StockEven

Legal

Data Processing Agreement

Last updated: October 9, 2026 · Article 28 GDPR

This agreement applies automatically to every store that uses StockEven and forms part of the Terms of Service. A signed copy is available on request at info@stockeven.com.

1. Parties

Controller: the business that connects its WooCommerce store and Square account to StockEven ("Customer").

Processor: Event Space Sp. z o.o., ul. Kanarkowa 47, 11-041 Olsztyn, Poland, VAT ID PL7394025935, KRS 0001210621 ("Processor").

2. Scope of processing

Subject and purposeSyncing stock quantities between the Customer's Square account and WooCommerce store, showing activity and sending alerts.
DurationWhile the store is connected, plus the deletion period in section 7.
NatureCollection, storage, comparison, transfer between the two systems, deletion.
DataMostly non-personal product data (IDs, SKUs, names, quantities). Personal data may appear incidentally: the alert email address, order numbers attached to stock changes, and personal names if used in product names.
Data subjectsThe Customer's staff (alert recipients) and, through order numbers, the Customer's buyers.

3. Processor duties

  • Process personal data only on the Customer's documented instructions, which are these terms and the settings chosen in the plugin, unless EU or Polish law requires otherwise.
  • Ensure that persons with access are bound by confidentiality.
  • Implement the measures in section 4.
  • Help the Customer answer data subject requests and meet its obligations under Articles 32–36 GDPR, taking into account the nature of the processing.
  • Inform the Customer if an instruction appears to break data protection law.

4. Security measures

  • TLS encryption for all traffic between the plugin, the service, Square and Stripe.
  • Square tokens and store secrets encrypted at rest; requests between plugin and service signed with HMAC per store.
  • Servers in the EU (Hetzner, Germany and Finland), access limited to authorized staff with SSH keys.
  • Daily database backups kept for 14 days; monitoring of service health with alerts.
  • Data minimization: only stock-related data is collected; buyer names, addresses and payment details are never collected.

5. Sub-processors

The Customer authorizes the following sub-processors:

Sub-processorPurposeLocation
Hetzner Online GmbHHosting and backupsGermany, Finland
Resend, Inc.Delivery of alert emailsEU sending region; USA (SCCs / DPF)
Cloudflare, Inc.DNSGlobal (SCCs / DPF)

The Processor informs the Customer of intended changes to this list by updating this page and by email to the alert address at least 14 days in advance. The Customer may object by disconnecting the store before the change. The Processor imposes data protection obligations on each sub-processor equivalent to this agreement.

6. Personal data breaches

The Processor notifies the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Customer's data, with the information available at the time.

7. End of processing

When the store is disconnected or the plugin is uninstalled, Square tokens are deleted immediately and other Customer data within 30 days. Backups containing the data are overwritten within 14 days after that. The Customer can request an export of its data before deletion.

8. Audits

On written request the Processor provides the information needed to demonstrate compliance with this agreement. On-site audits are possible once a year with 30 days' notice, at the Customer's cost, and subject to confidentiality.

9. Final provisions

This agreement is governed by Polish law. If it conflicts with the Terms of Service on data protection, this agreement prevails. Liability under this agreement follows section 10 of the Terms of Service, to the extent permitted by the GDPR.