1. Parties
Controller: the business that connects its WooCommerce store and Square account to StockEven ("Customer").
Processor: Event Space Sp. z o.o., ul. Kanarkowa 47, 11-041 Olsztyn, Poland, VAT ID PL7394025935, KRS 0001210621 ("Processor").
2. Scope of processing
| Subject and purpose | Syncing stock quantities between the Customer's Square account and WooCommerce store, showing activity and sending alerts. |
|---|---|
| Duration | While the store is connected, plus the deletion period in section 7. |
| Nature | Collection, storage, comparison, transfer between the two systems, deletion. |
| Data | Mostly non-personal product data (IDs, SKUs, names, quantities). Personal data may appear incidentally: the alert email address, order numbers attached to stock changes, and personal names if used in product names. |
| Data subjects | The Customer's staff (alert recipients) and, through order numbers, the Customer's buyers. |
3. Processor duties
- Process personal data only on the Customer's documented instructions, which are these terms and the settings chosen in the plugin, unless EU or Polish law requires otherwise.
- Ensure that persons with access are bound by confidentiality.
- Implement the measures in section 4.
- Help the Customer answer data subject requests and meet its obligations under Articles 32–36 GDPR, taking into account the nature of the processing.
- Inform the Customer if an instruction appears to break data protection law.
4. Security measures
- TLS encryption for all traffic between the plugin, the service, Square and Stripe.
- Square tokens and store secrets encrypted at rest; requests between plugin and service signed with HMAC per store.
- Servers in the EU (Hetzner, Germany and Finland), access limited to authorized staff with SSH keys.
- Daily database backups kept for 14 days; monitoring of service health with alerts.
- Data minimization: only stock-related data is collected; buyer names, addresses and payment details are never collected.
5. Sub-processors
The Customer authorizes the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and backups | Germany, Finland |
| Resend, Inc. | Delivery of alert emails | EU sending region; USA (SCCs / DPF) |
| Cloudflare, Inc. | DNS | Global (SCCs / DPF) |
The Processor informs the Customer of intended changes to this list by updating this page and by email to the alert address at least 14 days in advance. The Customer may object by disconnecting the store before the change. The Processor imposes data protection obligations on each sub-processor equivalent to this agreement.
6. Personal data breaches
The Processor notifies the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Customer's data, with the information available at the time.
7. End of processing
When the store is disconnected or the plugin is uninstalled, Square tokens are deleted immediately and other Customer data within 30 days. Backups containing the data are overwritten within 14 days after that. The Customer can request an export of its data before deletion.
8. Audits
On written request the Processor provides the information needed to demonstrate compliance with this agreement. On-site audits are possible once a year with 30 days' notice, at the Customer's cost, and subject to confidentiality.
9. Final provisions
This agreement is governed by Polish law. If it conflicts with the Terms of Service on data protection, this agreement prevails. Liability under this agreement follows section 10 of the Terms of Service, to the extent permitted by the GDPR.