Data Processing Agreement
Last updated August 20, 2026
This agreement governs our processing of personal data contained in the stores you host with us. It forms part of the Terms of Service and applies automatically from the moment you open an account — there is nothing to sign. If your procurement process requires a countersigned copy, write to [email protected] and we will provide one.
Roles
You are the controller of the personal data in your store: your shoppers' details, your staff's accounts, anything your extensions collect. You decide why and how it is processed.
We are the processor. We process that data only to provide the service, and only on your documented instructions — which are these terms, the settings you choose in the dashboard, and the commands you run.
Development Orest Oliinyk, a sole trader registered in Poland (jednoosobowa działalność gospodarcza), of ul. Towarowa 12/407, 35-231 Rzeszów, woj. podkarpackie, Poland, NIP 5170374110, is the processor.
If we ever believe an instruction breaches data protection law, we will tell you and may decline to act on it.
Subject matter and duration
The subject matter is the hosting and deployment of your store. Processing lasts as long as your account exists, plus the retention periods below.
Annex I — What is processed
Categories of data subject: your shoppers and prospective shoppers; your staff and contractors who use the store's admin; anyone whose data your store or extensions collect.
Categories of personal data: names, email addresses, telephone numbers, billing and delivery addresses, order and payment history (we do not receive card numbers), account credentials as stored by Magento, customer support correspondence held in the store, and IP addresses and user agents recorded in web server logs.
Special category data: none is expected. Do not use Nautvia to process special category or criminal-offence data without agreeing additional measures with us in writing.
How your store's data reaches us
Being precise about this matters more than being reassuring:
- The database. Your Magento database runs on a server we provision for you. We hold credentials capable of reading it, because provisioning, backups and restores require them.
- Backups. Your database server dumps itself and uploads the result straight to object storage using a short-lived signed URL. The dump contains everything in your database.
- Media. Product images and other
pub/mediafiles stay on a block volume attached to your server. We create, mount and resize that volume; we do not read its contents. - Logs. When you view logs in the dashboard we read them live over SSH from your server and cache them for five seconds. Web server logs contain shopper IP addresses and the pages they requested.
- Commands. When you run a command from the dashboard, its output is stored with the record of that command. If a command prints personal data, that data is stored — see the retention table.
Annex II — Security measures
- Each team's servers sit in their own private network, with provider firewalls that expose only the ports the role requires.
- Access to your servers is by SSH key. Passwords are not accepted for shell access.
- Traffic to your store is served over TLS, with certificates issued and renewed automatically.
- Secrets we hold for you are encrypted at rest: the platform SSH private key, your database passwords, your Magento encryption key and admin password, your environment variables, your deploy-webhook secrets, and your source-control tokens.
- Database dumps are transferred through signed URLs that expire in hours, not days.
- Platform access is limited to the operator named above and protected by two-factor authentication.
- Deploys are atomic and reversible, which limits the blast radius of a bad release.
We will review and improve these measures as the service grows, without reducing the level of protection.
Sub-processors
You authorise the sub-processors listed in the Privacy Policy, which sets out what each one receives. That list is the current one; if we add or replace a sub-processor we will announce it by email at least 30 days beforehand. If you object on reasonable data-protection grounds, tell us within those 30 days and we will work with you to find an alternative; if we cannot, you may terminate the affected service without penalty.
Each sub-processor is bound by written terms no less protective than these.
Confidentiality
Anyone with access to your data is bound by confidentiality obligations that survive the end of this agreement.
Assisting you
Taking into account the nature of the processing, we will help you:
- respond to requests from data subjects — although in most cases you can serve these yourself from your own store's admin;
- carry out data protection impact assessments and prior consultations;
- meet your own security and breach-notification duties.
Personal data breaches
If we become aware of a breach affecting your data we will notify you without undue delay, with what we know: what happened, which data and roughly how many people are affected, the likely consequences, and what we are doing about it. Where the picture is incomplete we will send what we have and follow up rather than wait.
Reporting to a supervisory authority and to affected individuals is your responsibility as controller.
International transfers
Your store's servers and backups are held in Germany. Some sub-processors operate outside the European Economic Area; those transfers rely on the European Commission's Standard Contractual Clauses.
Return and deletion
At the end of the service you may export your data at any time: download your database backups from the dashboard, and copy your media from the server before tearing it down.
Deleting your account removes our account records. It does not by itself destroy the servers, volumes and backups held at our infrastructure provider — those are destroyed when you tear down your environments, or on written request to [email protected], which we will complete within 30 days and confirm. Backups age out on the schedule your plan provides.
We keep no copy beyond that, except where law requires it.
Audits
We will make available the information needed to show we meet Article 28, and will answer reasonable written questions about our processing. Where that is not enough for you, we will agree an audit with reasonable notice, no more than once a year unless a regulator or a breach requires otherwise, at your cost and without disruption to other customers.
Liability and precedence
Liability under this agreement is subject to the limits in the Terms of Service. Where this agreement and the terms conflict on data protection, this agreement prevails.