Annex 1 to the Zendat Terms of Service: Data processing terms

These terms are part of the Zendat Terms of Service and apply from the moment the merchant installs the app. They are the contract article 28(3) of the GDPR asks for between a controller and its processor.

1. Parties and roles

  • Controller: the merchant that installs the app, for the personal data of its buyers that the app processes to build and send documents.
  • Processor: Jason den Hartog, trading as Zendat, sole proprietorship, KVK 42169110, VAT NL005552054B70, De Kriek 30, 3451 KK Vleuten, the Netherlands.

For the merchant's own data (the shop, its settings, its plan, support mail) Zendat is a controller in its own right; that is described in the privacy policy, not here.

2. Subject matter, nature and purpose

Zendat processes buyers' personal data on the merchant's behalf for one purpose: to build an electronic invoice or credit note from an order or a refund in the merchant's Shopify shop, have it checked, hand it to the Access Point for delivery over the Peppol network, record what became of it, and show that to the merchant. Nothing else is done with the data.

The processing consists of: reading the order, the refund and the buyer's details from Shopify when a document is built; writing the buyer's VAT number and its verification status onto the order in Shopify; checking the VAT number with VIES; sending the document to the Access Point; receiving delivery reports; keeping per order the records described in section 5.

3. Duration

For as long as the app is installed, and for the erasure that follows uninstalling (section 8).

4. Data subjects and types of data

Data subjects: the merchant's buyers, being the people who place an order and give a VAT number, and the contact persons named on an order.

Types of data: name, company name, billing address, email address, VAT number and its verification status; the order (number, date, lines, amounts, taxes, shipping, discounts, payment terms, purchase order number) and any refund of it; Shopify's identifiers of the order and the refund. No special categories of data, and no phone number: the app never reads it.

5. What is stored, and where

  • Not stored by Zendat: the buyer's name, company, address and email address, and the order's lines and amounts. They are read from Shopify at the moment a document is built and go into the document sent to the Access Point.
  • Stored by Zendat, per order: Shopify's identifier and number of the order and of the refund; the Access Point's identifier of the document and its state; dates; and, while an order is being handled, the reason shown to the merchant and the Access Point's answer when a document was refused, both of which can contain the buyer's VAT number.
  • Stored in Shopify, written by Zendat: the buyer's VAT number and its verification status, as metafields on the order.
  • Stored at the Access Point: every document created, with the buyer's details, and its PDF.
  • Logs: the hosting provider keeps the app's log lines, which name shops, order numbers and documents and can repeat the reason shown to the merchant, for the period in the privacy policy.

6. Zendat's obligations

Zendat:

  • (a) processes the data only on the merchant's documented instructions, which are these terms, the Terms of Service, and the settings the merchant chooses in the app (sending by hand, automatic sending, the VAT number a merchant enters for a buyer); and tells the merchant if an instruction would in Zendat's view break the GDPR;

  • (b) makes sure that everyone who has access to the data is bound to confidentiality: today that is the owner of Zendat alone;

  • (c) takes the security measures of section 7;

  • (d) engages no other processor than the ones in section 9, and informs the merchant of any change to that list as section 9 says;

  • (e) helps the merchant answer requests from data subjects (access, rectification, erasure, restriction, portability, objection) as far as the data Zendat holds is concerned: in the first place through Shopify's privacy requests, which Zendat answers as section 8 says, and otherwise within ten working days of the merchant's request by email;

  • (f) helps the merchant meet its duties under articles 32 to 36 GDPR (security, breach notification, impact assessments) as far as the processing here is concerned, with the information Zendat has;

  • (g) at the end of the processing, erases the data as section 8 says;

  • (h) makes available the information needed to show that these terms are met, and allows and contributes to audits as section 10 says.

Zendat informs the merchant without undue delay, and at the latest within 48 hours of becoming aware of it, of a personal data breach concerning the merchant's data, with what Zendat knows about its nature, the data and the data subjects concerned, its likely consequences, and the measures taken. Zendat does not notify the supervisory authority or data subjects on the merchant's behalf unless the merchant asks it to.

