Data Processing
Agreement (DPA)
Rules for processing your end customers' data - the Merchant as controller, DoSwiftly as processor (Art. 28 GDPR).
When you run a Store on DoSwiftly, you are the controller of your end customers' data - and we act as processor on your instructions. This page is an integral part of the Terms: it defines our obligations, sub-processors, security measures and the breach notification procedure. Accepting the DoSwiftly Terms means accepting this DPA.
§ 1 Parties and preamble
This Data Processing Agreement (hereinafter: DPA) is concluded between:
| Entrepreneur | Jakub Gabrychowicz, sole proprietorship |
|---|---|
| Company | JAKUB GABRYCHOWICZ GameGoods |
| Service brand | DoSwiftly |
| Address | ul. Łęczycka 15/1, 99-340 Krośniewice |
| NIP / REGON | 7752647541 / 360765637 |
| Contact | kontakt@doswiftly.pl |
and the Controller - the DoSwiftly User (Merchant) identified in the Account dashboard - hereinafter jointly referred to as the Parties.
Preamble. The Parties have concluded an agreement for the provision of the DoSwiftly platform services (hereinafter: the Main Agreement), under which the Controller entrusts the Processor with the processing of personal data for the purpose of providing the Service. This DPA meets the requirements of Art. 28(3) GDPR and forms an integral part of the Main Agreement. Accepting the DoSwiftly Terms is equivalent to concluding this DPA.
§ 2 Definitions
Terms used in this DPA have the meaning given to them by the GDPR, in particular:
- Personal data - any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
- Processing - operations performed on Personal data (Art. 4(2) GDPR).
- Controller - the Merchant running a Store on DoSwiftly.
- Processor - the DoSwiftly Operator.
- Sub-processor - a further processor to which the Processor entrusts the performance of operations on Personal data.
- Personal data breach - a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal data (Art. 4(12) GDPR).
§ 3 Subject matter, nature, duration and purpose of processing
3.1. Subject matter and purpose
The Processor processes Personal data solely for the purpose of providing the DoSwiftly Service in accordance with the Main Agreement, in particular: hosting the Store, running the product catalog, cart and checkout, order fulfillment and shipping, sending transactional emails, marketing features and the loyalty program, Store traffic statistics, reporting and backups.
3.2. Nature of processing
Automated and manual (via the dashboard) operations: collection, recording, organization, storage, modification, retrieval, transmission, combination, restriction and erasure.
3.3. Categories of data subjects
- end customers of the Controller's Store (buyers, customer-account users);
- people contacting the Store through its forms and signing up for the Store's newsletter;
- the Controller's employees / associates with access to the dashboard;
- loyalty program members and gift card recipients.
3.4. Categories of Personal data
- identifying and contact data (first name, last name, email, phone, address);
- order data (products, amounts, payment method, transaction identifiers);
- shipping and billing address data;
- customer account data (hashed password, tokens);
- behavioral data and logs (IP, user-agent, events);
- communications (content submitted through the Store's forms; for transactional emails - the recipient, subject and delivery status, without the message body).
As a rule, the processing does not cover special categories of Personal data (Art. 9 GDPR). If the Controller intends to process such data (e.g. health data in the medical sector), it should request an addendum to the DPA and carry out a DPIA.
3.5. Duration
The DPA applies for the duration of the Main Agreement. After its termination, § 11 applies.
