Data Processing Agreement
Effective date: Sep 30, 2026 · Last updated: Sep 30, 2026
1. Overview
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Koarge Terms of Service (the "Agreement") between Koarge Inc. ("Koarge," "we," "Processor") and the customer that has agreed to the Agreement (the "Merchant," "you," "Controller"). It governs Koarge's processing of Customer Personal Data on your behalf. If you accept the Agreement, you also accept this DPA. In the event of a conflict between this DPA and the rest of the Agreement regarding the processing of Customer Personal Data, this DPA prevails.
2. Definitions
"Applicable Data Protection Laws" means all privacy and data-protection laws applicable to the processing of Customer Personal Data under this DPA, including, as applicable, Canada's PIPEDA and provincial privacy laws; the EU General Data Protection Regulation 2016/679 ("EU GDPR"); the UK GDPR and Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); and U.S. state privacy laws.
"Customer Personal Data" means personal data that Koarge processes on your behalf in providing the Service, relating to Your Customers, as described in Annex 1. "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Personal Data Breach," and "Supervisory Authority" have the meanings given in Applicable Data Protection Laws. Where a term (such as "service provider," "business," or "sub-processor") is used in a specific law, it has the corresponding meaning under that law.
"Standard Contractual Clauses" (or "SCCs") means the standard contractual clauses for the transfer of personal data to third countries under EU Commission Implementing Decision (EU) 2021/914, as completed in Annex 4.
"UK Addendum" means the UK Information Commissioner's International Data Transfer Addendum to the SCCs.
"Sub-processor" means any third party engaged by Koarge to process Customer Personal Data. Capitalized terms not defined here have the meaning given in the Agreement (including "Your Customers," "Service," "Merchant Content," "Digital Product," and "Third-Party Services").
3. Roles and Scope
2.1 For Customer Personal Data, you are the Controller and Koarge is the Processor. Where you act as a processor on behalf of another controller, Koarge acts as a sub-processor, and you are responsible for the other controller's authorizations and instructions.
2.2 This DPA applies only to Customer Personal Data. Personal data for which Koarge determines the purposes and means (for example, your account and billing information) is processed by Koarge as a Controller and is governed by our Privacy Policy, not this DPA.
2.3 The subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects are described in Annex 1.
2.4 Merchant Content and Digital Products. Files you upload to sell as Digital Products, and other Merchant Content, are not Customer Personal Data, and Koarge's storage, screening, and delivery of them is governed by the Agreement and our Privacy Policy rather than this DPA. If a file you upload contains personal data, you remain solely responsible for that content, for holding all rights and legal bases necessary to store and distribute it through the Service, and for complying with Applicable Data Protection Laws in doing so. This DPA does apply to the personal data of Your Customers that Koarge processes in order to deliver a Digital Product, such as delivery and download records.
4. Your Obligations as Controller
3.1 You will comply with Applicable Data Protection Laws in your use of the Service, including having a valid legal basis for the processing, providing all required notices to Your Customers, and obtaining all required consents.
3.2 Your instructions to Koarge for processing Customer Personal Data must comply with Applicable Data Protection Laws. You are responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which you acquired it.
3.3 You will not provide Koarge with special categories of sensitive personal data except as necessary for an order, and you are responsible for any such data you choose to process through the Service. You will not upload Digital Products containing sensitive personal data.
5. Koarge's Obligations as Processor
4.1 Processing on instructions. Koarge will process Customer Personal Data only on your documented instructions — including as set out in this DPA, the Agreement, and your configuration and use of the Service — and to complete transactions, send receipts and download links, deliver Digital Products purchased by Your Customers, provide order records, and otherwise provide the Service. If required by law to process otherwise, Koarge will inform you unless legally prohibited.
4.2 Unlawful instructions. Koarge will inform you if, in its opinion, an instruction infringes Applicable Data Protection Laws, without obligation to actively monitor your compliance.
4.3 Purpose limitation. Koarge will not sell Customer Personal Data, will not retain, use, or disclose it for any purpose other than providing the Service, and will not combine it with other data except as needed to provide the Service. Koarge certifies it understands and will comply with these restrictions.
6. Confidentiality
Koarge will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only on a need-to-know basis to provide the Service.
7. Security
6.1 Koarge will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, costs, and the nature, scope, and purposes of processing. Those measures are described in Annex 2.
6.2 Koarge may update its security measures from time to time, provided the updates do not materially reduce the overall level of protection.
8. Sub-processing
7.1 Authorization. You give Koarge general authorization to engage Sub-processors to process Customer Personal Data, subject to this Section. Koarge's current Sub-processors are listed in Annex 3.
7.2 Flow-down. Koarge will impose on each Sub-processor data-protection obligations that are substantially the same as, and no less protective than, those in this DPA, and remains liable to you for the acts and omissions of its Sub-processors as if they were its own.
