Data Processing Addendum
Last updated: [TBD] · This is a working draft pending legal review.
This Data Processing Addendum ("DPA") forms part of the Coded Terms of Service or other written agreement between Coded B.V. ("Coded", "we", "us") and the customer that has accepted those terms ("Customer", "you") (together, the "Agreement"). It governs Coded's processing of personal data on the Customer's behalf in connection with the Coded commerce platform and related services (the "Services").
Coded B.V. is a private limited company incorporated in the Netherlands (a subsidiary of Coded Holding B.V.), registered with the Netherlands Chamber of Commerce under number 42027097, VAT number NL869368795B01, with its registered office at De Taling 15, 2761 SL Zevenhuizen, The Netherlands. Coded operates internationally and serves merchants worldwide.
Where the Customer acts as a controller of personal data and Coded processes that data on the Customer's instructions, Coded acts as a processor. This DPA sets out the terms on which Coded processes such data. In the event of a conflict between this DPA and the rest of the Agreement on a data protection matter, this DPA prevails. This DPA takes effect on 11 June 2026 or, if later, on the date the Customer accepts the Agreement.
1. Definitions
Capitalised terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.
- Data Protection Law means all laws and regulations applicable to the processing of Personal Data under this DPA, including: (a) the EU General Data Protection Regulation 2016/679 ("GDPR") and the Dutch GDPR Implementation Act (Uitvoeringswet AVG); (b) the UK GDPR and the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection; (d) US state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and comparable laws of other US states; and (e) any other data protection or privacy law applicable to a party's processing of Personal Data, in each case as amended or replaced over time.
- Personal Data means any information relating to an identified or identifiable natural person (or, where a US state law applies, "personal information" relating to a consumer or household) that Coded processes on the Customer's behalf under the Agreement ("Customer Personal Data").
- Processing, controller, processor, data subject, personal data breach, and supervisory authority have the meanings given in the GDPR; equivalent terms under other Data Protection Law (including "business", "service provider", "consumer", and "sale/share" under CCPA/CPRA) are construed accordingly.
- Sub-processor means any third party engaged by Coded to process Customer Personal Data on Coded's behalf.
- Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.
- End User means a natural person whose Personal Data is processed through the Services, including the Customer's authorised users, buyers/customers of the Customer's projects, and visitors to those projects.
2. Roles of the Parties
2.1 Customer as controller; Coded as processor. For Customer Personal Data processed under the Agreement, the Customer is the controller and Coded is the processor. Where the Customer itself acts as a processor for a third-party controller, Coded acts as a sub-processor, and the Customer warrants that it has the authority and instructions necessary for Coded to process the data as set out in this DPA.
2.2 Coded as controller for limited purposes. Coded acts as an independent controller for a limited set of data it processes for its own purposes — for example, account administration, billing and tax records, security and fraud prevention, product analytics conducted on a privacy-by-design, cookieless basis, and compliance with its own legal obligations. That processing is governed by the Coded Privacy Policy, not by this DPA.
2.3 Payments. Payment processing on the Services is carried out by Stripe and Mollie. In respect of cardholder and payment-account data that those providers collect and process to provide regulated payment services, the relevant payment provider acts as an independent controller (or processor for the Customer) under its own terms. Coded does not store full card numbers and is not in the regulated card-data path for those flows. Coded charges no platform fee on the Customer's payment transactions; the Customer pays only the pass-through processing cost charged by Stripe or Mollie.
2.4 Customer responsibilities. The Customer is responsible for: (a) ensuring it has a valid legal basis and any required notices and consents for the Personal Data it routes through the Services; (b) the accuracy, quality and legality of Customer Personal Data and the means by which it was acquired; and (c) handling and responding to communications from data subjects and authorities, except as this DPA expressly provides for Coded's assistance.
3. Scope and Details of Processing
The subject-matter, duration, nature, purpose, types of data, and categories of data subjects are described below and, where required by Data Protection Law, in Annex I.
3.1 Subject-matter and duration
The subject-matter of the processing is Coded's provision of the Services to the Customer. Processing continues for the term of the Agreement and for any additional period during which Coded processes Customer Personal Data on the Customer's behalf, after which Section 11 (Return and Deletion) applies.
3.2 Nature and purpose
Coded processes Customer Personal Data to host, operate, secure, support, and provide the Services — including running the Customer's projects (such as branded online shops), maintaining the product catalog, enabling orders and built-in fulfilment, facilitating built-in payments through Stripe and Mollie, providing analytics and account features, and providing technical support.