§ 4 Processor's obligations (Art. 28(3) GDPR)
The Processor undertakes to:
- process Personal data only on the Controller's documented instructions - including those expressed through the DoSwiftly dashboard configuration, acceptance of the Terms and correspondence to kontakt@doswiftly.pl;
- not transfer Personal data to a third country or an international organization unless required to do so by Union or Member State law (in which case the Processor will inform the Controller before processing) - subject to § 9;
- ensure that persons authorized to process the data have committed to confidentiality or are under a statutory obligation of confidentiality;
- take all measures required under Art. 32 GDPR (see § 6);
- comply with the conditions for engaging sub-processors (§ 5);
- assist the Controller - by appropriate technical and organizational measures, including dashboard features for finding, anonymizing and deleting an End customer's data - in fulfilling its obligation to respond to data subject requests (Art. 12-22 GDPR);
- assist the Controller in complying with the obligations under Art. 32-36 GDPR (security, breach notification, impact assessment, prior consultation);
- after the end of the provision of the Service - at the Controller's choice - delete or return the Personal data and delete all copies, unless Union or Member State law requires further storage;
- make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Art. 28 GDPR and allow for and contribute to audits by the Controller (§ 8);
- immediately inform the Controller if, in its opinion, an instruction given to it infringes the GDPR or other data protection provisions.
§ 5 Sub-processors
The Controller gives general authorization (Art. 28(2) GDPR) for the Processor to engage the sub-processors listed below. The Processor ensures that the data protection obligations set out in this DPA are passed on to sub-processors through appropriate agreements.
5.1. Current list of sub-processors
| Sub-processor | Scope of services | Location | Transfer basis |
|---|---|---|---|
| OVH SAS | Hosting of application servers, databases and backups | Poland (EEA) | - |
| Cloudflare, Inc. | CDN, DNS, network protection, Workers (Store hosting), R2 object storage (files, shipping labels, archive copies), KV, Custom Hostnames | USA + EU edge | SCC + EU-US DPF |
| AC PM, LLC (Postmark) | Transactional email delivery (order confirmations, invoices, system notifications, password reset) | Chicago, Illinois, USA (Deft + AWS US) | EU-US Data Privacy Framework (AC PM, LLC certification) + SCC Module 2 incorporated into the Postmark ToS; current sub-processor list: postmarkapp.com/eu-privacy |
Payment operators (PayU, Przelewy24) and carriers (including InPost, Orlen Paczka) with which the Controller connects the Store using its own account process the data under agreements concluded with the Controller and are not sub-processors of the Processor.
5.2. Changes to the sub-processor list
The Processor announces any change or addition of a sub-processor 14 days in advance - by updating this page and notifying Controllers. Within 14 days the Controller may raise a reasoned objection. If the concerns cannot be resolved, the Controller has the right to terminate the Main Agreement without paying fees for the remaining period.
§ 6 Technical and organizational measures (Art. 32 GDPR)
The Processor implements and maintains appropriate technical and organizational measures, including:
- Encryption: TLS 1.2+ in transit; authenticated encryption of credentials for external services (including payment-operator and carrier keys) and encryption of backups; files kept in object storage encrypted on the provider's side.
- Tenant isolation: a separate database and separate access credentials for each Store.
- Access control: roles and permissions in the dashboard, least-privilege principle, administrative access to the infrastructure limited to the Processor's authorized persons.
- Network and protection: protection against DDoS and bot traffic, request rate limits, security monitoring and intrusion detection.
- Secrets: authenticated encryption (AEAD) of sub-processor credentials at rest, with a key managed solely by the Processor; a short-lived, secure internal cache for performance. Key management follows good practice.
- Backups: encrypted, performed daily, with periodic restore tests; rotation max. 90 days.
- Audit logs: logging of key actions in the dashboard in a tamper-protected log, with 365-day retention.
- Procedures: change management, incident response policy, employee access policy, confidentiality clauses.
- Personnel: confidentiality commitment (including after the collaboration ends), data protection training.
- Continuity: regular disaster recovery tests; declared RTO ≤ 24h, RPO ≤ 24h (targets).
The full description of the current measures is set out in Annex A - the TOM available on email request (kontakt@doswiftly.pl). The Processor updates the TOM where changes in technology, risk or regulations require it.
§ 7 Personal data breach
The Processor will notify the Controller of a Personal data breach without undue delay, no later than 24 hours after becoming aware of the breach - ahead of the Controller's statutory 72-hour deadline toward PUODO (Art. 33 GDPR).
