ZweiHost
PrivacyTermsData processingData deletion
Български

Data Processing Agreement (DPA)

Version v0.2 · Effective: 20 August 2026

This Agreement is concluded between Zwei Soft Ltd., UIC 208515196, operator of the ZweiHost platform (hereinafter “ZweiHost”), and the Customer, and supplements the Terms of Service. It governs the processing of personal data in accordance with Art. 28 of Regulation (EU) 2016/679 (GDPR).

1. Parties and roles

  • Customer (Controller): the entity registered in ZweiHost whose legal name and UIC (EIK) are recorded on its account.
  • ZweiHost (Processor): processes personal data on the Controller's instruction and only for the purpose of the service.

When the Customer's site collects data from its visitors (contact forms, bookings, newsletter, etc.), the Customer is the independent Controller and ZweiHost is the Processor.

2. Subject-matter, nature, purpose and duration of processing

ZweiHost processes personal data on the Customer's behalf to provide, support, secure, host, deliver email for, store files/images for, fulfil orders for, run customer accounts and Facebook/Google sign-in for, back up, and technically administer the Customer's online shop/site. Processing runs for the subscription term plus 30 days after termination (error-recovery window), after which the Customer's data is deleted or anonymised, unless applicable law requires longer retention or the Customer has opted to have the data returned in a reasonably maintained format before deletion.

3. Categories of data and subjects

  • Visitors and shoppers on the Customer's site/shop: name, email, phone, delivery address, order history, favourite products, marketing consent, contact-form message content, booking time, technical logs, IP address and browser data necessary for the security and operation of the service; for Facebook/Google sign-in — name, email and a stable provider identifier; for product personalisation — shopper-uploaded images and text for printing, plus a small preview of the finished design and its description.
  • End customers of the Customer: data per the services the Customer offers.

The Customer is responsible for not uploading special-category data (health, political, biometric) without explicit written agreement.

4. ZweiHost obligations

ZweiHost will:

  • process data only on the Customer's documented instructions, including as to third-country transfers, unless required otherwise by law;
  • inform the Customer if, in ZweiHost's view, an instruction infringes the GDPR or other applicable data-protection law;
  • ensure the confidentiality of persons with access;
  • apply appropriate technical and organisational security measures (encryption in transit, tenant_id isolation, encryption of sensitive secrets, password hashing, role-based access, backups, access control and logging);
  • assist the Customer with data-subject requests and with security, breach notification, impact assessment and prior-consultation obligations, to the extent applicable;
  • notify the Customer of a personal-data breach without undue delay after becoming aware;
  • at the Customer's choice, return or delete the personal data after the service ends, unless EU or Member State law requires retention;
  • provide the information necessary to demonstrate compliance with this DPA and allow reasonable audit on reasonable notice (annually, or upon incident) under conditions that do not endanger the security and confidentiality of other customers.

5. Sub-processors and changes

ZweiHost uses only sub-processors for which the Customer grants general authorisation by accepting this DPA. ZweiHost notifies the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, except for an urgent change for security or service-continuity reasons, where notice is given without undue delay. The Customer may object on reasonable data-protection grounds. ZweiHost imposes on each sub-processor, by contract, the same material data-protection obligations set out in this DPA.

Current sub-processors:

  • Cloudflare, Inc. — R2 object storage for files/images (EU), Workers hosting of the public shops, CDN and traffic protection (global edge, including visitors' IP addresses); inbound email forwarding for customer domains that enable business email forwarding (email content and correspondent addresses - in transit only, no storage on our side).
  • Stripe — payments — EU / USA (SCC).
  • Amazon Web Services (Amazon SES) — email — EU (eu-central-1) / USA (SCC).
  • Railway — hosting of the API, the admin panel and the main PostgreSQL database, including merchant and shopper data — EU West (Amsterdam, Netherlands).
  • Functional Software, Inc. (Sentry) — application error tracking and diagnostics; receives technical error data only (message, stack trace, browser/environment type), with request bodies, cookies, credentials and user identifiers stripped before sending — EU (Germany) / USA (SCC).
  • Borica AD — card payments for Bulgarian merchants (planned, inactive as of this version).

Meta Platforms and Google LLC are not ZweiHost sub-processors: for Facebook/Google sign-in and, with consent, advertising/analytics, they act as independent controllers under their own privacy policies.

6. International transfers

Where personal data is transferred outside the EEA, ZweiHost applies a Chapter V GDPR mechanism, including an adequacy decision where applicable, or the European Commission's Standard Contractual Clauses (SCC) plus supplementary technical/organisational measures according to risk. The Customer may request information on the applicable mechanism and a copy of or access to the relevant safeguards, to the extent this does not breach trade secrecy or the security of the service.

7. Liability

Each party is liable for breaches arising from its own conduct. The Customer indemnifies ZweiHost against claims arising from unlawful data uploads, lack of a legal basis, unlawful instructions or content by the Customer. The liability limitations in the Terms do not apply to the extent they would conflict with mandatory liability under the GDPR, including for damage from processing carried out in breach of the GDPR.

8. Precedence

In case of conflict between this DPA and the Terms, this DPA prevails on data-processing matters.

© 2026 ZweiHostPrivacyTermsData processingData deletion