Skip to content
buyerfly

Data processing agreement

Effective · Version 1.1

This agreement governs the personal data that Buyerfly processes on behalf of a customer when it provides the service.

1. Parties and status

This Data Processing Agreement ("DPA") forms part of the agreement between the customer that accepts the Buyerfly terms of service or an order ("Customer") and Nikolaus Redl, Kleistgasse 18/41, 1030 Vienna, Austria ("Buyerfly"). It takes effect when Customer accepts the agreement or first gives Buyerfly Customer Personal Data.

"Data Protection Law" means the GDPR, the national laws that implement or supplement it, and, where they apply, the UK GDPR and the Swiss Federal Act on Data Protection. Terms such as controller, processor, personal data, processing, and personal data breach have the meaning that the GDPR gives them. "Customer Personal Data" means the personal data that Buyerfly processes on behalf of Customer under the agreement.

Customer is the controller of Customer Personal Data, or a processor for another controller. Buyerfly is the processor or sub-processor of Customer. Buyerfly stays an independent controller for its own account, security, billing, legal, and website data, as the privacy policy describes.

2. Instructions and compliance

Buyerfly processes Customer Personal Data only on the documented instructions of Customer and as necessary to provide, secure, support, and bill the service, unless Union or Member State law requires otherwise. The agreement, this DPA, the settings of Customer, and the requests that the users of Customer make in the app, including chat messages to the AI agent, are documented instructions.

If the law requires processing outside these instructions, Buyerfly tells Customer before the processing, unless the law forbids this. Buyerfly tells Customer promptly if it believes that an instruction infringes Data Protection Law, and it can pause the affected processing until the parties resolve the matter.

Customer is responsible for the lawfulness of its instructions and of the content of its sites, for the notices to its site visitors and other data subjects, and for a legal basis for the personal data that it gives Buyerfly. Customer must not intentionally give Buyerfly special categories of personal data, data about criminal offences, data of children, health data, payment card data, or government identification numbers, unless the parties first agree on appropriate safeguards in writing.

3. Confidentiality and personnel

Buyerfly gives access to Customer Personal Data only to personnel who need it to provide, secure, or support the service. These persons are bound by a statutory or contractual duty of confidentiality and receive appropriate privacy and security instructions.

Buyerfly support staff can sign in to the account of a Customer user only for support, troubleshooting, or abuse checks. The audit log of the workspace records each such session.

4. Security

Buyerfly maintains appropriate technical and organizational measures under Article 32 GDPR. It takes into account the state of the art, the costs of implementation, and the nature, scope, context, purposes, and risks of the processing. Annex II describes the current measures. Buyerfly can update them if the overall security of the service does not decrease materially.

5. Sub-processors

Customer gives Buyerfly general written authorization to use the sub-processors in Annex III. Buyerfly imposes data protection obligations on each sub-processor that give at least the protection that Article 28 GDPR requires for the processing that it performs. Buyerfly stays responsible for the performance of each sub-processor as the law requires.

Buyerfly tells Customer at least 30 days before it adds or replaces a sub-processor that processes Customer Personal Data, by email or in the app. Customer can object within that period on reasonable data protection grounds. The parties then look in good faith for a reasonable alternative. If there is none, Customer can end the affected service before the change takes effect.

Providers that process sign-in or billing data as independent controllers, such as Stripe and Google, are described in the privacy policy. For that processing, they are not sub-processors under this DPA.

6. Assistance and data subject requests

Taking into account the nature of the processing, Buyerfly gives Customer reasonable help, with appropriate technical and organizational measures, to answer requests for access, correction, deletion, restriction, data portability, objection, and information about recipients. If Buyerfly receives such a request about Customer Personal Data, it does not answer for Customer unless Customer authorizes it or the law requires it. Buyerfly forwards the request to Customer when it can identify Customer.

Buyerfly also gives reasonable information and help for the obligations of Customer under Articles 32 to 36 GDPR, including security reviews, breach notifications, data protection impact assessments, and prior consultation, considering the processing and the information available to Buyerfly.

