Data Processing Agreement
Article 28 GDPR. Applies where Rocket Juice processes end-customer data on a brand's behalf.
Draft, pending legal review. Written from the platform as built; not yet reviewed by counsel.
- Processor
- Rocket Juice s. r. o.
- Registered seat
- Vajanského 1955/58, 921 01 Piešťany, Slovak Republic
- Company ID (IČO)
- 57730393
- Tax ID (DIČ)
- 2122903222
- VAT
- Not registered for VAT
- Commercial register
- Obchodný register Okresného súdu Trnava, oddiel: Sro, vložka č. 63692/T
- Contact
- marek@getrocketjuice.com
- Document
- Rocket Juice — Data Processing Agreement
- Forms part of
- The Rocket Juice Brand Terms and Conditions
- Last updated
- 18 August 2026
- Version
- 1.0 — draft, pending legal review
1. WHAT THIS IS AND WHO IT BINDS
This Data Processing Agreement (the "DPA") is entered into between the business that operates a Brand account on the Platform (the "Controller") and Rocket Juice s. r. o. (the "Processor"), and forms part of the Rocket Juice Brand Terms and Conditions. It records the terms required by Article 28(3) of Regulation (EU) 2016/679 (the GDPR).
It applies only where the Processor processes personal data on the Controller's behalf — in practice, the end-customer data that reaches the Platform from the Controller's connected store and tracking parameters. Where Rocket Juice determines its own purposes — operating and securing the Platform, calculating what is owed, complying with its own legal obligations — it acts as an independent controller and its Privacy Policy applies instead, not this DPA. Clause 6.1 of the Brand Terms draws the same line.
Where this DPA conflicts with the Brand Terms, this DPA prevails.
2. THE CONTROLLER'S INSTRUCTIONS
2.1 Documented instructions
The Processor processes the personal data only on the Controller's documented instructions, including as to transfers to a third country, unless required to do otherwise by Union or Member State law — in which case the Processor informs the Controller of that requirement before processing, unless the law prohibits it on important grounds of public interest. Article 28(3)(a).
The Brand Terms, this DPA and the Controller's use of the Platform's own settings are the documented instructions. Nothing else is.
2.2 Unlawful instructions
The Processor informs the Controller without delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law, and may suspend the affected processing until the instruction is withdrawn or confirmed. Article 28(3), final paragraph.
2.3 The Controller's own responsibilities
The Controller warrants that it has a lawful basis for the processing it instructs, that it has provided the transparency information its customers are owed, and that it has obtained and honours any consent required for cookies, pixels, device access and conversion tracking under the ePrivacy rules. The Controller must not transmit special-category data, data of children, or data collected without a lawful basis. Clause 6.1.4 of the Brand Terms says the same.
3. CONFIDENTIALITY
The Processor ensures that persons authorised to process the personal data are bound by an obligation of confidentiality, contractual or statutory, and that access is limited to those who need it to provide the Services. Article 28(3)(b).
4. SECURITY
The Processor implements the technical and organisational measures set out in Annex II, which are appropriate to the risk within the meaning of Article 32 GDPR. The Processor may change them provided the level of protection is not reduced.
5. SUB-PROCESSORS
5.1 General authorisation
The Controller gives general written authorisation for the Processor to engage sub-processors. Those engaged at the date of this DPA are listed in Annex III. Article 28(2).
5.2 Changes, and the right to object
The Processor gives the Controller at least 30 days' notice of an intended addition or replacement, by e-mail to the Brand account's registered address and by updating Annex III. The Controller may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, either party may terminate the affected Services without penalty.
5.3 Liability for sub-processors
The Processor imposes on each sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for that sub-processor's performance. Article 28(4).
6. ASSISTANCE TO THE CONTROLLER
6.1 Data subject rights
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling requests to exercise rights under Chapter III GDPR. Article 28(3)(e). A request received directly by the Processor is forwarded to the Controller without undue delay and is not answered by the Processor, except where the Platform's own automated redaction path applies (clause 6.3).
6.2 Security, breach and impact assessments
The Processor assists the Controller in ensuring compliance with Articles 32 to 36, taking into account the nature of processing and the information available to it. Article 28(3)(f).
6.3 Erasure requests received through Shopify
Where the Controller's store is connected through Shopify, the Processor receives and actions the mandatory customers/redact and shop/redact topics automatically, removing the personal keys from the stored order payloads. Because the Platform stores only the minimised payload described in Annex I, most such requests find no personal data to remove.
7. PERSONAL DATA BREACHES
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and in any event in time to allow the Controller to meet its own obligation under Article 33(1). The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, and the measures taken or proposed. Article 33(2).
The Processor does not notify a supervisory authority or a data subject on the Controller's behalf unless instructed to.
