Data Processing Agreement
Last updated: 27.09.2026 · Version history
Need a signed copy? Sign online
Showing the annexes for and the parts common to all apps. Show all apps
This Data Processing Agreement ("DPA") is concluded between Progus sp. z o.o., ul. Sklepowa 27, 97-500 Radomsko, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for Łódź-Śródmieście in Łódź, XX Commercial Division of the National Court Register, under KRS number 0001078024, NIP 7722434496, share capital PLN 10,000.00 ("Progus", "Processor"), and the merchant that installs or uses any of the Services ("Merchant", "Controller").
This DPA forms part of our Terms & Conditions ("Terms") and applies from the moment the Merchant installs or uses a Service, whenever Progus processes personal data on the Merchant's behalf. The Merchant may also accept it electronically at progus.com/dpa/sign. Acceptance in electronic form satisfies the written form required by Article 28(9) GDPR. The person who accepts this DPA confirms that they are authorised to bind the Merchant. One acceptance covers all stores and all Services used by the same legal entity, including Services it starts using later; the Annex entries for such a Service apply from that moment, in the version then in force.
1. Definitions
"Services" means all applications, integrations and services provided by Progus, on any platform (such as Shopify, Wix, WordPress or Shoper) or directly, now or in the future. "GDPR" means Regulation (EU) 2016/679. "Data Protection Laws" means the GDPR and the laws implementing or supplementing it, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP") and, where they apply to the processing, the privacy laws of US states, including the California Consumer Privacy Act as amended ("CCPA"). "Merchant personal data" has the meaning given in section 2. "Sub-processor" means a third party engaged by Progus to process Merchant personal data (Annex III, part A); it does not include the Merchant-selected integrations (Annex III, part B). "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.
2. Roles and scope
The Merchant is the controller and Progus is the processor of the personal data of the Merchant's customers, store visitors and other persons described in Annex I ("Merchant personal data"). Where the Merchant itself is a processor for another controller, Progus acts as its sub-processor and the Merchant confirms that its instructions are authorised by that controller. Personal data of the Merchant's own account (owner name, e-mail, store domain, billing) is processed by Progus as an independent controller under our Privacy Policy and is outside this DPA.
Where the CCPA or a similar US state law applies, Progus acts as the Merchant's "service provider" or "processor". Progus does not sell or share Merchant personal data, does not retain, use or disclose it for any purpose other than providing the Services under this DPA or outside its direct business relationship with the Merchant, and does not combine it with personal data it receives from others, except as those laws permit. Progus informs the Merchant if it can no longer meet these obligations.
When the Merchant connects a third-party service with its own account (the Merchant-selected integrations in Annex III, part B), Progus transmits data to that service on the Merchant's instruction. That service acts under its own contract with the Merchant and is not a sub-processor of Progus; Progus is responsible for transmitting the data securely to the destination the Merchant configured.
3. Instructions
Progus processes Merchant personal data only on the Merchant's documented instructions, including with regard to transfers of personal data to a third country or an international organisation. These instructions are: the Terms, this DPA (including the transfers to the sub-processors and locations listed in Annex III, made under section 13), and the Merchant's configuration and use of the Services, including connecting Merchant-selected integrations. Further instructions must be given in writing and be consistent with the Services. Progus informs the Merchant if, in its opinion, an instruction infringes Data Protection Laws, and processes data otherwise only where required by EU or Member State law, in which case it informs the Merchant beforehand unless the law prohibits it.
4. Purpose limitation
Progus uses Merchant personal data only to provide, support and secure the Services for the Merchant. It does not use Merchant personal data for its own purposes, for advertising or to train AI models. Progus may use only aggregated or anonymised data, from which no person can be identified, to secure, maintain and improve the Services.
5. Obligations of the Merchant
The Merchant is responsible for the lawfulness of the processing it instructs and warrants that: (a) it has a valid legal basis under Data Protection Laws for the processing and for the transfers that result from its instructions; (b) it gives data subjects the information required by law, including about the Services and the Merchant-selected integrations it uses; (c) where the law requires consent, it obtains and documents it, in particular the consent of each real person before it creates a Progus AI Studio model profile of them (the Service's own consent request supports but does not replace this obligation), and the consent of store visitors to the conversion tracking and advertising pixels it enables in Progus COD Form, where the law applicable to its store requires it; (d) it does not use the Services to process special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences; and (e) its instructions comply with Data Protection Laws. To the extent permitted by law, the Merchant indemnifies Progus against claims of third parties, administrative fines and reasonable costs arising from processing Progus carried out in accordance with the Merchant's instructions where those instructions infringed Data Protection Laws, or from a breach of these warranties.
