Nur auf Englisch. Dieses Dokument liegt derzeit nur in englischer Sprache vor. Es ist ein Vertragstext, und eine ungeprüfte Übersetzung wäre hier schlechter als keine. Fragen dazu auf Deutsch beantworte ich gern per E-Mail an [email protected].
Legal

Data processing agreement

Last updated 10 September 2026 · Version 1.0 (English)

This is the agreement under Art. 28(3) GDPR between BTNG B.V., the company that operates Zeppol, and every merchant who installs the Zeppol app on a Shopify store. It names each sub-processor, says what data reaches it, and sets out how long invoice records are kept and why.

A German version follows. Until it is published, this English text is the only text. After it is published the two versions carry the same meaning, and where they differ the English version prevails.

Parties

Processor: BTNG B.V., a private limited company under Dutch law, registered in Deventer, the Netherlands, operator of the Zeppol app ("Zeppol", "the Processor").

Controller: the merchant who installs the Zeppol app on a Shopify store and accepts these terms ("the Merchant", "the Controller").

This agreement forms part of the Zeppol terms of service and takes effect when the Merchant installs the app. It applies to all processing of personal data that BTNG B.V. carries out on the Merchant's behalf through Zeppol. Where this agreement and the terms of service conflict on a matter of data protection, this agreement prevails.

1. Definitions

Terms such as personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meaning given to them in Regulation (EU) 2016/679 (the GDPR).

Invoice record means the EN 16931 invoice document that Zeppol generates for an order (Peppol BIS Billing 3.0 UBL), its PDF rendering, the invoice number, the amounts, the buyer's name and address as frozen at issue time, the issue date, the hand-over timestamp and the AS4 receipt id where one exists.

Operational data means everything Zeppol holds that is not an invoice record: the reusable buyer profile, the link from an invoice back to a Shopify order, workflow state, settings and credentials.

2. Roles

The Merchant is the controller. The Merchant decides which orders become invoices, what those invoices say, which buyers receive them and by which channel. The Merchant is the issuer of record of every invoice Zeppol generates: the invoice is the Merchant's document, issued in the Merchant's name and under the Merchant's invoice number sequence.

BTNG B.V. is the processor. Zeppol acts as a technical transmission agent for the Merchant: it builds the document the Merchant has configured, validates it, hands it to the Peppol network or to an email channel, and keeps the Merchant's copy. Zeppol does not decide the content of an invoice and does not use the data for any purpose of its own.

Shopify Inc. is not a sub-processor of BTNG B.V. Shopify processes the Merchant's store data under the Merchant's own agreement with Shopify. Zeppol reads from and writes to the Merchant's Shopify store through the Shopify Admin API under the permissions the Merchant grants at installation.

3. Subject matter

The subject matter of the processing is the generation, validation, transmission and retention of business-to-business e-invoices for orders placed in the Merchant's Shopify store, together with the buyer identity data those invoices require.

4. Duration

The processing lasts for as long as the Zeppol app is installed on the Merchant's store, and after uninstallation for the period described in section 13 (deletion or return).

5. Nature and purpose of the processing

Zeppol processes personal data in order to:

  1. read the order and its buyer details from the Merchant's Shopify store;
  2. validate the buyer's VAT number against the European Commission's VIES service and record the verdict;
  3. map the order to an EN 16931 invoice document and validate it against the Peppol and German national rulesets before anything is sent;
  4. allocate an invoice number from the Merchant's sequence;
  5. archive the document and its PDF in the Merchant's invoice archive;
  6. check whether the buyer is reachable on the Peppol network, and transmit the document over Peppol through a certified Access Point, or send it by email with the XML and PDF attached when the Merchant has selected email delivery;
  7. record the hand-over of the document and the AS4 receipt id, and show that state to the Merchant in the Shopify admin;
  8. alert the Merchant when a send is blocked or parked for review;
  9. answer the Merchant's data-subject requests as described in section 11;
  10. keep the invoice records for the statutory retention period described in section 13.

The processing is automated. It takes place on servers in the European Union, with the qualifications set out in section 15.

Zeppol does not track delivery to, or acceptance by, the buyer. The final state Zeppol records is the hand-over of the document to the receiving Access Point, evidenced by the AS4 receipt id.

