Data Processing Agreement (Art. 28 GDPR)

Version 1.0 · Effective: 21 July 2026

Parties:
(1) Golden Inventory (Serhii Korsunenko), Berlin, Germany — "Processor"
(2) The Customer using the Golden Inventory service at inventory-system.com as a registered organization — "Controller"

This DPA is incorporated into the Golden Inventory Terms of Service and applies when the Controller creates an organization account and enters personal data into the service. By using the service, the Controller accepts this DPA.

1. Subject matter and duration

The Processor will process personal data on behalf of the Controller for the purpose of providing the Golden Inventory inventory-management SaaS. Processing begins when the Controller creates an organization and enters data, and ends upon deletion of the Controller's organization or termination of the service agreement, whichever is later. The Processor will delete or return all personal data within 30 days after termination, except where EU or Member State law requires continued storage (see §147 AO / GoBD for invoice data — such data is retained in restricted form for 10 years, with party names anonymized per section 7).

2. Nature and purpose of processing

The Processor provides a multi-tenant, cloud-hosted inventory management application. Processing consists of: storing, retrieving, indexing, searching, aggregating, converting (document type conversions), exporting (PDF, CSV, XLSX), and transmitting (email delivery of documents, webhook forwarding, e-commerce synchronization) the Controller's business data as instructed through the application's user interface and API.

3. Types of personal data

The Controller determines which personal data to enter. The service supports the following categories:

Data excluded from this DPA (not personal data under GDPR): item master records, SKUs, barcodes, stock quantities, bill-of-material structures, tax code definitions, and any data the Controller has fully anonymized before entry.

4. Categories of data subjects

As determined by the Controller, data subjects may include: the Controller's customers, vendors/suppliers, employees, subcontractors, service technicians, waitstaff, and other natural persons whose data the Controller enters into the service.

5. Technical and organizational measures (TOMs)

The Processor implements and maintains the following measures, appropriate to the risk (Art. 32 GDPR):

AreaMeasure
Encryption in transitTLS 1.3, HSTS, secure cookies (HttpOnly; Secure; SameSite=Lax)
Encryption at restBackups encrypted client-side (AES-256-CBC) before transmission; database files on encrypted volumes (Hetzner default)
Access controlJWT-based authentication with role-based authorization (owner/admin/manager/cashier/waiter/kitchen); all tenant queries filtered by org_id at the database layer
Password storagebcrypt hashing (no plaintext, no reversible encryption)
Network isolationPostgreSQL on internal Docker network, no public port; application is the sole database client
Rate limitingSlowAPI rate limits on authentication endpoints (registration, login, password reset) per client IP
Audit trailImmutable billing webhook event log (GumroadWebhookEvent); inv_audit_log for admin actions
Backup & restoreDaily incremental + weekly full database backups with 30-day rolling retention; monthly restore tests
Logging & monitoringAccess logs retained 14 days (nginx) / 30 days (app); UptimeRobot health-check monitoring
Patch managementOS and dependency updates applied within 7 days of release (critical: 48 hours)
Data isolationMulti-tenant architecture with per-org data partitioning; no cross-tenant queries possible without explicit org-scoping

6. Sub-processors

The Controller authorizes the following sub-processors. The Processor will inform the Controller of any intended addition or replacement at least 14 days before the change, giving the Controller the opportunity to object on reasonable data-protection grounds. If the objection cannot be resolved, the Controller may terminate the service with 30 days' notice without penalty.

Sub-processorServiceLocationAdequacy mechanism
Hetzner Online GmbHInfrastructure (VPS, block storage, Storage Box)EU (DE/FI)Art. 45 — within EU
Scaleway / OVHSecondary backup storage (restic target)EU (FR)Art. 45 — within EU
nocdirect (Josef)SMTP relay for transactional emailUS (TX)Art. 46(2)(c) — Standard Contractual Clauses (hosting provider's DPA)
Gumroad, Inc.Payment processing, subscription managementUSArt. 46(2)(c) — Standard Contractual Clauses (Gumroad DPA); only email + license key + payment amounts shared

No tenant business data (documents, parties, stock) is transferred to sub-processors outside the EU.

7. Assistance with data subject rights

The Processor will, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Articles 15–21 GDPR. The Controller directs such requests to support@inventory-system.com. The Processor will:

8. Breach notification

The Processor will notify the Controller without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting the Controller's tenant data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. The Processor will cooperate with the Controller's own breach-notification obligations under Art. 33/34 GDPR.

9. Deletion and return of data

Upon termination of the service agreement, the Processor will:

10. Audit rights

The Controller may, no more than once per calendar year and with 30 days' written notice, request evidence of compliance with this DPA. The Processor will provide:

On-site audits require mutual agreement on scope, timing, and cost (borne by the Controller) and are limited to business hours. The Processor may redact confidential information not relevant to the Controller's data.

11. Processor's own staff

The Processor ensures that all personnel authorized to process the Controller's personal data are bound by confidentiality obligations (employment contracts or standalone NDAs) and have received data-protection training appropriate to their role.

12. Liability

Liability under this DPA follows the liability provisions of the Terms of Service and Art. 82 GDPR. The Processor is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed at processors or acted outside or contrary to the Controller's lawful instructions.

13. Governing law & jurisdiction

This DPA is governed by the law of the Federal Republic of Germany. The courts of Berlin, Germany, have jurisdiction. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails for data-protection matters.

Processor — Golden Inventory
Serhii Korsunenko, Berlin
support@inventory-system.com
Controller — Customer
Accepted by creating an organization account
and using the Golden Inventory service.