information reasonably necessary to demonstrate compliance with this DPA, including this DPA, Annex 2, the current sub-processor list and, on request, summaries of security reviews. Where that information is insufficient, the Merchant (or an independent auditor bound by confidentiality) may audit Composerie's processing once per twelve months, with at least 30 days' written notice, during business hours, without unreasonably disrupting operations, and at the Merchant's cost. Additional audits are permitted where required by a supervisory authority or after a personal data breach affecting the Merchant.
13. Deletion and Return
The Merchant can export its designs, product configurations and order data from the Service at any time and may request a complete machine-readable export before closing the account. When the Merchant closes its organization, Composerie keeps the data for a 30-day recovery period and then deletes it, including files in object storage, unless Composerie must retain specific records by law (for example invoices and order records for tax purposes, which are retained for 7 years with personal identifiers removed as described in the Privacy Policy). Encrypted backups expire within a further 30 days, except that the four most recent backups are always kept as a recovery point and are deleted as soon as newer backups replace them. For Shopify stores, an uninstall triggers the shop/redact process described in Section 10.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Law does not allow such limitation. Each party is liable for administrative fines imposed on it by a supervisory authority to the extent the fine results from its own breach.
15. Term, Precedence and Governing Law
- Term — this DPA takes effect when the Merchant accepts the Terms and remains in force for as long as Composerie processes Merchant Personal Data.
- Precedence — in case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails. Where the Standard Contractual Clauses apply, they prevail over both.
- Changes — Composerie may update this DPA to reflect changes in Data Protection Law or the Service; material changes are announced at least 30 days in advance as described in the Terms.
- Governing law — this DPA is governed by the laws of the Netherlands, and disputes are subject to the jurisdiction clause in the Terms of Service, without prejudice to data subjects' rights under Data Protection Law.
Annex 1 — Sub-processors and Other Recipients
Current as of September 5, 2026. Sub-processors engaged by Composerie:
| Sub-processor | Purpose | Location and safeguard |
|---|---|---|
| Hetzner Online GmbH | Application hosting, databases, background job queues and backups on dedicated servers | Germany (EU) |
| Cloudflare, Inc. | DNS, TLS, content delivery, DDoS and bot protection, and object storage (R2) for uploads, previews, print files and encrypted backups | EU/US edge network; EU-US Data Privacy Framework and Standard Contractual Clauses |
| Upstash, Inc. | Managed Redis for rate limiting and short-lived caches | Frankfurt, Germany (EU); Standard Contractual Clauses |
| Resend, Inc. | Transactional email delivery (account, billing, order, status and support notices) and routing of inbound support email | United States; EU-US Data Privacy Framework and Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Error monitoring and performance diagnostics | EU data residency (Frankfurt, Germany) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing and invoicing for merchants who are not billed through Shopify | Ireland (EU) and United States; Standard Contractual Clauses |
Recipients engaged by the Merchant (not sub-processors of Composerie):
| Recipient | What they receive | Location |
|---|---|---|
| Shopify International Ltd. / Shopify Inc. | The merchant's e-commerce platform: store, product, order and billing data are exchanged through the Shopify APIs the merchant authorizes | Canada and Ireland; governed by the merchant's Shopify agreement |
| Print and fulfillment partners the merchant connects (for example Printful, Printify, MerchOne) | Receive order line items, print files and the recipient's shipping details to produce and ship personalized orders | Per partner; governed by the merchant's agreement with that partner |
| AI providers the merchant connects with its own account (for example OpenAI, Anthropic, Google, Stability AI, Replicate, fal.ai, remove.bg) | Receive the images, text and prompts the merchant submits to the optional AI design and product-description tools | Per provider; governed by the merchant's agreement with that provider |
| Google LLC / Microsoft Corporation | Identity provider when a user chooses to sign in with Google or Microsoft; shares the name, email address and profile picture with Composerie | Per provider; independent controller of the sign-in |
Annex 2 — Technical and Organizational Measures
- Encryption — TLS 1.2 or higher for all data in transit, including between Composerie services; encryption at rest for databases, object storage and backups; connected-platform access tokens and provider credentials encrypted with keys managed outside the database.
- Access control — role-based access with least privilege for merchants, their team members and Composerie staff; multi-factor authentication available for all accounts and required for administrative access; short-lived signed tokens for the storefront customizer, embedded surfaces and webhooks; every tenant query scoped to the organization.
- Data minimization — Shopify order payloads are reduced to an allowlist of shipping fields before storage; billing addresses are stripped at ingress and rejected by a database constraint; the Web Pixel sends no personally identifiable information; no customer-profile scope is requested.
- Secret management — all credentials are stored in a dedicated secrets manager and injected at runtime; no secrets are stored in source code or container images; secrets are rotated when personnel or providers change.
- Logging and monitoring — application and security logging with request identifiers, centralized error monitoring with EU data residency, audit logging of administrative and support actions (retained 24 months), uptime monitoring with a public status page and incident timeline.
- Resilience — weekly encrypted database backups retained for 30 days, of which the four most recent are always kept so that a period of failed backups cannot leave us without a recovery point, with periodic restore tests; redundant job processing with automatic retries; rate limiting and abuse detection on public endpoints.
- Secure development — peer review and automated review of every change before release, automated tests and security audits in continuous integration, dependency vulnerability scanning, staged releases through a staging environment with verification gates before production, and a documented rollback path.
- Sub-processor management — written data-processing terms with every sub-processor, transfer safeguards recorded in Annex 1, and a 30-day announcement period for changes.
- Incident response — a documented incident-response procedure with severity classification, a 48-hour notification commitment to affected merchants, root-cause analysis and corrective actions.
- Deletion — automated retention jobs enforce the periods in the Privacy Policy; Shopify redaction webhooks are processed automatically with durable retries; organization deletion purges databases and object storage after the 30-day recovery period.