Data processing agreement
Last updated 10 September 2026 · Version 1.0 (English)
This is the agreement under Art. 28(3) GDPR between BTNG B.V., the company that operates Zeppol, and every merchant who installs the Zeppol app on a Shopify store. It names each sub-processor, says what data reaches it, and sets out how long invoice records are kept and why.
Parties
Processor: BTNG B.V., a private limited company under Dutch law, registered in Deventer, the Netherlands, operator of the Zeppol app ("Zeppol", "the Processor").
Controller: the merchant who installs the Zeppol app on a Shopify store and accepts these terms ("the Merchant", "the Controller").
This agreement forms part of the Zeppol terms of service and takes effect when the Merchant installs the app. It applies to all processing of personal data that BTNG B.V. carries out on the Merchant's behalf through Zeppol. Where this agreement and the terms of service conflict on a matter of data protection, this agreement prevails.
1. Definitions
Terms such as personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meaning given to them in Regulation (EU) 2016/679 (the GDPR).
Invoice record means the EN 16931 invoice document that Zeppol generates for an order (Peppol BIS Billing 3.0 UBL), its PDF rendering, the invoice number, the amounts, the buyer's name and address as frozen at issue time, the issue date, the hand-over timestamp and the AS4 receipt id where one exists.
Operational data means everything Zeppol holds that is not an invoice record: the reusable buyer profile, the link from an invoice back to a Shopify order, workflow state, settings and credentials.
2. Roles
The Merchant is the controller. The Merchant decides which orders become invoices, what those invoices say, which buyers receive them and by which channel. The Merchant is the issuer of record of every invoice Zeppol generates: the invoice is the Merchant's document, issued in the Merchant's name and under the Merchant's invoice number sequence.
BTNG B.V. is the processor. Zeppol acts as a technical transmission agent for the Merchant: it builds the document the Merchant has configured, validates it, hands it to the Peppol network or to an email channel, and keeps the Merchant's copy. Zeppol does not decide the content of an invoice and does not use the data for any purpose of its own.
Shopify Inc. is not a sub-processor of BTNG B.V. Shopify processes the Merchant's store data under the Merchant's own agreement with Shopify. Zeppol reads from and writes to the Merchant's Shopify store through the Shopify Admin API under the permissions the Merchant grants at installation.
3. Subject matter
The subject matter of the processing is the generation, validation, transmission and retention of business-to-business e-invoices for orders placed in the Merchant's Shopify store, together with the buyer identity data those invoices require.
4. Duration
The processing lasts for as long as the Zeppol app is installed on the Merchant's store, and after uninstallation for the period described in section 13 (deletion or return).
5. Nature and purpose of the processing
Zeppol processes personal data in order to:
- read the order and its buyer details from the Merchant's Shopify store;
- validate the buyer's VAT number against the European Commission's VIES service and record the verdict;
- map the order to an EN 16931 invoice document and validate it against the Peppol and German national rulesets before anything is sent;
- allocate an invoice number from the Merchant's sequence;
- archive the document and its PDF in the Merchant's invoice archive;
- check whether the buyer is reachable on the Peppol network, and transmit the document over Peppol through a certified Access Point, or send it by email with the XML and PDF attached when the Merchant has selected email delivery;
- record the hand-over of the document and the AS4 receipt id, and show that state to the Merchant in the Shopify admin;
- alert the Merchant when a send is blocked or parked for review;
- answer the Merchant's data-subject requests as described in section 11;
- keep the invoice records for the statutory retention period described in section 13.
The processing is automated. It takes place on servers in the European Union, with the qualifications set out in section 15.
Zeppol does not track delivery to, or acceptance by, the buyer. The final state Zeppol records is the hand-over of the document to the receiving Access Point, evidenced by the AS4 receipt id.
