Data Processing Agreement Codixio EU Revocation Button

1. Parties and subject matter

This data processing agreement pursuant to Art. 28 GDPR applies between the operator of the Shopware shop installing the app Codixio EU Revocation Button (controller, hereinafter the merchant) and Matthias Jakisch, Hauptstr. 34, OT Etingen, 39359 Oebisfelde-Weferlingen, Germany, phone +49 39059 974988, e-mail general support@codixio.com, e-mail data protection and legal legal@codixio.com, sole proprietorship (no commercial register entry), operating under the trade name Codixio, VAT identification number pursuant to Sec. 27a UStG: DE296346917, tax status: small business under Sec. 19 UStG (processor, hereinafter Codixio). The subject matter is the operation of the app including the associated backend for receiving, verifying and confirming revocation requests of the merchant's customers.

2. Duration

The agreement begins with the installation of the app and ends with its uninstallation. The deletion obligations under Section 10 remain unaffected.

3. Nature and purpose of processing, types of data, categories of data subjects

Nature and purpose: receipt of revocation requests via the app's form, verification against the order data of the merchant's shop, dispatch of the confirmation e-mails via the shop's mail infrastructure, rate limiting for abuse prevention, creation of pseudonymised verification records, automatic deletion after expiry of the retention period. Types of data: name, e-mail address, order number, optionally postcode, optionally reason for revocation, selected order items, IP address; of these, only HMAC digests of e-mail address and IP address, order number, timestamp, verification result and the server-resolved items are stored permanently. Categories of data subjects: customers of the merchant declaring a revocation.

4. Processing on documented instructions

Codixio processes the data exclusively on documented instructions from the merchant. The installation, configuration and use of the app and this agreement constitute such instructions. If Codixio considers an instruction unlawful, Codixio shall inform the merchant without undue delay.

5. Confidentiality

Codixio ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Technical and organisational measures

Codixio implements the measures required under Art. 32 GDPR, in particular: transport encryption of all connections (TLS), pseudonymisation of e-mail address and IP address via HMAC-SHA256 with a secret server key prior to any storage, no storage or logging of plain-text IP or plain-text e-mail, rate limiting against automated abuse, server logs free of personal data, operation in German data centres (Hetzner, Falkenstein and Nuremberg), access restriction to the backend via cryptographic registration credentials per shop, automatic, time-bound deletion of the verification records, and complete deletion of the shop data in the backend upon uninstallation.

7. Sub-processors

The merchant approves the use of the following sub-processor: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, activity hosting provider for application servers and Postgres database, processing locations Falkenstein (DE) and Nuremberg (DE). Coolify is used as a self-operated open-source container orchestration on this infrastructure and is not an external service provider. There are no further sub-processors; in particular, no external mail service provider and no AI service are used. Codixio shall inform the merchant in text form in advance of any intended changes; the merchant may object on important data protection grounds.

8. Assistance obligations

Codixio assists the merchant with appropriate technical and organisational measures in fulfilling data subject rights (Art. 12 to 23 GDPR) and the obligations under Art. 32 to 36 GDPR, insofar as the processing under this agreement is concerned. Note: Codixio cannot attribute the pseudonymised verification records to any person without additional information (Art. 11 GDPR).

9. Notification of breaches

Codixio shall notify the merchant of any personal data breach within the scope of this agreement without undue delay after becoming aware of it.

10. Deletion and return

The pseudonymised verification records reside in the database of the merchant's shop and thus under the merchant's direct control; the app deletes them automatically after 90 days. The shop registration and tariff data stored in the backend is deleted automatically and completely by Codixio upon uninstallation of the app. No further copies exist.

11. Evidence and audits

Codixio provides the merchant with all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and enables reasonable audits. Audits take place after prior notice during normal business hours; meaningful documentation and attestations are provided with priority.

12. Demarcation: Codixio's own responsibility

The processing of the merchant's own registration, contract and tariff data is not subject to this agreement; in this respect, Codixio is an independent controller. The app does not deliver publicly accessible pages via Codixio infrastructure.

13. Final provisions

German law applies, excluding the UN Convention on Contracts for the International Sale of Goods. Should individual provisions be invalid, the validity of the remainder shall remain unaffected. The authoritative version of this agreement is available at https://legal.codixio.com/apps/eu-widerrufsbutton-shopware/dpa.en; the app's privacy policy at https://legal.codixio.com/apps/eu-widerrufsbutton-shopware/privacy.en.