Data processing agreement
Last updated 3 October 2026
1. Parties and scope
This agreement is between the operator that accepts the Terms of service (the controller) and [Company name], registered in Estonia under registry code [registry code] (the processor). It applies to personal data the processor handles on the controller's behalf while providing Stortrace.
2. Clauses
[Clauses 1 to 10 of the Standard Contractual Clauses (Decision 2021/915), with the optional clauses chosen.]
3. Annex I: Parties
[Controller: the operator, as registered. Processor: Stortrace, contact privacy@stortrace.com.]
4. Annex II: Description of the processing
[Data subjects: the operator's customers, and the operator's staff and drivers.]
[Categories: names, addresses, phone numbers, email addresses, personal identity numbers (sealed), photographs and other custody evidence, invoices.]
[Purpose: storing, collecting and redelivering customers' items, and billing for it.]
[Retention: custody evidence and invoices as decided in GDPR.md, then deleted or pseudonymised.]
5. Annex III: Security measures
[Encryption in transit and at rest, tenant isolation, access control and roles, secrets in Key Vault, backups, logging.]
6. Annex IV: Subprocessors
Microsoft Azure, West Europe: application hosting, database, file storage, messaging and logs.
Cloudflare: website delivery and DNS.
[Email provider, once chosen.]
[Payment provider, once billing exists.]