Omni Store
PricingCustomersDocsContact
Sign in Start free
EN FR
Omni Store
PricingCustomersDocsContact Sign in
Start free
EN FR
Omni Store / Legal

OmniStore Data Processing Agreement

Version 1.1.6 · Effective 2026-06-01 · Updated 2026-07-05

All policies

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use Policy
  • Refund Policy
  • Data Processing Agreement
  • DMCA / Copyright Policy
  • Imprint
  • Subprocessors

OmniStore Data Processing Agreement

Effective Date: June 1, 2026 Last Updated: May 24, 2026 Version: 1.0.0


Preamble

This Data Processing Agreement (the “DPA”) forms part of the Terms of Service at useomnistore.com/legal/terms (the “Principal Agreement”) between OmniStore (operated by Harold Voufack as an unincorporated individual operator, “OmniStore”, “Processor”, “we”) and you, the Merchant (“Merchant”, “Controller”, “you”). It is entered into to comply with Article 28 of Regulation (EU) 2016/679 (the “GDPR”), Article 28 of the UK GDPR, the comparable provisions of the Cameroonian Loi N° 2010/012 du 21 décembre 2010 (data-protection facets) and Loi N° 2010/021 du 21 décembre 2010, and the equivalent laws of any other jurisdiction in which a Data Subject whose Personal Data is Processed under this DPA is located.

This DPA applies whenever you Process Personal Data of Data Subjects in the European Economic Area, the United Kingdom, Switzerland, or any other jurisdiction whose data-protection law requires a written processor agreement, through the OmniStore Platform. By using the OmniStore Platform to Process such Personal Data, you accept this DPA in addition to the Principal Agreement.

If you require a separately-signed counterpart of this DPA (for example because your internal procurement procedures require it), email legal@useomnistore.com and we will provide one. The substantive provisions of any signed counterpart are identical to those in this DPA.


1. Definitions and roles

1.1 Definitions

Capitalised terms used in this DPA have the meanings given to them in the GDPR or in the Principal Agreement, except as defined below. The following definitions apply:

  • “Authorised Subprocessor” means a third party engaged by OmniStore to Process Personal Data on its behalf in connection with the provision of the Platform.
  • “Customer Personal Data” means Personal Data of the Merchant’s Customers, employees, suppliers, or other Data Subjects, that the Merchant uploads to or generates on the Platform and that OmniStore Processes on the Merchant’s behalf.
  • “Data Protection Laws” means the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the Loi N° 2010/012, the California Consumer Privacy Act and California Privacy Rights Act (where applicable), and any other applicable laws governing the Processing of Personal Data.
  • “Personal Data” has the meaning in Art. 4(1) of the GDPR.
  • “Processing” has the meaning in Art. 4(2) of the GDPR.
  • “Standard Contractual Clauses” or “SCCs” means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

1.2 Roles

For the Processing covered by this DPA, the parties are:

  • The Merchant is the Controller of the Customer Personal Data. The Merchant determines the purposes and the means of the Processing.
  • OmniStore is the Processor. OmniStore Processes the Customer Personal Data on documented instructions from the Merchant, as set out in the Principal Agreement and this DPA.

For Personal Data of the Merchant’s own staff (Account holders, Team Members, the OWNER), OmniStore acts as a separate Controller with respect to its own purposes (Account administration, security, billing, audit). That Processing is governed by the Privacy Policy at useomnistore.com/legal/privacy and is outside the scope of this DPA.


2. Scope of Processing

2.1 Subject matter

OmniStore Processes Customer Personal Data on behalf of the Merchant for the purpose of providing the Platform under the Principal Agreement.

2.2 Duration

OmniStore Processes Customer Personal Data for as long as the Merchant maintains an active Account on the Platform, plus the retention windows described in the Privacy Policy and in this DPA Section 9.

2.3 Nature and purposes

The nature and purposes of the Processing are as set out in the Principal Agreement: providing point-of-sale, inventory, sales-tracking, staff-management, promotion-management, and customer-facing storefront functionality.

2.4 Categories of Personal Data and Data Subjects

The categories of Personal Data Processed under this DPA, and the categories of Data Subjects, are set out in Schedule A (file dpa-schedule-a-data-categories.md). In summary:

  • Categories of Data Subjects: the Merchant’s Customers, the Merchant’s staff (where the Merchant invites them as Team Members), and any other natural persons identified in Customer Personal Data.
  • Categories of Personal Data: identification data, contact data, transaction data, communications data, and operational/behavioural data.