6. Confidentiality
Progus ensures that persons authorised to process Merchant personal data are bound by confidentiality obligations and access it only as needed to provide, support and secure the Services.
7. Security
Progus implements the technical and organisational measures described in Annex II, appropriate to the risk as required by Article 32 GDPR, and may update them provided the overall level of protection does not decrease.
8. Sub-processors
The Merchant gives Progus general authorisation to engage the sub-processors listed in Annex III, part A. Progus notifies any intended addition or replacement of a sub-processor at least 14 days before it takes effect, by e-mail to the signatory of every Merchant that accepted this DPA electronically and by publishing the change in the version history of this DPA on progus.com/dpa. Where a change is urgently needed for security reasons or to keep a Service running, Progus may make it immediately and notifies it without undue delay. The Merchant may object in writing to [email protected] within the notice period, giving reasonable grounds relating to data protection; if it does not object within that period, the change is deemed accepted. After a reasoned objection, Progus will make reasonable efforts to offer an alternative, such as a change of configuration or processing the Merchant's data without that sub-processor. If no alternative is available within 30 days, the Merchant may terminate the affected Service and Progus refunds, pro rata, the fees prepaid for the period after termination. Progus imposes on each sub-processor, by contract, data protection obligations equivalent to this DPA and remains fully responsible to the Merchant for its sub-processors' performance.
9. Assistance
Taking into account the nature of the processing, Progus assists the Merchant
in responding to data subject requests (for Shopify apps, including through
Shopify's customers/data_request and customers/redact
webhooks), and with security, breach notification, data protection impact
assessments and prior consultation under Articles 32 to 36 GDPR, using the
information available to it. If a data subject contacts Progus directly about
Merchant personal data, Progus refers them to the Merchant.
10. Personal data breaches
Progus notifies the Merchant without undue delay, and in any case within 48 hours after becoming aware of a personal data breach affecting Merchant personal data, with the information then available (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed), and supplements it as further information becomes available.
11. Deletion and return
When the Merchant uninstalls a Service or stops using it, on any platform, or
when the agreement for a Service ends, Progus deletes the Merchant personal data
processed by that Service within 30 days, unless EU or Member State law requires
it to be stored. For Shopify apps, the deletion is completed at the latest when
Shopify sends its shop/redact request, normally 48 hours after
uninstalling. Before uninstalling, the Merchant can export its data with the
Service's export features, where available, or ask for a copy at
[email protected]. Copies in backups are removed as the backups expire, at the
latest 35 days after the deletion. Progus confirms the deletion in writing on
request.
12. Audits and information
Progus makes available to the Merchant the information necessary to demonstrate compliance with Article 28 GDPR, in the first place by answering written questionnaires. Where that is not sufficient, the Merchant may carry out an audit, by itself or through an independent auditor bound by confidentiality, on 30 days' written notice, not more than once in 12 months (unless required by a supervisory authority or after a personal data breach), during business hours and at its own cost.
13. International transfers
Progus is established in the European Union. Where a sub-processor processes Merchant personal data outside the European Economic Area in a country without an adequacy decision, Progus ensures the transfer is covered by: (a) an adequacy decision, including the EU-US Data Privacy Framework for a certified recipient; (b) the SCCs, Module 3 (processor to processor), concluded between Progus and the sub-processor; or (c) another transfer mechanism under Chapter V GDPR. If an adequacy decision relied on (including the Data Privacy Framework) is invalidated or suspended, Progus relies on the SCCs or another Chapter V mechanism for the affected transfers, without the need to amend this DPA.
Where the Merchant is established outside the European Economic Area in a country without an adequacy decision, the parties agree, to the extent Progus transfers Merchant personal data to the Merchant, the SCCs, Module 4 (processor to controller), incorporated in this DPA by reference, with Progus as data exporter and the Merchant as data importer, without the optional Clause 7, with Polish law under Clause 17 and the courts of Poland under Clause 18, and with their Annex I completed from the parties' details and Annex I of this DPA.
For Merchant personal data subject to the UK GDPR, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner applies to the transfers described in this section, with its tables completed from this DPA and its Annexes. For Merchant personal data subject to the FADP, the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, references to the GDPR read as references to the FADP, and data subjects in Switzerland may bring claims in their place of habitual residence.