7. Personal data breaches

Buyerfly notifies Customer without undue delay after it becomes aware of a personal data breach that affects Customer Personal Data. As information becomes available, the notice describes the nature of the breach, the affected data and people, the likely consequences, the measures taken or proposed, and a contact for questions. Buyerfly takes reasonable steps to contain, investigate, and reduce the effects of the breach. A notice is not an admission of fault or liability.

8. Return, deletion, and duration

This DPA applies while Buyerfly processes Customer Personal Data. When the agreement ends, or on a verified written request, Buyerfly returns or deletes Customer Personal Data, as Customer chooses, unless the law requires Buyerfly to keep it. Customer can ask for an export of its site files before the agreement ends. Buyerfly normally removes the data from active systems within 30 days. Copies in the backups of providers are deleted in the normal backup cycle. Until then, the data stays protected, and Buyerfly restores it only to recover from a disaster.

Buyerfly stores each media file once, by its content. When several sites use the same file, Buyerfly deletes it after no site uses it any more.

Buyerfly does not store the messages of contact forms. It only sends them by email to the recipient that Customer chose.

9. Information and audits

Buyerfly makes available the information that is reasonably necessary to show compliance with Article 28 GDPR. Customer can audit this compliance once a year and after a substantiated incident. An audit normally starts with current policies, questionnaires, and independent reports. A further remote or on-site audit needs reasonable notice, must protect other customers and confidential information, must not unreasonably disrupt operations, and is at the cost of Customer, unless it finds a material breach by Buyerfly.

10. International transfers

Buyerfly is established in Austria. Its app, its database, and the Sandboxes that run previews and edits are in Frankfurt, Germany. Where Customer Personal Data goes to a country without an adequacy decision, Buyerfly uses a lawful transfer mechanism and appropriate supplementary measures. This includes the requirement that sub-processors use the Standard Contractual Clauses of the European Commission or another valid safeguard.

Where a direct transfer between the parties requires the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, they are incorporated by reference. Module Two applies where Customer is a controller, and Module Three where Customer is a processor. The docking clause applies. Clause 9 uses option 2, general authorization, with the notice period in section 5. The optional language in clause 11 does not apply. Austria is the governing Member State, and the courts of Vienna are selected for clauses 17 and 18. Annex I and Annex II below complete the corresponding annexes of the clauses. The UK Addendum or the Swiss changes apply where required.

11. Liability and precedence

The liability of each party under this DPA is subject to the lawful liability limits of the agreement. If this DPA conflicts with the agreement on the protection of Customer Personal Data, this DPA controls. The Standard Contractual Clauses control over terms that conflict with them. Austrian law governs this DPA, except where mandatory Data Protection Law or the Standard Contractual Clauses require otherwise.

12. Acceptance and contact

The electronic acceptance of the Buyerfly terms, an order that refers to this DPA, or the use of the service to process Customer Personal Data counts as signature by the parties where electronic acceptance is legally effective. Send signed copies or privacy questions to contact@supercenter.app.

Annex I: Details of processing

Data exporter
Customer, with the contact and establishment details in its account or order. Controller or processor, as applicable.
Data importer
Nikolaus Redl (Buyerfly), Kleistgasse 18/41, 1030 Vienna, Austria. Privacy contact: contact@supercenter.app. Processor or sub-processor, as applicable.
Subject matter and purpose
Building, editing, previewing, storing, publishing, and hosting the websites of Customer with an AI agent; storing versions, media files, and chat attachments; sending contact-form messages to Customer; security; troubleshooting; and support.
Nature and frequency
Collection, storage, structuring, change, transmission to AI model providers and other sub-processors, display, publication on the instruction of Customer, email delivery, deletion, and related operations. Continuous during the term of the agreement, whenever Customer uses the service or a visitor uses a site of Customer.
Data subjects
The users and staff of Customer; people whose data Customer puts into its sites, chat messages, attachments, or media files, such as staff, customers, and business partners; visitors of the published sites of Customer; and people who send messages through the contact forms of Customer.
Personal data
Names, contact details, texts, pictures, and other content in sites, chat messages, attachments, and media files; the fields of contact forms as the form of Customer defines them, usually name, email address, and message; IP addresses, browser data, and request data of site visitors; IP addresses in the rate-limit records of contact forms; and preview error logs. No special category of personal data is required.
Duration
The term of the agreement and the deletion period in section 8, subject to documented legal retention duties.
Supervisory authority
The Austrian Data Protection Authority, without prejudice to another authority that is competent under Data Protection Law.

