Data processing agreement
Effective · Version 1.1
This agreement governs the personal data that Buyerfly processes on behalf of a customer when it provides the service.
1. Parties and status
This Data Processing Agreement ("DPA") forms part of the agreement between the customer that accepts the Buyerfly terms of service or an order ("Customer") and Nikolaus Redl, Kleistgasse 18/41, 1030 Vienna, Austria ("Buyerfly"). It takes effect when Customer accepts the agreement or first gives Buyerfly Customer Personal Data.
"Data Protection Law" means the GDPR, the national laws that implement or supplement it, and, where they apply, the UK GDPR and the Swiss Federal Act on Data Protection. Terms such as controller, processor, personal data, processing, and personal data breach have the meaning that the GDPR gives them. "Customer Personal Data" means the personal data that Buyerfly processes on behalf of Customer under the agreement.
Customer is the controller of Customer Personal Data, or a processor for another controller. Buyerfly is the processor or sub-processor of Customer. Buyerfly stays an independent controller for its own account, security, billing, legal, and website data, as the privacy policy describes.
2. Instructions and compliance
Buyerfly processes Customer Personal Data only on the documented instructions of Customer and as necessary to provide, secure, support, and bill the service, unless Union or Member State law requires otherwise. The agreement, this DPA, the settings of Customer, and the requests that the users of Customer make in the app, including chat messages to the AI agent, are documented instructions.
If the law requires processing outside these instructions, Buyerfly tells Customer before the processing, unless the law forbids this. Buyerfly tells Customer promptly if it believes that an instruction infringes Data Protection Law, and it can pause the affected processing until the parties resolve the matter.
Customer is responsible for the lawfulness of its instructions and of the content of its sites, for the notices to its site visitors and other data subjects, and for a legal basis for the personal data that it gives Buyerfly. Customer must not intentionally give Buyerfly special categories of personal data, data about criminal offences, data of children, health data, payment card data, or government identification numbers, unless the parties first agree on appropriate safeguards in writing.
3. Confidentiality and personnel
Buyerfly gives access to Customer Personal Data only to personnel who need it to provide, secure, or support the service. These persons are bound by a statutory or contractual duty of confidentiality and receive appropriate privacy and security instructions.
Buyerfly support staff can sign in to the account of a Customer user only for support, troubleshooting, or abuse checks. The audit log of the workspace records each such session.
4. Security
Buyerfly maintains appropriate technical and organizational measures under Article 32 GDPR. It takes into account the state of the art, the costs of implementation, and the nature, scope, context, purposes, and risks of the processing. Annex II describes the current measures. Buyerfly can update them if the overall security of the service does not decrease materially.
5. Sub-processors
Customer gives Buyerfly general written authorization to use the sub-processors in Annex III. Buyerfly imposes data protection obligations on each sub-processor that give at least the protection that Article 28 GDPR requires for the processing that it performs. Buyerfly stays responsible for the performance of each sub-processor as the law requires.
Buyerfly tells Customer at least 30 days before it adds or replaces a sub-processor that processes Customer Personal Data, by email or in the app. Customer can object within that period on reasonable data protection grounds. The parties then look in good faith for a reasonable alternative. If there is none, Customer can end the affected service before the change takes effect.
Providers that process sign-in or billing data as independent controllers, such as Stripe and Google, are described in the privacy policy. For that processing, they are not sub-processors under this DPA.
6. Assistance and data subject requests
Taking into account the nature of the processing, Buyerfly gives Customer reasonable help, with appropriate technical and organizational measures, to answer requests for access, correction, deletion, restriction, data portability, objection, and information about recipients. If Buyerfly receives such a request about Customer Personal Data, it does not answer for Customer unless Customer authorizes it or the law requires it. Buyerfly forwards the request to Customer when it can identify Customer.
Buyerfly also gives reasonable information and help for the obligations of Customer under Articles 32 to 36 GDPR, including security reviews, breach notifications, data protection impact assessments, and prior consultation, considering the processing and the information available to Buyerfly.
