Legal

Reqursor Platform Data Processing Addendum

Last updated: October 5, 2026 · Reqursor Technologies · Rev 1.1

All legal documents

In plain language

  • This addendum applies when we process personal data for you through Reqursor Platform, as your processor.
  • Your stores' business data stays in each store's own isolated storage, and we do not read it except in a migration you agree to.
  • AI features send only the store settings needed for a task to our AI provider, one organization per request.
  • We tell you 30 days before we add or replace a sub-processor, and you can object.
  • We sign a copy on request.

Background and Scope

This Data Processing Addendum (the "Addendum" or "DPA") forms part of the agreement between the customer ("Controller") and Reqursor Technologies, a company based in Rotterdam, The Netherlands (KvK number: 42184274) ("Reqursor" or "Processor"), under which Reqursor provides Reqursor Platform (the "Agreement"). It meets the requirements of article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").

Reqursor Platform is an AI platform that builds, moves and runs online stores for agencies. Where Reqursor processes personal data contained in or generated by those online stores on behalf of the Controller, it does so as a processor.

This Addendum does not apply where Reqursor is the controller. Reqursor is the controller for the account, billing and usage data it uses to provide and bill Reqursor Platform, as described in the Reqursor Privacy Policy. Reqursor Development has its own Data Processing Agreement, which is not part of this Addendum.

In the event of any conflict between this Addendum and the Agreement in respect of the processing of personal data, this Addendum prevails. Capitalized terms not defined in this Addendum have the meaning given to them in the Agreement.

1. Definitions

Terms used but not defined in this Addendum have the meaning given to them in the GDPR. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", "Supervisory Authority" and "Special Categories of Personal Data" have the meanings given to them in Article 4 and Article 9 of the GDPR. "Applicable Data Protection Law" means the GDPR and any national implementing or supplementary laws of the Netherlands, together with any other data protection or privacy laws applicable to the processing of Personal Data under the Agreement. "Customer Personal Data" means the Personal Data that Reqursor processes on behalf of the Controller under this Addendum. "Sub-processor" means a processor that Reqursor engages to process Customer Personal Data. "Standard Contractual Clauses" means the standard contractual clauses of the European Commission for the transfer of personal data to third countries, adopted by Implementing Decision (EU) 2021/914, or any successor clauses. "Services" means Reqursor Platform and the related services provided to the Controller under the Agreement.

2. Roles of the Parties

For the purposes of this Addendum and with respect to the Customer Personal Data, the Controller acts as the controller (or, where the Controller itself acts as a processor for its own clients, as a processor) and Reqursor acts as the processor, or as the Controller's sub-processor in the second case. The Controller determines the purposes and means of the processing and is responsible for having a legal basis for it, for giving the notices that the law requires to the people concerned and for the instructions it gives. If the Controller processes the data for someone else as their processor, it confirms that it is authorized to give these instructions, and Reqursor acts as its sub-processor on the terms of this Addendum. Each party is responsible for complying with the obligations that apply to it under Applicable Data Protection Law.

3. Subject Matter, Duration, Nature and Purpose of Processing

Subject matter. The processing concerns the Personal Data contained in or generated by the online stores that the Controller builds and runs with Reqursor Platform, and the store setup data that Reqursor Platform manages for them (store definitions, design settings, page layouts, managed settings and the history of changes). Store business data. Product catalogs, customer orders, media and store settings that Reqursor Platform does not manage stay in each store's own isolated storage. Reqursor does not access or read this data, except while it moves an existing store to Reqursor Platform: then only with the Controller's explicit consent, read-only and only for as long as the move takes. Duration. Reqursor processes Customer Personal Data for the term of the Agreement and for any further period during which it is required or permitted to keep the data under this Addendum or Applicable Data Protection Law, after which the data is deleted or returned in accordance with Clause 11. Nature and purpose. The nature of the processing includes hosting, running and monitoring online stores, building and deploying changes, isolating each store, storing and deleting data, and, where the Controller uses AI features, sending the store settings needed for a task to the AI provider. The purpose is solely to provide, secure and support the Services in accordance with the Agreement and the Controller's instructions.

