Annex 3 to the Terms of Service for the Axon service – an agreement within the meaning of Article 28(3) GDPR, concluded upon acceptance of the Terms.
This is an English translation provided for convenience. In case of any discrepancy between language versions, the Polish version prevails. Read the binding Polish version →
Annex 3 to the Terms of Service for the Axon service.
The Agreement is concluded between:
the Controller – the Customer whose identification details were provided in the Panel when adding the Store,
and
the Processor – CREHLER Sp. z o.o. with its registered office in Zielona Góra, ul. Generała Władysława Sikorskiego 4/120, 65-454 Zielona Góra, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court in Zielona Góra, 8th Commercial Division of the National Court Register, under KRS number: 0000589243, share capital PLN 48,000.00, NIP: 9731024669, REGON: 363109359.
The Agreement is concluded upon acceptance of the Terms and forms an integral part thereof. Separate signing of the document is not required; at the Controller's request, the Processor shall sign a copy with a qualified electronic signature.
The Agreement fulfils the obligation under Article 28(3) of Regulation (EU) 2016/679 (GDPR). Terms not defined herein have the meaning given to them in the GDPR and in the Terms.
§ 1. Subject matter and scope of entrustment
- The Controller entrusts the Processor with the processing of personal data to the extent and for the purpose necessary to provide the Axon Service.
- The detailed scope – the subject matter, duration, nature and purpose of processing, the type of data and the categories of persons – is set out in Annex A.
- The Processor processes data only on documented instructions from the Controller. The Terms, this Agreement, the Service documentation and actions taken by the Controller and its users in the Service are deemed to be such instructions.
- If an obligation to process arises from Union or Member State law, the Processor shall inform the Controller thereof before processing, unless that law prohibits such information.
- The Processor shall immediately inform the Controller if, in its opinion, an instruction given infringes the GDPR or other data protection provisions.
§ 2. Service architecture and scope of processing
This provision describes the factual situation relevant to assessing the scope of processing. It may not be interpreted as limiting the obligations arising from the GDPR.
- The Axon application runs in the browser of the Controller's user and connects directly to the Controller's Shopware instance. Business data does not pass through the Processor's infrastructure and is not stored or cached in it.
- User authentication is performed by the Controller's Shopware instance, on the basis of credentials assigned by the Controller. The Processor neither receives nor stores the passwords of the Controller's users.
- Interface settings of individual users are saved in the Controller's Shopware instance.
- The Processor's infrastructure stores only the Store configuration: the Shopware instance address, technical name, any custom domain, the sales channel API access key and appearance settings.
- In accordance with the Shopware architecture, the sales channel API access key is public in integrations using the Store API and does not constitute an independent credential granting access to the personal data of the Controller's customers.
- Personal data is also processed in the local cache on the devices of the Controller's users, to the extent described in the Service documentation. The customer data cache is deleted upon logout.
- The scope of the Processor's actual access to the Controller's personal data is limited to the situations described in § 3(10) – handling support requests and remedying failures, where the Controller itself provides such data.
§ 3. Obligations of the Processor
The Processor undertakes to:
- process data only for the purpose and to the extent specified in the Agreement;
- ensure that persons authorised to process data have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and grant authorisations to the minimum extent and revoke them immediately once the need ceases;
- apply technical and organisational measures ensuring a level of security appropriate to the risk, described in Annex B, and keep them up to date;
- respect the conditions for engaging another processor set out in § 5;
- not introduce changes to the application that would result in the transmission of the Controller's business data to the Processor's infrastructure or to third parties, without informing the Controller 30 days in advance and enabling it to terminate the agreement on the terms set out in § 5(4);
- insofar as possible, assist the Controller, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR;
- assist the Controller in fulfilling its obligations under Articles 32–36 GDPR, taking into account the nature of processing and the information available;
- after the end of the provision of the Service, deal with the data in accordance with § 8;
- make available to the Controller the information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allow audits on the terms set out in § 7;
- access the Controller's personal data only when necessary to handle a support request or remedy a failure, to the extent indicated by the Controller, and delete such data immediately after the matter is closed;
- maintain a record of categories of processing activities carried out on behalf of the Controller, in accordance with Article 30(2) GDPR.
§ 4. Obligations of the Controller
- The Controller represents that it is the controller of the entrusted data or is authorised to entrust it, and that it has a legal basis for processing.
- The Controller is responsible for fulfilling information obligations towards data subjects, including its own employees using the Service and business customers.
- The Controller is responsible for the configuration of permissions in Shopware, for the scope of permissions of the sales channel from which the access key originates, and for granting and revoking users' access.
- The Controller is responsible for the security of its own Shopware instance, including installing security patches without undue delay. The parties acknowledge that the personal data to which the Service relates is located in that instance, and securing it remains outside the Processor's control.
- The Controller undertakes not to introduce into the Service special categories of data within the meaning of Article 9 GDPR or data relating to criminal convictions and offences. The Service is not designed to process such data.
- The Controller undertakes not to provide personal data in support requests to an extent broader than necessary to examine the matter.
