Skip to content
shopify apps
AppsSupport
effware
AppsSupport

Inventur & Stock Take for Shopify

Data processing agreement (DPA)

This is a translation for convenience. Only the German version is legally binding.

between the merchant who installs the Shopify app “effware: Inventur & Stock Take” in their store (controller),

and Mitterschida Ventures UG (haftungsbeschränkt), Mitterschida 1, 94327 Bogen, Germany, represented by its managing director Felix Groß (processor).

1. Subject matter and duration

  1. The processor provides the app to the controller for carrying out and documenting stock counts (stock takes). In doing so it processes personal data on behalf of the controller.
  2. The agreement applies as long as the app is installed in the controller’s store and ends with the deletion of the data under section 9.

2. Nature and purpose of processing, type of data, data subjects

  1. Purpose: recording, storing, comparing and logging counts; booking stock to Shopify on the controller’s instruction; generating and keeping stock take reports.
  2. Type of data: names or initials of counters; Shopify user ID and name of the people who create, review or close counts; timestamps per entry and count; a random device ID per browser; free text (notes, cancellation and difference reasons); address of the location; content of the stored reports.
  3. Data subjects: employees and agents of the controller who count, review or operate the app.
  4. Customer and order data is not processed; the app has no access to it.

3. Instructions

  1. The processor processes the data only on documented instructions of the controller. Instructions are the use of the app’s functions and instructions by email to support@efflabs.de.
  2. If the processor considers an instruction unlawful, it informs the controller without undue delay (Art. 28 (3) sentence 3 GDPR).
  3. Processing without instruction takes place only where the processor is required to do so by EU or German law; it informs the controller beforehand unless the law prohibits this.

4. Obligations of the processor

  1. Confidentiality: Only the processor’s managing director has access to the data. Other people get access only if they are bound to confidentiality.
  2. Security: The processor implements the technical and organizational measures under Art. 32 GDPR set out in annex 1. It may develop them further as long as the level of protection does not decrease.
  3. Data subject rights: The processor supports the controller with requests from data subjects. The app provides the log of each count as CSV for this (filterable by person). On instruction the processor pseudonymizes all name fields of a person or deletes stored reports.
  4. Assistance: The processor assists the controller with the obligations under Art. 32 to 36 GDPR (security, breach notification, data protection impact assessment) within the information available to it.
  5. Breaches: The processor notifies the controller of a personal data breach without undue delay after becoming aware of it, through a notice in the app and by email to the shop owner’s address stored in Shopify, which the processor retrieves from Shopify for this purpose when needed and does not store. If the app has already been uninstalled, the notification is made by publication on effware.com.
  6. Evidence: On request the processor provides the controller with the information necessary to demonstrate compliance with Art. 28 GDPR and allows audits after prior agreement during normal business hours without disrupting operations for other customers. Evidence is primarily provided by written information.

5. Sub-processors

  1. The controller approves the sub-processors listed in annex 2.
  2. The processor informs the controller at least 30 days before engaging a new or replacing a sub-processor by updating this page (with the date under “Last updated”) and through a notice in the app. The controller may object within this period for an important data protection reason; if no agreement is possible, the controller can end the use by uninstalling the app.
  3. The processor contractually binds sub-processors to a level of protection equivalent to this agreement (Art. 28 (4) GDPR).

6. Place of processing

The app’s data is processed exclusively in Germany (data centers of Hetzner Online GmbH in Nuremberg and Falkenstein). Only where the controller sends personal data to support by email is it processed via Google Workspace; a transfer to the USA is possible, secured by Google LLC’s certification under the EU-US Data Privacy Framework (Art. 45 GDPR).

7. Obligations of the controller

The controller is responsible for the lawfulness of the processing, in particular for informing the counters (Art. 13 GDPR) and, where applicable, involving a works council. It notifies the processor of errors or irregularities it detects when checking the results.

8. Liability

Liability is governed by Art. 82 GDPR. Otherwise the liability rules of the terms of use apply.

9. Deletion and return

  1. During use the controller can download all reports as PDF and CSV.
  2. After the app is uninstalled, the processor deletes all data of the store from the database 48 hours after Shopify’s notification, including the stored reports. In the encrypted backups, which are locked against changes, the data is deleted after 30 days at the latest.
  3. Excluded is a pseudonymized statistics row without count data for which the processor is itself the controller (see the app’s privacy policy); it is deleted 24 months after the uninstall.

10. Conclusion and changes

  1. This agreement is part of the terms of use and is deemed agreed upon installation of the app. Electronic form is sufficient (Art. 28 (9) GDPR). On request the controller receives a version signed by the processor.
  2. Changes are announced to the controller at least 30 days in advance on this page and through a notice in the app.
  3. In case of conflict this agreement takes precedence over the terms of use with regard to the protection of personal data.

Annex 1: Technical and organizational measures (Art. 32 GDPR)

Confidentiality

  • Physical access: servers in data centers of Hetzner Online GmbH (Nuremberg, Falkenstein) with access control by Hetzner; the processor has no physical access.
  • System access: the server firewall allows only SSH, HTTP and HTTPS inbound. The API of the management platform (Coolify) is blocked from outside and reachable only through an SSH tunnel. Administrative access only by the managing director with a personal account. Credentials and keys are not in the source code but only in the server environment and a password manager.
  • Data access: merchants access their store’s data only via the Shopify login (Shopify session tokens). All data is assigned to the store and queried separately per store. Links for the camera scan page contain a random access key, are valid for 12 hours and can be revoked at any time.
  • Separation: separate Shopify apps and databases for development and production. The database is reachable only within the server’s internal network.
  • Pseudonymization and data minimization: minimal Shopify permissions (products, inventory, locations), no customer or order data. Initials are enough for names. Statistics rows are pseudonymized with HMAC-SHA256 after deletion. Server logs contain no names, no free text and no parameters from addresses; access keys in paths are masked.

Integrity

  • Transfer: all connections are encrypted with TLS (Let’s Encrypt). Backups are encrypted with AES-256 and our own key before upload.
  • Input: count entries are only appended, never overwritten. Name, device, server time and device time are stored for every entry; corrections remain traceable in the log. Stored reports receive a SHA-256 checksum.

Availability and resilience

  • Daily backup of database and reports to Hetzner Object Storage (Falkenstein, a different location from the server) with Object Lock: locked against deletion and changes for 30 days. Restoring has been tested.
  • Automatic availability checks; a new version that fails the health check is not rolled out.
  • Entries recorded by a device without a connection are stored and transferred as soon as the connection is back.

Review

  • Data protection review before releasing changes that affect personal data. Deletion after uninstall has been tested against the production environment.

Annex 2: Sub-processors

CompanyServiceLocation
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germanyserver, database, backupsGermany (Nuremberg, Falkenstein)
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irelandemail (Google Workspace), support communication onlyEU; transfer to the USA possible (EU-US Data Privacy Framework)

Back to Inventur & Stock Take for Shopify

Last updated: 2026-10-09

© 2026 effware · Mitterschida Ventures UG (haftungsbeschränkt)
SupportImprintPrivacyDPA