Data Processing Agreement

Effective from: 24 June 2026

Last updated: 19 July 2026

This document governs the processing of personal data where SUBVENTUM s.r.o. acts as a personal data processor for a customer of the ProfitEcom service.

This document forms the standard data processing agreement for the ProfitEcom service, unless the customer and SUBVENTUM s.r.o. agree otherwise in writing.

Processor:

SUBVENTUM s.r.o.

Kaprova 42/14

110 00 Prague 1

Czech Republic

Company ID: 08239771

VAT ID: CZ08239771

Privacy contact: privacy@profitecom.com

Security contact: security@profitecom.com

1. Roles of the parties

For the purposes of this document:

  • the Customer is the data controller if it provides, uploads, connects or makes personal data from its systems available to the ProfitEcom service,
  • SUBVENTUM s.r.o. is the data processor if it processes such data for the purpose of providing the ProfitEcom service,
  • ProfitEcom is the service through which the processor provides analytics, reporting, integrations, data transformations and related services to the customer.

This document does not apply to cases where SUBVENTUM s.r.o. acts as an independent data controller, for example when managing its own business contacts, user accounts, billing or service security. These cases are described in the Privacy Policy.

2. Subject matter of processing

The subject matter of processing is the processing of personal data and customer data that the customer makes available to ProfitEcom for the purpose of providing the agreed services.

ProfitEcom may process data in particular from:

  • e-commerce platforms,
  • ERP systems,
  • PIM systems,
  • CRM systems,
  • marketing platforms,
  • web analytics platforms,
  • warehouse and logistics systems,
  • customer spreadsheets,
  • other sources according to the specific implementation.

The scope of specific processing is governed in particular by:

  • the contract with the customer,
  • the order,
  • the implementation analysis,
  • the data contract,
  • the technical specification,
  • the integration settings,
  • the customer’s instructions in the application or during implementation.

3. Duration of processing

The processing of personal data continues for the duration of the provision of the ProfitEcom service to the customer.

After termination of the service, customer data will be deleted or anonymized according to the rules set out in the Privacy Policy and Data Deletion documents, unless the parties agree otherwise or unless applicable law requires longer retention.

Customer data is generally deleted or anonymized within 30 days after termination of the service.

Technical backups and technical copies may continue to exist for a limited period according to backup cycles and the standards of the providers used. Our target is that technical copies are not retained for more than 90 days, unless a longer period follows from the provider’s technical settings or a legal obligation.

4. Nature and purpose of processing

Processing is carried out for the purpose of providing the ProfitEcom service.

Processing may include in particular:

  • retrieving data from the customer’s systems,
  • receiving data through APIs, files, spreadsheets or integrations,
  • retrieving data from authorized marketing and web analytics platforms, such as Google Ads, Google Analytics, Meta or similar services,
  • storing data in the data platform,
  • data transformations,
  • data cleaning and unification,
  • creating analytical tables,
  • connecting marketing, web analytics, business and economic data,
  • calculating margins, costs, returns, profitability and other metrics,
  • creating dashboards and reports,
  • making reports available to authorized users of the customer,
  • checking data quality,
  • resolving technical errors,
  • security and operational logging,
  • managing integrations.

The processor must not process the customer’s personal data for its own purposes that are not compatible with the provision of the ProfitEcom service or with the customer’s instructions.

5. Types of personal data

The scope of personal data depends on the specific customer implementation.

The standard ProfitEcom data model does not require direct identifiers of end customers of an e-commerce store, such as names, e-mail addresses, phone numbers or postal addresses.

Depending on the specific implementation, the following types of data may be processed in particular:

  • pseudonymized identifiers of end customers,
  • order identifiers,
  • order data,
  • order item data,
  • product data,
  • return data,
  • cost, margin and price data,
  • sales channel data,
  • country or market data,
  • payment and shipping method data,
  • inventory movement data,
  • marketing campaign data, costs, clicks, impressions, conversions and performance metrics,
  • website traffic data, traffic sources, campaigns, events, conversions, e-commerce metrics, devices, countries and landing pages,
  • business case data,
  • CRM lead or sales record data,
  • business contact details,
  • data about customer users,
  • technical identifiers and logs,
  • other data according to the implementation analysis.

