WPNoti
Back to siteSign up
PrivacyTermsAccount deletionData processing

WPNoti Data Processing Addendum

Last updated 24 September 20268 min read
Parties, scope and priorityProcessing descriptionInstructions and Customer dutiesConfidentiality and securitySubprocessorsInternational transfersAssistance with rights and compliancePersonal data breachesReturn and deletionInformation and auditsLiability and survivalSchedule A — Provider and transfer registerSchedule B — Security measures to verify before acceptance
In short
When WPNoti handles your store’s personal data, you are the controller and WPNoti is the processor.
The addendum covers instructions, subprocessors, security, breaches, and deletion.
Hostinger and Supabase accounts are held in the name of MB DEVELOPERIS.
01

Parties, scope and priority

This Data Processing Addendum (“DPA”) forms part of the WPNoti Terms of Service between MB DEVELOPERIS, company code 305652066, VAT number LT100015358510, Daukšių g. 2, Daukšių k., LT-18102 Švenčionių r., Lietuva (Lithuania), and the customer identified in the accepted service order/account (“Customer”). Privacy contact: [email protected].

It applies to personal data processed by WPNoti on Customer’s behalf through connected stores (“Customer Personal Data”). Customer is normally controller and WPNoti processor. If Customer is a processor for another controller, WPNoti acts as subprocessor and Customer confirms that it has authority to instruct and appoint us. Obligations to the ultimate controller continue to apply through Customer.

GDPR terms have their GDPR meanings. This DPA governs conflicts with the service terms about Customer Personal Data. Applicable mandatory transfer clauses prevail over conflicting contractual terms. Our independent controller activities, such as subscription administration and legally required accounting, are described in the Privacy Policy and are not reclassified as processor activities by this DPA.

02

Processing description

ItemDescription
Subject matter and purposeProvide Customer’s requested WooCommerce management, information, monitoring, notification, team-access and support functions.
DurationThe service relationship, followed by return/deletion and restricted backup expiry as specified below.
Nature of processingReceive, retrieve, transmit, display, organise, cache, store selected summaries/previews, match security inventory, implement authorised updates, restrict and delete data. Processing may be continuous for events/monitoring and on demand for live screens.
Data subjectsStore customers and prospective customers, form submitters, visitors, store administrators and staff, Customer’s authorised users, and other people whose information is lawfully included in store records.
Data categoriesOrder identifiers/status/value/items/payment-method information; customer identity/contact and billing/delivery details; notes and purchase history; form content/previews; staff/admin identifiers and activity; pseudonymous visitor identifiers/page paths/counts; store alerts and error content; related support records and connection information where personal.
Sensitive informationNo deliberate processing of special-category or criminal-offence data is intended. Free-text fields could contain such data; Customer must minimise it, establish any required legal conditions and obtain a separate agreement on safeguards before intentionally using the service for it.
InstructionsThe agreed service configuration, enabled features, commands by authorised users, accepted Terms and this DPA, supplemented by lawful documented instructions sent through support.
03

Instructions and Customer duties

We process Customer Personal Data only on documented instructions, including for transfers, unless EU or Member State law requires otherwise. In that event we inform Customer of the requirement before processing unless the law prohibits notice on important public-interest grounds. We immediately inform Customer if, in our opinion, an instruction infringes applicable data-protection law, and may pause the affected operation while it is resolved.

Customer determines the purposes, lawful bases, notices, tracking-consent configuration and authorised users for its processing. It must minimise data and provide lawful instructions. We do not use Customer Personal Data for our own advertising, sale of customer lists or unrelated profiling. No general permission to train AI models on Customer Personal Data is granted.

04

Confidentiality and security

We ensure that people authorised to process Customer Personal Data are subject to confidentiality obligations and access it only as necessary for their duties. We implement and maintain appropriate technical and organisational measures under Article 32 GDPR, taking account of risk, including the nature of the data and potential effects on individuals.

Schedule B describes the measures that must be in place. Material changes must not reduce the overall protection. We assist Customer with its security obligations using information reasonably available to us. Customer remains responsible for its own store, devices and access decisions; this does not diminish our responsibility for our systems or subprocessors.

05

Subprocessors

Customer gives general written authorisation for the subprocessors identified in the completed Schedule A. We provide their identity, function, processing locations and relevant transfer safeguards. We will notify Customer at least 30 days before adding or replacing a subprocessor, allowing a reasonable opportunity to object on substantiated data-protection grounds before the new processing starts.

We will work in good faith to resolve an objection, including through a reasonable alternative. If no suitable resolution is possible, Customer may terminate the affected service before the proposed appointment takes effect and obtain a proportional refund of unused prepaid fees. We will not treat unresolved silence following inadequate notice as informed authorisation.

We bind each subprocessor by written obligations providing at least the data protection required by this DPA for its activities, and remain fully liable to Customer for its performance of those obligations. Further subcontracting must preserve these protections and provide the information needed for Customer’s authorisation and oversight.

06

International transfers

We transfer Customer Personal Data outside the EEA only under documented instructions and a valid GDPR Chapter V mechanism. Schedule A must identify the actual destinations and mechanism. Where required, we enter into the applicable European Commission standard contractual clauses, complete their annexes, assess the transfer and apply supplementary measures. This DPA is not itself a substitute for those clauses or assessments.

We inform Customer of material changes affecting transfer protection and cooperate on a lawful solution. If lawful protection cannot be maintained, we suspend the affected transfer. Additional UK or Swiss provisions require completion where those laws apply; no unsupported certification or universal adequacy claim is made here.