6. Categories of personal data

CategoryFieldsSource
Buyer identitycompany name, VAT number, Peppol participant identifier, country, billing address, contact name and email address on the orderthe Merchant's Shopify order and the buyer profile the Merchant maintains
Order dataorder number, line items, quantities, prices, currency, VAT amounts, order status, fulfilment and payment datesthe Merchant's Shopify store
Invoice recordsas defined in section 1generated by Zeppol
VAT validationthe VIES verdict for the buyer's VAT number and the time it was obtainedVIES
Merchant identitythe Merchant's company name, VAT number, Peppol participant identifier, country, address, the email address that receives alertsentered by the Merchant
Store connectionthe Shopify store domain and the access token Shopify issues to the appShopify
Access Point credentialsthe API key for the Merchant's Access Point account, encrypted at restthe Merchant or Zeppol's onboarding

Zeppol does not process payment card data. Card details never reach the app.

Where a buyer is a company, most of the fields above are company data rather than personal data. They are treated as personal data in full, because sole traders, partnerships and named contact persons appear in the same fields and cannot be told apart in advance.

7. Categories of data subjects

  1. The Merchant's business customers, where those customers are natural persons (sole traders, freelancers, partners in a partnership).
  2. Contact persons at the Merchant's business customers, whose names and email addresses appear on an order or on an invoice.
  3. The Merchant's own staff: the Shopify admin users who operate the app and the person who receives alert emails.

8. Instructions

Zeppol processes personal data only on documented instructions from the Merchant. The instructions are:

Zeppol informs the Merchant without delay if it considers that an instruction infringes the GDPR or other Union or Member State data protection law. Section 13 records one such standing position in advance, so that the Merchant knows it before issuing the instruction.

Zeppol transfers personal data to a third country or an international organisation only where section 15 provides for it, or where Union or Member State law requires it. In the latter case Zeppol informs the Merchant of the legal requirement before the processing, unless that law prohibits the information on important grounds of public interest.

9. Confidentiality

Only persons who need access to personal data to operate Zeppol have it. Each of them is bound by a contractual duty of confidentiality or a statutory obligation of professional secrecy. At the date of this agreement that is one person, the director of BTNG B.V.

10. Security of processing

Zeppol implements the technical and organisational measures in Annex 2. They are appropriate to the risk of the processing under Art. 32 GDPR, taking into account that the data are business identity and invoice data, that the volume per Merchant is small and that the consequence of loss is a statutory record the Merchant cannot reproduce.

Zeppol may update the measures in Annex 2, provided the level of protection does not fall below the level described there. Material changes are published on this page and notified as in section 12.

11. Assistance with data-subject rights

Zeppol assists the Merchant, by appropriate technical and organisational measures, in responding to requests by data subjects to exercise their rights under Chapter III GDPR. For a Shopify app that assistance is built in:

Zeppol charges no fee for this assistance.

12. Assistance with security, breach notification and impact assessments

Zeppol assists the Merchant in meeting the Merchant's obligations under Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to Zeppol.

Personal data breach. Zeppol notifies the Merchant of a personal data breach affecting the Merchant's data without undue delay after becoming aware of it, and in any case within 48 hours. The notification goes to the email address the Merchant has set as the alert recipient, or otherwise to the store owner's email address in Shopify, and describes what is known at that point: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and the contact point at BTNG B.V. Information that is not yet available follows as soon as it is.

Impact assessments and prior consultation. Where the Merchant needs to carry out a data protection impact assessment, or to consult a supervisory authority, for processing that involves Zeppol, Zeppol provides the information about its processing that this agreement and its annexes contain, and answers reasonable further questions.

13. Deletion or return of personal data

13.1 Export

The Merchant can export the invoice archive from the app at any time while the app is installed, and the export includes every invoice record and its documents in a form the Merchant can retain independently of Zeppol. The export is what makes the deletion in 13.2 safe to perform, so Zeppol treats it as a core function of the app, not a courtesy.

13.2 End of the processing

When the Merchant uninstalls the app, Shopify sends the shop/redact webhook about 48 hours later. On receipt Zeppol deletes every record belonging to that store: settings, credentials, buyer profiles, operational data, invoice records and generated documents, including the copies in the invoice archive. Existing backup copies expire on the backup retention schedule in Annex 2. After that, Zeppol holds nothing for the Merchant.

