← Rechna

Data Processing Agreement

Last updated: 1 August 2026 · Deutsche Fassung: AVV

This Data Processing Agreement (DPA) forms part of the Terms of Service and sets out how Rechna processes personal data on your behalf under Art. 28 GDPR. It applies whenever you use Rechna to issue, deliver, or archive invoices. No signature is required — installing the app accepts it.

1. Roles

For the order and customer data Rechna reads to issue invoices — line items, amounts, taxes, and your customers' names, billing addresses, email addresses, and VAT IDs — you (the merchant) are the controller and Rechna is the processor. Rechna processes this data only on your documented instructions, the instruction being your use of the app (issuing, correcting, delivering, archiving, exporting). Rechna acts as an independent controller only for your merchant-account data, which is covered by the Privacy Policy, not this DPA.

2. Subject matter, nature, purpose, duration

Subject matter: creating legally compliant invoices from your Shopify orders and retaining them. Nature and purpose: reading order and customer data through Shopify's APIs, rendering invoice documents (PDF, ZUGFeRD, XRechnung), optionally emailing them to the customer, and archiving them write-once for the statutory retention period. Duration: for as long as the app is installed — plus, for the archived invoices themselves, the statutory retention period (Section 8).

3. Categories of data and data subjects

Data subjects: your customers (buyers). Data categories: name, billing address, email address, VAT ID where present, and the transaction data of their orders (items, quantities, prices, taxes). No special-category data (Art. 9 GDPR) is processed, and Rechna requests no access to payment credentials.

4. Our obligations

5. Sub-processors

You authorise the sub-processors listed on the Sub-processors page. We remain responsible for their performance. We will give notice before adding or replacing one; if you object on reasonable data-protection grounds, your remedy is to disable the affected feature or uninstall.

6. International transfers

Processing and storage take place in the EU (AWS eu-central-1, Frankfurt). Administration from Switzerland relies on the European Commission's adequacy decision for Switzerland. Optional email delivery uses Resend (United States) under Standard Contractual Clauses and transfers only the recipient's email address and the invoice document; it runs only if you enable delivery.

7. Security

Encryption in transit (TLS) and at rest; the invoice archive is write-once (S3 Object Lock, compliance mode) with no delete path in the application; production access limited to the operator over audited sessions with no public admin interface; read-only Shopify scopes — Rechna cannot modify your store; invoice contents and webhook payloads are not logged.

8. Return and deletion

On uninstall we delete your shop's data — settings, seller details, drafts — in response to Shopify's shop/redact request. The archived invoices are accounting records under a statutory retention obligation (§147 AO, §14b UStG); they are technically locked against deletion for that period, which Art. 28(3)(g) GDPR expressly accommodates, and are deleted after it expires. You can export your archive (ZIP with CSV index) before uninstalling. We honour Shopify's customers/redact and customers/data_request topics within the same statutory limits.

9. Audit

On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate compliance with this DPA. Contact: hello@anmelda.com.