6. Categories of personal data
| Category | Fields | Source |
|---|---|---|
| Buyer identity | company name, VAT number, Peppol participant identifier, country, billing address, contact name and email address on the order | the Merchant's Shopify order and the buyer profile the Merchant maintains |
| Order data | order number, line items, quantities, prices, currency, VAT amounts, order status, fulfilment and payment dates | the Merchant's Shopify store |
| Invoice records | as defined in section 1 | generated by Zeppol |
| VAT validation | the VIES verdict for the buyer's VAT number and the time it was obtained | VIES |
| Merchant identity | the Merchant's company name, VAT number, Peppol participant identifier, country, address, the email address that receives alerts | entered by the Merchant |
| Store connection | the Shopify store domain and the access token Shopify issues to the app | Shopify |
| Access Point credentials | the API key for the Merchant's Access Point account, encrypted at rest | the Merchant or Zeppol's onboarding |
Zeppol does not process payment card data. Card details never reach the app.
Where a buyer is a company, most of the fields above are company data rather than personal data. They are treated as personal data in full, because sole traders, partnerships and named contact persons appear in the same fields and cannot be told apart in advance.
7. Categories of data subjects
- The Merchant's business customers, where those customers are natural persons (sole traders, freelancers, partners in a partnership).
- Contact persons at the Merchant's business customers, whose names and email addresses appear on an order or on an invoice.
- The Merchant's own staff: the Shopify admin users who operate the app and the person who receives alert emails.
8. Instructions
Zeppol processes personal data only on documented instructions from the Merchant. The instructions are:
- this agreement;
- the Merchant's configuration of the app, including which orders become invoices, the delivery channel, the invoice number sequence and the alert recipient;
- the Merchant's actions in the Shopify admin, including issuing an invoice, parking one, requesting an export or requesting deletion;
- the privacy webhooks Shopify sends on the Merchant's behalf (
customers/data_request,customers/redact,shop/redact).
Zeppol informs the Merchant without delay if it considers that an instruction infringes the GDPR or other Union or Member State data protection law. Section 13 records one such standing position in advance, so that the Merchant knows it before issuing the instruction.
Zeppol transfers personal data to a third country or an international organisation only where section 15 provides for it, or where Union or Member State law requires it. In the latter case Zeppol informs the Merchant of the legal requirement before the processing, unless that law prohibits the information on important grounds of public interest.
9. Confidentiality
Only persons who need access to personal data to operate Zeppol have it. Each of them is bound by a contractual duty of confidentiality or a statutory obligation of professional secrecy. At the date of this agreement that is one person, the director of BTNG B.V.
10. Security of processing
Zeppol implements the technical and organisational measures in Annex 2. They are appropriate to the risk of the processing under Art. 32 GDPR, taking into account that the data are business identity and invoice data, that the volume per Merchant is small and that the consequence of loss is a statutory record the Merchant cannot reproduce.
Zeppol may update the measures in Annex 2, provided the level of protection does not fall below the level described there. Material changes are published on this page and notified as in section 12.
11. Assistance with data-subject rights
Zeppol assists the Merchant, by appropriate technical and organisational measures, in responding to requests by data subjects to exercise their rights under Chapter III GDPR. For a Shopify app that assistance is built in:
- Access and portability. On Shopify's
customers/data_requestwebhook, Zeppol returns the invoice records and buyer profile held for that customer to the Merchant. - Erasure. On Shopify's
customers/redactwebhook, Zeppol erases the buyer profile and the operational data for that customer. Invoice records are retained. Section 13 and Annex 3 explain why, and the Merchant sees the same explanation in the admin whenever a request touches a retained invoice. - Rectification. The Merchant corrects buyer data in Shopify or in the buyer profile; Zeppol reads the corrected data for every subsequent invoice. An invoice already issued is corrected by a credit note and a new invoice, not by editing the issued document.
- Other requests. Requests that reach Zeppol directly from a data subject are forwarded to the Merchant within five working days and are not answered on the Merchant's behalf unless the Merchant asks for that.
Zeppol charges no fee for this assistance.
12. Assistance with security, breach notification and impact assessments
Zeppol assists the Merchant in meeting the Merchant's obligations under Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to Zeppol.
Personal data breach. Zeppol notifies the Merchant of a personal data breach affecting the Merchant's data without undue delay after becoming aware of it, and in any case within 48 hours. The notification goes to the email address the Merchant has set as the alert recipient, or otherwise to the store owner's email address in Shopify, and describes what is known at that point: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and the contact point at BTNG B.V. Information that is not yet available follows as soon as it is.
Impact assessments and prior consultation. Where the Merchant needs to carry out a data protection impact assessment, or to consult a supervisory authority, for processing that involves Zeppol, Zeppol provides the information about its processing that this agreement and its annexes contain, and answers reasonable further questions.