For custom reports, the data scope may be broader, but always according to the approved data scope.

6. Categories of data subjects

Depending on the specific implementation, processing may concern in particular the following categories of persons:

  • users of the customer,
  • employees or collaborators of the customer,
  • customer contact persons,
  • end customers of the customer’s e-commerce store,
  • business leads,
  • customers or business partners of the customer,
  • contact persons in companies,
  • persons included in the customer’s CRM or business data.

ProfitEcom is primarily focused on business, economic and analytical data, not on detailed personal profiles of natural persons.

7. Special categories of personal data and sensitive data

The customer must not provide ProfitEcom with special categories of personal data or other sensitive data unless this has been expressly agreed in writing.

Without an express agreement, the customer must not provide in particular:

  • health data,
  • biometric data,
  • genetic data,
  • data concerning political opinions,
  • data concerning religious or philosophical beliefs,
  • data concerning trade union membership,
  • data concerning sex life or sexual orientation,
  • criminal offence data,
  • national identification numbers,
  • children’s data,
  • payment card numbers,
  • passwords and access credentials of third parties.

If the customer provides such data without prior agreement, the customer is responsible for the legal consequences of such provision. The processor may require the removal of such data, refuse to process it or temporarily restrict processing of the affected data source.

8. Customer instructions

The processor processes personal data only on the basis of the customer’s instructions.

Customer instructions include in particular:

  • the contract,
  • the order,
  • these data processing terms,
  • the implementation analysis,
  • the data contract,
  • integration settings,
  • application settings,
  • written instructions from the customer,
  • instructions of authorized users in the application.

If, in the processor’s opinion, a customer instruction would violate applicable law, the processor will inform the customer, unless prohibited from doing so by law.

9. Obligations of the processor

The processor undertakes in particular to:

  • process personal data only for the purposes of providing the ProfitEcom service,
  • process personal data only according to the customer’s instructions,
  • ensure that persons authorized to process personal data are bound by confidentiality,
  • implement appropriate technical and organizational measures,
  • assist the customer in meeting its GDPR obligations to a reasonable extent,
  • assist the customer in handling data subject requests, where technically possible and reasonable,
  • inform the customer about security incidents concerning its data without undue delay,
  • engage other processors only under the conditions set out in this document,
  • delete or anonymize customer data after termination of the service according to the agreed rules,
  • provide the customer with reasonable information necessary to demonstrate compliance with the obligations under this document.

10. Obligations of the customer

The customer undertakes in particular to:

  • ensure that it has a legal basis for the processing of personal data,
  • ensure that it has the right to provide or make the data available to ProfitEcom,
  • inform data subjects where required,
  • comply with the agreed data scope,
  • not provide data that is not necessary for the service,
  • not provide special categories of personal data without an express agreement,
  • manage user permissions,
  • protect the access credentials of its users,
  • ensure the accuracy and lawfulness of the data,
  • respond to data subject requests if it is the data controller,
  • inform the processor about relevant instructions and changes.

The customer is responsible for the content, lawfulness, accuracy and proportionality of the data that it provides or makes available to ProfitEcom.

11. Technical and organizational measures

The processor uses appropriate technical and organizational measures to protect data.

These measures include in particular:

  • encrypted data transmission via HTTPS/TLS,
  • encrypted storage of long-term authorization tokens,
  • separation of data of individual customers and tenants,
  • role-based access control,
  • restriction of internal access to production data,
  • MFA for key services,
  • use of a dedicated Xano instance,
  • data processing primarily in European infrastructure,
  • access control in Power BI using RLS,
  • limitation of storing sensitive tokens outside the backend,
  • transfer of only short-term access tokens to the integration layer for authorized platforms, such as Google Ads, Google Analytics or Meta,
  • revocation or removal of tokens when an integration is disconnected,
  • technical logging and limited retention of execution data,
  • an incident response procedure,
  • backups and technical copies according to the capabilities of the providers used.

A more detailed public description of security measures is provided on the Security page.

The processor may change security measures over time, provided that this does not reduce the overall level of protection.

12. Sub-processors

The customer agrees to the engagement of further processors and technology providers necessary for the operation of the ProfitEcom service.