3.3 Types of Personal Data
Depending on how the Customer configures and uses the Services, Customer Personal Data may include: identification and contact details (name, email, telephone, billing and shipping address); account and authentication data; order, transaction, and fulfilment data; customer-service and communications content; device, log, and limited technical data; and any other Personal Data the Customer chooses to submit through the Services. The Customer must not submit special categories of Personal Data (Article 9 GDPR) or government-identifier data except as agreed in writing, and remains responsible for any such data it submits.
3.4 Categories of data subjects
End Users, including the Customer's authorised users and staff, and the buyers, customers, and visitors of the Customer's projects.
4. Customer Instructions
4.1 Coded processes Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law (or other applicable law) to which Coded is subject; in that case, Coded informs the Customer of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.
4.2 The Agreement, this DPA, the Customer's configuration and use of the Services through their features and documented settings, and any further written instructions agreed by the parties together constitute the Customer's complete and final processing instructions. Processing outside that scope requires a written agreement between the parties.
4.3 Coded informs the Customer if, in its opinion, an instruction infringes Data Protection Law. Coded may decline an instruction that it reasonably considers unlawful, without liability for the resulting non-performance.
5. Processor Obligations
Coded undertakes to:
5.1 Confidentiality. Ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and are made aware of the confidential nature of the data.
5.2 Security. Implement and maintain the technical and organisational measures described in Annex II, appropriate to the risk, in accordance with Section 8.
5.3 Sub-processors. Engage Sub-processors only in accordance with Section 6.
5.4 Data subject requests. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligation to respond to requests from data subjects exercising their rights under Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection, and equivalent rights under US state law such as the right to know, delete, correct, and opt out). Where Coded receives such a request directly, it will, unless legally prohibited, promptly inform the requester to contact the Customer and notify the Customer.
5.5 Assistance with compliance. Taking into account the nature of processing and the information available to Coded, assist the Customer in ensuring compliance with its obligations regarding security of processing, personal data breach notification, data protection impact assessments, and prior consultation with supervisory authorities (Articles 32–36 GDPR and equivalents).
5.6 Records. Maintain records of processing activities carried out on behalf of the Customer to the extent required by Article 30(2) GDPR.
5.7 No sale or unauthorised use. Coded does not sell or share Customer Personal Data (as "sell" and "share" are defined under CCPA/CPRA and comparable laws), and does not retain, use, or disclose Customer Personal Data for any purpose other than performing the Services, or as otherwise permitted by Data Protection Law. Coded does not combine Customer Personal Data with data from other sources except as permitted by Data Protection Law to provide the Services. Coded does not use Customer Personal Data for cross-context behavioural advertising.
6. Sub-processors
6.1 General authorisation. The Customer provides a general written authorisation for Coded to engage Sub-processors to process Customer Personal Data, subject to this Section 6.
6.2 Current Sub-processors. Coded's current Sub-processors — including infrastructure, payment, communication, and support providers — are listed in the Coded Subprocessors document, referenced in the Agreement and available at coded.co/legal/subprocessors. The list identifies each Sub-processor, the processing it performs, and its location.
6.3 Obligations flow-down. Coded imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, including appropriate security measures. Where a Sub-processor fails to fulfil its data protection obligations, Coded remains liable to the Customer for the performance of that Sub-processor's obligations.
6.4 Notice of changes and objection. Coded gives the Customer reasonable prior notice (by updating the Subprocessors document and/or by a reasonable notification mechanism) before adding or replacing a Sub-processor. The Customer may object on reasonable, documented data protection grounds within a defined notice period (target: 30 days). The parties will work in good faith to resolve the objection; if they cannot, the Customer may, as its sole remedy, terminate the affected portion of the Services in accordance with the Agreement.
7. International Transfers
7.1 Hosting location. Coded hosts production Customer Personal Data on infrastructure located in the European Union (Frankfurt, Germany). This is a deliberate privacy-by-design feature of the platform.
7.2 Transfer mechanism. Where Coded or a Sub-processor transfers Customer Personal Data originating in the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the transfer is governed by an appropriate safeguard under Chapter V GDPR (and equivalent UK/Swiss rules), in the following order of preference: (a) an adequacy decision where one applies; otherwise (b) the Standard Contractual Clauses, which are incorporated into this DPA by reference and completed as set out in Section 7.3; and (c) any supplementary measures identified by a transfer impact assessment as necessary to ensure an essentially equivalent level of protection.