2.5 Documented instructions

The Merchant’s instructions to OmniStore in relation to the Processing are set out in the Principal Agreement, this DPA, and the Privacy Policy. The Merchant may issue further written instructions consistent with the Principal Agreement; OmniStore will use commercially reasonable efforts to comply, provided the instructions do not breach Data Protection Laws or require disproportionate effort. If OmniStore considers an instruction to breach Data Protection Laws, it will inform the Merchant.

2.6 Instructions outside the Platform’s standard functionality

The Platform’s standard functionality (recording sales, listing products, displaying a Storefront) is itself a documented instruction. The Merchant does not need to issue separate instructions for the Platform’s standard behaviour.


3. Authorised Subprocessors

3.1 General authorisation

The Merchant generally authorises OmniStore to engage Authorised Subprocessors to Process Customer Personal Data, subject to the requirements of this Section 3.

3.2 Current Authorised Subprocessors

The current list of Authorised Subprocessors is maintained at useomnistore.com/legal/subprocessors and is incorporated into this DPA by reference. The list includes for each subprocessor: name, purpose, categories of Personal Data, location, and (where applicable) the transfer mechanism used for international transfers.

3.3 Change-notice mechanism

OmniStore will inform the Merchant of any intended additions or replacements to the list of Authorised Subprocessors at least thirty (30) days before the change takes effect. Notification is by email to the Account email and by an update to the useomnistore.com/legal/subprocessors page.

3.4 Right to object

The Merchant may object on reasonable data-protection grounds to a new Authorised Subprocessor by emailing legal@useomnistore.com within the 30-day notice window with the subject “Subprocessor Objection - [Merchant name]”. Where the objection is reasonable, OmniStore will use commercially reasonable efforts to provide an alternative subprocessor or an alternative arrangement that does not involve the objected-to subprocessor for that Merchant. If no such alternative can be agreed within a further thirty (30) days, the Merchant’s exclusive remedy is to terminate the Subscription, with a pro-rata refund of pre-paid Fees for any period after termination.

3.5 Subprocessor obligations

OmniStore imposes on each Authorised Subprocessor data-protection obligations no less protective than those imposed on OmniStore under this DPA, including obligations of confidentiality, security, breach notification, and (where applicable) compliance with Standard Contractual Clauses for international transfers. OmniStore remains fully liable to the Merchant for the performance of each Authorised Subprocessor’s obligations.


4. Security measures

4.1 Technical and organisational measures

OmniStore implements appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, such data. The current measures are set out in Schedule A (file dpa-schedule-a-data-categories.md).

4.2 Personnel

OmniStore ensures that personnel with access to Customer Personal Data (today this is solely Harold Voufack, who operates OmniStore personally) are bound by appropriate confidentiality obligations.

4.3 Updates to security measures

OmniStore may update its security measures from time to time, provided that the overall level of protection is not diminished. Material reductions in the security measures will be communicated to the Merchant at least thirty (30) days in advance.


5. Assistance with Data-Subject rights

5.1 Forwarding requests

If OmniStore receives a request from a Data Subject who is a Customer of the Merchant exercising a right under Data Protection Laws (access, rectification, erasure, restriction, portability, objection, automated-decision-making), OmniStore will inform the Merchant of the request, generally within five (5) business days, and will not respond to the Data Subject directly unless the Merchant asks us to or unless Data Protection Laws require us to do so.

5.2 Assistance with response

OmniStore will provide reasonable assistance to the Merchant in responding to Data-Subject rights requests, taking into account the nature of the Processing. The Platform provides built-in mechanisms (Customer export, Customer deletion, sales export) that the Merchant can use to respond to most rights requests directly through the Admin App.

5.3 Charges

Assistance described in Section 5.2 is provided at no extra charge for the first such request per Customer per twelve (12) month period. For materially excessive or repetitive requests, OmniStore may charge a reasonable fee or refuse, as permitted by Art. 12(5) of the GDPR.


6. Personal-data breach notification

6.1 Notification timing

OmniStore will notify the Merchant of any personal-data breach (as defined in Art. 4(12) of the GDPR) affecting Customer Personal Data of that Merchant without undue delay and in any event within seventy-two (72) hours of OmniStore becoming aware of the breach.

6.2 Notification content

The notification will include, to the extent known at the time:

  • A description of the nature of the breach, including (where possible) the categories and approximate number of Data Subjects and Personal Data records concerned.
  • The name and contact details of the OmniStore point of contact for the breach (typically legal@useomnistore.com).
  • A description of the likely consequences of the breach.
  • A description of the measures taken or proposed to address the breach and to mitigate its possible adverse effects.