7. Personal data breaches
Buyerfly notifies Customer without undue delay after it becomes aware of a personal data breach that affects Customer Personal Data. As information becomes available, the notice describes the nature of the breach, the affected data and people, the likely consequences, the measures taken or proposed, and a contact for questions. Buyerfly takes reasonable steps to contain, investigate, and reduce the effects of the breach. A notice is not an admission of fault or liability.
8. Return, deletion, and duration
This DPA applies while Buyerfly processes Customer Personal Data. When the agreement ends, or on a verified written request, Buyerfly returns or deletes Customer Personal Data, as Customer chooses, unless the law requires Buyerfly to keep it. Customer can ask for an export of its site files before the agreement ends. Buyerfly normally removes the data from active systems within 30 days. Copies in the backups of providers are deleted in the normal backup cycle. Until then, the data stays protected, and Buyerfly restores it only to recover from a disaster.
Buyerfly stores each media file once, by its content. When several sites use the same file, Buyerfly deletes it after no site uses it any more.
Buyerfly does not store the messages of contact forms. It only sends them by email to the recipient that Customer chose.
9. Information and audits
Buyerfly makes available the information that is reasonably necessary to show compliance with Article 28 GDPR. Customer can audit this compliance once a year and after a substantiated incident. An audit normally starts with current policies, questionnaires, and independent reports. A further remote or on-site audit needs reasonable notice, must protect other customers and confidential information, must not unreasonably disrupt operations, and is at the cost of Customer, unless it finds a material breach by Buyerfly.
10. International transfers
Buyerfly is established in Austria. Its app, its database, and the Sandboxes that run previews and edits are in Frankfurt, Germany. Where Customer Personal Data goes to a country without an adequacy decision, Buyerfly uses a lawful transfer mechanism and appropriate supplementary measures. This includes the requirement that sub-processors use the Standard Contractual Clauses of the European Commission or another valid safeguard.
Where a direct transfer between the parties requires the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, they are incorporated by reference. Module Two applies where Customer is a controller, and Module Three where Customer is a processor. The docking clause applies. Clause 9 uses option 2, general authorization, with the notice period in section 5. The optional language in clause 11 does not apply. Austria is the governing Member State, and the courts of Vienna are selected for clauses 17 and 18. Annex I and Annex II below complete the corresponding annexes of the clauses. The UK Addendum or the Swiss changes apply where required.
11. Liability and precedence
The liability of each party under this DPA is subject to the lawful liability limits of the agreement. If this DPA conflicts with the agreement on the protection of Customer Personal Data, this DPA controls. The Standard Contractual Clauses control over terms that conflict with them. Austrian law governs this DPA, except where mandatory Data Protection Law or the Standard Contractual Clauses require otherwise.
12. Acceptance and contact
The electronic acceptance of the Buyerfly terms, an order that refers to this DPA, or the use of the service to process Customer Personal Data counts as signature by the parties where electronic acceptance is legally effective. Send signed copies or privacy questions to contact@supercenter.app.
Annex I: Details of processing
- Data exporter
- Customer, with the contact and establishment details in its account or order. Controller or processor, as applicable.
- Data importer
- Nikolaus Redl (Buyerfly), Kleistgasse 18/41, 1030 Vienna, Austria. Privacy contact: contact@supercenter.app. Processor or sub-processor, as applicable.
- Subject matter and purpose
- Building, editing, previewing, storing, publishing, and hosting the websites of Customer with an AI agent; storing versions, media files, and chat attachments; sending contact-form messages to Customer; security; troubleshooting; and support.
- Nature and frequency
- Collection, storage, structuring, change, transmission to AI model providers and other sub-processors, display, publication on the instruction of Customer, email delivery, deletion, and related operations. Continuous during the term of the agreement, whenever Customer uses the service or a visitor uses a site of Customer.
- Data subjects
- The users and staff of Customer; people whose data Customer puts into its sites, chat messages, attachments, or media files, such as staff, customers, and business partners; visitors of the published sites of Customer; and people who send messages through the contact forms of Customer.