7.3 SCC operation. Where the SCCs apply:
-
For transfers from Coded (as processor) to the Customer's onward parties or where Coded exports to a Sub-processor, Module Two (controller-to-processor) or Module Three (processor-to-processor) applies as relevant to the role of each party.
-
The optional docking clause (Clause 7) applies; the general authorisation option in Clause 9(a) applies, with the notice period stated in Section 6.4; the option in Clause 11(a) regarding independent dispute resolution does not apply.
-
For the purposes of Clause 17, the SCCs are governed by the law of the Netherlands; for the purposes of Clause 18, disputes are resolved before the courts of Amsterdam, the Netherlands.
-
Annex I (description of transfer), Annex II (technical and organisational measures), and Annex III (list of Sub-processors) to the SCCs are populated by, respectively, Section 3 and Annex I of this DPA, Annex II of this DPA, and the Subprocessors document.
-
The UK International Data Transfer Addendum (issued under section 119A of the UK Data Protection Act 2018) applies to UK transfers, and the SCCs are adapted to Swiss law for Swiss transfers, in each case completed by reference to the same Annexes.
7.4 Transfer impact assessment. Coded will, on reasonable request and to the extent it holds relevant information, assist the Customer in carrying out a transfer impact assessment.
8. Security Measures
8.1 Coded implements and maintains appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk to data subjects. The current measures are described in Annex II.
8.2 Coded may update its security measures from time to time, provided the updates do not materially reduce the overall level of protection.
8.3 Coded does not currently claim any specific third-party security certification (such as SOC 2, ISO 27001, or PCI-DSS Level 1) under this DPA, and the Customer should not rely on the existence of any such certification unless Coded confirms it in writing.
<!-- confirm certification status before publication -->9. Personal Data Breach
9.1 Coded notifies the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.
9.2 The notification will include, to the extent then known and to the extent Coded is reasonably able to provide it: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Where information is not available at the time of the initial notification, Coded provides it in phases as it becomes available.
9.3 Coded takes reasonable steps to contain and remediate the breach and reasonably cooperates with the Customer. The Customer is responsible for any notifications it is required to make to supervisory authorities or data subjects; Coded's notification under this Section is not an acknowledgement of fault or liability.
10. Audit and Information Rights
10.1 Coded makes available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, and contributes to audits and inspections conducted by the Customer or an auditor mandated by the Customer.
10.2 To satisfy audit requests, Coded may, in the first instance, provide documentation such as summaries of its security measures, relevant policies, and any third-party reports or attestations it holds. Where that documentation does not reasonably satisfy the Customer's audit right, the Customer may conduct an on-site audit subject to: reasonable prior written notice (target: at least 30 days); conduct during business hours; no more than once per twelve (12) month period (save where required by a supervisory authority or following a personal data breach); appropriate confidentiality undertakings; and reasonable measures to avoid disruption to Coded's operations or other customers' data. The Customer bears its own audit costs.
11. Return and Deletion of Personal Data
11.1 On termination or expiry of the Agreement, and on the Customer's written request, Coded will — at the Customer's choice — return Customer Personal Data to the Customer and/or delete it, and delete existing copies, unless Data Protection Law or other applicable law requires continued storage.
11.2 Coded will complete deletion within a reasonable period after the end of the applicable post-termination retention window (target: 30 days, after which export self-service may no longer be available), subject to routine backup cycles. Customer Personal Data residing in encrypted backups is deleted in accordance with Coded's backup rotation schedule and is protected from active processing until deleted.
11.3 Coded may retain Customer Personal Data to the extent required by applicable law, in which case Coded continues to protect it in accordance with this DPA and processes it only as necessary for the purpose of the legal retention.
12. Liability, Term, and General
12.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
12.2 This DPA takes effect on the date stated in the introduction and continues for as long as Coded processes Customer Personal Data on the Customer's behalf. Sections that by their nature should survive termination (including Sections 11 and 12) survive.
12.3 Governing law and jurisdiction. This DPA is governed by the law of the Netherlands, and the courts of Amsterdam have exclusive jurisdiction over disputes arising out of or in connection with it, without prejudice to (a) the operation of the SCCs' own governing-law and jurisdiction clauses where they apply, and (b) any mandatory consumer-protection or data-protection law of a data subject's or Customer's jurisdiction that applies regardless of this choice of law.
12.4 If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force, and the parties replace the affected provision with a valid provision that most closely reflects its intent.
