Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Lumexus GmbH and the customer using OdooSync. It applies where OdooSync processes personal data on the customer's behalf, and takes effect automatically when the customer accepts the Terms — no signature is required.
1. Roles of the parties
The customer is the controller and determines the purposes and means of processing. Lumexus GmbH (“OdooSync”) is the processor and processes personal data only on the customer's documented instructions. Using the service — configuring which records sync, and running syncs — constitutes those instructions.
This DPA is governed by Art. 28 GDPR and by Art. 9 of the Swiss Federal Act on Data Protection (revDSG), whichever applies to the customer.
2. Subject matter and duration
The subject matter is the synchronisation of product, inventory, order, and customer records between the customer's Odoo instance and their WooCommerce store. Processing lasts for the term of the subscription, plus the deletion period in section 9.
3. Nature of the data
Categories of data subjects: the customer's own end customers, and the customer's personnel who hold OdooSync accounts.
Categories of personal data: names, email addresses, postal and billing addresses, telephone numbers, and order details transmitted between the two systems; and for account holders, name, email address, and company name.
OdooSync is not designed for special categories of personal data under Art. 9 GDPR, and the customer must not configure it to sync such data.
4. Obligations of the processor
- Process personal data only on the customer's documented instructions, including for transfers, unless required otherwise by law — in which case we inform the customer first, unless that law prohibits it.
- Ensure that everyone authorised to process the data is bound by confidentiality.
- Implement the technical and organisational measures described in section 5.
- Assist the customer, so far as reasonably possible, in responding to data subject requests and in meeting its obligations under Art. 32–36 GDPR.
- Make available the information needed to demonstrate compliance with this DPA.
5. Security measures
- All data in transit is encrypted with TLS; data at rest is encrypted by the hosting provider.
- API keys are stored only as SHA-256 hashes — the plaintext key is shown once at creation and never retained.
- Each API key is pinned to the first domain that uses it, and is rate limited per minute.
- Database access is enforced by row-level security, so a customer's records are reachable only by that customer.
- Privileged operations run through authenticated server-side functions, never from the browser.
- Every API call is logged with its outcome, source domain, and timestamp, and retained for audit.
6. Subprocessors
The customer gives general authorisation for the subprocessors listed at odoo-sync.io/subprocessors. We impose data protection obligations on each of them no less protective than those in this DPA, and remain fully liable for their performance.
We will give at least 30 days' notice before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the customer may terminate the affected subscription without penalty.
7. International transfers
Customer data is hosted in Zurich, Switzerland. Where a subprocessor processes personal data outside Switzerland or the EEA, the transfer relies on the European Commission's Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC, or on an applicable adequacy decision.
8. Personal data breaches
We will notify the customer without undue delay after becoming aware of a personal data breach affecting their data. The notification will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed.
9. Deletion and return
On termination, the customer may request an export of their data, which we provide in a machine-readable format within 30 days. We delete personal data processed on the customer's behalf within 30 days of termination, except where retention is required by law — for example, invoices retained under Swiss accounting rules.
10. Audits
On reasonable written request, and no more than once per year unless required by a supervisory authority, we will provide the information necessary to demonstrate compliance with this DPA. Where the customer reasonably requires an on-site audit, the parties will agree scope and timing in advance, and the customer bears its own costs.
11. Contact
Data protection enquiries, data subject requests, and audit requests: info@odoo-sync.io. Postal address is on our Impressum.
If your organisation requires a countersigned copy of this DPA, or your own DPA template, email us and we will arrange it.