Annex II: Security measures

  • TLS for data in transit. Encryption at rest by the database and storage providers.
  • Sign-in with one-time email codes that are valid for 10 minutes, allow 5 attempts, and are stored only as hashes. Rate limits on sign-in.
  • Sessions in secure, HTTP-only cookies. OAuth tokens encrypted in the database. SCIM tokens stored only as HMAC digests.
  • Role-based workspace permissions (owner, admin, editor, viewer), checked on the server for each request. Database constraints that keep the records of each workspace separate.
  • Site code in private repositories. Site code runs in isolated Vercel Sandboxes for previews and edits, and in its own Vercel project when it is published, never inside the Buyerfly app, which holds the platform keys. A Sandbox can reach only the hosts that its task needs, such as the media store.
  • Private previews that need a signed link, valid for 60 seconds, and then a session cookie that lasts 15 minutes.
  • Chat attachments in a private store. The AI model receives copies of pictures without metadata.
  • Checks on the web requests of the AI agent that block private and internal network addresses, with limits on size, time, and number.
  • Contact forms with origin checks, rate limits, and spam checks, and without storage of the messages.
  • An audit log of workspace changes that database triggers record, including support sessions.
  • Idempotent billing operations, backups by the database provider, and a scheduled job that repairs interrupted work.
  • Review of providers, confidentiality duties, sub-processor management, and procedures for return and deletion.

Annex III: Authorized sub-processors

Vercel

Processing
Hosting of the Buyerfly app and of each published site, serverless functions, the Sandboxes that run previews and AI edits, file storage (Vercel Blob), and AI Gateway, which sends requests to AI models.
Data
Request data such as IP address and browser, account and workspace data, site code and content, media files, chat attachments, and the requests to AI models.
Location
The app, the Sandboxes, and the media store run in Frankfurt, Germany. Vercel delivers published sites through its global network. Vercel Inc. is based in the United States.
Safeguards
Vercel DPA and EU Standard Contractual Clauses.

Neon

Processing
PostgreSQL database.
Data
Account, workspace, sign-in, chat, version, billing, credit, and audit records.
Location
Frankfurt, Germany (AWS eu-central-1). Support can involve other locations.
Safeguards
Neon DPA and EU Standard Contractual Clauses where they apply.

GitHub

Processing
Version history. The code of each site lives in a private repository of our GitHub organization.
Data
Site code, texts, links to media files, and commit messages that start with the text of each chat request.
Location
United States and other GitHub locations.
Safeguards
GitHub Data Protection Agreement, EU-US Data Privacy Framework, and EU Standard Contractual Clauses.

AI model providers, through Vercel AI Gateway

Processing
The AI model that reads each change request and changes the site. The default model today is Claude from Anthropic.
Data
Chat messages, the site files that the agent reads, attachments, screenshots of preview pages, and the text of web pages that the agent loads.
Location
United States and other locations of the model provider.
Safeguards
Vercel's contracts with the model providers and EU Standard Contractual Clauses.

Firecrawl

Processing
Loads a public web page that a user names in the chat, so that the agent can read it.
Data
The address of the page. Firecrawl returns the content of the page.
Location
United States.
Safeguards
Data processing terms and EU Standard Contractual Clauses where they are required.

Resend

Processing
Email delivery: sign-in codes, workspace invites, and the messages of contact forms on published sites.
Data
Recipient address, email content, and delivery records.
Location
United States and Resend sub-processor locations.
Safeguards
Resend DPA and EU Standard Contractual Clauses.