- Personal data
- Names, contact details, texts, pictures, and other content in sites, chat messages, attachments, and media files; the fields of contact forms as the form of Customer defines them, usually name, email address, and message; IP addresses, browser data, and request data of site visitors; IP addresses in the rate-limit records of contact forms; and preview error logs. No special category of personal data is required.
- Duration
- The term of the agreement and the deletion period in section 8, subject to documented legal retention duties.
- Supervisory authority
- The Austrian Data Protection Authority, without prejudice to another authority that is competent under Data Protection Law.
Annex II: Security measures
- TLS for data in transit. Encryption at rest by the database and storage providers.
- Sign-in with one-time email codes that are valid for 10 minutes, allow 5 attempts, and are stored only as hashes. Rate limits on sign-in.
- Sessions in secure, HTTP-only cookies. OAuth tokens encrypted in the database. SCIM tokens stored only as HMAC digests.
- Role-based workspace permissions (owner, admin, editor, viewer), checked on the server for each request. Database constraints that keep the records of each workspace separate.
- Site code in private repositories. Site code runs in isolated Vercel Sandboxes for previews and edits, and in its own Vercel project when it is published, never inside the Buyerfly app, which holds the platform keys. A Sandbox can reach only the hosts that its task needs, such as the media store.
- Private previews that need a signed link, valid for 60 seconds, and then a session cookie that lasts 15 minutes.
- Chat attachments in a private store. The AI model receives copies of pictures without metadata.
- Checks on the web requests of the AI agent that block private and internal network addresses, with limits on size, time, and number.
- Contact forms with origin checks, rate limits, and spam checks, and without storage of the messages.
- An audit log of workspace changes that database triggers record, including support sessions.
- Idempotent billing operations, backups by the database provider, and a scheduled job that repairs interrupted work.
- Review of providers, confidentiality duties, sub-processor management, and procedures for return and deletion.
Annex III: Authorized sub-processors
Vercel
- Processing
- Hosting of the Buyerfly app and of each published site, serverless functions, the Sandboxes that run previews and AI edits, file storage (Vercel Blob), and AI Gateway, which sends requests to AI models.
- Data
- Request data such as IP address and browser, account and workspace data, site code and content, media files, chat attachments, and the requests to AI models.
- Location
- The app, the Sandboxes, and the media store run in Frankfurt, Germany. Vercel delivers published sites through its global network. Vercel Inc. is based in the United States.
- Safeguards
- Vercel DPA and EU Standard Contractual Clauses.
Neon
- Processing
- PostgreSQL database.
- Data
- Account, workspace, sign-in, chat, version, billing, credit, and audit records.
- Location
- Frankfurt, Germany (AWS eu-central-1). Support can involve other locations.
- Safeguards
- Neon DPA and EU Standard Contractual Clauses where they apply.
GitHub
- Processing
- Version history. The code of each site lives in a private repository of our GitHub organization.
- Data
- Site code, texts, links to media files, and commit messages that start with the text of each chat request.
- Location
- United States and other GitHub locations.
- Safeguards
- GitHub Data Protection Agreement, EU-US Data Privacy Framework, and EU Standard Contractual Clauses.
AI model providers, through Vercel AI Gateway
- Processing
- The AI model that reads each change request and changes the site. The default model today is Claude from Anthropic.
- Data
- Chat messages, the site files that the agent reads, attachments, screenshots of preview pages, and the text of web pages that the agent loads.
- Location
- United States and other locations of the model provider.
- Safeguards
- Vercel's contracts with the model providers and EU Standard Contractual Clauses.
Firecrawl
- Processing
- Loads a public web page that a user names in the chat, so that the agent can read it.
- Data
- The address of the page. Firecrawl returns the content of the page.
- Location
- United States.
- Safeguards
- Data processing terms and EU Standard Contractual Clauses where they are required.
Resend
- Processing
- Email delivery: sign-in codes, workspace invites, and the messages of contact forms on published sites.
- Data
- Recipient address, email content, and delivery records.
- Location
- United States and Resend sub-processor locations.
- Safeguards
- Resend DPA and EU Standard Contractual Clauses.