Data Processing

Wotaso Ring Sizer Data Processing Terms

Article 28 GDPR data processing terms for business merchants. Effective 10 August 2026.

Processor: Wotaso GmbH, Bostonring 5, 71686 Remseck am Neckar, Germany, represented by Lucas Damian Orzan, Managing Director

Controller: the Shopify merchant that installs and enables the app for its storefront.

Privacy contact: contact@wotaso.com

Contact / imprint: https://wotaso.com/imprint

Public DPA URL: https://app.ringsizerpro.com/legal/dpa

1. Scope, subject matter, and duration

These terms apply where the processor handles personal data on behalf of the merchant through Wotaso Ring Sizer. Processing begins when the merchant enables the relevant app function and continues until uninstall, termination, or deletion in accordance with these terms. Controller processing performed by the operator for its own account administration, legal obligations, and service security is described separately in the privacy notice.

2. Nature and purpose

3. Data subjects and data categories

4. Documented instructions

The processor acts only on documented instructions expressed through the merchant's app installation, configuration, feature selection, support requests, and these terms, unless Union or Member State law requires otherwise. The processor will inform the merchant before legally required processing unless prohibited by law. The processor will promptly notify the merchant if an instruction appears to infringe applicable data-protection law.

5. Confidentiality and personnel

The processor ensures that persons authorised to process personal data are bound by confidentiality and receive access only where required for operation, support, security, or incident response.

6. Technical and organisational measures

7. Subprocessors

The merchant grants general authorisation for the subprocessors on the current subprocessor list. The processor will give reasonable advance notice of a material new subprocessor so the merchant can object on substantiated data-protection grounds. The processor imposes equivalent data-protection obligations on subprocessors and remains responsible for their performance under Article 28 GDPR.

8. Data-subject requests and compliance assistance

Taking into account the nature of processing, the processor will reasonably assist the merchant with data-subject requests, data-protection impact assessments, prior consultations, and compliance with Articles 32–36 GDPR. Because the app does not persist customer identifiers, the merchant must provide sufficient verified context for any request.

9. Security incidents

The processor will notify the merchant without undue delay after becoming aware of a personal-data breach affecting merchant data and provide available information needed for the merchant's assessment and notification duties. The merchant remains responsible for notifications required in its controller role.

10. Deletion, return, and retention

Optional measurement and funnel analytics are retained for 90 days by default. Verified shop-redact requests delete the shop record and associated app data; uninstall clears the access token and sessions. At termination, the processor deletes or returns processor-held personal data at the merchant's choice where technically available, unless law requires retention. Encrypted backup copies, when enabled, remain inaccessible for ordinary use and expire under the documented rotation; deleted data is not intentionally restored into production.

11. Audits and evidence

On reasonable written request, the processor will provide information necessary to demonstrate compliance with these terms. Audits must protect other customers, security, and confidentiality; remote documentation review is preferred, and on-site inspection requires reasonable notice unless a regulator or confirmed incident requires urgency.

12. International transfers

The primary application and database workload is hosted in Germany. Where a subprocessor transfers personal data outside the EEA, the processor relies on an applicable adequacy decision or safeguards under Chapter V GDPR and makes available relevant transfer information.

13. Order of precedence and review status

These terms supplement the merchant agreement and prevail for processor obligations if there is a conflict. They become binding only through valid incorporation or acceptance by the merchant. The operational controls and wording must still receive qualified legal review before broad EU rollout.