← Anmelda

Data Processing Agreement

This Data Processing Agreement ("DPA") is entered into between the merchant installing Anmelda (the "Controller") and the operator of Anmelda (the "Processor"), and forms part of the agreement between them. It reflects Art. 28 GDPR.

Version 1.0 · Last updated: 17 July 2026

1. Parties

Processor: Santo Gigliotti, trading as Anmelda, Via Vergiò 27, 6932 Lugano, Switzerland. Contact: hello@anmelda.com.

Controller: the merchant operating the Shopify store on which Anmelda is installed. Installing the app constitutes acceptance of this DPA.

2. Subject matter, duration, nature and purpose

Subject matter. Processing applications from prospective wholesale customers of the Controller, verifying the businesses behind them against public registries, and creating a native Shopify B2B company on approval.

Duration. For as long as Anmelda is installed, plus the deletion periods in clause 10.

Nature and purpose. Collection, storage, registry lookup, transmission of a decision by email, creation of a B2B company in the Controller's Shopify store, and erasure. The Processor processes for no other purpose.

3. Categories of data subject and personal data

Data subjects: individuals who submit a wholesale application to the Controller's store, in their capacity as a representative of a business, including sole traders acting in their own name.

Personal data:

  • Contact details — first name, last name, email address
  • Business details — company name, country, business address
  • Business identifiers — VAT number, commercial register number
  • Optional details — phone, website, expected monthly volume, free-text message
  • Verification results — registry response, status, timestamp, and consultation ID

No special categories of data (Art. 9) and no criminal-offence data (Art. 10) are processed. The Processor does not request payment or identity-document data.

The Parties acknowledge that business identifiers may themselves be personal data: a sole trader's VAT number, or a company name combined with it, can identify an individual. Such data is treated as personal data throughout.

4. Processor obligations

The Processor shall:

  1. process personal data only on the Controller's documented instructions, this DPA being the initial complete set of instructions, and including for transfers to a third country, unless required by law — in which case the Processor informs the Controller first, unless that law forbids it;
  2. inform the Controller if, in its opinion, an instruction infringes the GDPR;
  3. ensure that anyone authorised to process the data is bound by confidentiality;
  4. implement the technical and organisational measures in clause 5;
  5. respect the conditions in clause 6 for engaging subprocessors;
  6. assist the Controller with data subject rights (clause 7);
  7. assist the Controller with Art. 32–36 obligations (clause 8);
  8. delete the data as set out in clause 10; and
  9. make available the information needed to demonstrate compliance, and allow audits (clause 11).

5. Security measures (Art. 32)

The Processor maintains:

  • Encryption — TLS in transit; encryption at rest for the database and its backups.
  • EU hosting — all application data is hosted in AWS eu-central-1 (Frankfurt, Germany), and outbound email is sent from that same region.
  • Access control — production access is limited to the Processor, over audited sessions, with no publicly exposed administrative interface. Access to the underlying cloud account is protected by multi-factor authentication.
  • Data minimisation in logging — applicant fields and webhook payloads are never written to logs. Logs record counts and identifiers only, so personal data cannot accumulate in them.
  • Minimisation toward registries — registry lookups transmit only a company identifier, never an applicant's name, address, phone or email.
  • Backups — encrypted, held in the EU, and automatically expired after 30 days, which also bounds their retention.
  • Resilience — the ability to restore availability of personal data after an incident, tested by restore drills.

Measures may be updated as the service evolves, provided the level of security is not reduced.

6. Subprocessors

The Controller gives general written authorisation for the Processor to engage subprocessors. Those currently engaged are listed at anmelda.com/subprocessors, which forms part of this DPA.

The Processor shall notify the Controller before adding or replacing a subprocessor, giving the Controller a reasonable period to object. If the Controller reasonably objects on data-protection grounds, and the change cannot be avoided, the Controller may terminate and receive a pro-rata refund of any prepaid fees.

The Processor imposes on each subprocessor the same data-protection obligations as in this DPA, and remains fully liable to the Controller for their performance.

7. Data subject rights

Taking into account the nature of the processing, the Processor assists the Controller with appropriate measures in fulfilling requests under Chapter III. Specifically, through Shopify's mandatory privacy webhooks and the app:

  • Access (Art. 15) — a complete export of everything held about an applicant, returning every field rather than a summary.
  • Erasure (Art. 17) — deletion of the application and its verification records. Erasure means deletion, not anonymisation, because an anonymised record retains re-identification risk through the company name and VAT number.
  • Storage limitation (Art. 5(1)(e)) — a per-shop retention window, applied daily. Where the Controller has set none, applications are deleted after 365 days.

If a data subject contacts the Processor directly, the Processor will not respond on the substance, and will forward the request to the Controller without undue delay.

8. Personal data breaches

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point.

Where full information is not immediately available, the Processor provides it in phases without further undue delay rather than delaying the initial notification. The Processor assists the Controller with its own obligations under Art. 33–34, and with data protection impact assessments and prior consultation under Art. 35–36.

Notification is not an admission of fault or liability.

9. International transfers

Application data is hosted in AWS eu-central-1 (Frankfurt), and decision emails are sent with Amazon SES in that same region. No subprocessor processes personal data outside the EEA.

The Processor is established in Switzerland. The Controller's disclosure of personal data to the Processor is therefore a transfer to a third country within the meaning of Chapter V, irrespective of the hosting region. Its legal basis is the European Commission's adequacy decision for Switzerland, so no Standard Contractual Clauses and no transfer impact assessment are required. Should that adequacy decision be suspended, repealed or annulled, the Parties shall put an alternative Art. 46 safeguard in place without undue delay.

Registry lookups reach EU, Swiss and UK public authorities; Switzerland and the United Kingdom both benefit from adequacy decisions, and receive only a company identifier in any case. Should the Processor ever engage a subprocessor that processes personal data in a country without an adequacy decision, it will ensure a valid transfer mechanism — the Standard Contractual Clauses with a transfer impact assessment — and will notify the Controller under clause 6 before doing so. Current arrangements are stated on the Subprocessors page.

10. Deletion and return

On uninstall, Shopify sends a shop redaction request 48 hours later, at which point the Processor deletes all of that shop's data: applications, verification records, settings, approval rules, email templates, and sessions. The 48-hour gap exists so that a merchant who reinstalls within it finds their applications intact.

Applications are also deleted continuously under the retention window in clause 7. Encrypted backups expire automatically after 30 days, which is the outer bound on deletion from backup media.

Data already written to the Controller's own Shopify store — the B2B company and its metafields — remains under the Controller's control and is not deleted by the Processor.

11. Audit

The Processor makes available to the Controller the information necessary to demonstrate compliance with Art. 28, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. Audits shall be on reasonable notice, during business hours, no more than once per year unless a breach or a supervisory authority requires otherwise, and must not compromise the confidentiality or security of other controllers' data.

12. Liability and precedence

Liability is governed by the agreement between the Parties. In the event of a conflict between this DPA and that agreement, this DPA prevails on matters of data protection. If any provision conflicts with the GDPR, the GDPR prevails.

13. Governing law

This DPA is governed by the substantive law of Switzerland, excluding its conflict-of-law rules and the Vienna Convention on the International Sale of Goods. The courts of Lugano, Canton of Ticino, have exclusive jurisdiction.

This choice does not deprive any data subject of the protection of the GDPR, nor of the mandatory rights they hold under the law of their habitual residence, and it does not limit any supervisory authority's competence. Where the GDPR and the Swiss Federal Act on Data Protection both apply to the same processing, the Processor complies with both, and with whichever sets the higher standard where they differ.

PrivacyDPASubprocessors