13. Deletion or return of personal data
13.1 Export
The Merchant can export the invoice archive from the app at any time while the app is installed, and the export includes every invoice record and its documents in a form the Merchant can retain independently of Zeppol. The export is what makes the deletion in 13.2 safe to perform, so Zeppol treats it as a core function of the app, not a courtesy.
13.2 End of the processing
When the Merchant uninstalls the app, Shopify sends the shop/redact webhook about
48 hours later. On receipt Zeppol deletes every record belonging to that store: settings, credentials,
buyer profiles, operational data, invoice records and generated documents, including the copies in
the invoice archive. Existing backup copies expire on the backup retention schedule in Annex 2. After
that, Zeppol holds nothing for the Merchant.
From the moment the Merchant ends the processing relationship, the statutory duty to retain the invoices rests with the Merchant alone, on the Merchant's own copy. That is why the export in 13.1 exists and why Zeppol deletes rather than retains at this point.
13.3 Statutory retention of invoice records during the term
While the app is installed, Zeppol retains every invoice record for eight years from the end of the calendar year in which the invoice was issued. This is the retention period for invoices under §14b(1) UStG, in force since 1 January 2025. It is not the ten-year period for the books under §147 AO; Zeppol holds invoices, not books, and the two periods must not be conflated.
The retention obligation binds the Merchant, as the issuer of the invoice, and Zeppol holds the record on the Merchant's behalf. Two consequences follow, and the Merchant agrees to both in advance:
-
A data subject's erasure request does not reach the invoice record. Art. 17(3)(b)
GDPR disapplies the right to erasure where the processing is necessary for compliance with a legal
obligation under Union or Member State law. §14b(1) UStG is such an obligation. On a
customers/redactwebhook, Zeppol erases the buyer profile and the operational data and keeps the invoice record, including the buyer's name and address frozen in it, because §14(4) Nr. 1 UStG requires an invoice to name its recipient and an invoice without one is no longer an invoice. - An instruction from the Merchant to delete individual invoice records before the end of the retention period is not carried out. Zeppol treats such an instruction as one that would put the Merchant in breach of §14b(1) UStG and, under section 8, informs the Merchant instead of acting on it. The Merchant who wants to hold the records elsewhere uses the export in 13.1 and ends the processing under 13.2; that path is always open.
Expiry of the eight years makes an invoice record eligible for deletion. It does not delete it. Zeppol does not purge records on a timer, because §147(3) AO preserves the suspension of the period where a tax assessment is still open, and because a Merchant whose accountant treats the invoice as a bookkeeping voucher keeps it for ten years. After expiry the Merchant decides, and instructs deletion through the app or by email to [email protected].
The full reasoning, and the exact list of which fields are retained and which are erased, is Zeppol's data retention position, summarised in Annex 3.
13.4 Certification
On request Zeppol confirms in writing that the deletion under 13.2 has taken place.
14. Audit
Zeppol makes available to the Merchant all information necessary to demonstrate that the obligations in Art. 28 GDPR are met. In the first instance that is this agreement, its annexes, the privacy policy and the written answers Zeppol gives to the Merchant's questions.
The Merchant, or an auditor mandated by the Merchant who is not a competitor of BTNG B.V. and who is bound to confidentiality, may audit Zeppol's processing under this agreement:
- once in any twelve-month period, or additionally where a supervisory authority requires it or a personal data breach has occurred;
- on at least 30 days' written notice, stating the scope;
- during business hours, remotely by default, and on site at BTNG B.V. only where a remote audit cannot answer the question;
- at the Merchant's cost, except where the audit reveals a material breach of this agreement by Zeppol.
Zeppol contributes to the audit and provides access to the systems and records within the stated scope. Audit findings are confidential to the parties.
15. International transfers
Zeppol stores and processes personal data in the European Union. Specifically:
- the application, the worker and the database run on a server operated by Hetzner Online GmbH in the European Union;
- the invoice archive and the database replica are stored in Cloudflare R2 buckets created with EU jurisdiction, which fixes the storage location to the European Union and cannot be changed after creation;
- Peppol transmission runs through Recommand's Access Point in Belgium.