14. Liability
Liability of each party under this DPA is subject to the limitation of liability in section 11 of the Terms, which applies to all claims under the Terms and this DPA together, except where Data Protection Laws or the SCCs do not allow liability to be limited, and except for wilful misconduct and gross negligence. The exclusion of indirect damages in the Terms does not limit the obligations of Progus under this DPA.
15. Term, survival and order of precedence
This DPA applies for as long as Progus processes Merchant personal data. Sections 6, 11, 12, 14 and 17 survive the end of the agreement until the deletion under section 11 is complete, and longer where they concern claims. In matters of personal data the following order of precedence applies: the SCCs (where they apply), then this DPA with its Annexes, then the Terms, then other Progus policies.
16. Amendments and versions
The version of this DPA accepted by the Merchant remains in force until the Merchant accepts a newer version, except for the following changes, which Progus may make without a new acceptance: (a) updates of Annex III under the procedure in section 8; (b) changes required by Data Protection Laws, by a decision of a supervisory authority or court, or to adopt new SCCs or another transfer mechanism; and (c) changes that do not reduce the protection of Merchant personal data, including adding Annex entries for a Progus Service the Merchant starts using. Changes under (b) take effect 30 days after Progus notifies them by e-mail to the signatory of every Merchant that accepted this DPA electronically and publishes them in the version history, or earlier where the law requires. Changes under (c) take effect when they are published in the version history. Every version, with a summary of its changes, is published in the version history on progus.com/dpa.
17. Governing law and jurisdiction
This DPA is governed by Polish law. Disputes arising from it are settled by the courts competent for the registered office of Progus. This does not limit the rights of data subjects under Data Protection Laws or the rules on governing law and jurisdiction of the SCCs where they apply.
Annex I: Details of processing
Subject matter and duration: providing the Progus Services the Merchant uses, for as long as it uses them, plus the deletion period in section 11.
Nature and purpose: collecting, storing, displaying, transmitting and deleting data as needed to run the Services' features for the Merchant's store, to support the Merchant and to secure the Services.
Frequency: continuous, while a Service is in use.
Special categories of data: none. The Services are not designed to process special categories of personal data. In Progus AI Studio, photos of real people are used only to generate images of that person with their consent; they are not processed through specific technical means to uniquely identify a person.
Data subjects, categories of data and retention, by Service:
- Progus Store Locator: visitors of the store map: the coordinates of a searched place or approximate position, its country, city, region and postal code, the nearest location and the product searched for, with no IP address or visitor identifier (search statistics, deleted after 12 months); the visitor's IP address and browser data, processed transiently by Cloudflare to estimate an approximate position and by the map and address providers the map loads (Annex III). Persons who submit the "become a dealer" form: business name, address, e-mail, phone, website, social media links, opening hours and uploaded images. Persons whose contact details or photos the Merchant enters for its locations (e-mail, phone, fax, photos). Kept until the Merchant deletes them or uninstalls the Service.
- Progus Subscriptions: subscribers of the Merchant's store, including subscriptions the Merchant imports from another subscription app (such as Recharge, Skio, Loop, Appstle or Seal): name, e-mail, phone, delivery address, Shopify customer ID, subscription contents, prices and schedules, related order records, records of e-mails sent to them and the identifiers of their payment method at the payment provider (customer, mandate or token IDs; no card or bank account numbers); for Tpay BLIK payments, the IP address and browser user agent. Kept until the Merchant uninstalls the Service.
- InPost by Progus: customers of the Merchant's store: name, e-mail, phone, delivery address, chosen pickup point, order and parcel details and tracking; an address typed to search for a pickup point (not stored); the e-mail address used for a pickup point reminder. Kept until the Merchant uninstalls the Service.
- Progus AI Studio: real people whose model profile the Merchant creates: photos, name, e-mail, consent record, the generated profile and the generated images showing their likeness. The source photos are deleted after the profile is generated or when consent is withdrawn; a consent request link expires after 7 days. Kept until the Merchant deletes them or uninstalls the Service.
- Progus COD Form: buyers in the Merchant's store who use the cash on delivery form: first and last name, phone number, e-mail address (where the form asks for it), delivery address, order contents and totals. Phone verification: phone number and calling code, verification sessions (deleted after 7 days) and SMS logs (deleted after 60 days). Form events (deleted after 180 days). Hashed e-mail address and phone number with order blocking events, for fraud prevention. Where the Merchant enables conversion tracking: IP address, browser user agent and hashed e-mail, phone, name, city, region, postal code and country, sent to the advertising platforms the Merchant connects. Other data is kept until the Merchant uninstalls the Service.
