Data Processing Agreement

Last updated August 20, 2026

This agreement governs our processing of personal data contained in the stores you host with us. It forms part of the Terms of Service and applies automatically from the moment you open an account — there is nothing to sign. If your procurement process requires a countersigned copy, write to [email protected] and we will provide one.

Roles

You are the controller of the personal data in your store: your shoppers' details, your staff's accounts, anything your extensions collect. You decide why and how it is processed.

We are the processor. We process that data only to provide the service, and only on your documented instructions — which are these terms, the settings you choose in the dashboard, and the commands you run.

Development Orest Oliinyk, a sole trader registered in Poland (jednoosobowa działalność gospodarcza), of ul. Towarowa 12/407, 35-231 Rzeszów, woj. podkarpackie, Poland, NIP 5170374110, is the processor.

If we ever believe an instruction breaches data protection law, we will tell you and may decline to act on it.

Subject matter and duration

The subject matter is the hosting and deployment of your store. Processing lasts as long as your account exists, plus the retention periods below.

Annex I — What is processed

Categories of data subject: your shoppers and prospective shoppers; your staff and contractors who use the store's admin; anyone whose data your store or extensions collect.

Categories of personal data: names, email addresses, telephone numbers, billing and delivery addresses, order and payment history (we do not receive card numbers), account credentials as stored by Magento, customer support correspondence held in the store, and IP addresses and user agents recorded in web server logs.

Special category data: none is expected. Do not use Nautvia to process special category or criminal-offence data without agreeing additional measures with us in writing.

How your store's data reaches us

Being precise about this matters more than being reassuring:

  • The database. Your Magento database runs on a server we provision for you. We hold credentials capable of reading it, because provisioning, backups and restores require them.
  • Backups. Your database server dumps itself and uploads the result straight to object storage using a short-lived signed URL. The dump contains everything in your database.
  • Media. Product images and other pub/media files stay on a block volume attached to your server. We create, mount and resize that volume; we do not read its contents.
  • Logs. When you view logs in the dashboard we read them live over SSH from your server and cache them for five seconds. Web server logs contain shopper IP addresses and the pages they requested.
  • Commands. When you run a command from the dashboard, its output is stored with the record of that command. If a command prints personal data, that data is stored — see the retention table.

Annex II — Security measures

  • Each team's servers sit in their own private network, with provider firewalls that expose only the ports the role requires.
  • Access to your servers is by SSH key. Passwords are not accepted for shell access.
  • Traffic to your store is served over TLS, with certificates issued and renewed automatically.
  • Secrets we hold for you are encrypted at rest: the platform SSH private key, your database passwords, your Magento encryption key and admin password, your environment variables, your deploy-webhook secrets, and your source-control tokens.
  • Database dumps are transferred through signed URLs that expire in hours, not days.
  • Platform access is limited to the operator named above and protected by two-factor authentication.
  • Deploys are atomic and reversible, which limits the blast radius of a bad release.

We will review and improve these measures as the service grows, without reducing the level of protection.

Sub-processors

You authorise the sub-processors listed in the Privacy Policy, which sets out what each one receives. That list is the current one; if we add or replace a sub-processor we will announce it by email at least 30 days beforehand. If you object on reasonable data-protection grounds, tell us within those 30 days and we will work with you to find an alternative; if we cannot, you may terminate the affected service without penalty.

Each sub-processor is bound by written terms no less protective than these.

Confidentiality

Anyone with access to your data is bound by confidentiality obligations that survive the end of this agreement.

Assisting you

Taking into account the nature of the processing, we will help you:

  • respond to requests from data subjects — although in most cases you can serve these yourself from your own store's admin;
  • carry out data protection impact assessments and prior consultations;
  • meet your own security and breach-notification duties.

Personal data breaches

If we become aware of a breach affecting your data we will notify you without undue delay, with what we know: what happened, which data and roughly how many people are affected, the likely consequences, and what we are doing about it. Where the picture is incomplete we will send what we have and follow up rather than wait.

Reporting to a supervisory authority and to affected individuals is your responsibility as controller.

International transfers

Your store's servers and backups are held in Germany. Some sub-processors operate outside the European Economic Area; those transfers rely on the European Commission's Standard Contractual Clauses.

Return and deletion

At the end of the service you may export your data at any time: download your database backups from the dashboard, and copy your media from the server before tearing it down.

Deleting your account removes our account records. It does not by itself destroy the servers, volumes and backups held at our infrastructure provider — those are destroyed when you tear down your environments, or on written request to [email protected], which we will complete within 30 days and confirm. Backups age out on the schedule your plan provides.

We keep no copy beyond that, except where law requires it.

Audits

We will make available the information needed to show we meet Article 28, and will answer reasonable written questions about our processing. Where that is not enough for you, we will agree an audit with reasonable notice, no more than once a year unless a regulator or a breach requires otherwise, at your cost and without disruption to other customers.

Liability and precedence

Liability under this agreement is subject to the limits in the Terms of Service. Where this agreement and the terms conflict on data protection, this agreement prevails.