Data Processing Agreement
1. Introduction
This Data Processing Agreement (DPA) forms part of the Terms of Service between you (the "Data Controller") and Mebsly B.V., trading as Depotely (the "Data Processor"). This agreement ensures compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
2. Definitions
- Personal Data: any information relating to an identified or identifiable natural person
- Processing: any operation performed on personal data (collection, storage, analysis, etc.)
- Data Controller: the entity that determines the purposes and means of processing
- Data Processor: the entity that processes personal data on behalf of the controller
- Data Subject: the individual whose personal data is being processed
- Sub-processor: third parties engaged by the processor to assist in data processing
3. Scope and purpose of processing
We process personal data for the following purposes:
- Providing e-commerce analytics and business intelligence services
- Managing user accounts and authentication
- Processing payments and billing
- Providing customer support and communication
- Improving our services and platform functionality
- Complying with legal and regulatory requirements
3.1 Categories of personal data
- Identity information (name, email, business details)
- Financial information (payment methods, billing addresses)
- E-commerce data (sales, inventory, customer information)
- Technical data (IP addresses, device information, usage analytics)
- Communication data (support requests, feedback)
4. Data processing principles
We adhere to the following data processing principles:
- Lawfulness: processing is based on legitimate legal grounds
- Fairness: processing is transparent and fair to data subjects
- Transparency: data subjects are informed about processing activities
- Purpose limitation: data is processed only for specified purposes
- Data minimisation: only necessary data is collected and processed
- Accuracy: personal data is kept accurate and up to date
- Storage limitation: data is retained only as long as necessary
- Security: appropriate technical and organisational measures are implemented
5. Technical and organisational measures
We implement comprehensive security measures to protect personal data:
5.1 Technical measures
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Multi-factor authentication and strong password policies
- Regular security updates and patch management
- Network security and firewall protection
- Intrusion detection and prevention systems
- Regular security assessments and penetration testing
5.2 Organisational measures
- Role-based access controls and the principle of least privilege
- Regular security training for all employees
- Background checks for personnel with data access
- Confidentiality agreements and data protection training
- Incident response procedures and breach notification protocols
- Regular audits and compliance monitoring
6. Data subject rights
We support the following data subject rights:
- Right of access: data subjects can request information about their personal data
- Right of rectification: data subjects can request correction of inaccurate data
- Right of erasure: data subjects can request deletion of their personal data
- Right to restrict processing: data subjects can limit how their data is processed
- Right to data portability: data subjects can receive their data in a portable format
- Right to object: data subjects can object to certain types of processing
- Rights related to automated decision-making: protection against automated profiling
7. Sub-processors
We may engage sub-processors to assist in providing our services. All sub-processors are bound by appropriate data protection agreements and security requirements.
7.1 Current sub-processors
- Database and storage: Supabase (hosted in the EU, Ireland) and Cloudflare R2 (backups and the activity log)
- Application servers: Contabo (Germany); website and DNS: Cloudflare
- Authentication and account management: Clerk
- Payment processing: Mollie (subscription payments; no card or bank details are stored by us)
- Transactional email: ZeptoMail by Zoho (EU)
- Sales channels and the shipping service you connect yourself (bol.com, Amazon, Shopify, WooCommerce, Etsy, BigCommerce, Kaufland, Sendcloud) act on your own instructions and are not our sub-processors
7.2 Sub-processor requirements
- All sub-processors must provide adequate data protection guarantees
- We maintain a list of current sub-processors and notify you of changes
- You have the right to object to new sub-processors
- Sub-processors are bound by the same data protection obligations
8. Data transfers
We may transfer personal data to countries outside the European Economic Area (EEA). Such transfers are protected by appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
- Binding Corporate Rules (BCRs) where applicable
- Certification schemes and codes of conduct
9. Data breach notification
In the event of a personal data breach, we will:
- Notify the relevant supervisory authority within 72 hours
- Inform affected data subjects without undue delay if there is a high risk
- Provide detailed information about the nature and scope of the breach
- Describe the likely consequences and the measures taken to address the breach
- Cooperate with authorities and data controllers in breach investigations
10. Data retention
We retain personal data only as long as necessary for the purposes outlined in this agreement:
- Account data: retained while the account is active plus 3 years for legal compliance
- Transaction data: retained for 7 years for tax and legal requirements
- Analytics data: retained for 2 years for service improvement
- Support communications: retained for 3 years for quality assurance
- Marketing data: retained until consent is withdrawn
11. Audit and compliance
We keep records of our data processing activities and apply the following measures:
- Channel credentials are stored encrypted and are never returned by the application, not even to the account owner
- Every change to tenant data is recorded in an activity log with the person who made it
- Regular internal security assessments of the application and its dependencies
- Data protection impact assessments for high-risk processing
- We do not hold a third-party certification such as SOC 2 or ISO 27001
12. Contact information
For questions about this Data Processing Agreement or our data protection practices:
- Email: info@depotely.com
- Address: Mebsly B.V. (trading as Depotely), Abbenbroekstraat 2, 1507 KE Zaandam, The Netherlands
13. Governing law
This Data Processing Agreement is governed by Dutch law and is subject to the jurisdiction of the Dutch courts. Any disputes will be resolved in accordance with applicable data protection laws and regulations.
Last updated: October 10, 2026 – Version 1.1