One sub-processor, Cloudflare, Inc., is established in the United States. Cloudflare provides the DNS, TLS termination and tunnel through which traffic reaches the app, the EU-jurisdiction object storage above and, where configured, the email service through which invoice and alert emails are sent. Data at rest with Cloudflare stays in the European Union under the EU jurisdiction setting. Data in transit is handled at the Cloudflare network location nearest to the party making the request, which for a European merchant and a European buyer is in the European Union, and for a request originating elsewhere may not be.
Transfers to Cloudflare, Inc. that fall under Chapter V GDPR are covered by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated in Cloudflare's data processing addendum, and by Cloudflare's certification under the EU-U.S. Data Privacy Framework. Cloudflare also offers a mode that confines traffic handling to the European Union; Zeppol will adopt it if the Merchant base warrants it.
No other sub-processor is established outside the European Union, and Zeppol does not transfer personal data to any other third country. If that changes, section 16 applies.
16. Sub-processors
The Merchant gives general written authorisation for Zeppol to engage the sub-processors in Annex 1. Each of them is bound by a written agreement that imposes the same data protection obligations as this agreement, in particular sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data protection obligations, BTNG B.V. remains fully liable to the Merchant for the performance of that sub-processor's obligations.
Zeppol informs the Merchant of any intended addition or replacement of a sub-processor at least 30 days before the change takes effect, by email to the alert recipient and by updating this page. The Merchant may object in writing within that period on reasonable data protection grounds. If the parties cannot resolve the objection, the Merchant may end the processing by uninstalling the app under section 13.2; no other remedy is owed for the change itself.
Sub-processors are engaged for the processing role stated in Annex 1 and for nothing else. Zeppol does not pass personal data to a sub-processor for that sub-processor's own purposes.
17. Liability, precedence and governing law
Liability between the parties is governed by the Zeppol terms of service, save that nothing in this agreement limits either party's liability towards data subjects under Art. 82 GDPR.
This agreement is governed by the law of the Netherlands. Disputes are brought before the competent court in the district where BTNG B.V. has its seat, without prejudice to any mandatory jurisdiction of a court in the Merchant's Member State for data protection claims.
18. Language and changes
This agreement is written in English. A German version follows. Until it is published the English text is the only text; after it is published the two versions are identical in meaning, and where they differ the English version prevails.
Zeppol may update this agreement to reflect changes in the processing or in the law. Material changes are notified as in section 16, with the same 30-day lead time and the same right to end the processing. The current version, with its date, is always on this page.
Annex 1: Sub-processors
Authorised sub-processors at the date of this agreement. Each row names the legal entity, where it is established, what it does for Zeppol and which categories of data reach it.
| Sub-processor | Entity and jurisdiction | Processing role | Data that reaches it |
|---|---|---|---|
| Recommand | BRBX BV, Belgium. Peppol Access Point and Service Metadata Publisher, certified under the Belgian Peppol Authority (BOSA). | Transmission. Receives the finished EN 16931 UBL document from Zeppol and transmits it over the Peppol network to the receiving Access Point using the AS4 protocol; returns the AS4 receipt. Performs the reachability lookup for the buyer's Peppol identifier. Holds the Merchant's sender registration. | The Merchant's company name, VAT number and Peppol identifier as sender; the full invoice document, which carries the buyer's name, address, VAT number and Peppol identifier and the order lines; the AS4 receipt. |
| Hetzner | Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. | Hosting. Provides the virtual server in the European Union on which the Zeppol web application, the worker process and the SQLite database run. | Everything in section 6, on encrypted disks under Zeppol's own operating system and access control. Hetzner has physical and network-level custody, not application-level access. |
| Cloudflare | Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, acting through Cloudflare's EU data centres for storage. | Storage, network edge and email. (a) R2 object storage with EU jurisdiction for the invoice archive and the continuous database replica; (b) DNS, TLS termination and the tunnel through which Shopify webhooks, OAuth and admin traffic reach the app; (c) where configured, the Email Service through which invoice emails and alert emails are sent. | (a) invoice documents and PDFs, the database replica and therefore everything in section 6; (b) request and response traffic in transit; (c) the buyer's or Merchant's email address and the invoice email with its attachments. |
Not sub-processors. The following appear in the data flow but are not engaged by Zeppol to process data on the Merchant's behalf:
- Shopify is the Merchant's own platform and processes store data under the Merchant's agreement with Shopify.