8. RETURN AND DELETION
On termination of the Services, the Processor deletes or returns the personal data processed on the Controller's behalf, at the Controller's choice, and deletes existing copies — unless Union or Member State law requires storage. Article 28(3)(g).
Two things are deliberately outside that. Data the Processor holds as an independent controller — the commercial record of what was accepted and what became payable, and the accounting records it is required to keep — is retained under its own retention rules, because it is not processed on the Controller's behalf. And the minimised order record described in Annex I contains no personal data once the personal keys are removed, so it is retained as a commercial record rather than deleted.
9. AUDIT
The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. Article 28(3)(h).
The Controller may exercise this once in any twelve-month period on 30 days' notice, and additionally after a personal data breach affecting its data or on a supervisory authority's requirement. Audits are conducted in business hours, without unreasonable disruption, and subject to confidentiality. The Processor may satisfy an audit request by providing an independent third-party report where one covers the scope in question.
10. INTERNATIONAL TRANSFERS
The Processor does not transfer personal data processed under this DPA outside the European Economic Area except on the basis of an adequacy decision under Article 45, the European Commission's Standard Contractual Clauses under Article 46(2)(c), or another mechanism permitted by Chapter V, together with a transfer impact assessment and any supplementary measures assessed as necessary. [Transfer mechanism relied on per sub-processor — to be confirmed and listed in Annex III.]
Platform data is stored in the European Union, in the Frankfurt (europe-west3) region.
ANNEX I — SUBJECT MATTER OF THE PROCESSING
| Subject matter | Attributing sales made in the Controller's store to creator content, and reporting on that attribution. |
| Duration | The term of the Brand Terms, plus any period required by clause 8. |
| Nature and purpose | Receiving order events, matching them to a tracking parameter, recording the result, and reporting it to the Controller. |
| Categories of data subject | The Controller's customers who complete a purchase carrying a Rocket Juice tracking parameter. |
| Categories of personal data | The order reference, order value and currency, the time and status of the order, and the tracking parameter identifying the creator content. The Platform enforces this as an allowlist at ingest: the buyer's name, e-mail address, telephone number, billing and shipping address, IP address, browser and device details, referring page and advertising click identifiers are discarded on arrival and are not stored. |
| Transient processing | Where the Controller has connected Meta and the Controller's integration supplies them, an e-mail address and telephone number are hashed with SHA-256 in memory and the hash is transmitted to Meta as a server-side purchase event. The plaintext is not written to storage. |
| Special categories | None. The Controller must not transmit special-category data (clause 2.3). |
ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES
Article 32 GDPR. Each measure below is implemented in the Platform as at the date of this DPA.
- Data minimisation at ingest. An allowlist discards the personal fields of an incoming order before it is stored (Annex I).
- Tenant isolation in the database. PostgreSQL row-level security policies scope every tenant table to the requesting principal, enforced by the database rather than by application code, and denying by default when no principal is set.
- Least-privilege database roles. The web application connects as a role holding SELECT only, which is not the schema owner and does not bypass row-level security; the schema owner is used only by the service and by migrations.
- Secret management. Access tokens for connected stores and advertising accounts are held in a managed secret store and are never written to the application database in plaintext.
- Encryption. TLS in transit; encryption at rest as provided by the cloud platform.
- Access control. Authentication through a managed identity provider; server-side session cookies that are httpOnly, Secure and SameSite; role- and tenant-scoped authorisation on every endpoint.
- Webhook authenticity. Inbound webhooks and platform callbacks are verified by HMAC or signed request over the raw body before the payload is parsed.
- Segregation of environments. Production, staging and development run in separate environments with separate credentials and separate data.
- Logging and monitoring. Application and access logging, with end-customer identifiers excluded from log messages.
- Restoration. [Backup schedule, retention and tested restoration procedure — to be confirmed.]
ANNEX III — SUB-PROCESSORS
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Ireland Limited (Google Cloud) | Hosting, database, object storage, messaging, and the identity platform used for authentication | European Union (Frankfurt, europe-west3) |
| Meta Platforms Ireland Limited | Delivery and measurement of partnership advertising, and server-side conversion events, where the Controller has connected Meta | European Union, with onward transfer under the mechanism referenced in clause 10 |
| Besteron a.s., Prešovská 38/B, Bratislava – mestská časť Ružinov 821 02, Slovak Republic, Company ID (IČO): 47866233, registered in the Commercial Register of the Municipal Court Bratislava III, section: Sa, insert no. 6004/B, a payment institution authorised and supervised by Národná banka Slovenska under licence no. ODB-6111/2015-7 | Payment services for amounts owed by the Controller to creators | European Union |
Shopify is not listed as a sub-processor: where the Controller connects a Shopify store, Shopify is the Controller's own processor under the Controller's agreement with it, and Rocket Juice receives data from it on the Controller's instruction.
See also our Terms and conditions and Privacy Policy.