We send the notification to the Controller's email address registered in the Account dashboard and, where possible, it includes:
- a description of the nature of the breach, including - where possible - the categories and approximate number of data subjects and records;
- the name and contact details of the responsible person on the Processor's side;
- a description of the likely consequences of the breach;
- a description of the measures taken or proposed to address the breach, including to mitigate its effects.
The Processor supports the Controller in meeting its notification obligations toward PUODO and - where applicable - toward the data subjects (Art. 34 GDPR).
§ 8 Audit
The Controller has the right to audit the Processor's compliance with the DPA - no more than once every 12 months and after a breach incident. An audit is announced at least 30 days in advance in writing and carried out during business hours in a way that minimizes disruption to the Service.
In the first instance, the Processor demonstrates compliance by making available:
- the current TOM (Annex A);
- external audit reports and certificates (e.g. SOC 2, ISO 27001), where available;
- policies and procedures at the Controller's request.
An on-site audit at the Processor's premises may be carried out by the Controller itself or by an appointed independent auditor, after signing an NDA. The cost of the audit is borne by the Controller, except where the audit reveals a material breach of the Processor's obligations - in which case the Processor bears the cost.
§ 9 Data transfers outside the EEA
Some sub-processors (Cloudflare, AC PM LLC / Postmark) operate outside the EEA. The Processor applies:
- the European Commission's Standard Contractual Clauses (SCC) version 2021/914;
- the EU-US Data Privacy Framework for certified providers;
- supplementary measures (including client-side encryption, pseudonymization) - where needed;
- a transfer impact assessment (TIA) for countries without an adequacy decision.
For AC PM, LLC (Postmark) - the transactional email provider - Data is processed in the United States (Chicago, Illinois). The transfer basis is AC PM, LLC's certification under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10.07.2023) and - additionally - the European Commission's Standard Contractual Clauses (Module 2 controller-to-processor transfer, Decision 2021/914) incorporated into the Postmark Terms of Service since 27.09.2021. Under the Postmark DPA (§ 3.a), AC PM, LLC has contractually committed not to store, use or disclose the entrusted Data for purposes other than providing the email delivery service. Postmark's sub-processors (Deft, AWS US) operate solely in the USA.
§ 10 Liability
Each Party is liable for damage caused by processing in accordance with Art. 82 GDPR and national law. The Processor is liable for damage resulting from its breach of the obligations arising from the DPA or imposed directly on the processor by the GDPR.
As regards contractual liability between the Parties, the limitations of liability set out in the Terms of the Main Agreement apply, except where such a limitation would conflict with mandatory law.
§ 11 Termination and return/deletion of Data
After the Main Agreement ends, the Processor - depending on the Controller's choice (deleting the Store in the dashboard or an instruction sent by email):
- Returns the Data to the Controller in a structured, human-readable format (JSON) - export within 30 days; the Controller can also download some of the data itself (CSV exports in the dashboard, Merchant API);
- Deletes the Data within 30 days of termination - until then the Store can be restored. If orders were placed in the Store, before deletion the Processor makes an archive copy of the Store's database for the statutory obligation to retain sales records and keeps it in separate, encrypted storage for 5 years from the end of the year in which the Store was deleted; only the Processor's authorized persons have access to the copy, and every access is logged. After that period the copy is deleted automatically.
Backups are erased in the rotation cycle (max. 90 days). The Processor will confirm the deletion of the Data at the Controller's request.
§ 12 Annexes
Annex A - Technical and organizational measures (TOM)
The detailed description of the measures covers: physical and logical security, network protection, identity and access management, encryption, backups, incident management, business continuity, risk assessment and internal policies. The current version is available on request (kontakt@doswiftly.pl).
Annex B - List of sub-processors
See § 5.1 above. Updated 14 days in advance.
Annex C - List of data and categories of subjects
See § 3.3 and § 3.4 above.
DPA version: 2.0, in force from 08.10.2026. The previous version 1.1 was in force from 21.05.2026.