Preamble
This Data Processing Agreement (the "DPA") forms part of, and is incorporated by reference into, the Sigmira Terms of Service (the "Main Agreement") between Sigmira and the merchant customer (the "Merchant") who accepts those Terms.
This DPA governs the Processing by Sigmira, as Processor, of Personal Data for which the Merchant is the Controller: specifically, the design content submitted by the Merchant’s shoppers/end-customers through the Sigmira product-customisation editor (uploaded images and photographs, text and monograms entered, and the generated design and print-ready files, together with any Personal Data they contain).
This DPA does not govern Sigmira’s Processing of the Merchant’s own account, billing, and administrative data, for which Sigmira acts as Controller; that Processing is described in Sigmira’s separate Privacy Notice.
By accepting the Main Agreement, the Merchant accepts this DPA.
1. Parties
| Role | Party | Details |
|---|---|---|
| Controller | The Merchant | The business customer that accepts the Main Agreement and embeds the Sigmira editor in its online store. Identity and contact details as recorded in the Merchant’s Sigmira account. |
| Processor | Sigmira (trade name of Quincy van der Ree) | A sole proprietorship (eenmanszaak) established in the Netherlands · KvK 82195757 · VAT NL003652487B20 · Verdiweg 671, 3816 KW Amersfoort, The Netherlands · hello@sigmira.com |
The Controller and the Processor are referred to individually as a "Party" and together as the "Parties".
2. Definitions
2.1. Capitalised terms used but not defined in this DPA have the meaning given to them in the GDPR.
2.2. In this DPA:
- "GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation), together with any national implementing legislation, including the Dutch Uitvoeringswet Algemene verordening gegevensbescherming (UAVG).
- "Applicable Data Protection Law" means the GDPR and any other data-protection or privacy law applicable to the Processing under this DPA.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings given in Article 4 GDPR.
- "Merchant Personal Data" means the Personal Data Processed by the Processor on behalf of the Controller under this DPA, as further described in Annex 1.
- "Services" means the Sigmira product-customisation platform and related services provided to the Merchant under the Main Agreement.
- "Sub-processor" means any third party engaged by the Processor to Process Merchant Personal Data on behalf of the Controller.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses adopted by the European Commission under Implementing Decision (EU) 2021/914.
- "Annex" means an annex to this DPA, which forms an integral part of it.
3. Subject-Matter and Details of Processing
3.1. The subject-matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1 (Details of Processing).
3.2. This DPA applies for as long as the Processor Processes Merchant Personal Data on behalf of the Controller, and survives termination of the Main Agreement to the extent the Processor retains any Merchant Personal Data (see Clause 11).
4. Roles of the Parties
4.1. As between the Parties, the Controller is the controller and the Processor is the processor of the Merchant Personal Data, each within the meaning of Article 4 GDPR.
4.2. The Controller is responsible for the lawfulness of the Processing, including establishing a valid legal basis under Article 6 GDPR (and, where applicable, Article 9 GDPR) for collecting and submitting the Merchant Personal Data to the Services, and for providing all required information and notices to Data Subjects. The Processor Processes the Merchant Personal Data only as a processor on the Controller’s behalf.
4.3.
5. Processing on Documented Instructions (Art. 28(3)(a))
5.1. The Processor shall Process the Merchant Personal Data only on documented instructions from the Controller, including with regard to transfers to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject. Where such a legal requirement applies, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
5.2. The Controller’s complete and final instructions at the date of this DPA are: (a) to Process the Merchant Personal Data as necessary to provide the Services in accordance with the Main Agreement and the documentation; (b) as further specified in Annex 1; and (c) as the Controller may otherwise issue in writing through the Services or in accordance with this DPA from time to time.
5.3. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Applicable Data Protection Law.
6. Confidentiality (Art. 28(3)(b))
6.1. The Processor shall ensure that persons authorised to Process the Merchant Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6.2. The Processor shall ensure that access to the Merchant Personal Data is limited to those personnel who require access to perform the Main Agreement, on a need-to-know basis.