From the moment the Merchant ends the processing relationship, the statutory duty to retain the invoices rests with the Merchant alone, on the Merchant's own copy. That is why the export in 13.1 exists and why Zeppol deletes rather than retains at this point.

13.3 Statutory retention of invoice records during the term

While the app is installed, Zeppol retains every invoice record for eight years from the end of the calendar year in which the invoice was issued. This is the retention period for invoices under §14b(1) UStG, in force since 1 January 2025. It is not the ten-year period for the books under §147 AO; Zeppol holds invoices, not books, and the two periods must not be conflated.

The retention obligation binds the Merchant, as the issuer of the invoice, and Zeppol holds the record on the Merchant's behalf. Two consequences follow, and the Merchant agrees to both in advance:

  1. A data subject's erasure request does not reach the invoice record. Art. 17(3)(b) GDPR disapplies the right to erasure where the processing is necessary for compliance with a legal obligation under Union or Member State law. §14b(1) UStG is such an obligation. On a customers/redact webhook, Zeppol erases the buyer profile and the operational data and keeps the invoice record, including the buyer's name and address frozen in it, because §14(4) Nr. 1 UStG requires an invoice to name its recipient and an invoice without one is no longer an invoice.
  2. An instruction from the Merchant to delete individual invoice records before the end of the retention period is not carried out. Zeppol treats such an instruction as one that would put the Merchant in breach of §14b(1) UStG and, under section 8, informs the Merchant instead of acting on it. The Merchant who wants to hold the records elsewhere uses the export in 13.1 and ends the processing under 13.2; that path is always open.

Expiry of the eight years makes an invoice record eligible for deletion. It does not delete it. Zeppol does not purge records on a timer, because §147(3) AO preserves the suspension of the period where a tax assessment is still open, and because a Merchant whose accountant treats the invoice as a bookkeeping voucher keeps it for ten years. After expiry the Merchant decides, and instructs deletion through the app or by email to [email protected].

The full reasoning, and the exact list of which fields are retained and which are erased, is Zeppol's data retention position, summarised in Annex 3.

13.4 Certification

On request Zeppol confirms in writing that the deletion under 13.2 has taken place.

14. Audit

Zeppol makes available to the Merchant all information necessary to demonstrate that the obligations in Art. 28 GDPR are met. In the first instance that is this agreement, its annexes, the privacy policy and the written answers Zeppol gives to the Merchant's questions.

The Merchant, or an auditor mandated by the Merchant who is not a competitor of BTNG B.V. and who is bound to confidentiality, may audit Zeppol's processing under this agreement:

Zeppol contributes to the audit and provides access to the systems and records within the stated scope. Audit findings are confidential to the parties.

15. International transfers

Zeppol stores and processes personal data in the European Union. Specifically:

One sub-processor, Cloudflare, Inc., is established in the United States. Cloudflare provides the DNS, TLS termination and tunnel through which traffic reaches the app, the EU-jurisdiction object storage above and, where configured, the email service through which invoice and alert emails are sent. Data at rest with Cloudflare stays in the European Union under the EU jurisdiction setting. Data in transit is handled at the Cloudflare network location nearest to the party making the request, which for a European merchant and a European buyer is in the European Union, and for a request originating elsewhere may not be.

Transfers to Cloudflare, Inc. that fall under Chapter V GDPR are covered by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated in Cloudflare's data processing addendum, and by Cloudflare's certification under the EU-U.S. Data Privacy Framework. Cloudflare also offers a mode that confines traffic handling to the European Union; Zeppol will adopt it if the Merchant base warrants it.

No other sub-processor is established outside the European Union, and Zeppol does not transfer personal data to any other third country. If that changes, section 16 applies.

16. Sub-processors

The Merchant gives general written authorisation for Zeppol to engage the sub-processors in Annex 1. Each of them is bound by a written agreement that imposes the same data protection obligations as this agreement, in particular sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data protection obligations, BTNG B.V. remains fully liable to the Merchant for the performance of that sub-processor's obligations.

Zeppol informs the Merchant of any intended addition or replacement of a sub-processor at least 30 days before the change takes effect, by email to the alert recipient and by updating this page. The Merchant may object in writing within that period on reasonable data protection grounds. If the parties cannot resolve the objection, the Merchant may end the processing by uninstalling the app under section 13.2; no other remedy is owed for the change itself.