4. Categories of Data Subjects and Personal Data

Categories of data subjects. Depending on how the Controller configures and runs its stores, the data subjects may include the shoppers and account holders of those stores, and the Controller's own team members and clients. Categories of personal data. The Personal Data may include identification and contact details (such as name, email address and postal and billing address), order and purchase records, and any other personal data that the Controller or its shoppers put into a store. The Controller decides what that is. AI features. The store settings that Reqursor Platform sends to the AI provider are limited to one organization per request and kept to the minimum needed for the task. Passwords, API keys and other credentials, orders, products and customer records are never included. Special categories. Reqursor Platform is not designed for the processing of Special Categories of Personal Data. The Controller shall not use it for such data unless the parties have agreed otherwise in writing.

5. Instructions and Confidentiality

Reqursor processes Customer Personal Data only on the Controller's documented instructions, including on transfers to a third country, unless Union or Member State law that applies to Reqursor requires otherwise. In that case Reqursor informs the Controller of that legal requirement before the processing, unless that law forbids it on important grounds of public interest. The Agreement, this Addendum and the Controller's use of the Services are the Controller's instructions, including its choice to use AI features, which send store settings to Anthropic. Reqursor informs the Controller without delay if, in its opinion, an instruction infringes Applicable Data Protection Law. Reqursor ensures that the persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality, and limits access to those who need it to provide the Services.

6. Security of Processing (Article 32 GDPR)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons, Reqursor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include:

  • Per-store isolation: each store runs in its own isolated environment, with its own private network and storage. No store can reach another store's data, and no organization can see another organization's stores, settings or status.
  • Encryption of all data in transit with TLS, with certificates for every store and custom domain issued and renewed automatically.
  • Secrets such as passwords and API keys encrypted at rest and never stored in plain text in logs or change history; account passwords stored as a salted hash.
  • Changes confirmed by the Controller before they take effect, checked before they go live, recorded, and reversible to a prior state.
  • Role-based access for the Controller's team members (Admin, Operator, Viewer) and multi-factor authentication where Reqursor Platform asks for it.
  • Hosting in the EU, in data centers in Germany and Finland.
  • Regular review and improvement of these measures as the risks and the technology change.

Reqursor describes its controls in more detail on its public security page. Reqursor does not state controls there or here that it does not operate.

7. Sub-processors

The Controller gives Reqursor a general written authorization to engage the Sub-processors listed in Annex A. Reqursor informs the Controller at least 30 days before it adds or replaces a Sub-processor, by email to the contacts on the Controller's account and by updating Annex A. The Controller keeps those contact addresses up to date, because notices are sent there. The Controller may object to a new Sub-processor on reasonable grounds relating to data protection, by email to [email protected] within 30 days of the notice. If the Controller does not object in time, the change takes effect at the end of the notice period. The parties work together in good faith to find a solution. If they cannot find one, the Controller may stop using the affected Services and cancel by written notice before the change takes effect, and Reqursor then refunds the prepaid fees for the period after the end date, if the Order provides for it. Where practical, Reqursor does not send Customer Personal Data to the new Sub-processor until the parties have discussed the objection. Reqursor has a written agreement with each Sub-processor that imposes data protection obligations meeting article 28(4) of the GDPR, and remains responsible to the Controller for what its Sub-processors do.

Annex A: Sub-processors

  • Anthropic: Purpose: AI provider for AI features, through the Claude API. Receives the store settings needed for a task, limited to one organization per request.; Location: Under its commercial terms with Reqursor; may process data outside the EEA, see Clause 8
  • [hosting provider name to be added]: Purpose: Hosting of Reqursor Platform in EU data centers; Location: Germany (Falkenstein and Nuremberg) and Finland (Helsinki)

Stripe processes payments for Reqursor Platform subscriptions. Reqursor and Stripe act as separate controllers for billing data, and Reqursor does not send Customer Personal Data to Stripe. Stripe is therefore not a Sub-processor under this Addendum, and is named here for transparency.

8. International Transfers

Reqursor is established in the European Union and hosts Reqursor Platform in data centers in Germany and Finland. Reqursor does not transfer Customer Personal Data to a country outside the European Economic Area, or to an international organization, unless the transfer has an appropriate safeguard under Applicable Data Protection Law. Anthropic may process data outside the European Economic Area. For such a transfer, Reqursor relies on an adequacy decision of the European Commission or on the Standard Contractual Clauses for transfers to processors (module 3). If a competent authority or the law that applies to the Controller requires a transfer safeguard for Customer Personal Data that Reqursor returns to the Controller outside the European Economic Area, and no other safeguard applies, the parties conclude the Standard Contractual Clauses that fit that situation, which at the date of this Addendum is module 4 (processor to controller). Reqursor signs them on request, and the parties agree in writing the choices that the clauses leave open before they apply. The clauses prevail over this Addendum where they conflict.

