Data Processing Addendum
This Addendum forms part of the Terms of Service between Kadosh (카도쉬), proprietor Kang Seung-hyun (강승현) ("Processor", "we") and the merchant installing GPSR Shield ("Controller", "you"). It applies where we process personal data on your behalf and, to that extent, reflects Article 28 GDPR. If it conflicts with the Terms on data processing, this Addendum controls.
1. Roles
You are the controller of the personal data you enter and publish through the App (including economic-operator contact details and reviewer identities). We act as processor, processing that personal data only to provide the App.
2. Subject-matter, duration, nature and purpose
- Subject-matter / nature: storing, organising, displaying and gap-checking GPSR Article 19 data on your storefront, and recording the current review and last product publication.
- Duration: for as long as the App is installed, plus the retention period in the Privacy Policy.
- Purpose: providing the App's functionality.
3. Categories of data and data subjects
- Data subjects: your economic operators (manufacturers, importers, responsible operators — including sole traders / natural persons) and your staff who review/publish.
- Personal data: names, postal addresses, electronic addresses, phone numbers, role; reviewer identifier and timestamps. No special-category data is required or intended.
4. Our obligations as processor
We will: (a) process personal data only on your documented instructions (the Terms, this DPA, and your use of the App), including for international transfers; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement appropriate technical and organisational security measures (Art. 32); (d) engage sub-processors only under written terms with equivalent obligations, and inform you of intended changes so you may object (current list: Shopify (app platform and merchant-store data), Vercel (application hosting, compute, and service logs), Neon (PostgreSQL session storage), and Google (support email when you contact us)); (e) assist you, taking into account the nature of processing, with data-subject requests and with your obligations under Arts. 32–36 (security, breach notification, DPIA); (f) notify you without undue delay after becoming aware of a personal-data breach; (g) at your choice, delete or return the personal data we hold at the end of the services, and delete existing copies unless retention is legally required; and (h) make available information necessary to demonstrate compliance and allow reasonable audits.
5. Your obligations as controller
You warrant that you have a lawful basis to process and to publicly display the personal data you enter (Article 19 requires public display of operator contact details), that your instructions are lawful, and that you will respond to data-subject requests for which you are responsible.
6. International transfers
Where personal data is transferred outside the EU/EEA (including to Republic of Korea), the parties rely on an appropriate transfer mechanism (e.g. EU Standard Contractual Clauses), which are incorporated by reference where applicable.
7. Sub-processors
Current sub-processors: Shopify (app platform and merchant-store data), Vercel (application hosting, compute, and service logs), Neon (PostgreSQL session storage), and Google (support email when you contact us). We remain responsible for their performance.
8. Liability
Liability under this Addendum is subject to the limitation of liability in the Terms of Service.
Signatures / acceptance: acceptance of the Terms of Service constitutes acceptance of this DPA.