Wotaso Ring Sizer Data Processing Terms
Article 28 GDPR data processing terms for business merchants. Effective 10 August 2026.
Processor: Wotaso GmbH, Bostonring 5, 71686 Remseck am Neckar, Germany, represented by Lucas Damian Orzan, Managing Director
Controller: the Shopify merchant that installs and enables the app for its storefront.
Privacy contact: contact@wotaso.com
Contact / imprint: https://wotaso.com/imprint
Public DPA URL: https://app.ringsizerpro.com/legal/dpa
1. Scope, subject matter, and duration
These terms apply where the processor handles personal data on behalf of the merchant through Wotaso Ring Sizer. Processing begins when the merchant enables the relevant app function and continues until uninstall, termination, or deletion in accordance with these terms. Controller processing performed by the operator for its own account administration, legal obligations, and service security is described separately in the privacy notice.
2. Nature and purpose
- Deliver finger and existing-ring sizing in the merchant storefront and map an exact existing-ring result to an available product variant.
- Process optional measurement and funnel analytics when the merchant enables them and Shopify Customer Privacy permits analytics processing.
- Maintain the app configuration, enforce bounded quotas and abuse controls, troubleshoot faults, and respond to verified privacy requests.
3. Data subjects and data categories
- Data subjects: merchant administrators and storefront shoppers using the sizing flow.
- Merchant data: shop domain, app settings, installation/session state, product configuration, and support context.
- Storefront data: product/variant context, measurement mode, diameter/circumference, recommended/matched size, and anonymous flow step.
- Security data: pseudonymous HMAC rate-limit keys and bounded operational logs. No raw IP address is stored in the rate-limit table.
- The sizing flow does not request camera access, collect images, or persist customer account identifiers.
4. Documented instructions
The processor acts only on documented instructions expressed through the merchant's app installation, configuration, feature selection, support requests, and these terms, unless Union or Member State law requires otherwise. The processor will inform the merchant before legally required processing unless prohibited by law. The processor will promptly notify the merchant if an instruction appears to infringe applicable data-protection law.
5. Confidentiality and personnel
The processor ensures that persons authorised to process personal data are bound by confidentiality and receive access only where required for operation, support, security, or incident response.
6. Technical and organisational measures
- TLS transport, restrictive security headers, Shopify session-token validation, HMAC verification for app-proxy/webhook requests, and least-privilege Shopify scope.
- No camera/image collection; optional analytics fails closed when consent state cannot be established.
- Pseudonymous rate-limit keys, bounded request bodies and inputs, log redaction, encrypted secrets, tenant-scoped database access, and aggregate-only owner analytics showing aggregate totals across shops.
- Automated 90-day analytics purge by default, verified shop-redact deletion, session/token deletion on uninstall, health/readiness checks, dependency scanning, code scanning, and tested recovery procedures before production use.
7. Subprocessors
The merchant grants general authorisation for the subprocessors on the current subprocessor list. The processor will give reasonable advance notice of a material new subprocessor so the merchant can object on substantiated data-protection grounds. The processor imposes equivalent data-protection obligations on subprocessors and remains responsible for their performance under Article 28 GDPR.
8. Data-subject requests and compliance assistance
Taking into account the nature of processing, the processor will reasonably assist the merchant with data-subject requests, data-protection impact assessments, prior consultations, and compliance with Articles 32–36 GDPR. Because the app does not persist customer identifiers, the merchant must provide sufficient verified context for any request.
9. Security incidents
The processor will notify the merchant without undue delay after becoming aware of a personal-data breach affecting merchant data and provide available information needed for the merchant's assessment and notification duties. The merchant remains responsible for notifications required in its controller role.
10. Deletion, return, and retention
Optional measurement and funnel analytics are retained for 90 days by default. Verified shop-redact requests delete the shop record and associated app data; uninstall clears the access token and sessions. At termination, the processor deletes or returns processor-held personal data at the merchant's choice where technically available, unless law requires retention. Encrypted backup copies, when enabled, remain inaccessible for ordinary use and expire under the documented rotation; deleted data is not intentionally restored into production.
11. Audits and evidence
On reasonable written request, the processor will provide information necessary to demonstrate compliance with these terms. Audits must protect other customers, security, and confidentiality; remote documentation review is preferred, and on-site inspection requires reasonable notice unless a regulator or confirmed incident requires urgency.
12. International transfers
The primary application and database workload is hosted in Germany. Where a subprocessor transfers personal data outside the EEA, the processor relies on an applicable adequacy decision or safeguards under Chapter V GDPR and makes available relevant transfer information.
13. Order of precedence and review status
These terms supplement the merchant agreement and prevail for processor obligations if there is a conflict. They become binding only through valid incorporation or acceptance by the merchant. The operational controls and wording must still receive qualified legal review before broad EU rollout.