12.5 Except as modified by this DPA, the Agreement remains in full force and effect.
Annex I — Description of Processing
This Annex completes the description required by the SCCs and Article 28 GDPR.
- Data exporter: the Customer (controller), identified in the Agreement.
- Data importer: Coded B.V. (processor), De Taling 15, 2761 SL Zevenhuizen, The Netherlands, KvK 42027097.
- Subject-matter, nature, and purpose of processing: as described in Section 3.1–3.2 — provision of the Coded commerce platform and related Services.
- Categories of data subjects: as described in Section 3.4.
- Categories of Personal Data: as described in Section 3.3.
- Special categories of data: none, unless separately agreed in writing.
- Frequency of transfer: continuous, for the duration of the Agreement.
- Duration / retention: for the term of the Agreement and the post-termination period in Section 11.
- Sub-processors: as listed in the Subprocessors document.
- Competent supervisory authority (for SCC purposes): the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), without prejudice to the competence of another authority where the Customer establishes a different lead supervisory authority. <!-- confirm appropriate competent supervisory authority -->
Annex II — Technical and Organisational Security Measures
Coded maintains measures including, as applicable to the Services:
- Encryption. Encryption of Customer Personal Data in transit (TLS) and at rest.
- Access control. Role-based access control, least-privilege provisioning, unique credentials, multi-factor authentication for privileged access, and prompt revocation of access on role change or departure.
- Hosting and isolation. Production data hosted on infrastructure in the European Union (Frankfurt, Germany), with logical tenant isolation between organizations.
- Network and application security. Edge protection (web application firewall, DDoS mitigation, bot management), hardened configurations, and secure software-development practices including code review and dependency/secret scanning.
- Logging and monitoring. Audit logging of privileged and administrative actions, security monitoring, and alerting, with personal-data minimisation in logs.
- Resilience and backups. Regular encrypted backups, redundancy across availability zones, and documented restoration procedures.
- Pseudonymisation and minimisation. Data minimisation by design, and pseudonymisation where appropriate.
- Vendor management. Security assessment of Sub-processors and contractual flow-down of data protection obligations.
- Personnel. Confidentiality undertakings and security awareness for personnel with access to Customer Personal Data.
- Incident response. A documented incident-response process supporting the breach-notification commitments in Section 9.
- Deletion. Secure deletion processes consistent with Section 11.
Annex III — Sub-processors
The current list of Sub-processors, their processing roles, and locations is maintained in the Coded Subprocessors document at coded.co/legal/subprocessors, which forms part of this DPA.
Contact
Questions about this DPA or Coded's processing of Personal Data can be directed to:
- Data protection / privacy: privacy@coded.eu
- Legal: legal@coded.eu
- Security and breach reports: security@coded.co
Coded B.V., De Taling 15, 2761 SL Zevenhuizen, The Netherlands · KvK 42027097 · VAT NL869368795B01
<!-- OPEN ITEMS FOR COUNSEL: - Confirm whether Coded has appointed (or must appoint) a Data Protection Officer and/or an Art. 27 EU/UK representative, and add contact details if so. - Confirm the correct SCC module mapping for each real data-flow (C2P vs P2P) and whether Coded is ever a data exporter vs importer; verify the docking clause and Clause 9/11/17/18 selections. - Confirm UK IDTA vs UK Addendum to the EU SCCs choice, and the Swiss adaptation wording (FDPIC, references to FADP, "data subject" extension to legal persons). - Verify Section 2.3 payments characterisation against the actual Stripe and Mollie contractual roles (controller vs processor vs sub-processor) and PCI scope; confirm Coded is genuinely out of the regulated card-data path. - Confirm whether the 72-hour breach-notification commitment in Section 9.1 should be tightened (e.g., "within 48 hours" / "without undue delay") for enterprise customers. - Confirm the sub-processor objection window (Section 6.4), post-termination retention/deletion window (Section 11.2), and audit cadence/notice (Section 10.2) against operational reality. - Confirm CCPA/CPRA service-provider language is complete (purpose limitation, no-sale/no-share certification, deletion on direction) and whether other US state laws (VA, CO, CT, etc.) need their own contractor terms. - Confirm the competent supervisory authority statement in Annex I and the certification disclaimer in Section 8.3. - Verify Annex II reflects only controls actually in place; remove or qualify anything not yet implemented. - Confirm execution model: click-through acceptance vs signed addendum, and how this DPA is incorporated into the Terms. -->