Data processing agreement

Last updated 3 October 2026

1. Parties and scope

This agreement is between the operator that accepts the Terms of service (the controller) and [Company name], registered in Estonia under registry code [registry code] (the processor). It applies to personal data the processor handles on the controller's behalf while providing Stortrace.

2. Clauses

[Clauses 1 to 10 of the Standard Contractual Clauses (Decision 2021/915), with the optional clauses chosen.]

3. Annex I: Parties

[Controller: the operator, as registered. Processor: Stortrace, contact privacy@stortrace.com.]

4. Annex II: Description of the processing

[Data subjects: the operator's customers, and the operator's staff and drivers.]

[Categories: names, addresses, phone numbers, email addresses, personal identity numbers (sealed), photographs and other custody evidence, invoices.]

[Purpose: storing, collecting and redelivering customers' items, and billing for it.]

[Retention: custody evidence and invoices as decided in GDPR.md, then deleted or pseudonymised.]

5. Annex III: Security measures

[Encryption in transit and at rest, tenant isolation, access control and roles, secrets in Key Vault, backups, logging.]

6. Annex IV: Subprocessors

Microsoft Azure, West Europe: application hosting, database, file storage, messaging and logs.

Cloudflare: website delivery and DNS.

[Email provider, once chosen.]

[Payment provider, once billing exists.]