Data Processing Agreement Codixio FAQs Everywhere
1. Parties and Applicability
This data processing agreement pursuant to Art. 28 GDPR is concluded between the operator of the Shopware shop installing the app Codixio FAQs Everywhere (controller, hereinafter the Merchant) and Matthias Jakisch, Hauptstr. 34, OT Etingen, 39359 Oebisfelde-Weferlingen, Germany, phone +49 39059 974988, e-mail general support@codixio.com, e-mail data protection/legal legal@codixio.com, legal form: sole proprietorship (no commercial register entry), operating under the trade name Codixio, VAT identification number pursuant to Sec. 27a UStG: DE296346917, tax status: small business under Sec. 19 UStG (processor). It takes effect upon installation and use of the app and applies for the duration of the installation.
2. Subject Matter, Nature and Purpose of Processing
The subject matter is the operation of the app including its backend. Processing on behalf comprises the request-related, transient retrieval, filtering, technical sanitising and delivery of the FAQ content maintained by the Merchant to the Merchant's storefront. FAQ content is not stored permanently by the processor. Data processed by Codixio as an independent controller (the Merchant's registration, contract and plan data as well as infrastructure logs) is not covered by this agreement; the privacy policy at https://legal.codixio.com/apps/faqs-everywhere-shopware/privacy.en applies to it.
3. Types of Data and Categories of Data Subjects
Processed are the FAQ content maintained by the Merchant (editorial content, generally without personal reference), technical shop and object identifiers and, at infrastructure level and for technical reasons, IP addresses of shop visitors in short-lived access logs. Categories of data subjects: visitors of the Merchant's shop and, where the Merchant includes personal information in FAQ content, the persons concerned. The Merchant is responsible for the lawfulness of information contained in FAQ content.
4. Processing on Documented Instructions
The processor processes the data solely on documented instructions of the Merchant (Art. 28(3)(a) GDPR). The installation, configuration and use of the app and the maintenance of FAQ content constitute such instructions. If the processor considers an instruction unlawful, it shall inform the Merchant without undue delay.
5. Confidentiality
The processor ensures that persons authorised to process the data have committed themselves to confidentiality (Art. 28(3)(b) GDPR).
6. Technical and Organisational Measures
The processor implements the measures required under Art. 32 GDPR, in particular: transport encryption (TLS) for all communication, signed authentication of shop-to-backend communication, access controls for servers and database, secrets kept exclusively in protected environment configuration, per-app isolated application with its own database, operation exclusively in data centres located in Germany, short-lived logs without application-level analysis, and automatic, complete deletion of the commissioned data upon uninstallation. The measures are kept up to date with the state of the art.
7. Sub-Processors
The Merchant grants general authorisation for the use of sub-processors (Art. 28(2) GDPR). The following sub-processor is used: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Activity: hosting provider for application servers and Postgres database. Processing locations: data centres Falkenstein (DE) and Nuremberg (DE). Third-country transfer: no. Coolify is used as a self-operated open-source container orchestration on Hetzner and is not an external service provider. No further sub-processors, in particular no mailing providers or AI services, are used. The processor will inform the Merchant in advance of intended changes; the Merchant may object on important grounds.
8. Assistance Obligations
The processor assists the Merchant by appropriate means in responding to data subject requests (Art. 28(3)(e) GDPR) and in complying with the obligations under Art. 32 to 36 GDPR (Art. 28(3)(f) GDPR), including notifying the Merchant without undue delay of any personal data breach.
9. Deletion and Return
Upon termination of use, at the latest upon uninstallation of the app, all data processed and stored on behalf of the Merchant is deleted automatically (Art. 28(3)(g) GDPR). As FAQ content is stored exclusively in the Merchant's shop, it remains there under the Merchant's control.
10. Evidence and Audits
The processor makes available to the Merchant all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for reasonable audits (Art. 28(3)(h) GDPR), as a rule by means of meaningful documentation; further on-site audits take place upon prior coordination.
11. Final Provisions
German law applies. Amendments to this agreement require text form. Should individual provisions be invalid, the validity of the remainder remains unaffected.
Last updated: 30 August 2026.