- Progus Upsell: buyers in the Merchant's store: the order e-mail address, order ID and products of orders attributed to upsell offers, used to report the revenue from the offers. Recommendations are computed from catalog data and co-purchase counts, which contain no personal data. Kept until the Merchant uninstalls the Service.
- Progus Sticky Add to Cart: no personal data of the Merchant's customers is stored. The bar works in the visitor's browser; the visitor's IP address and browser data are processed transiently by the hosting providers to deliver it.
- Progus Trust Badges: no personal data of the Merchant's customers is stored. View statistics contain only the shop name and view counts. The visitor's IP address and browser data are processed transiently by the hosting providers to deliver the badges.
- All Services: any other personal data that the Merchant, its staff or its customers enter or upload into a Service (for example in free-text fields, custom fields, notes or files), processed for the same purposes and deleted in the same way as the data of that Service.
Annex II: Technical and organisational measures
As of 27.09.2026.
All Progus applications:
- Hosting on providers with independent security certifications (Amazon Web Services, Heroku/Salesforce, Fly.io, Cloudflare), in their managed data centres.
- Encryption at rest: application databases and their backups are encrypted by Amazon RDS (AES-256, keys managed in AWS KMS).
- Backups: automated daily database backups with point-in-time recovery, kept for 35 days for Progus Store Locator and 7 days for the other applications, and then deleted automatically.
- Encryption in transit: all traffic to our applications uses HTTPS (TLS).
- Two-factor authentication on all administrative accounts: cloud hosting, source code repositories and the Shopify Partner account.
- Access control: access to production systems and databases is limited to the managing director and the employees who need it for their work, and is removed on the day a person leaves.
- A written incident response procedure: containment, risk assessment, notification of Merchants within 48 hours and of the supervisory authority within 72 hours where required, and an incident register.
- Server logs are kept by hosting and logging providers for a limited period: 7 days on Fly.io, and in Better Stack 15 days for the Progus Store Locator application and 8 days for its storefront API. Cloudflare does not keep request logs.
- AI providers used by our support team work under business terms with training on customer data turned off.
- Storage limitation: the store's data is deleted when the Merchant uninstalls the application, at the latest when Shopify sends
shop/redact(section 11). - Progus COD Form: phone verification sessions are deleted automatically after 7 days, SMS logs after 60 days and form events after 180 days; fraud prevention identifiers are stored as hashes, not in plain text. Server logs are kept in Better Stack for 8 days.
- Progus AI Studio: a model profile of a real person is created only after that person confirms consent through an e-mail link, which expires after 7 days; the source photos are deleted after the profile is generated or when consent is withdrawn.
- Progus Trust Badges: view statistics contain only the shop name and view counts.
Progus Store Locator, in addition:
- All connections between application servers and the database use TLS with certificate verification.
- Data minimisation: map search statistics contain no IP address or visitor identifier; the IP-based position is determined by Cloudflare, which already handles each request, and is not stored with the statistic.
- Storage limitation: automatic deletion of search statistics after 12 months and of the store's data on uninstall, with a second deletion pass on Shopify's
shop/redact. - Error reports from the storefront map (Sentry) are stored in Sentry's European Union region, kept for up to 90 days and exclude user details, cookies, request headers and form contents.
- Credentials: database credentials are kept in the hosting providers' secret stores, not in source code; merchants' access tokens are stored server-side only and never sent to the browser.
Annex III: Sub-processors and Merchant-selected integrations
Each entry gives the provider, the purpose, the data and the location. Where a location is given as the United States, Progus treats the processing as a transfer outside the European Economic Area even if the provider also uses data centres in the European Union (section 13).
Part A. Sub-processors engaged by Progus
All applications:
- Amazon Web Services, Inc.: database hosting and encrypted backups (United States, us-east-1). Data: the Merchant personal data stored by the Services.
- Cloudflare, Inc.: content delivery, caching and protection against attacks (global network). Data: IP address, browser data and request contents in transit.
- Gleap GmbH: support chat (European Union), including session replays of the Merchant's admin panel. Data: the contents of support conversations, including any Merchant personal data the Merchant's staff shares, and, in Progus Subscriptions, the subscriber details its AI support agent looks up by e-mail at the request of the Merchant's staff.
- Anthropic PBC and OpenAI: AI tools used by our support team to investigate and answer support requests, under business terms with training on customer data turned off (United States). Data: the contents of support requests and the Merchant personal data needed to investigate them.
