1. Parties and automatic effect
This Data Processing Agreement ("DPA") is between admorris GmbH as provider and the business customer identified in an accepted HYPRCART Order ("Customer"). It forms part of the B2B Terms of Service and any Order that references or incorporates those Terms.
This DPA becomes binding automatically, without a separate signature, when HYPRCART accepts a subscription or other Order for which the Customer has accepted the Terms. It applies to Customer Personal Data from the first processing operation and remains in effect for as long as HYPRCART processes that data on the Customer's behalf.
The Customer's electronic acceptance during subscription checkout or acceptance of a signed Order incorporates this DPA. If the parties sign a negotiated DPA, that signed document prevails for its subject matter.
2. Definitions and roles
"Customer Personal Data", "controller", "processor", "data subject", "processing", "personal data breach" and "supervisory authority" have the meanings in the GDPR. "Data Protection Law" means the GDPR and applicable national data-protection law.
The Customer is controller or processor, as applicable, for Customer Personal Data. admorris GmbH is the Customer's processor or subprocessor. Each party is an independent controller for personal data it processes for its own account administration, security, billing, legal compliance and business operations.
3. Documented instructions
We will process Customer Personal Data only on documented Customer instructions, including the Terms, Order, Customer configuration, authorised API calls, support requests and lawful use of service functions, unless EU or Member State law requires other processing. Where lawful, we will notify the Customer before legally required processing.
We will promptly inform the Customer if, in our opinion, an instruction infringes Data Protection Law and may suspend the affected instruction while the parties resolve it. We do not determine whether Customer instructions, notices or legal bases are sufficient and the Customer remains responsible for them.
4. Confidentiality and security
Personnel authorised to process Customer Personal Data are bound by confidentiality and receive access only as needed. We maintain technical and organisational measures appropriate to the risk under GDPR Article 32. The current measures are described in Annex 2 below.
The Customer is responsible for secure configuration, user permissions, credentials, endpoints, integrations, lawful data minimisation and its own systems. The Customer will not submit special-category data, criminal-conviction data, government identity documents, health data or payment-card authentication data unless the Order expressly supports it and the parties agree any required additional safeguards.
5. Subprocessors
The Customer gives general written authorisation for the subprocessors on the current Subprocessor List. We impose data-protection obligations that provide materially the same protection required by this DPA and remain responsible for a subprocessor's performance to the extent required by law.
We will provide at least 30 days' advance notice of a new subprocessor that may process Customer Personal Data, normally by updating the list and notifying the Customer's account contact. The Customer may object within 15 days on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate the affected service without penalty before the new subprocessor begins processing; fees for unused prepaid affected service will be refunded.
6. Data-subject, DPIA and regulator assistance
Taking account of the nature of processing and information available to us, we will assist the Customer with appropriate technical and organisational measures for data-subject requests and with GDPR Articles 32–36 obligations, including security, breach assessment, data protection impact assessments and prior consultation.
If a data subject or authority contacts us about Customer Personal Data, we will redirect the request to the Customer unless law requires a direct response. The Customer is responsible for decisions and responses. Assistance beyond standard service functions may be charged at agreed reasonable rates unless caused by our breach.
7. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. The notice will include information reasonably available to us about the nature of the breach, likely consequences, affected data and persons, mitigation and a contact point. Information may be provided in phases.
Notification is not an admission of fault. The Customer is responsible for regulator and data-subject notifications unless law assigns that duty to us. We will take reasonable steps to contain, investigate, remediate and document the incident.
8. Restricted transfers
Customer authorises processing in the locations on the Subprocessor List. Where Customer Personal Data is transferred from the EEA to a country without an adequacy decision, the parties incorporate the controller-to-processor or processor-to-processor module, as applicable, of the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. The optional docking clause applies; Austrian law and the Austrian supervisory authority apply where the clauses require a selection; and subprocessors may use an applicable adequacy or transfer mechanism.
We will provide reasonable information for transfer-risk assessments and implement supplementary measures where required. The SCCs prevail over conflicting terms for the restricted transfer.
9. Return, export and deletion
During the service term, the Customer may retrieve Customer Data through available export tools, APIs or a support-assisted export. Following termination, we will make exportable data available for at least the agreed or legally required retrieval period, normally at least 30 days where the EU Data Act applies.