9. Assistance to the Controller

Taking into account the nature of the processing, Reqursor assists the Controller: (a) by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability and objection). Where a data subject sends such a request to Reqursor, Reqursor refers the data subject to the Controller and informs the Controller, unless the law forbids it, and does not respond except on the Controller's documented instructions. Reqursor Platform also lets the Controller export its data in standard formats (JSON and CSV) with the Data Export feature; (b) in ensuring compliance with the Controller's obligations on security of processing, personal data breaches, data protection impact assessments and prior consultation with a Supervisory Authority (articles 32 to 36 of the GDPR), by giving the Controller the information it reasonably needs for those obligations.

10. Personal Data Breach Notification

Reqursor notifies the Controller without undue delay after it becomes aware of a Personal Data Breach that affects Customer Personal Data, including a breach at a Sub-processor, by email to the contacts on the Controller's account. Reqursor states what it knows about the nature of the breach, the data and the people concerned, the likely consequences and the measures it takes, and updates the Controller as it finds out more. The Controller decides whether and how to tell the Supervisory Authority and the people concerned. Reqursor does not notify a Supervisory Authority or data subjects in the Controller's name without the Controller's prior written instruction, except where the law requires it.

11. Retention, Deletion and Return

Reqursor keeps Customer Personal Data in line with the retention periods in its Privacy Policy: store definitions for as long as the organization exists, deployment artifacts for 90 to 365 days depending on their type, audit logs for 365 days and AI interaction logs for 30 days. When the Controller deletes its account, a 7-day grace period starts. During it, stores keep serving traffic but team access is revoked. After the grace period the stores go offline, and all data is permanently purged within 30 days after the grace period ends. Before that, the Controller may export its data with the Data Export feature. On termination or expiry of the Agreement, or earlier on the Controller's written request, Reqursor, at the Controller's choice, returns the Customer Personal Data it still holds or deletes it, and deletes existing copies, unless Union or Member State law requires it to keep them. Reqursor confirms in writing on request that it has done so. Financial records and other data that Reqursor holds as a controller are covered by the Privacy Policy and are not Customer Personal Data.

12. Information and Audits

Reqursor gives the Controller the information it reasonably needs to show that Reqursor meets this Addendum and article 28 of the GDPR. Reqursor first answers the Controller's questions and security questionnaires in writing, if the Controller sends them to [email protected]. If that is not enough, the Controller may have an audit carried out by itself or by an independent auditor bound by confidentiality, once a year, and also whenever a Supervisory Authority requires it or after a Personal Data Breach that affects Customer Personal Data. The Controller gives at least 30 days' notice (less where the authority requires it), the audit takes place during business hours without unreasonable disruption, it does not give access to data of other customers, and it is at the Controller's cost.

13. Liability

The liability limits of the Agreement apply to this Addendum, and one limit applies to the Agreement and this Addendum together. They do not limit the rights of data subjects against either party under article 82 of the GDPR, or any liability that cannot be limited by law. If Standard Contractual Clauses apply under Clause 8, clause 12 of those clauses prevails.

14. Term, Order of Precedence and Governing Law

This Addendum lasts as long as Reqursor processes Customer Personal Data for the Controller. If it conflicts with the Agreement, an order or another agreement on the processing of Personal Data, this Addendum prevails. Reqursor may update this Addendum for a valid reason, such as a change in the law, and informs the Controller 30 days in advance, as the Agreement describes for changes. A change never reduces the protection that article 28 of the GDPR requires and never changes Standard Contractual Clauses that apply. Dutch law applies. The District Court of Rotterdam (Rechtbank Rotterdam) has exclusive jurisdiction, without limiting the rights of data subjects or any mandatory jurisdiction under Applicable Data Protection Law. If a provision of this Addendum is invalid or unenforceable, the other provisions remain in force, and the parties replace the provision with a valid one that comes closest to its intent.

Questions about this Addendum: For questions about this Addendum, to ask for a signed copy or to object to a Sub-processor, contact [email protected] or [email protected].

Data Protection Contact

[email protected] · Reqursor Technologies, Rotterdam, The Netherlands