Data Processing Agreement (Art. 28 GDPR)
Version 1.0 · Effective: 21 July 2026
(1) Golden Inventory (Serhii Korsunenko), Berlin, Germany — "Processor"
(2) The Customer using the Golden Inventory service at inventory-system.com as a registered organization — "Controller"
This DPA is incorporated into the Golden Inventory Terms of Service and applies when the Controller creates an organization account and enters personal data into the service. By using the service, the Controller accepts this DPA.
1. Subject matter and duration
The Processor will process personal data on behalf of the Controller for the purpose of providing the Golden Inventory inventory-management SaaS. Processing begins when the Controller creates an organization and enters data, and ends upon deletion of the Controller's organization or termination of the service agreement, whichever is later. The Processor will delete or return all personal data within 30 days after termination, except where EU or Member State law requires continued storage (see §147 AO / GoBD for invoice data — such data is retained in restricted form for 10 years, with party names anonymized per section 7).
2. Nature and purpose of processing
The Processor provides a multi-tenant, cloud-hosted inventory management application. Processing consists of: storing, retrieving, indexing, searching, aggregating, converting (document type conversions), exporting (PDF, CSV, XLSX), and transmitting (email delivery of documents, webhook forwarding, e-commerce synchronization) the Controller's business data as instructed through the application's user interface and API.
3. Types of personal data
The Controller determines which personal data to enter. The service supports the following categories:
- Party master data: names, contact details (phone, email, postal address), tax identifiers (VAT numbers)
- Document data: party references on sales/purchase/inventory documents, line-item details, payment references
- Asset data: vehicle registration plates, VINs, meter readings linked to customer records
- Workforce attribution: technician names on work orders/service lines, waiter names on restaurant tabs
- E-commerce data: customer records imported from Shopify/WooCommerce (name, address, order metadata)
- Authentication data of the Controller's own users (email addresses for invitation and role management)
Data excluded from this DPA (not personal data under GDPR): item master records, SKUs, barcodes, stock quantities, bill-of-material structures, tax code definitions, and any data the Controller has fully anonymized before entry.
4. Categories of data subjects
As determined by the Controller, data subjects may include: the Controller's customers, vendors/suppliers, employees, subcontractors, service technicians, waitstaff, and other natural persons whose data the Controller enters into the service.
5. Technical and organizational measures (TOMs)
The Processor implements and maintains the following measures, appropriate to the risk (Art. 32 GDPR):
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.3, HSTS, secure cookies (HttpOnly; Secure; SameSite=Lax) |
| Encryption at rest | Backups encrypted client-side (AES-256-CBC) before transmission; database files on encrypted volumes (Hetzner default) |
| Access control | JWT-based authentication with role-based authorization (owner/admin/manager/cashier/waiter/kitchen); all tenant queries filtered by org_id at the database layer |
| Password storage | bcrypt hashing (no plaintext, no reversible encryption) |
| Network isolation | PostgreSQL on internal Docker network, no public port; application is the sole database client |
| Rate limiting | SlowAPI rate limits on authentication endpoints (registration, login, password reset) per client IP |
| Audit trail | Immutable billing webhook event log (GumroadWebhookEvent); inv_audit_log for admin actions |
| Backup & restore | Daily incremental + weekly full database backups with 30-day rolling retention; monthly restore tests |
| Logging & monitoring | Access logs retained 14 days (nginx) / 30 days (app); UptimeRobot health-check monitoring |
| Patch management | OS and dependency updates applied within 7 days of release (critical: 48 hours) |
| Data isolation | Multi-tenant architecture with per-org data partitioning; no cross-tenant queries possible without explicit org-scoping |
6. Sub-processors
The Controller authorizes the following sub-processors. The Processor will inform the Controller of any intended addition or replacement at least 14 days before the change, giving the Controller the opportunity to object on reasonable data-protection grounds. If the objection cannot be resolved, the Controller may terminate the service with 30 days' notice without penalty.
| Sub-processor | Service | Location | Adequacy mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Infrastructure (VPS, block storage, Storage Box) | EU (DE/FI) | Art. 45 — within EU |
| Scaleway / OVH | Secondary backup storage (restic target) | EU (FR) | Art. 45 — within EU |
| nocdirect (Josef) | SMTP relay for transactional email | US (TX) | Art. 46(2)(c) — Standard Contractual Clauses (hosting provider's DPA) |
| Gumroad, Inc. | Payment processing, subscription management | US | Art. 46(2)(c) — Standard Contractual Clauses (Gumroad DPA); only email + license key + payment amounts shared |
No tenant business data (documents, parties, stock) is transferred to sub-processors outside the EU.
7. Assistance with data subject rights
The Processor will, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Articles 15–21 GDPR. The Controller directs such requests to support@inventory-system.com. The Processor will:
- Export all data associated with a data subject within 10 business days (for access/portability requests).
- Apply party anonymization (overwrite name/contact fields, preserve document numbers/amounts for legal retention) within 10 business days (for erasure requests where documents are under retention).
- Confirm completion in writing.
8. Breach notification
The Processor will notify the Controller without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting the Controller's tenant data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. The Processor will cooperate with the Controller's own breach-notification obligations under Art. 33/34 GDPR.
9. Deletion and return of data
Upon termination of the service agreement, the Processor will:
- Provide the Controller with a full export of all tenant data in machine-readable format (JSON/XLSX) within 10 business days of request.
- Delete all tenant data from the live database within 30 days after the export is confirmed received, or immediately if no export is requested.
- Retain encrypted backups for up to 30 days (standard backup lifecycle), after which the data is irrecoverably purged.
- Where EU or Member State law (e.g. GoBD §147 AO) requires retention of invoice records, retain only those document records that are legally required, with party personal data anonymized (names/contact fields overwritten with placeholders).
10. Audit rights
The Controller may, no more than once per calendar year and with 30 days' written notice, request evidence of compliance with this DPA. The Processor will provide:
- A current SOC 2 Type II report or equivalent third-party audit report if available, or
- A completed security questionnaire (the Processor's standard information security self-assessment), and
- Log excerpts demonstrating the technical measures in section 5 upon reasonable request.
On-site audits require mutual agreement on scope, timing, and cost (borne by the Controller) and are limited to business hours. The Processor may redact confidential information not relevant to the Controller's data.
11. Processor's own staff
The Processor ensures that all personnel authorized to process the Controller's personal data are bound by confidentiality obligations (employment contracts or standalone NDAs) and have received data-protection training appropriate to their role.
12. Liability
Liability under this DPA follows the liability provisions of the Terms of Service and Art. 82 GDPR. The Processor is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed at processors or acted outside or contrary to the Controller's lawful instructions.
13. Governing law & jurisdiction
This DPA is governed by the law of the Federal Republic of Germany. The courts of Berlin, Germany, have jurisdiction. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails for data-protection matters.
support@inventory-system.com
and using the Golden Inventory service.