At the Customer's choice, and subject to mandatory retention, we will delete or return Customer Personal Data after service completion and delete remaining copies. Data may remain inaccessible in encrypted or access-restricted backups until normal overwrite cycles complete. During that period this DPA continues to protect it. We may retain minimal records necessary to demonstrate compliance, resolve claims and meet legal duties.
10. Information and audits
We will make available information reasonably necessary to demonstrate compliance, including security summaries, relevant third-party reports or certifications when available, and written responses. The Customer may audit once per 12 months and after a material breach or regulator request, on at least 30 days' notice unless urgent.
Audits must be proportionate, during business hours, avoid access to other customers' data and our security-sensitive or trade-secret information, and use an independent qualified auditor bound by confidentiality. The Customer bears its audit costs and our reasonable extraordinary assistance costs unless the audit shows a material breach by us. Supervisory-authority powers remain unaffected.
11. Liability, term and priority
The Terms' liability allocation applies to this DPA to the maximum extent lawful. It does not limit liability to data subjects or authorities where such limitation is prohibited. This DPA ends when we no longer process Customer Personal Data, except that confidentiality, deletion, audit and transfer protections survive as needed.
This DPA prevails over the Terms for data-processing subject matter. The SCCs prevail over this DPA for a covered transfer. Austrian law and the venue stated in the Terms apply without restricting data-subject or supervisory-authority rights.
Annex 1 — Processing description
- Subject matter and purpose
- Providing, securing, supporting and terminating the ordered HYPRCART commerce platform, storefront, administration, communications, integrations, APIs, search, hosting and related services.
- Duration
- The service term plus the agreed export, deletion and backup-overwrite periods.
- Nature of processing
- Collection, receipt, organisation, structuring, storage, hosting, adaptation, retrieval, consultation, use, transmission, indexing, rendering, backup, support, restriction, export and deletion on Customer instructions.
- Data subjects
- Customer staff, contractors and contacts; Customer buyers and prospective buyers; account holders; recipients; suppliers; reviewers and question authors; app developers and other individuals whose data the Customer submits.
- Personal data
- Identity and contact data; account, role and authentication data; addresses; customer profiles and groups; cart, order, fulfilment, refund and commerce records; product reviews and questions; communication and consent records; device and security data; integration identifiers; and Customer-defined fields.
- Sensitive data
- Not intended by default. Incidental data may appear in free text. Supported payment processing uses payment providers so HYPRCART does not store raw card data.
- Frequency
- Continuous or as initiated by Customer users, storefront visitors, integrations and automated Customer configurations during the service term.
- Controller instructions
- The Terms, Order, service configuration, authorised actions, API calls, imports and support instructions.
Annex 2 — Technical and organisational measures
- Access control: authenticated accounts, organisation and role scoping, least-privilege administrative access, separate operator controls and optional/mapped multi-factor safeguards.
- Encryption and transport: TLS for data in transit; provider-managed encryption at rest for primary cloud storage and databases; secrets kept outside application source.
- Tenant separation: organisation-scoped database and application access controls, buyer-safe API boundaries and separation of public projections from authoritative private data.
- Availability and resilience: managed cloud infrastructure, backups, recovery controls, cache/projection rebuild paths, queue retry handling and bounded failure isolation.
- Secure development: version control, review and automated type/test/build checks, dependency management, environment separation, controlled deployment and rollback procedures.
- Logging and monitoring: access, security, operational and audit signals with purpose-based retention, redaction controls and incident investigation procedures.
- Data minimisation: scoped service contracts, limited public projections, customer-controlled fields and permissions, tokenised/provider-hosted payment functions and bounded diagnostic payloads.
- Incident management: triage, containment, remediation, evidence preservation, recovery and Customer notification procedures.
- Personnel and vendors: confidentiality obligations, need-to-know access, provider due diligence, contractual data-protection obligations and maintained subprocessor records.
- Deletion: account/service deletion workflows, export and transition process, retention controls and eventual backup overwrite.
Measures may evolve with technology and risk, provided the overall protection is not materially reduced during the service term.