United Kingdom

Data Processing Agreement

How Comrc processes your customers' personal data on your behalf, under Article 28 of the UK GDPR.

Operated by:
Raversys LTD
Last updated:
25 September 2026

1. Who this agreement is between

This Data Processing Agreement ("DPA") is between you, the merchant who runs a store on Comrc ("you", the controller), and Raversys LTD (Companies House registration number 16528284), trading as Comrc, of Portland House, Belmont Business Park, Belmont, Durham, DH1 1TW, United Kingdom ("we", the processor).

It forms part of, and is accepted together with, our Terms of Service. It applies whenever we process personal data on your behalf in providing the Comrc platform to you. Where this DPA and the Terms conflict on the protection of personal data, this DPA prevails. Read the Terms of Service.

Terms such as "controller", "processor", "personal data", "data subject", "personal data breach" and "processing" have the meanings given in the UK GDPR and the Data Protection Act 2018.

2. Subject matter, duration, nature and purpose

  • Subject matter: the personal data of your store's shoppers that we host and process so your online store, ordering, payments, fulfilment and customer communications work.
  • Duration: for as long as you use the platform, and afterwards only for the deletion period in section 9.
  • Nature: collecting through your storefront and apps, storing, organising, retrieving, displaying to you and your staff, transmitting (for example order emails and notifications), and deleting.
  • Purpose: to provide the platform to you under the Terms and your instructions — taking and fulfilling orders, sending the order and account messages your store sends, and giving you the tools to run your store. We do not use your shoppers' personal data for our own purposes, and we never sell it.

3. Types of personal data and data subjects

Data subjects: the shoppers and diners who visit, create an account with, or order from your store, and anyone they name as a recipient.

  • Shopper contact details: name, email address and phone number
  • Delivery and billing addresses, and collection details
  • Order history: items, prices, totals, discounts and gift-card use, order status, delivery and tracking information, returns, and the notes a shopper adds to an order (which can include information they choose to share, such as an allergy)
  • Account data where a shopper creates an account: login details (passwords are stored only as hashes), saved addresses, loyalty points and reviews
  • Communications: the order and account emails your store sends and their delivery status
  • Technical data: IP addresses and device information in security logs

Card details are entered directly into Stripe's hosted checkout and never reach our servers.

4. Your instructions

We process your shoppers' personal data only on your documented instructions. Those instructions are the Terms, this DPA, and the choices you make in your store's settings and console. We will not process it for any other purpose unless the law requires us to — in which case we will tell you first, unless the law forbids that.

If we believe an instruction breaks data protection law we will tell you promptly and may decline to follow it.

You are responsible for having a lawful basis for the processing, for telling your shoppers about it (your store's privacy notice), and for the lawfulness of your instructions.

5. Confidentiality

Everyone we authorise to process your shoppers' personal data is bound by a duty of confidentiality, whether contractual or statutory, and has access only as far as their role requires.

6. Security

We maintain technical and organisational measures appropriate to the risk, as Article 32 of the UK GDPR requires. They include:

  • Encryption in transit (HTTPS/TLS) for every connection to the platform
  • Payment and platform credentials stored encrypted, and card data kept out of our systems entirely
  • Strict separation between stores, so one merchant's data can never be read through another's
  • Role-based access for your team and ours, with two-factor sign-in available
  • Nightly backups that are verified, and monitoring of the platform's health and errors on our own servers
  • Keeping our software and dependencies up to date, and reviewing changes that touch personal data

7. Sub-processors

You give us general written authorisation to use the sub-processors listed below. We impose on each of them data protection obligations that are no less protective than this DPA, and we remain liable to you for their performance.

  • IONOS — our hosting provider; hosts the platform's servers, database and backups
  • Stripe — processes shoppers' card payments through Stripe Connect when your store takes cards
  • Google Firebase (Cloud Messaging) — delivers new-order push notifications to your team's merchant app

Order and account emails are sent from our own servers, and our error tracking and uptime monitoring are self-hosted, so no further third party receives your shoppers' data. A delivery carrier you connect (such as DHL or DPD) receives shipping details under your own contract with that carrier.

We will tell you at least 30 days before we add or replace a sub-processor, by email to your account address and in your console. You may object on reasonable data protection grounds by writing to privacy@comrc.app; if we can't resolve the objection, you may end the affected service before the change takes effect.

8. Assistance and personal data breaches

Taking into account the nature of the processing, we help you respond to your shoppers' requests to exercise their rights — your console lets you find, export and delete a shopper's data, and we will pass on any request we receive directly and assist you with it.

We also help you meet your obligations on security, personal data breach notification, data protection impact assessments and prior consultation with the regulator, using the information available to us.

If we become aware of a personal data breach affecting your shoppers' data, we will notify you without undue delay. Our notice will describe, as far as we then know, the nature of the breach, the categories and approximate numbers of people and records concerned, its likely consequences, and the measures taken or proposed — and we will follow up as we learn more.

9. Deletion or return at the end

When you close your store you can export your orders and customer data from your console first. After the service ends we delete your shoppers' personal data within 30 days, unless the law requires us to keep some of it, in which case we keep it only for that purpose and protect it under this DPA. Copies in our backups are overwritten on their normal rotation.

10. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and this DPA, and allow for and contribute to audits, including inspections, by you or an auditor you appoint. Please give us at least 30 days' notice; audits are limited to once a year unless required by a regulator or following a personal data breach, take place in business hours, and are subject to confidentiality. Requests go to privacy@comrc.app.

11. International transfers

Where a sub-processor processes your shoppers' personal data outside the UK, we make sure the transfer is covered by UK adequacy regulations or by appropriate safeguards such as the UK International Data Transfer Agreement or Addendum.

12. Governing law and contact

This DPA is governed by the laws of England and Wales, and the the courts of England and Wales have jurisdiction, as set out in the Terms. The supervisory authority is the Information Commissioner's Office (ICO).

Questions about this DPA: privacy@comrc.app. Raversys LTD — Portland House, Belmont Business Park, Belmont, Durham, DH1 1TW, United Kingdom.

We use essential cookies to run this site, and analytics cookies to understand how it's used — only if you allow them. Privacy & cookies.