Sub-processors are engaged for the processing role stated in Annex 1 and for nothing else. Zeppol does not pass personal data to a sub-processor for that sub-processor's own purposes.

17. Liability, precedence and governing law

Liability between the parties is governed by the Zeppol terms of service, save that nothing in this agreement limits either party's liability towards data subjects under Art. 82 GDPR.

This agreement is governed by the law of the Netherlands. Disputes are brought before the competent court in the district where BTNG B.V. has its seat, without prejudice to any mandatory jurisdiction of a court in the Merchant's Member State for data protection claims.

18. Language and changes

This agreement is written in English. A German version follows. Until it is published the English text is the only text; after it is published the two versions are identical in meaning, and where they differ the English version prevails.

Zeppol may update this agreement to reflect changes in the processing or in the law. Material changes are notified as in section 16, with the same 30-day lead time and the same right to end the processing. The current version, with its date, is always on this page.

Annex 1: Sub-processors

Authorised sub-processors at the date of this agreement. Each row names the legal entity, where it is established, what it does for Zeppol and which categories of data reach it.

Sub-processorEntity and jurisdictionProcessing roleData that reaches it
Recommand BRBX BV, Belgium. Peppol Access Point and Service Metadata Publisher, certified under the Belgian Peppol Authority (BOSA). Transmission. Receives the finished EN 16931 UBL document from Zeppol and transmits it over the Peppol network to the receiving Access Point using the AS4 protocol; returns the AS4 receipt. Performs the reachability lookup for the buyer's Peppol identifier. Holds the Merchant's sender registration. The Merchant's company name, VAT number and Peppol identifier as sender; the full invoice document, which carries the buyer's name, address, VAT number and Peppol identifier and the order lines; the AS4 receipt.
Hetzner Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. Hosting. Provides the virtual server in the European Union on which the Zeppol web application, the worker process and the SQLite database run. Everything in section 6, on encrypted disks under Zeppol's own operating system and access control. Hetzner has physical and network-level custody, not application-level access.
Cloudflare Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, acting through Cloudflare's EU data centres for storage. Storage, network edge and email. (a) R2 object storage with EU jurisdiction for the invoice archive and the continuous database replica; (b) DNS, TLS termination and the tunnel through which Shopify webhooks, OAuth and admin traffic reach the app; (c) where configured, the Email Service through which invoice emails and alert emails are sent. (a) invoice documents and PDFs, the database replica and therefore everything in section 6; (b) request and response traffic in transit; (c) the buyer's or Merchant's email address and the invoice email with its attachments.

Not sub-processors. The following appear in the data flow but are not engaged by Zeppol to process data on the Merchant's behalf:

Annex 2: Technical and organisational measures

The measures below are what Zeppol runs today. Each one is either visible in the repository or verifiable by the audit in section 14.

Annex 3: Retention position, summarised

QuestionAnswer
How long are invoice records retained?Eight years from the end of the year of issue, §14b(1) UStG.
Is that ten years?No. Ten years applies to the books under §147 AO. Zeppol holds invoices, not books.
Does a buyer's erasure request delete an invoice?No. Art. 17(3)(b) GDPR disapplies erasure where retention is a legal obligation; §14b(1) UStG is one. The buyer profile and the operational data are erased; the invoice record, including the buyer's name and address frozen in it, is kept.
Can the Merchant instruct deletion of an individual invoice record before the eight years end?No. Zeppol informs the Merchant that the instruction would breach §14b(1) UStG and does not act on it. The Merchant can export the archive and end the processing instead.
Is anything deleted automatically at eight years?No. Expiry makes a record eligible for deletion. The Merchant decides.
What happens at uninstall?About 48 hours after uninstall, Shopify sends shop/redact and Zeppol deletes everything for the store, invoices included. The retention duty then rests with the Merchant on the exported copy.

The sentence the Merchant sees in the admin when a redaction touches a retained invoice:

The buyer's personal data has been erased. The invoices already issued to them are kept: German law requires the merchant to retain an invoice for eight years (§14b(1) UStG), and Art. 17(3)(b) GDPR permits that retention. The invoices are no longer linked to a buyer profile.

Contact

BTNG B.V. · Deventer, the Netherlands · [email protected]

Zeppol is an independent app and is not affiliated with or endorsed by Shopify.