7.3 Changes and objection. Koarge will give you at least 30 days' notice before adding or replacing a Sub-processor that processes Customer Personal Data (by email to the address on your account). If you have a reasonable, data-protection-based objection, you may notify Koarge within that period; the parties will work in good faith to resolve it, and if they cannot, you may terminate the affected part of the Service as your sole remedy.
9. Data Subject Requests
8.1 Taking into account the nature of the processing, Koarge will provide reasonable assistance — through appropriate technical and organizational measures, and insofar as possible — to help you respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws.
8.2 Where the Service provides functionality allowing you to access, correct, export, restrict, or delete Customer Personal Data, you will use that functionality to respond to such requests. Where you cannot, Koarge will assist on your documented request.
8.3 If Koarge receives a request directly from one of Your Customers, it will not respond except to acknowledge and, where appropriate, direct them to you, unless legally required to respond.
10. Assistance to the Controller
Taking into account the nature of processing and the information available to Koarge, Koarge will provide reasonable assistance to help you comply with your obligations regarding: (a) security of processing; (b) notification of Personal Data Breaches to Supervisory Authorities and Data Subjects; (c) data protection impact assessments; and (d) prior consultations with Supervisory Authorities.
11. Personal Data Breach Notification
10.1 Koarge will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and where feasible will aim to do so within 72 hours.
10.2 The notification will include, to the extent known and permitted by law, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Where information is not all available at once, Koarge may provide it in phases without undue further delay.
10.3 Koarge will take reasonable steps to mitigate and remediate the breach. Notification of a breach is not an acknowledgment of fault or liability.
12. International Transfers
11.1 You authorize Koarge and its Sub-processors to transfer and process Customer Personal Data in the locations described in Annex 3, including Canada, the European Union, and the United States.
11.2 Transfers from the EEA, UK, and Switzerland. Where Customer Personal Data protected by EU GDPR, UK GDPR, or the FADP is transferred to a country not recognized as providing an adequate level of protection, the transfer is governed by the SCCs, completed as set out in Annex 4, together with the UK Addendum for UK transfers and the applicable amendments for Swiss transfers. Where a Sub-processor is certified under a recognized framework (such as the EU–US / UK–US Data Privacy Framework), that framework may serve as an additional or alternative safeguard.
11.3 Order of precedence. If there is any conflict between the SCCs and this DPA, the SCCs prevail with respect to the transfers they govern.
11.4 Adequacy. The parties acknowledge that Canada benefits from an adequacy recognition for commercial organizations under EU and UK law, which supports transfers of Customer Personal Data from the EEA and UK to Koarge in Canada.
13. Audits and Records
12.1 Koarge will make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
12.2 To satisfy 12.1, Koarge may first provide relevant documentation, security summaries, or third-party certifications or reports where available. An on-site or more detailed audit may be conducted no more than once per twelve months (unless required by a Supervisory Authority or following a Personal Data Breach), on reasonable prior written notice of at least 30 days, during business hours, without unreasonably disrupting Koarge's operations, subject to confidentiality, and at your expense.
14. Deletion or Return of Customer Personal Data
13.1 When your account is closed, or the Agreement is terminated, Koarge will, at your choice, return Customer Personal Data (including through the export functionality in the Service) or delete it and existing copies within the 90-day period described in our Privacy Policy, unless retention is required by applicable law. A request to return data after closure must be made within that 90-day period.
13.2 Where deletion is not immediately feasible (for example, data held in secure backups), Koarge will isolate and protect the data from further processing until deletion occurs on its normal backup cycle.
13.3 Deletion of Merchant Content, including Digital Product files you have uploaded, is governed by the Agreement and our Privacy Policy rather than this Section. You are responsible for retaining your own copies of any Digital Products you wish to keep.
15. Liability
14.1 Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement, and any reference to a party's liability means aggregate liability under the Agreement and this DPA combined.
14.2 Nothing in this DPA limits any rights that Data Subjects have under Applicable Data Protection Laws or the SCCs, including any third-party-beneficiary rights under the SCCs.
16. Term and Termination
This DPA takes effect when you accept the Agreement and continues for as long as Koarge processes Customer Personal Data on your behalf. Termination of the Agreement terminates this DPA, subject to Sections that survive by their nature (including Sections 10, 13, and 14).
17. Governing Law and Precedence
16.1 This DPA is governed by the laws of the Province of Manitoba and the federal laws of Canada applicable therein, except that the SCCs are governed as specified in Annex 4, and mandatory Applicable Data Protection Laws continue to apply.
16.2 This DPA supplements the Agreement. Except as expressly modified here, the Agreement remains in full force. Order of precedence for data-protection matters: (1) the SCCs (for transfers they govern), (2) this DPA, (3) the rest of the Agreement.
18. General
17.1 If any provision of this DPA is invalid or unenforceable, the remainder continues in effect, and the parties will replace the affected provision with a valid one achieving a similar result.