- VIES (VAT Information Exchange System) is a service of the European Commission. Zeppol sends it a VAT number and receives a verdict. It is a public authority acting under its own legal basis, not a processor.
- The receiving Access Point and the buyer receive the invoice because the Merchant sends it to them. They are recipients, not processors.
- Kit and Plausible are used only for the zeppol.com website (early-access emails and cookieless analytics) and never touch app data. They are described in the privacy policy.
Annex 2: Technical and organisational measures
The measures below are what Zeppol runs today. Each one is either visible in the repository or verifiable by the audit in section 14.
- Encryption in transit. All traffic to and from the app is encrypted with TLS. Shopify webhooks are verified against their HMAC signature before they are processed. Calls to the Access Point, to VIES and to object storage use TLS.
- Encryption of credentials at rest. Access Point API credentials are stored under envelope encryption, AES-256-GCM with a per-value random IV and authentication tag, under a 32-byte key that exists only in the server's environment and in an escrowed copy held in a password manager. Shopify access tokens are stored server-side only. Credentials are never written to logs.
- EU-jurisdiction storage. The invoice archive and the database replica live in Cloudflare R2 buckets created with EU jurisdiction. The setting is immutable and confines the stored objects to the European Union. The application refuses to start in production without storage credentials, so an invoice is never issued without an archived copy.
- Access control. The app runs as a Shopify embedded app; a Merchant's staff reach it only through a Shopify session for that store, and every record is scoped to the store it belongs to. Administrative access to the server is by SSH key held by one named person. Shopify API permissions are limited to the scopes the invoicing function needs. Secrets are kept in a password-manager environment, not in the repository.
- Backups with a tested restore. The database is replicated continuously to the EU R2 replica bucket. The restore procedure was walked on 2 September 2026 against a scratch copy beside the live database, with row counts compared, and is repeated after any change to the backup setup. Backup copies expire within 30 days of the data they hold being deleted.
- Integrity of the invoice archive. Every invoice document is validated against the Peppol and German national Schematron rulesets before it is archived or sent, and a document that fails is blocked, never transmitted. Invoice numbers are allocated inside the same database transaction that creates the invoice, so a number is never skipped or reused.
- Isolation and availability. The Zeppol containers run with memory limits, so a fault in Zeppol cannot exhaust the host. Health checks and alerting cover the public endpoint.
- Logging. Application logs record events and identifiers, never credentials or full invoice documents. Logs are held on the server and expire with the container log rotation.
- Data minimisation. Zeppol reads from Shopify only the order fields that appear on an invoice. It does not read customer records beyond the order, browsing behaviour or payment details.
- Organisational. One person operates Zeppol and is bound by this agreement's confidentiality clause. There is no offshore support, no outsourced operations and no third party with a login to the production system.
Annex 3: Retention position, summarised
| Question | Answer |
|---|---|
| How long are invoice records retained? | Eight years from the end of the year of issue, §14b(1) UStG. |
| Is that ten years? | No. Ten years applies to the books under §147 AO. Zeppol holds invoices, not books. |
| Does a buyer's erasure request delete an invoice? | No. Art. 17(3)(b) GDPR disapplies erasure where retention is a legal obligation; §14b(1) UStG is one. The buyer profile and the operational data are erased; the invoice record, including the buyer's name and address frozen in it, is kept. |
| Can the Merchant instruct deletion of an individual invoice record before the eight years end? | No. Zeppol informs the Merchant that the instruction would breach §14b(1) UStG and does not act on it. The Merchant can export the archive and end the processing instead. |
| Is anything deleted automatically at eight years? | No. Expiry makes a record eligible for deletion. The Merchant decides. |
| What happens at uninstall? | About 48 hours after uninstall, Shopify sends shop/redact and Zeppol deletes everything for the store, invoices included. The retention duty then rests with the Merchant on the exported copy. |
The sentence the Merchant sees in the admin when a redaction touches a retained invoice:
Contact
BTNG B.V. · Deventer, the Netherlands · [email protected]
Zeppol is an independent app and is not affiliated with or endorsed by Shopify.