Legal

GDPR and data processing

Last updated: 2 October 2026

When you connect your online store to sync.imode.si, we import data about orders and customers into the application. You are the controller of this data, and we process it only on your instructions. This document is a data processing agreement under Article 28 of the General Data Protection Regulation (GDPR) and forms an integral part of the terms and conditions.

  1. 1. Roles of the parties

    The controller is the client (online store), which determines the purpose and means of processing its customers’ data.

    The processor is the provider of the sync.imode.si service, which processes data solely to provide the analytics service.

  2. 2. Subject, purpose and duration

    The purpose of processing is to prepare overviews, analyses and reports on the client store’s sales: revenue, discounts, products, customers, abandoned carts and shipments.

    Processing lasts for as long as the service contract is in force, plus 30 days after termination for a possible export.

  3. 3. Types of data and data subjects

    • Data subjects: customers and visitors of the client’s store, and the client’s application users.
    • Data: full name, email address, phone, city and delivery address, order and cart contents, coupons and discounts used, payment and shipping method, shipment tracking numbers.

    The service does not need special categories of personal data (e.g. health data). If the store nevertheless stores such data in orders (e.g. in notes), the client informs the provider so that additional measures can be agreed.

  4. 4. Processor’s obligations

    • Processes data only on the client’s documented instructions and not for its own purposes.
    • Ensures that persons with access are bound by confidentiality.
    • Implements appropriate technical and organisational measures (section 5).
    • Assists the client in responding to data subject requests and with impact assessments.
    • Notifies the client of a personal data breach without undue delay, at the latest within 48 hours.
    • Returns or deletes the data at the end of the contract, at the client’s choice.
    • Allows the client to verify compliance and provides the necessary information.
  5. 5. Technical and organisational measures

    • Data separation: each client has a separate space; database rules prevent access to other clients’ data.
    • Encryption: all traffic uses HTTPS; store API keys are stored encrypted with AES-256.
    • Least privilege: the application has read-only access to the store and does not change store data.
    • Access control: personal user accounts, roles (viewer, editor), access granted only by an administrator.
    • Location: servers and database in the European Union.
    • Backups and the ability to restore data.
    • Abuse protection: rate limiting and form protection.
  6. 6. Sub-processors

    The client gives general authorisation for the following categories of sub-processors:

    • a cloud infrastructure provider for hosting the application and database (EU),
    • an email delivery provider (only for system notifications and reports).

    The provider informs the client of an intended addition or replacement of a sub-processor at least 14 days in advance; the client may raise a justified objection during that time. Sub-processors are bound by the same data protection obligations.

  7. 7. Data subject rights

    Store customers have the right of access, rectification, erasure, restriction of processing, portability and objection. They address requests to the store as controller.

    If we receive a request directly, we forward it to the client without delay. At the client’s request we delete or correct an individual’s data in the application; note that data is imported again from the store on the next sync, so it must also be corrected in the store.

  8. 8. Personal data breaches

    If a breach is suspected (e.g. unauthorised access), the provider immediately acts to limit the consequences, notifies the client within 48 hours at the latest and provides all the information needed for a possible notification to the Information Commissioner within 72 hours and to the data subjects.

  9. 9. Transfers to third countries

    Data is processed in the EU/EEA. Transfers to third countries are allowed only with prior notice to the client and with appropriate safeguards under Chapter V of the GDPR.

  10. 10. Return and deletion of data

    • The client can export data at any time as PDF, CSV or Excel.
    • After termination the provider keeps data for 30 more days for a possible export, then permanently deletes it, including the store access keys.
    • Data is deleted from backups as they rotate, at the latest within 90 days.
  11. 11. Controller’s obligations

    • Ensures a lawful basis for collecting customer data and sharing it for analytics.
    • Informs customers in its privacy policy about the use of external analytics tools.
    • Grants access to the application only to people who need it for their work.
  12. 12. Contact

    For questions about data processing, deletion requests or breach reports, write to info@imode.si. On request we send the client a signed copy of the data processing agreement.

Send questions about this document to info@imode.si.