Where it is not possible to provide all of this information at once, OmniStore will provide it in phases as it becomes available.

6.3 No prejudice

OmniStore’s notification under this Section 6 is not an acknowledgement of fault or liability by OmniStore. The notification is provided to allow the Merchant to comply with its own obligations under Data Protection Laws (in particular Art. 33 and Art. 34 of the GDPR).

6.4 Cooperation

OmniStore will cooperate with the Merchant and provide reasonable assistance in investigating, mitigating, and remediating the breach, including assistance with notifications to supervisory authorities and (where required) to affected Data Subjects.


7. Audit rights

7.1 Compliance information

OmniStore will, on the Merchant’s reasonable written request and no more than once per twelve (12) month period (except where a supervisory authority requires more frequent audit or where there has been a personal-data breach), make available all information reasonably necessary to demonstrate compliance with OmniStore’s obligations under this DPA.

7.2 Audits

OmniStore will allow for and contribute to audits, including inspections, conducted by the Merchant or another auditor mandated by the Merchant, subject to the following:

  • The audit will be conducted on a date mutually agreed at least thirty (30) days in advance.
  • The auditor will be bound by appropriate confidentiality obligations.
  • The audit will be conducted in a manner that minimises disruption to OmniStore’s operations.
  • The Merchant bears the costs of the audit, except where the audit reveals material non-compliance, in which case OmniStore bears its own costs.

7.3 Third-party audits

Where OmniStore makes available the results of an independent third-party audit (e.g. SOC 2 Type II, ISO 27001 certification), the Merchant agrees that those results may, in OmniStore’s discretion, substitute for an on-site audit under Section 7.2. As of the effective date of this DPA, OmniStore does not hold such third-party certifications; this provision is forward-looking.


8. International transfers

8.1 Transfers covered

Some Authorised Subprocessors are located outside the European Economic Area, the United Kingdom, or other jurisdictions whose data-protection law restricts international transfers. Examples include Amazon Web Services (United States, for transactional email via SES), Cloudflare (global edge network), and Stripe (United States, for card processing).

8.2 Transfer mechanism

For transfers of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a third country that is not subject to an adequacy decision under the applicable law, the parties incorporate by reference into this DPA the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as approved by Commission Implementing Decision (EU) 2021/914, Module Two (Transfer Controller to Processor).

For the purposes of the Standard Contractual Clauses:

  • Data exporter: the Merchant.
  • Data importer: OmniStore.
  • Annex I.A - List of Parties: the Merchant’s Account details on file with OmniStore, and Harold Voufack, contactable at legal@useomnistore.com.
  • Annex I.B - Description of transfer: as set out in Schedule A.
  • Annex I.C - Competent supervisory authority: the supervisory authority of the EU/EEA Member State in which the Merchant has its principal place of business, or, where the Merchant is not established in the EU/EEA, the Irish Data Protection Commission (acting in its lead-supervisory-authority capacity where applicable).
  • Annex II - Technical and organisational measures: as set out in Schedule A.
  • Annex III - Authorised Subprocessors: as listed at useomnistore.com/legal/subprocessors.
  • Optional clauses:
    • Clause 7 (Docking) - not opted in.
    • Clause 9(a) (General written authorisation for subprocessors) - opted in, with the 30-day notice period set in Section 3.3 of this DPA.
    • Clause 11 (Redress) - independent dispute resolution body not opted in.
    • Clause 17 (Governing law) - the law of the Republic of Ireland (selected as a Member State of the European Union with established data-protection jurisprudence).
    • Clause 18 (Choice of forum and jurisdiction) - the courts of Ireland; subject always to Section 12 of the Principal Agreement for any matter outside the Standard Contractual Clauses.

8.3 UK GDPR transfers

For transfers subject to the UK GDPR, the parties incorporate the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office (the “UK Addendum”), as a complement to the Standard Contractual Clauses referenced above. Where there is any conflict between the UK Addendum and the Standard Contractual Clauses for UK GDPR transfers, the UK Addendum prevails.

8.4 Swiss FADP transfers

For transfers subject to the Swiss Federal Act on Data Protection (“FADP”), the Standard Contractual Clauses apply with the following adaptations: references to “Member State” include Switzerland; references to “GDPR” include the FADP; the competent supervisory authority is the Federal Data Protection and Information Commissioner.

8.5 Future transfer mechanisms

If a new transfer mechanism (e.g. an updated set of Standard Contractual Clauses, or a Data Privacy Framework adequacy decision) becomes available and the parties prefer to use it, the parties will use reasonable efforts to update this DPA to incorporate it.