7. Security of Processing (Art. 28(3)(c); Art. 32)
7.1. The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
7.2. The technical and organisational measures in place at the date of this DPA are described in Annex 2 (Security Measures). The Processor may update these measures from time to time provided that the updated measures do not materially reduce the overall level of security.
8. Sub-processors (Art. 28(3)(d); Art. 28(2) and (4))
8.1. The Controller grants the Processor a general written authorisation to engage Sub-processors to Process Merchant Personal Data, subject to this Clause 8. The Sub-processors engaged at the date of this DPA are listed in Annex 3 (Sub-processors).
8.2. The Processor shall inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller a reasonable opportunity (at least 30 days before the change takes effect) to object on reasonable, data-protection-related grounds.
8.3. If the Controller objects on reasonable grounds and the Parties cannot agree a resolution, the Controller may, as its sole and exclusive remedy, terminate the affected part of the Services in accordance with the Main Agreement.
8.4. The Processor shall impose on each Sub-processor, by way of a written contract, data-protection obligations that are equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in compliance with Article 28 GDPR.
8.5. Where a Sub-processor fails to fulfil its data-protection obligations, the Processor remains fully liable to the Controller for the performance of that Sub-processor’s obligations.
9. Assistance to the Controller (Art. 28(3)(e) and (f); Arts. 12–23, 32–36)
9.1. Data-subject rights. Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Controller’s obligation to respond to requests by Data Subjects exercising their rights under Chapter III GDPR (Articles 12–23). If the Processor receives such a request directly, it shall, unless legally prohibited, promptly forward it to the Controller and shall not respond except on the Controller’s documented instructions.
9.2. Compliance assistance. Taking into account the nature of Processing and the information available to the Processor, the Processor shall assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security; breach notification to the Supervisory Authority and to Data Subjects; data protection impact assessments; prior consultation).
9.3.
10. Personal Data Breach (Art. 33)
10.1. The Processor shall notify the Controller without undue delay and in any event within 48 hours after becoming aware of a Personal Data Breach affecting the Merchant Personal Data.
10.2. The notification shall, to the extent known and reasonably available, include: (a) the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed; and (d) a point of contact. Where information cannot be provided at once, it may be provided in phases without undue further delay.
10.3. The Processor shall take reasonable steps to mitigate the breach and cooperate with the Controller’s obligations under Articles 33 and 34 GDPR. The Processor shall not notify a Supervisory Authority or Data Subjects on the Controller’s behalf unless instructed in writing by the Controller.
11. Return or Deletion of Personal Data (Art. 28(3)(g))
11.1. At the choice of the Controller, upon the end of the provision of the Services relating to Processing, the Processor shall delete or return all Merchant Personal Data to the Controller, and delete existing copies, unless Union or Member State law requires storage.
11.2. Unless the Controller elects return (or another option is agreed) within 30 days of the end of the provision of the Services, the Processor will delete the Merchant Personal Data, and in any event within 6 months of the end of the provision of the Services, subject to Clause 11.3.
11.3. The Processor may retain Merchant Personal Data to the extent, and for the period, required by law, and shall keep it confidential and Process it only as necessary for that purpose.
12. Audits and Information (Art. 28(3)(h))
12.1. The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and this DPA.
12.2. The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
12.3. Audits shall be: (a) on at least 30 days prior written notice (except on a Supervisory Authority instruction or following a breach); (b) no more than once per 12 months save where required by a Supervisory Authority or following a breach; (c) during normal business hours; (d) subject to confidentiality; and (e) conducted so as not to unreasonably disrupt the Processor’s business or compromise other customers’ data. The Processor may satisfy audit requests in the first instance via third-party certifications or audit reports.
13. International Transfers (Ch. V GDPR)
13.1. The Processor Processes and stores the Merchant Personal Data within the European Union, specifically on Amazon Web Services infrastructure in the eu-central-1 (Frankfurt, Germany) region, including database storage, file/asset storage, content delivery, and server-side rendering.
13.2. The Processor shall not transfer Merchant Personal Data outside the EEA, or to an international organisation, except on the Controller’s documented instructions or as required by law.