17.2 Koarge may update this DPA on notice to reflect changes in Applicable Data Protection Laws or its Sub-processors, provided the changes do not materially reduce protection for Customer Personal Data.
17.3 This DPA may be accepted electronically, and electronic acceptance is valid and binding.
19. Annex 1 — Details of Processing
A. Parties
The Controller is the Merchant identified in the Agreement. The Processor is Koarge Inc., 99 Dalhousie Drive, Winnipeg, Manitoba R3T 3M2, Canada.
B. Description of processing
Subject matter: Provision of the Koarge checkout Service.
Duration: For the term of the Agreement, plus the retention periods in the Privacy Policy.
Nature and purpose: Processing Customer Personal Data so the Merchant can accept payments and complete orders through the checkout on the Merchant's website — including facilitating payment through the Merchant's Stripe account, sending order receipts, storing order records, making them available to the Merchant, and, where the Merchant sells digital products, delivering the purchased file to Your Customers through an access-controlled download link.
Types of Customer Personal Data: name; email address; billing address; shipping address (where applicable); order and product details; communications relating to an order; delivery and download records relating to digital products (such as delivery and download timestamps, download counts, and IP address); and technical data such as IP address. Full payment card numbers are not processed by Koarge — card details are transmitted directly to Stripe.
Categories of Data Subjects: the Merchant's customers, shoppers, and website visitors who initiate or complete a purchase through the Service.
Special categories: none intended or required. The Merchant must not submit sensitive data except as necessary to fulfil an order, and must not upload Digital Products containing sensitive personal data.
Merchant Content: Digital Product files uploaded by the Merchant are Merchant Content, not Customer Personal Data, and are processed under the Agreement rather than this DPA, as set out in Section 2.4.
20. Annex 2 — Technical and Organizational Measures
Koarge maintains measures including: encryption of data in transit (TLS); access controls, authentication, and least-privilege access for personnel; segregation of production and non-production environments; secure, access-controlled hosting infrastructure (Hetzner, EU); reliance on Stripe's PCI-DSS–compliant systems for payment card data, with no storage of full card numbers or Merchant Stripe secret keys by Koarge; logging and monitoring for security and fraud prevention; regular backups with controlled restoration; incident-response procedures for Personal Data Breaches; automated malware and file-type screening of merchant-uploaded Digital Product files, including files contained within archives, with rejection of blocked file types and of encrypted or password-protected files that cannot be scanned; and access-controlled storage of merchant-uploaded images and Digital Product files in Amazon S3, delivered through expiring signed URLs subject to download limits rather than public access.
21. Annex 3 — Sub-processors
Sub-processors engaged to process Customer Personal Data:
Stripe, Inc. — Payment processing on the Merchant's connected account — USA/Ireland
Postmark — Transactional and receipt email delivery, including download links — USA
Hetzner Online GmbH — Hosting and infrastructure — Finland (EU)
Amazon Web Services (Amazon S3) — Storage and delivery of merchant-uploaded images, Digital Product files, and assets — USA (us-east-1)
The current authoritative list is maintained in, or linked from, our Privacy Policy, and may be updated in accordance with Section 7. Additional backend sub-processors may be added and disclosed as the Service evolves. Sub-processors that process only the Merchant's own account data (for example, analytics, advertising, marketing-email, and support tools) are Koarge's Controller-side providers and are addressed in the Privacy Policy rather than this Annex.
22. Annex 4 — Standard Contractual Clauses (completion)
For transfers governed by Section 11, the SCCs are incorporated by reference and completed as follows:
Module in operation: Module Two (Controller to Processor) where the Merchant is a controller; Module Three (Processor to Processor) where the Merchant acts as a processor.
Clause 7 (Docking clause): applies.
Clause 9 (Sub-processors): Option 2 (general written authorization); minimum notice period for changes: 30 days, per Section 7.3.
Clause 11 (Independent dispute resolution): does not apply.
Clause 17 (Governing law): the law of the EU Member State in which the data exporter is established; where the data exporter is not established in an EU Member State, the law of Ireland.
Clause 18 (Choice of forum and jurisdiction): the courts of that same Member State (or Ireland, as applicable).
Annex I (Parties, description, competent authority): as set out in Annex 1 of this DPA; competent Supervisory Authority determined per SCC Clause 13.
Annex II (Technical and organizational measures): as set out in Annex 2 of this DPA.
Annex III (Sub-processors): as set out in Annex 3 of this DPA.
UK transfers: the UK Addendum applies, with the SCCs as the "Approved EU SCCs," Tables completed using the information above, and neither party permitted to end the Addendum except as it provides.
Swiss transfers: the SCCs apply with references to the GDPR read as the FADP, the Swiss Federal Data Protection and Information Commissioner as competent authority, and protection extended to data of legal entities where required.