Data processing terms

An Article 28 GDPR data processing agreement between the shop operator and Shingen s.r.o. Version dated 20 September 2026; it takes effect for a controller when accepted while ordering the add-on or service.

This is a translation for convenience. Once published and accepted, the Czech terms are binding; if the versions differ, the Czech wording prevails.

Parties and roles

The shop operator that orders the Korzaro add-on or service is the controller. Shingen s.r.o., company ID 192 48 334, registered at Na Hřebenkách 3340/122, Smíchov, 150 00 Prague 5, Czech Republic, is the processor. The processor's contact is [email protected], telephone +420 603 402 154.

These terms form part of the Korzaro service agreement. Electronic acceptance of the terms or a confirmed order constitutes a written arrangement between the controller and processor. They apply while the processor provides the service to the controller and holds its personal data.

Subject matter, purpose and nature of processing

On the controller's instructions, the processor reads and stores selected data from the shop and connected services, normalises it, calculates reports and prepares alerts and recommendations. Operations include collection, storage, organisation, comparison, aggregation, display, backup and deletion. In its current scope, Korzaro does not write to Shoptet or other connected services.

Categories of people and data

Data subjects may include shop customers and visitors, recipients of commercial messages, supplier contacts and users of the shop's accounts. Depending on the connected features, processing may include:

  • order, customer and account identifiers, and the customer's name and e-mail,
  • order content and status, purchased items, prices, discounts, delivery and payment,
  • registrations, customer groups and aggregated purchase history,
  • traffic, marketing events and pseudonymous identifiers,
  • technical and audit data needed for secure operation.

The controller determines the exact scope through the sources it connects and permissions it approves. The processor does not use the data for its own advertising or decisions about data subjects.

Controller instructions

Documented instructions include installing the add-on, configuring connected sources, choices made in Korzaro and the controller's later written requests. The processor processes data, including any transfer outside the EEA, only under those instructions. If EU or Czech law requires processing, it informs the controller before processing unless the law prohibits this on important grounds of public interest. If the processor believes an instruction infringes data-protection law, it informs the controller without delay and may suspend the instruction.

Controller duties and rights

The controller determines the purposes and means of processing, ensures a valid legal basis and the required information to data subjects, and gives only lawful instructions. It is also responsible for being authorised to connect the shop and other sources and to disclose their data to Korzaro. Without a prior written agreement, it will not use the service for special-category data under Article 9 GDPR or criminal-offence data under Article 10.

The controller may change its instructions, request assistance, information and an audit under these terms, object to a subprocessor change, and choose return or deletion of personal data when the service ends.

Processor duties

  • allow access only to people bound by confidentiality and only to the extent necessary,
  • maintain appropriate technical and organisational measures set out in the security annex,
  • assist the controller, as appropriate to the processing, with data-subject requests, risk assessments and duties under Articles 32 to 36 GDPR,
  • notify the controller of a personal data breach without undue delay after discovery and progressively provide known information about its nature, scope, impact and remedy,
  • keep required records and give the controller information needed to demonstrate compliance,
  • not use the controller's personal data for its own purposes and, when the service ends, return or delete it at the controller's choice.

Subprocessors

The controller gives general written authorisation to use subprocessors required for the service. The processor contractually binds them to no less protective duties and remains liable to the controller for their performance. It informs the controller before an intended addition or replacement; the controller may object on documented personal-data protection grounds.

  • Hetzner Online GmbH – server and database hosting in the European Union,
  • Cloudflare, Inc. – network protection and backups encrypted before upload in its European jurisdiction,
  • Functional Software, Inc. (Sentry) – error diagnostics without default collection of personal data, request bodies or local variables,
  • Resend, Inc. – delivery of service e-mails to recipients determined by the controller,
  • PostHog, Inc. – product analytics in its European cloud; Korzaro sends only approved screen names, milestones and technical data, without a shop name, address or content,
  • Anthropic, PBC – synthesis and wording of outputs from inputs that passed the personal-data check; use of its commercial API is governed by its data processing terms.

Korzaro disables PostHog automatic capture, session recording and cookies, and respects Global Privacy Control and Do Not Track. Language-model inputs pass a deterministic check that rejects recognised customer names, e-mails, telephone numbers, addresses and other personal data. These restrictions reduce the data disclosed but do not replace contractual safeguards with the listed providers.

Transfers outside the European Economic Area

Primary operation is in the European Union and backups are encrypted before upload. Some subprocessors are established in the United States or may process data outside the EEA. In that case, the processor uses a valid Chapter V GDPR mechanism, in particular an adequacy decision or Standard Contractual Clauses, and explains on request how to obtain a copy.

Data-subject requests

The processor forwards a request concerning shop data to the controller and does not answer it substantively without the controller's instruction unless required by law. It provides available tools and reasonable assistance with search, correction, export, restriction or deletion.

Termination, return and deletion

After the service ends, the processor, at the controller's choice, returns personal data in a structured, commonly used format or deletes it and removes existing copies unless the law requires retention. Operational data is removed without undue delay after a confirmed instruction. Older copies may remain only in backups encrypted before upload, locked against change and automatically expiring within 90 days; they are restored only after a disaster and the deletion is reapplied after recovery.

Audit

On reasonable request, the processor provides information and existing evidence about its measures. An audit is arranged in advance, must not endanger other clients' data, security or ordinary operation, and is performed under a duty of confidentiality. If it identifies a breach, the processor remedies it without undue delay.

Precedence and contact

For personal-data processing, these terms prevail over the service's general terms in case of conflict. Send questions and instructions to [email protected].