§ 5. Sub-processing
- The Controller gives general authorisation for the Processor to engage the sub-processors listed in Annex C.
- The Processor shall inform the Controller of any intended change concerning the addition or replacement of a sub-processor at least 30 days in advance, to the email address assigned to the Account and by publication in Annex C.
- The Controller may raise a reasoned objection within 14 days of receiving the information. The objection must indicate a specific risk to data protection.
- In the event of an objection, the parties shall make a good-faith attempt to agree on a solution. If they do not reach agreement within 30 days, the Controller may terminate the agreement for the provision of the Service with effect from the date of the planned change, without incurring costs and without the obligation to pay for the period after that date.
- The Processor imposes on sub-processors data protection obligations corresponding to the obligations under this Agreement and is liable to the Controller for their performance of those obligations as for its own actions.
§ 6. Personal data breaches
- The Processor shall notify the Controller of any personal data breach concerning the entrusted data without undue delay, no later than within 24 hours of becoming aware of it.
- The notification shall contain at least: a description of the nature of the breach, the categories and approximate number of persons and records concerned, a description of the likely consequences, a description of the measures taken or proposed to address the breach, and the details of the contact point.
- If full information is not available immediately, the Processor shall provide it in phases, without undue delay.
- Notification to the supervisory authority and communication to data subjects are the responsibility of the Controller. The Processor shall provide the necessary assistance in this respect.
- The Processor maintains internal documentation of breaches and makes it available to the Controller upon request, to the extent relating to its data.
- The parties acknowledge that breaches concerning the Controller's Shopware instance remain beyond the Processor's ability to detect, and handling them is the responsibility of the Controller.
§ 7. Audit
- The Controller has the right to verify the manner in which the Agreement is performed, including by means of an audit, carried out in person or by an authorised auditor who is not a competitor of the Processor.
- An audit requires notice given 14 days in advance, takes place on working days, during working hours, no more than once per calendar year, and may not disrupt the Processor's business or infringe the rights of other customers.
- The limitations in § 7(2) do not apply where a personal data breach concerning the Controller's data has been identified or where an audit is requested by a supervisory authority.
- Auditors are bound by confidentiality; the Processor may make admission to the audit conditional on the signing of a confidentiality agreement.
- The Processor may, in the first instance, present current certificates, reports from audits by independent entities or a completed security questionnaire. If these documents do not resolve the Controller's doubts, an on-site audit may not be refused.
- The Controller bears its own costs of the audit. If the audit reveals a material breach of the Agreement by the Processor, the costs are borne by the Processor.
§ 8. End of processing
- After the end of the provision of the Service, the Processor shall, at the choice of the Controller, return the data or delete it together with existing copies.
- The absence of a decision by the Controller within 30 days of the end of the provision of the Service constitutes an instruction to delete.
- The sales channel API access key is deleted without delay, no later than within 7 days of termination of the agreement or deletion of the Store, regardless of the decision under § 8(1).
- Local data caches on users' devices are deleted upon logout and upon loss of access to the Store.
- The Controller's business data remains in its Shopware instance and is not subject to return or deletion by the Processor, as it was never located in the Processor's infrastructure.
- The Processor may retain data only to the extent and for the period required by Union or Member State law, in particular tax and accounting regulations. Such data remains protected on the terms of this Agreement and is not processed for any other purpose.
- At the Controller's request, the Processor confirms the deletion of data by means of a statement.
§ 9. Transfers outside the EEA
- Data covered by this Agreement is processed in Poland, in the OVH data centre in Warsaw.
- A transfer outside the EEA is permissible only where a basis under Chapter V GDPR is ensured – an adequacy decision or standard contractual clauses together with a transfer impact assessment and supplementary safeguards – and after informing the Controller on the terms set out in § 5.
§ 10. Liability
- Each party is liable for damage caused by processing that infringes the GDPR on the terms set out in Article 82 GDPR.
- The limitations of liability provided for in the Terms do not apply to liability towards data subjects or to administrative fines imposed on a party due to a breach of obligations by the other party.
- In relations between the parties, a party which has paid full compensation has the right of recourse against the other party for the part corresponding to the other party's responsibility for the damage.
§ 11. Final provisions
- The Agreement remains in force for the term of the agreement for the provision of the Service and for the period necessary to perform the obligations under § 8.
- The Agreement is amended in the procedure applicable to amendments to the Terms. Amendments resulting from changes in legislation or from guidelines of supervisory authorities enter into force within the time limit resulting from those provisions.
- In matters not regulated herein, the GDPR, the Personal Data Protection Act and the Civil Code apply.
- Annexes A, B and C form an integral part of the Agreement.
Annex A – Scope and nature of processing
A.1 Subject matter and duration
Subject matter: processing of personal data to the extent necessary to make available to the Controller the Axon sales application, constituting a presentation layer on top of the Controller's Shopware instance.
Duration: the term of the agreement for the provision of the Service, extended by the period specified in § 8.
