EU DATA ACT

Data Portability and Switching Policy

The exportable data, formats, switching process, transition period, retrieval and deletion framework for HYPRCART customers.

Provideradmorris GmbH · HYPRCART
Effective22 July 2026
Version2026-07-22.3 · English

1. Scope and application

This policy is the online information register and switching procedure for HYPRCART as a data processing service under the EU Data Act. It applies to each business Customer that enters into a HYPRCART subscription or other service contract.

The accepted Order may describe additional export interfaces, data volumes, service-specific limitations and assistance. This policy forms part of the contractual switching framework together with the Terms and the Order.

2. Exportable data and digital assets

Subject to the Customer's configuration and rights, exportable data includes:

  • organisation, users, roles and service configuration;
  • products, variants, categories, collections, prices, inventory and related catalogue data;
  • storefront, market, language, tax, shipping, discount and checkout configuration;
  • Customer-uploaded media files and associated metadata;
  • theme, page and structured content documents in the available platform format;
  • customer, address, cart, order, fulfilment, refund and commerce records;
  • reviews, questions, answers, consent and communication records controlled by the Customer;
  • app and integration configuration that is Customer-owned and technically portable; and
  • available audit and delivery records provided to the Customer through the service.

Exports may be provided as JSON, CSV, original media/object files and documented API responses, depending on the data. Schema descriptions and field documentation will be made available with the export or relevant API documentation.

3. Excluded or protected data

Export does not include:

  • HYPRCART source code, platform binaries, algorithms and internal system configuration;
  • security-sensitive credentials, secrets, fraud rules, detection logic or data that would compromise another party;
  • internal operational, telemetry, debugging and provider-management data not generated by the Customer's use for its own purposes;
  • aggregated or anonymised platform statistics that do not relate specifically to the Customer;
  • third-party data or licensed materials we are not permitted to transfer; and
  • data whose disclosure would violate law or the rights of another person.

We will apply exclusions narrowly and use proportionate measures to protect trade secrets without preventing effective switching. We will explain material exclusions on request where doing so does not undermine security or third-party rights.

4. How to request export or switching

  1. Email legal@hyprcart.com from an authorised Customer contact with the organisation, requested scope, desired destination and target date.
  2. We verify authority and confirm the data, digital assets, format, expected volume, transition plan and any Customer actions.
  3. The Customer chooses transfer to another provider, transfer to its own infrastructure, or erasure after retrieval.
  4. We make a secure export available or cooperate with the stated destination using available interfaces.
  5. The Customer validates receipt and informs us of material transfer issues promptly.

We will not request unnecessary commercially sensitive information about the new provider. The Customer must ensure that the destination is authorised and secure.

5. Notice, transition and continuity

Unless a shorter period is agreed, switching begins after a notice period that will not exceed two months. The standard transition period will not exceed 30 calendar days. The Customer may extend that transition once for a period it considers more appropriate.

If switching is technically unfeasible within 30 days, we will notify the Customer within 14 working days after the request, explain the technical reason and state an alternative period not exceeding seven months. During transition we will maintain reasonable continuity of contracted core functions and provide assistance within our responsibilities, subject to security and the Customer's cooperation.

6. Switching charges

Until 12 January 2027, any switching charge will be limited to the direct costs incurred for the specific switching process and will be disclosed before it is incurred. From 12 January 2027, no switching charge will apply where the EU Data Act prohibits it. Standard unpaid subscription fees, third-party fees chosen by the Customer and exceptional services outside mandatory switching assistance remain due.

7. Retrieval, termination and deletion

After the transition period, the Customer will have at least 30 calendar days to retrieve exportable data unless a longer period is agreed. The contract terminates and data is deleted on the dates agreed for the completed switch, subject to mandatory legal retention, unresolved payment records and backup overwrite cycles.

During backup retention, Customer Data is access-restricted and not returned to normal use. We will confirm completion of deletion on reasonable request. The DPA continues to apply until Customer Personal Data has been deleted or anonymised.

8. International access safeguards

We take reasonable contractual, technical and organisational measures to prevent unlawful international governmental access to or transfer of non-personal data held in the EU where the EU Data Act requires such protection. Personal-data transfers are governed by the GDPR and DPA.

Questions about schemas, export scope or a planned switch may be sent to legal@hyprcart.com before contracting.