Data Processing Agreement
Our GDPR Article 28 commitments for business customers who entrust personal data to SafeCart.
Last updated: June 2026
GDPR Article 28
For Business Customers
When you use SafeCart to process personal data, you are the data controller and SafeCart is your processor. This agreement describes how we protect that data on your behalf. Need a countersigned copy? Email [email protected].
1. Background and Scope
This Data Processing Agreement ("DPA") forms part of the agreement between SafeCart ("Processor," "we," or "us") and the customer subscribing to our services ("Controller," "Customer," or "you") for the provision of SafeCart's product safety monitoring and compliance services (the "Services").
This DPA reflects the parties' agreement regarding the processing of personal data carried out by SafeCart on behalf of the Customer, in accordance with Article 28 of the General Data Protection Regulation ("GDPR").
Where the Customer processes the personal data of EU/EEA data subjects through the Services, the Customer acts as the Controller and SafeCart acts as the Processor.
2. Definitions
Capitalised terms used in this DPA have the meaning given to them in the GDPR. In particular:
• "Personal Data" means any information relating to an identified or identifiable natural person processed under the Services.
• "Processing" means any operation performed on Personal Data.
• "Data Subject" means the individual to whom Personal Data relates.
• "Subprocessor" means any third party engaged by SafeCart to process Personal Data on the Customer's behalf.
• "Supervisory Authority" means the competent data protection authority.
3. Roles and Responsibilities
The Customer is the Controller and determines the purposes and means of processing Personal Data through the Services. SafeCart is the Processor and processes Personal Data only on the documented instructions of the Customer, including as set out in this DPA and the main agreement.
The Customer is responsible for ensuring that it has a valid legal basis for the processing and for the accuracy and lawfulness of the Personal Data it provides. SafeCart will inform the Customer if, in its opinion, an instruction infringes applicable data protection law.
4. Subject Matter and Details of Processing
Subject matter: Provision of product safety monitoring and compliance services, including matching the Customer's product catalogue against the EU Safety Gate database and delivering alerts.
Duration: For the term of the main agreement, plus any retention period set out below.
Nature and purpose: Hosting, storing, and analysing product and account data to deliver safety alerts, compliance tooling, notifications, and support.
Categories of Data Subjects: The Customer's authorised users and account administrators.
Categories of Personal Data: Account holder name and email address, company details, authentication data, support communications, and usage data. Product catalogue data (such as product names and GTIN/barcodes) is generally not personal data but is processed as Customer content.
SafeCart does not require, and the Customer should not upload, special categories of personal data through the Services.
5. Processor Obligations
SafeCart shall:
• Process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required by EU or Member State law.
• Ensure that persons authorised to process Personal Data are bound by confidentiality.
• Implement appropriate technical and organisational measures as described in Annex II.
• Respect the conditions for engaging Subprocessors set out below.
• Assist the Customer, taking into account the nature of the processing, in responding to Data Subject requests.
• Assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments).
• At the Customer's choice, delete or return all Personal Data at the end of the provision of Services, and delete existing copies unless storage is required by law.
• Make available to the Customer information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits.
6. Subprocessors
The Customer provides general authorisation for SafeCart to engage the Subprocessors listed in Annex III to process Personal Data in connection with the Services.
SafeCart shall:
• Impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, by way of a written contract.
• Remain fully liable to the Customer for the performance of each Subprocessor's obligations.
• Inform the Customer of any intended addition or replacement of a Subprocessor, giving the Customer the opportunity to object on reasonable data protection grounds.
7. International Data Transfers
SafeCart processes Personal Data primarily within the European Union and European Economic Area.
Where a transfer of Personal Data to a country outside the EU/EEA is necessary (for example, when a Subprocessor processes data outside the EEA), SafeCart ensures that an appropriate transfer mechanism is in place, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with any additional safeguards identified through a transfer impact assessment.
8. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, SafeCart implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II.
These measures include encryption of data in transit and at rest, strict access controls, row-level security on all data tables, continuous monitoring, and regular review of effectiveness.
9. Personal Data Breaches
SafeCart shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer's Personal Data. The notification will, to the extent available, describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
SafeCart will reasonably assist the Customer in meeting its own breach notification obligations to Supervisory Authorities and affected Data Subjects.
10. Data Subject Requests
Taking into account the nature of the processing, SafeCart will assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligation to respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, and objection).
If SafeCart receives a request directly from a Data Subject relating to the Customer's data, it will, where legally permitted, refer the request to the Customer rather than respond directly.
11. Return and Deletion of Data
Upon termination or expiry of the Services, and at the Customer's choice, SafeCart will delete or return all Personal Data processed on behalf of the Customer and delete existing copies, unless EU or Member State law requires continued storage.
Following account deletion, Personal Data is removed in line with the retention periods described in our Privacy Policy. Backups containing Personal Data are deleted on a rolling cycle.
12. Audits
SafeCart will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior notice, and subject to confidentiality obligations, SafeCart will contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
Where available, SafeCart may satisfy audit requests by providing relevant certifications, reports, or documentation describing its security measures and those of its Subprocessors.
13. Liability and Term
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the main agreement. This DPA takes effect on the date the Customer accepts the main agreement and remains in force for as long as SafeCart processes Personal Data on the Customer's behalf.
In the event of any conflict between this DPA and the main agreement regarding the processing of Personal Data, this DPA prevails.
Annex I — Description of Processing
Controller: The Customer subscribing to the Services.
Processor: SafeCart.
Subject matter and duration: As set out in Section 4 and for the term of the main agreement.
Nature and purpose of processing: Hosting, storage, analysis, and transmission of account and product data to deliver product safety monitoring, alerts, and compliance tooling.
Types of Personal Data: Names, email addresses, company information, authentication data, support communications, and usage data.
Categories of Data Subjects: The Customer's authorised users and administrators.
Annex II — Technical and Organisational Security Measures
• Encryption of Personal Data in transit (TLS) and at rest.
• Row-Level Security (RLS) enforced on all database tables so that each tenant can access only its own data.
• Authentication and access controls, including secure password handling and session management.
• Input sanitisation and protection against common web vulnerabilities (including XSS).
• Continuous error and security monitoring, with alerting on anomalous activity.
• Least-privilege access for personnel on a need-to-know basis.
• Logging and audit trails for security-relevant events.
• Regular review and updating of security measures.
• Documented incident response procedures.
Annex III — Authorised Subprocessors
SafeCart engages the following Subprocessors to provide the Services:
• Supabase — Database, authentication, real-time services, edge functions, and hosting infrastructure (EU region).
• Stripe — Payment and subscription processing for paid plans.
• Sentry — Application error tracking and performance monitoring.
• Google (Generative AI / Gemini) — AI-assisted compliance analysis features.
• Cloudflare — Web application hosting and content delivery.
• Email delivery provider — Transactional and notification emails via SMTP.
Each Subprocessor is bound by a written contract imposing data protection obligations consistent with this DPA. The current list is maintained here and updated as Subprocessors change.
How to Sign This DPA
This page sets out SafeCart's standard Data Processing Agreement. Business customers who require a countersigned copy for their records can request one from [email protected], and we will provide an executable version.
By subscribing to and using the Services, the Customer accepts the terms of this DPA where SafeCart acts as a Processor of Personal Data on the Customer's behalf.
Need a Signed DPA?
Our team can provide an executable copy for your compliance records
Request a Signed DPA