13.3. Where any transfer outside the EEA does occur, it shall be carried out only on the basis of: (a) an adequacy decision (Art. 45 GDPR); or (b) the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (controller-to-processor), hereby incorporated by reference, together with any supplementary measures required following a transfer impact assessment; or (c) another lawful Chapter V mechanism.
14. Liability and Indemnity (Art. 82)
14.1. Liability under or in connection with this DPA is governed by, and subject to the limitations and exclusions of liability set out in, the Main Agreement, except where Applicable Data Protection Law requires otherwise.
14.2. Liability for damage caused by Processing shall be allocated in accordance with Article 82 GDPR.
14.3.
15. Term, Precedence, Governing Law and Acceptance
15.1. Term. This DPA takes effect on the date the Merchant accepts the Main Agreement and continues for as long as the Processor Processes Merchant Personal Data on the Controller’s behalf. Clauses that by their nature should survive (including 6, 11, 12, 14 and this 15) shall survive.
15.2. Precedence. In the event of conflict between this DPA and the Main Agreement on matters of data protection, this DPA prevails. The incorporated Standard Contractual Clauses (where they apply under Clause 13) prevail over this DPA in the event of conflict.
15.3. Governing law and jurisdiction. This DPA is governed by the laws of the Netherlands; the Parties submit to the exclusive jurisdiction of the competent Dutch courts, without prejudice to any mandatory provision of Applicable Data Protection Law.
15.4. Acceptance. This DPA is accepted upon the Merchant’s acceptance of the Main Agreement. No physical signature is required; the Parties may execute a counter-signed copy on request.
Annex 1 — Details of Processing
| Item | Description |
|---|---|
| Subject-matter | Processing of design content submitted by the Controller’s shoppers/end-customers through the Sigmira product-customisation editor, to provide the Services to the Controller. |
| Duration | For the term of the Main Agreement and until return or deletion under Clause 11. |
| Nature | Collection, storage, hosting, organisation, retrieval, transformation/rendering (generation of print-ready files), transmission, and deletion, by automated means. |
| Purpose | Providing the product-customisation, design, and server-side rendering service, enabling the Controller’s shoppers to personalise products and producing a print-ready file per order. |
| Types of Personal Data | Images/photographs uploaded by end-customers (which may depict identifiable individuals); text, names, and monograms entered; the generated design/print files; and any Personal Data contained therein. |
| Special categories | Not intentionally Processed; uploaded photographs may incidentally contain such data; responsibility for any Art. 9 condition rests with the Controller. |
| Categories of Data Subjects | The Controller’s shoppers / end-customers who use the Sigmira editor on the Controller’s store. |
| Frequency | Continuous / ongoing, triggered by end-customer use of the editor. |
Annex 2 — Security Measures (Art. 32)
- Encryption in transit — TLS for all data to/from the Services.
- Encryption at rest — database and file/asset storage encrypted at rest.
- EU data residency — hosted and Processed within the EU, AWS eu-central-1 (Frankfurt) (RDS PostgreSQL, S3 + CloudFront, server-side rendering).
- Access control — least privilege — access restricted on a need-to-know basis.
- Authentication — authentication controls on platform and administrative systems.
- Logging and monitoring — of system activity, supporting detection and response.
- Confidentiality — authorised personnel bound by confidentiality (Clause 6).
- Resilience and recovery —
- Sub-processor security — infrastructure provided by AWS under its certified security programme.
- Testing and review —
Annex 3 — Sub-processors
| Sub-processor | Entity / Contracting party | Service | Processing location |
|---|---|---|---|
| Amazon Web Services | Amazon Web Services EMEA SARL (and, where applicable, Amazon Web Services, Inc.) | Cloud hosting, database (RDS PostgreSQL), storage (S3), CDN (CloudFront), server-side rendering | EU — eu-central-1 (Frankfurt, Germany) |
Note: Sigmira’s payment/billing provider (Paddle) is not a Sub-processor under this DPA, because it Processes the Merchant’s own account/billing data (for which Sigmira acts as Controller) and does not Process the end-customer design content governed by this DPA.