- Google (Google Workspace): company e-mail, including transactional e-mails sent from [email protected] and [email protected] (European Union and United States). Data: recipient e-mail address and message contents.
Progus Store Locator:
- Salesforce, Inc. (Heroku): application servers and storefront API (United States). Data: all data processed by the application.
- Fly.io, Inc.: application servers (European Union, Amsterdam) and storefront API (United States, Los Angeles). Data: all data processed by the application.
- Cloudflare, Inc.: approximate position of map visitors from their IP address; storage of location photos and dealer images (Cloudflare R2) (global network). Data: IP address; photos and images.
- Better Stack, Inc.: server log storage, 15 days for the application and 8 days for the storefront API (United States). Data: IP address, browser data and request details.
- Functional Software, Inc. (Sentry): error reports from the storefront map (European Union, Germany). Data: technical error data, without user details, cookies, request headers or form contents.
- PostHog, Inc.: product analytics and session replays of the merchant admin panel, with form inputs and third-party personal data masked (European Union). Data: usage events of the Merchant's staff.
- OpenStreetMap Foundation: map tiles for the default Progus map style and as a fallback, and Nominatim, which turns a browser-provided position into an address (United Kingdom). Data: visitor's IP address and browser data, position.
- Unwired Labs (LocationIQ): address suggestions in the map search bar (United States endpoint). Data: text typed by the visitor, IP address.
- Google (Google Maps Platform): geocoding of the Merchant's store addresses and of addresses from dealer applications; on paid plans, Places address suggestions and Google Fonts on the dealer application form (United States). Data: addresses; the applicant's IP address, browser data and typed text.
- TomTom International B.V.: geocoding of the Merchant's store addresses and of addresses from dealer applications (European Union, Netherlands). Data: addresses.
- Cloudinary Ltd.: storage and delivery of older location photos (United States). Data: photos, visitor's IP address when a photo is shown.
Progus Subscriptions:
- Fly.io, Inc.: application servers (United States, Virginia) and the Subscriptions MCP connector (European Union, Frankfurt). Data: all data processed by the application.
- Resend: transactional emails to subscribers (United States; Resend, Inc.). Data: subscriber name, e-mail and the contents of the e-mail, such as upcoming orders, subscription details and payment updates.
- PostHog, Inc.: product analytics and session replays of the merchant admin panel, with form inputs and screens showing customer data masked (European Union). Data: usage events of the Merchant's staff.
- OpenAI: subscription plan suggestions (United States). Data: product catalog only, no personal data.
InPost by Progus:
- Fly.io, Inc.: application servers (European Union, Amsterdam). Data: all data processed by the application.
- Resend: pickup point reminder e-mails (United States; Resend, Inc.). Data: customer e-mail address and order details.
- Unwired Labs (LocationIQ): pickup point search by address (United States endpoint). Data: the address typed by the customer.
- Google (Google Maps Platform): pickup point map loaded in the customer's browser (United States). Data: customer's IP address, browser data and map position.
Progus AI Studio:
- Fly.io, Inc.: application servers (United States, Chicago). Data: all data processed by the application.
- NexusAI Services LLC (Kie.ai): image generation, which Kie.ai carries out with image models of OpenAI or Google (United States). Data: product images and instructions and, for every campaign that uses a model profile of a real person, that person's likeness.
- OpenAI: creation of model profiles from the person's photos, text generation and quality checks of generated images (United States). Data: photos and generated images of the person, product content.
- Resend: consent requests and notification e-mails (United States; Resend, Inc.). Data: name and e-mail address of the person asked for consent, e-mail contents.
- Cloudflare, Inc. (Cloudflare R2): storage of campaign images, including copies of a model's likeness (global network). Data: images.
- PostHog, Inc.: product analytics and error diagnostics of the merchant admin panel (European Union). Data: usage events of the Merchant's staff.
Progus COD Form:
- Salesforce, Inc. (Heroku): application servers (United States). Data: all data processed by the application.
- Walkover Web Solutions Pvt. Ltd. (MSG91): SMS one-time passwords for phone verification (India; the service is hosted in the United States or Germany). Data: buyer's phone number and the shop name.
- Better Stack, Inc.: server log storage (United States). Data: IP address, browser data and request details.
- Google (Google Fonts): fonts of the storefront form, loaded in the buyer's browser (United States). Data: buyer's IP address and browser data.
- Cloudflare, Inc. (Cloudflare R2): storage of geographic reference data and icons (global network). Data: no personal data.
Progus Upsell:
- Fly.io, Inc.: application servers (United States, Virginia). Data: all data processed by the application.
