Technical and organisational measures
An annex to the data processing terms for the Korzaro add-on for Shoptet. State as at 20 September 2026.
This is a translation for convenience. The Czech annex is binding; if the versions differ, the Czech wording prevails.
Permissions and transport
- Integrations use read-only permissions and the smallest available scope.
- Communication between the browser, Korzaro and sources uses encrypted HTTPS connections.
- Long-lived integration keys are encrypted in the database with a separate key and are not displayed in the interface or logs.
Client isolation and human access
- Each stored record belongs to a specific project, and access checks the user's membership and role.
- The production database and cache are not directly accessible from the internet.
- Administrative access is individual, protected by multiple layers and audited.
- Development and test environments do not use non-anonymised production customer data.
Personal data and language models
- Customer names and e-mail addresses are not sent to a language model; a deterministic personal-data check runs before input is sent.
- Logs, analytics and error reports do not transmit request bodies, e-mails, customer names, cookies or access keys.
- If an operating counter needs to distinguish an address, it uses a one-way digest instead of a readable e-mail. The account registry keeps the e-mail in the primary database because it is needed for sign-in and communication.
- One client's data is not used as context for another client or for joint training without a separate legal basis.
Backups and recovery
- The database and essential configuration are encrypted each day before upload to private Cloudflare R2 storage in its European jurisdiction.
- A daily backup is locked against overwriting for 35 days and is automatically removed within 90 days.
- Recovery is regularly tested in an isolated database. The recovery point objective after a complete outage is no more than 24 hours; an isolated database recovery targets 30 minutes.
Operational security
- Production runs under an unprivileged account, with a restricted filesystem, firewall and automatic security updates.
- Sign-in limits repeated attempts and uses secure password hashing and secure cookies.
- External monitoring checks application, database and cache availability. Errors are reported without default collection of personal data.
- Changes pass automated tests, vulnerability checks and a pre-release gate.
Incidents and deletion
During an incident, impact is contained first, evidence is preserved and the scope is established without copying personal data into tickets or chat. The controller receives the information needed to meet its own duties. After a confirmed request, data is removed from operating systems; encrypted backup copies expire within the 90-day retention period.