A.2 Nature and purpose of processing
Provision of an application enabling the preparation of quotes, placing orders on behalf of business customers, issuing invoices, browsing the catalogue and the history of cooperation; storage of the configuration of the connection with the Store; caching data on the user's device; handling support requests.
A.3 Delineation of layers
Relevant to assessing the scope and the measures applied.
| Layer | Where it takes place | Who has access |
|---|
| Business data: quotes, orders, invoices, customers, products | The Controller's Shopware instance | The Controller; the Processor has no access |
| Presentation of and work on data | The browser of the Controller's user | The Controller's user |
| Local cache | The device of the Controller's user | The Controller's user |
| User interface settings | The Controller's Shopware instance | The Controller |
| Store configuration | The Processor's infrastructure, OVH Warsaw | The Processor |
| Support requests | The Processor's infrastructure | The Processor, to the extent provided by the Controller |
A.4 Categories of data subjects
- Users of the Controller – sales representatives and system administrators
- Business customers of the Controller who are natural persons, and persons representing customers that are legal persons
- Employees of the Controller's business customers holding accounts within the B2B features
- Contact persons indicated in delivery and billing addresses
A.5 Types of personal data
Processed in the Processor's infrastructure:
| Group | Data |
|---|
| Store configuration | Shopware instance address, technical name, custom domain, sales channel API access key |
| Support requests | Data provided by the Controller in the content of the request, including any screenshots |
Processed in the browser and on the user's device, using software supplied by the Processor:
| Group | Data |
|---|
| Users of the Controller | First name, surname, login, email address, position, interface language, time zone |
| Customers and their representatives | Name, first name and surname, email address, telephone number, NIP, billing address, delivery address, customer number |
| Transaction data | Content of quotes and orders, line items, quantities, prices, discounts, payment and delivery statuses, document numbers, correspondence in the quote thread |
| B2B organisational data | Roles, permissions, assignment to organisational units, budgets, approval rules |
Excluded data: special categories of data under Article 9 GDPR and data under Article 10 GDPR are not covered by the entrustment and should not be entered into the Service.
Data not processed: passwords of the Controller's users, users' IP addresses (no access logs), content of users' screens (no error monitoring or analytics tools in the application).
A.6 Place of processing
OVH data centre in Warsaw, Poland. In addition, the end devices of the Controller's users and the Controller's Shopware instance, in a location chosen by the Controller.
Annex B – Technical and organisational measures
This document describes the measures applied in accordance with Article 32 GDPR, as at 22.09.2026. The Processor may change them, provided that the level of security is maintained at no lower level than that described.
B.1 Measures arising from the architecture
The design of the Service itself limits risk and constitutes a security measure within the meaning of Article 32:
- business data is not stored in the Processor's infrastructure;
- the Processor does not store the passwords of the Controller's users;
- no analytics, tracking or error monitoring tools operate in the application or in the Panel;
- no server access logs are kept, and consequently users' IP addresses are not collected;
- user settings are saved in the Controller's system, not with the Processor.
B.2 Pseudonymisation and encryption
- Encryption of transmission using the TLS protocol in version 1.2 or higher for all traffic
- Panel account passwords stored only in hashed form using a function resistant to dictionary attacks
- No storage of payment card data; processing handled by the payment operator
B.3 Confidentiality
- Role-based access control, the principle of least privilege
- Separation of individual Controllers' data at application level
- Confidentiality undertakings for all persons with access to data
- A formal procedure for granting and revoking permissions
B.4 Integrity
- Code version control, review of changes before deployment
- Separation of production and development environments; prohibition on using production data in non-production environments
B.5 Availability
- Availability monitoring carried out with an independent tool, on infrastructure separate from the production infrastructure
- Infrastructure in the OVH data centre in Warsaw
B.6 Organisation
- A designated person responsible for data protection
- Staff training in data protection and security
- A breach response procedure with a deadline of up to 24 hours for notifying the Controller
- A procedure for vetting sub-processors before commencing cooperation
Annex C – List of sub-processors
Version dated 22.09.2026. The current version is published at useaxon.io. Changes are communicated in accordance with § 5 of the Agreement.
| Sub-processor | Registered office | Role in the Service | Scope of data | Place of processing | Transfer outside the EEA |
|---|
| OVH | France | Infrastructure of the application, Panel and configuration database | Store configuration, Account data, billing data | Warsaw, Poland | None |
| Stripe Payments Europe, Ltd. | Ireland | Payment and subscription processing | Billing data, transaction data | Ireland, USA | Standard contractual clauses |
| Google Ireland Limited | Ireland | Sending system messages from the Panel | Email address, content of messages | Ireland (contracting entity) | Standard contractual clauses – in accordance with the Cloud Data Processing Addendum |
The following are not sub-processors within the meaning of this Agreement: Google Ireland Limited and Microsoft Ireland Operations Limited, whose analytics tools operate solely on the useaxon.io marketing website, are launched only after the visitor has given consent, and have no access to the data entrusted by the Controller or to the Axon application and the Panel.
The Processor does not use external error monitoring tools, product analytics or ticketing systems operating on third-party infrastructure.