Legal
Data Processing Agreement
Last updated: September 2026. Template per GDPR Article 28.
Definitions
For the purpose of this DPA:
- Controller means the merchant ("Client") who determines the purposes and means of processing end-user personal data via the Service.
- Processor means WoltersWorks, who processes personal data on behalf of the Controller.
- Personal Data has the meaning given in GDPR Article 4(1) and includes data that end-users submit to the AI product advisor (e.g., preference inputs, conversation data, device identifiers).
- Service means the WoltersWorks AI product advisor as described in the Order Form.
- GDPR means Regulation (EU) 2016/679.
Subject matter and nature of processing
WoltersWorks processes personal data solely to provide, maintain, and improve the Service on behalf of the Controller. The nature of processing includes:
- Receiving and processing user inputs (product preferences, use-case descriptions)
- Generating personalized product recommendations
- Storing conversation sessions to improve recommendation quality (subject to retention limits)
- Logging and analytics to maintain service reliability
Categories of data subjects: End-users (visitors and customers) of the Controller's storefront.
Categories of personal data: User-provided preference data, conversation transcripts, session identifiers, IP addresses, and browser metadata.
Duration: For the term of the agreement between WoltersWorks and the Controller, plus any post-termination period required for deletion.
Processor obligations (WoltersWorks)
WoltersWorks agrees to:
- Process personal data only on documented instructions from the Controller, unless required by EU or Dutch law
- Ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations
- Implement appropriate technical and organisational security measures per GDPR Article 32, including encryption at rest and in transit, access controls, and regular security reviews
- Not engage sub-processors without prior written authorisation from the Controller (general authorisation is given at onboarding; a current sub-processor list is maintained at the email address below)
- Assist the Controller in responding to data subject rights requests, data protection impact assessments, and breach notifications
- Delete or return all personal data upon termination of the agreement, at the Controller's choice, within 30 days
- Make available all information necessary to demonstrate compliance and allow for audits conducted by the Controller or an appointed auditor (with reasonable notice and at the Controller's cost)
Sub-processors
WoltersWorks uses the following categories of sub-processors:
- Cloud hosting and infrastructure (servers, databases, CDN)
- AI model providers (underlying large language models used to power product recommendations)
- Monitoring and logging services (error tracking, uptime monitoring)
WoltersWorks will notify the Controller of any intended changes to the sub-processor list at least 2 weeks in advance. The Controller may object to a new sub-processor within that period, in which case WoltersWorks will work in good faith to find an alternative or, if not possible, the Controller may terminate the agreement without penalty.
To request the current sub-processor list, email legal@woltersworks.com.
International transfers
Where personal data is transferred outside the European Economic Area (EEA), WoltersWorks ensures an appropriate transfer mechanism is in place: Standard Contractual Clauses (SCCs) adopted by the European Commission, an adequacy decision, or another lawful basis under GDPR Chapter V.
WoltersWorks will promptly inform the Controller if it believes an instruction from the Controller would infringe applicable data protection law.
Security and breach notification
WoltersWorks implements appropriate technical and organisational measures to protect personal data against accidental loss, destruction, alteration, unauthorised disclosure, or access.
In the event of a personal data breach affecting personal data processed on the Controller's behalf, WoltersWorks will notify the Controller without undue delay and in any case within 48 hours of becoming aware, to the extent possible including: a description of the nature of the breach, the approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
Data subject rights
Taking into account the nature of the processing, WoltersWorks will assist the Controller by appropriate technical and organisational measures where possible in fulfilling the Controller's obligation to respond to requests by data subjects to exercise their rights under GDPR (Articles 15-22), including access, rectification, erasure, restriction, portability, and objection.
Governing law
This DPA is governed by Dutch law and forms part of the agreement between WoltersWorks and the Controller. In case of conflict between this DPA and the General Terms and Conditions, this DPA prevails with respect to personal data processing matters.