7. Security

Taking into account the state of the art, the costs of implementation and the nature of the processing, Zendat has these measures in place:

  • Servers and database in the EU (Frankfurt), at a hosting provider that is ISO 27001 certified and SOC 2 Type 2 audited, and certified under the EU-US Data Privacy Framework with its UK extension (render.com/trust, read on 2026-09-26; the reports are available from Render on request).
  • All connections encrypted with TLS: the buyer's browser, Shopify, the Access Point, VIES.
  • Requests from the checkout block carry Shopify's session token, and the app checks that the order a buyer names is theirs before it writes a VAT number on it.
  • Every request from Shopify and from the Access Point is checked against its signature before it is acted on.
  • The keys and secrets of a merchant's account at the Access Point are encrypted at rest (AES-256-GCM) with a key that lives only on the server, decrypted only at the moment a document is sent or a delivery report is verified, and never written to a log, an error or a page.
  • Every database query is scoped to one shop; an automated test refuses any page of the app that reaches for a table directly; every write to a document's record names the shop it belongs to.
  • Buyers' names and addresses are not stored by Zendat at all (section 5).
  • Access to the servers, the database and the logs is limited to the owner of Zendat, with two-factor authentication on the accounts at Render, GitHub, Shopify Partners and Google.
  • Secrets are read from the environment of the running app, never from the code, and are never printed.

8. Erasure

  • Shopify's privacy requests. Shopify sends the app a request when a merchant erases a customer or a customer asks to be forgotten (customers/redact), when a customer asks for their data (customers/data_request), and 48 hours after the app is uninstalled (shop/redact). Zendat writes every request down with its 30-day deadline, and:
    • on customers/redact, erases within the request every free text about the named orders (the reason shown to the merchant, the Access Point's answer), and with it every VAT number Zendat wrote down itself, and stops a queued order for that customer. Per order the minimal record stays: shop, order identifier and number, document identifier, state and dates;
    • on customers/data_request, writes the request down and answers it to the merchant by email within thirty days with what the app holds about the named orders;
    • on shop/redact, deletes the shop's settings, plan, queued orders, delivery reports, account record at the Access Point and any session, and erases the free text of every document record. The minimal record per document stays, as does Zendat's record of privacy requests and its billing records.
  • On uninstalling, before that: Shopify's access token is deleted at once, queued orders are cancelled and automatic sending is switched off.
  • What stays, and why. The minimal record per document (shop, order identifier and number, document identifier, state and dates) is kept so that a reinstall can never send a second document for an order that already has one; it holds nothing about a person beyond the order's identifier. The billing records are kept for seven years as accounting records.
  • The VAT number on the order in Shopify stays with the order and follows Shopify's own erasure of the order.
  • Documents at the Access Point are outside Zendat's erasure: a document sent over Peppol cannot be recalled, and the Access Point holds it under its own rules (Terms of Service, section 8.5).
  • Return of data. On request within twelve months of uninstalling, Zendat gives the merchant the records it still holds about the merchant's orders, in a readable form, by email.

9. Sub-processors

The merchant agrees to these sub-processors:

Sub-processor What it does Where
e-invoice.be, Belgium The Peppol access point: checks, holds and delivers every document, and reports delivery Belgium, EU
Render Services, Inc., 525 Brannan St, San Francisco, CA 94131, United States Hosting of the app, its database and its logs, in Render's Frankfurt region; under Render's Data Processing Addendum with the EU Standard Contractual Clauses, and Render's certification under the EU-US Data Privacy Framework Servers in Germany, EU; the company in the United States
Google (Google Workspace), under Google's data processing addendum Zendat's mailbox, for support mail that can name a buyer or an order EU and elsewhere, under Google's addendum and the EU-US Data Privacy Framework

Not sub-processors, but recipients on the merchant's instruction: Shopify, the platform the merchant already contracts with, which the app reads from and writes to; VIES, the European Commission's VAT register, which receives only the country code and the VAT number being checked; and the buyer's own access point, which receives the delivered document over the Peppol network.

Zendat announces a new or replaced sub-processor at least 30 days before it starts processing the merchant's data, in the app or by email to the shop's contact address. A merchant who objects on reasonable data protection grounds, and with whom no solution is found, may end the agreement by uninstalling the app before the change takes effect. Zendat remains liable to the merchant for its sub-processors' performance of these terms.

10. Audits and information

Zendat answers the merchant's reasonable questions about how these terms are met within ten working days, and provides the reports and certifications its hosting provider makes available. An audit on site is possible once a year, or after a breach, with thirty days' notice, during business hours, at the merchant's cost, by an auditor bound to confidentiality who is not a competitor of Zendat; where a written questionnaire answers the question, that comes first.

11. Transfers outside the EU

The data is processed in the EU. Zendat's hosting provider and mail provider are companies in the United States that process the data in the EU, with support access from the United States under the EU Standard Contractual Clauses and their certification under the EU-US Data Privacy Framework (section 9). Zendat makes no other transfer. Delivery of a document to a buyer's access point outside the EU is a transfer the merchant makes by invoicing that buyer.

12. Liability and precedence

The limitations of liability in the Terms of Service apply to these terms as well, except where the GDPR does not allow it. Where these terms and the Terms of Service differ on personal data, these terms prevail.

13. Term

These terms apply for as long as the app is installed and until the erasure of section 8 is done.