9. Term, return, and deletion

9.1 Term

This DPA takes effect at the same time as the Principal Agreement and remains in force for as long as OmniStore Processes Customer Personal Data on behalf of the Merchant.

9.2 Return or deletion on termination

On termination of the Principal Agreement, OmniStore will, at the Merchant’s choice expressed in writing within thirty (30) days of termination, either:

  • Return the Customer Personal Data to the Merchant in a structured, commonly-used, machine-readable format (the Platform’s existing export functionality satisfies this); or
  • Delete the Customer Personal Data.

If the Merchant does not express a choice within the 30-day window, OmniStore will delete the Customer Personal Data under the retention schedule described in the Privacy Policy.

9.3 Retention required by law

OmniStore may retain Customer Personal Data after termination only to the extent required by applicable law, and only for the period required. Examples: invoices retained for ten (10) years for tax compliance; audit-log rows retained indefinitely for security and legal-defence purposes. Such retained data continues to be subject to the security and confidentiality obligations of this DPA.

9.4 Backup copies

OmniStore may retain Customer Personal Data in routine, secure backups for a maximum of ninety (90) days after deletion from the active production systems. Backup-resident copies will not be Processed for any purpose and will be overwritten in the normal course of backup rotation.


10. Liability and indemnification

10.1 Allocation

Liability between the parties arising out of this DPA is allocated as set out in the Principal Agreement (Section 9 of the Terms of Service: aggregate cap, exclusion of indirect damages, carve-outs). Nothing in this DPA increases the cap on aggregate liability under the Principal Agreement.

10.2 Compensation under GDPR Art. 82

Each party’s liability towards a Data Subject under GDPR Art. 82 is independent of the contractual liability under this DPA and is determined by GDPR Art. 82(2) - (5). Where one party has paid full compensation under Art. 82 for damage caused jointly, that party may claim contribution from the other party corresponding to the other party’s part of responsibility for the damage.

10.3 Indemnification

The Merchant indemnifies OmniStore against any third-party claim (including a Data Subject claim or a supervisory-authority enforcement action) arising from (a) the Merchant’s instructions, (b) the Merchant’s breach of its obligations as Controller, or (c) the content of the Customer Personal Data the Merchant uploads to the Platform, except to the extent the claim is caused by OmniStore’s breach of this DPA.


11. General

11.1 Order of precedence

If there is any conflict between this DPA and the Principal Agreement in relation to the Processing of Customer Personal Data, this DPA prevails to the extent of the conflict.

11.2 Modifications

OmniStore may update this DPA from time to time. Material modifications that adversely affect the Merchant’s rights or expand the Merchant’s obligations under this DPA will be communicated at least thirty (30) days before they take effect. Continued use of the Platform after the modifications take effect constitutes acceptance of the modified DPA.

11.3 Governing law

This DPA is governed by the law of the Republic of Cameroon, except where Section 8 incorporates Standard Contractual Clauses (which have their own choice-of-law set out at Section 8.2 in the Annex I.A).

11.4 Severability

If any provision of this DPA is held to be invalid, the remainder remains in effect. The invalid provision will be enforced to the maximum extent permissible.

11.5 Signatures

This DPA is effective on the date the Merchant accepts the Principal Agreement. A separately-signed counterpart may be requested under Section 11 of the Preamble.


Schedule A - Categories of Personal Data and Security Measures

The categories of Personal Data Processed under this DPA and the technical and organisational security measures applied to that Processing are set out in the companion document dpa-schedule-a-data-categories.md (also published at useomnistore.com/legal/dpa-schedule-a).


Contact

For all matters arising under this DPA, including Data-Subject-rights requests routed to OmniStore in error, breach notifications, audit requests, and Subprocessor objections:

legal@useomnistore.com


Changes to this DPA

We may update this DPA from time to time. Material changes will be communicated to OmniStore account holders by email and through the in-app banner at least 30 days before they take effect. The current version, effective date, and change summary appear at the top of this page.

Version history is maintained in CHANGELOG.md in the OmniStore legal documents repository.

Omni Store Omni Store

The operating system for independent shops.

EN FR

Product

  • Counter
  • Stockroom
  • Storefront
  • Pricing

Company

  • About
  • Customers
  • Contact
  • Help Center

Legal

  • Privacy
  • Terms
  • Cookies
  • Refunds
  • Imprint

© 2026 Omni Store. Built for independent shops.

Omni Store uses cookies to understand how the site is used and improve it. Analytics is optional - essential cookies are always on. See the privacy policy.