07

Assistance with rights and compliance

Taking account of the nature of processing, we assist Customer through appropriate technical and organisational measures with requests for access, correction, erasure, restriction, objection and portability. We promptly forward a request concerning Customer Personal Data to Customer and do not substantively answer it except on instruction or as required by law. We may acknowledge receipt and direct the person to Customer.

Taking account of the processing and information available to us, we assist Customer with security, breach notification, data-protection impact assessments and prior consultation with authorities under Articles 32–36 GDPR. We provide information needed to demonstrate compliance. Reasonable arrangements for exceptional assistance may be agreed in advance, but fees or scheduling cannot prevent legally required cooperation or deadlines.

08

Personal data breaches

We notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Where available, the notice describes the incident and affected data/individuals, likely consequences, steps taken or proposed, and a contact for further information. We provide information in stages if necessary and do not delay an initial notice while completing an investigation.

We take reasonable steps to contain, investigate and mitigate the breach, preserve relevant evidence and assist Customer’s notifications. Customer decides notifications as controller unless the law independently requires us to notify. The controller’s possible 72-hour supervisory-notification deadline does not give us 72 hours to delay informing Customer.

09

Return and deletion

At the end of the relevant processing services, we will, at Customer’s choice, return Customer Personal Data and delete remaining copies, or delete it, unless EU or Member State law requires retention. Customer should request return before initiating irreversible workspace deletion; we provide a support route where no export interface exists. An authorised workspace-deletion command is an instruction to delete the affected data.

We carry out deletion without undue delay, including instructing subprocessors, and confirm completion on request. Restricted backup copies are isolated from ordinary use until scheduled expiry; if restored, deletion instructions are reapplied. Legally required retained data is restricted to that purpose and deleted when the obligation ends.

Deleting one member does not instruct deletion of a workspace that other authorised members still use. We assist with the departing person’s data-rights request without treating all shared data as automatically exempt from erasure. Deleting WPNoti does not delete data in Customer’s own WooCommerce system.

10

Information and audits

We make available information needed to demonstrate our compliance with this DPA and allow and contribute to audits, including inspections, by Customer or an independent auditor it appoints. Routine audits may start with documentation and use reasonable notice, confidentiality and security arrangements to protect other customers. These arrangements do not block necessary inspections, regulator access, investigations of a breach or a legally required audit. We inform Customer promptly if an audit instruction would infringe applicable data-protection law.

11

Liability and survival

The service terms govern the parties’ contractual liability only to the extent lawful. Nothing in either document reduces an individual’s GDPR compensation rights, restricts supervisory powers or displaces mandatory controller/processor duties. Confidentiality, security, transfer and deletion obligations continue while we or our subprocessors retain Customer Personal Data.

12

Schedule A — Provider and transfer register

Brand names below identify known technical services. Verify the exact contracting entity, all relevant countries, role, written DPA and actual transfer mechanism. Where a provider has a mixed role, identify the processing performed as subprocessor separately. Include relevant onward providers and support locations.

ServiceRelevant functionConfirmed location informationRequired completion
HostingerPlatform hosting; email where Customer Personal Data is includedThe Hostinger account is in the name of MB DEVELOPERIS. Platform server in Lithuania. File backups in France. Email through Hostinger until MB DEVELOPERIS deletes the mailbox copy.How many days the Hostinger plan keeps backups; Article 28 terms
SupabaseDatabase and authenticationThe Supabase account is in the name of MB DEVELOPERIS. Project in Frankfurt, Germany. No database backups on the current free plan. Backups begin when the project is on Supabase Pro.Pro backup period and location when that plan starts; DPA and safeguards
ExpoNotification delivery, including any store-personal-data payloadsNot confirmedEntity; processing locations; retention; DPA, onward providers and safeguards
Apple/Google push delivery chainDeliver payloads to devicesNot confirmedConfirm actual APNs/FCM route, roles, applicable terms, countries and protections; do not misdescribe independent-controller activities as subcontracting
Other support/observability/backup providers, if usedOnly the functions actually usedNot confirmedProduction inventory; remove row if none, otherwise add full details

Stripe and Apple/Google payment or sign-in operations are principally relevant to the separate controller disclosures in the Privacy Policy, not automatically this subprocessor register. Customer’s chosen WordPress host is normally Customer’s own provider. Wordfence is not listed as a Customer-data subprocessor solely because WPNoti downloads a public vulnerability feed. Resend must be added and assessed before activation if it would receive Customer Personal Data.

13

Schedule B — Security measures to verify before acceptance

The source material and limited code review identify encrypted stored connection credentials and vulnerability reports, workspace-based access controls, optional two-factor authentication, secure mobile-session storage and hashed purchase-token records. These are partial controls, not a completed security assessment.

  • Encryption in transit, stored-data protection, key management and credential rotation/revocation.
  • Individual staff accounts, least-privilege access, administrative multi-factor authentication, access review and confidentiality training.
  • Workspace isolation, authorisation testing and secure handling of production access.
  • Data minimisation and redaction in logs, error reports, support and push payloads.
  • Patch/vulnerability management and testing proportionate to risk.
  • Backup protection, locations, recovery testing, rotation periods and reapplication of deletions after recovery.
  • Incident detection, escalation and Customer breach-notification procedures.
  • Scheduled retention/deletion, subprocessor deletion instructions, monitoring and failure recovery.
  • Periodic evaluation of safeguards and continuity/recovery arrangements appropriate to the service.

The commercial contract should not claim certifications, specific encryption standards, recovery targets or audit programmes that have not been verified.

Questions about this document?
Write to us and a person will answer.
[email protected]
© 2026 WPNoti. WooCommerce and WordPress are trademarks of their respective owners.PrivacyTermsAccount deletionData processing