The providers used may include in particular:

  • Auth0 / Okta,
  • Microsoft Azure / Microsoft Fabric / Power BI,
  • Microsoft 365,
  • Xano,
  • Hetzner,
  • Webflow,
  • Cookiebot / Usercentrics,
  • Mandrill / Mailchimp Transactional Email,
  • Stripe,
  • Raynet,
  • Google,
  • Meta,
  • Microsoft Advertising,
  • LinkedIn,
  • Smartsupp,
  • other providers according to the specific implementation or deployed tools.

The current overview of main providers is included in the Privacy Policy.

The processor will ensure that further processors provide appropriate safeguards for the protection of personal data and are bound by corresponding contractual or legal obligations.

If a change of a further processor would have a material impact on the processing of customer personal data, the processor may inform the customer in an appropriate manner, for example by updating documentation, by e-mail or by notice in the application.

13. Transfers outside the EU/EEA

ProfitEcom data is primarily processed within the European Union or the European Economic Area.

However, some providers may process personal data outside the EU/EEA as part of their services.

If personal data is transferred outside the EU/EEA, the processor relies on appropriate legal mechanisms, in particular:

  • adequacy decisions,
  • standard contractual clauses,
  • contractual and technical measures of providers,
  • other mechanisms under GDPR.

14. Assistance with data subject rights

If a data subject submits a request concerning personal data that the processor processes for the customer, the processor will provide the customer with reasonable assistance.

This may include requests concerning:

  • access to data,
  • rectification of data,
  • deletion,
  • restriction of processing,
  • data portability,
  • objection to processing.

If a data subject contacts the processor directly and the processor is able to identify the relevant customer as the controller, the processor may forward the request to the customer or refer the data subject to the customer.

15. Security incidents

If the processor becomes aware of a security incident concerning personal data processed for the customer, it will inform the customer without undue delay after becoming aware of the incident.

The notification may include in particular:

  • a description of the nature of the incident,
  • affected systems or data sources,
  • expected scope,
  • measures taken or proposed,
  • available information necessary to assess the risk,
  • contact point for further communication.

The processor will provide the customer with reasonable assistance in meeting its obligations under applicable law.

The customer, as the controller, is responsible for assessing whether the incident must be notified to the supervisory authority or to data subjects, unless applicable law provides otherwise.

16. Audit cooperation

The processor will provide the customer with reasonable information necessary to demonstrate compliance with the obligations under this document.

The customer may request information concerning:

  • security measures,
  • engaged providers,
  • basic description of processing,
  • incident response procedure,
  • data deletion,
  • technical documentation relevant to the processing.

Audits, inspections or questionnaires must be reasonable, announced in advance and must not compromise service security, confidentiality of data of other customers or infrastructure operation.

If an audit or assistance exceeds the ordinary scope of support, the parties may agree on reimbursement of reasonable costs.

17. Deletion or return of data

After termination of the service, the processor will delete or anonymize customer data according to the Privacy Policy and Data Deletion documents, unless the parties agree otherwise.

Before termination of the service, the customer may request a data export, where technically possible and where this corresponds to the agreed scope of the service.

Some data may be retained for a longer period if necessary for:

  • compliance with a legal obligation,
  • accounting,
  • protection of legal claims,
  • security logs,
  • technical backups,
  • demonstrating performance of the contract.

Such data will not be used for ordinary provision of the service.

18. Confidentiality

The processor will ensure that persons with access to personal data are bound by confidentiality or an equivalent duty of confidentiality.

Internal access to production data is limited to persons who need it for the operation, development, support, security or administration of the service.

19. Changes to this document

The processor may update this document, especially in the event of changes to the service, legal requirements, providers, technical measures or processing methods.

The current version will be available on the ProfitEcom website.

If a change is material, the processor may inform customers by e-mail or by notice in the application.

20. Contact

For questions concerning personal data processing, please contact: privacy@profitecom.com

For security notifications: security@profitecom.com

Processor:

SUBVENTUM s.r.o.

Kaprova 42/14

110 00 Prague 1

Czech Republic

Company ID: 08239771

VAT ID: CZ08239771