- OpenAI: product recommendations (United States). Data: product catalog and co-purchase counts only, no personal data.
Progus Sticky Add to Cart:
- Fly.io, Inc.: application servers (United States). Data: IP address and browser data of visitors in transit.
- Cloudflare, Inc. (Cloudflare R2): storage of sticker images (global network). Data: no personal data.
Progus Trust Badges:
- Fly.io, Inc.: application servers (United States, San Jose). Data: IP address and browser data of visitors in transit.
- Cloudflare, Inc.: storage of images the Merchant uploads (Cloudflare R2), and view statistics (Cloudflare Workers and D1) (global network). Data: images; shop name and view counts, no personal data.
Part B. Merchant-selected integrations
The following services receive Merchant personal data only if the Merchant connects or enables them, with its own account or by its own choice. They are not sub-processors of Progus (section 2): each acts under its own terms with the Merchant, which is responsible for choosing them and, where required, for concluding its own data processing and transfer agreements with them.
Progus Store Locator: map styles the Merchant selects instead of the Progus styles.
- Google (Google Maps), Mapbox, Inc. and Apple Inc. (MapKit JS): map display (United States). Data: visitor's IP address, browser data and the map area viewed.
- OpenStreetMap France ("Cold" map style): map tiles (European Union, France). Data: visitor's IP address and browser data.
Progus Subscriptions:
- Mollie B.V.: recurring payments through the Merchant's Mollie account (European Union, Netherlands). Data: subscriber name and e-mail, amounts, payment and mandate identifiers.
- Krajowy Integrator Płatności S.A. (Tpay): recurring payments through the Merchant's Tpay account (European Union, Poland). Data: subscriber name and e-mail, amounts, payment identifiers; for BLIK payments also the IP address and browser user agent.
- Adyen N.V.: recurring payments through the Merchant's Adyen account, where available (European Union, Netherlands). Data: subscriber name and e-mail, amounts, payment identifiers.
- Klaviyo, Inc.: subscription events for the Merchant's own Klaviyo account, for each event type the Merchant enables (United States). Data: subscriber e-mail, phone, name, Shopify customer ID and subscription contents with prices.
- The Merchant's own AI assistant (for example Claude or ChatGPT) connected through the Progus Subscriptions MCP connector: answering the Merchant's questions and carrying out the actions it asks for (location chosen by the AI provider the Merchant uses). Data: the subscriber and subscription data the Merchant requests.
InPost by Progus:
- InPost sp. z o.o. and other InPost group companies (ShipX, points and InPost Global APIs), with the Merchant's own InPost account: shipments, labels and tracking (European Union, Poland). Data: receiver name, e-mail, phone, delivery address, pickup point and parcel details.
- Apilo sp. z o.o.: shipments through the Merchant's Apilo account (European Union, Poland). Data: receiver name, e-mail, phone and delivery address.
- Apaczka: shipments through the Merchant's Apaczka account (European Union, Poland); Apaczka passes the data to the carrier that handles the parcel, ORLEN Paczka or DPD. Data: receiver name, e-mail, phone and delivery address.
Progus COD Form: advertising and analytics platforms the Merchant connects for conversion tracking.
- Server-side conversion events: Meta Platforms (Conversions API), TikTok (Events API) and Google (Google Analytics 4 Measurement Protocol). Data: hashed e-mail, phone, first and last name, city, region, postal code and country, IP address, browser user agent, order value and products. Location: the platform's infrastructure, including outside the European Economic Area.
- Browser pixels on the COD form: Meta Pixel, Google Ads, TikTok, Snapchat, Pinterest, X, Microsoft Bing, Taboola, Reddit, Kwai and ShareChat. Data: the platform's cookies and identifiers, IP address, browser data and conversion events. Location: the platform's infrastructure, including outside the European Economic Area.
Version history
- 27.09.2026: Progus COD Form now deletes store data on uninstall like the other Progus applications, so the exception in section 11 is removed; customer data of stores that uninstalled it earlier has been deleted. Annex I: Progus COD Form data other than the data with its own retention period is kept until the Merchant uninstalls the Service. Section 16: changes that do not reduce the protection of Merchant personal data take effect when they are published in the version history. Annex II: Progus COD Form server logs are kept for 8 days. Annex III: removed unpkg and Mapbox right-to-left text support, because these files are now served from Progus's own servers.
- 26.09.2026: First version offered for signing online at progus.com/dpa/sign. Covers all Progus Services on every platform, now and in the future, and adds: Merchant obligations and warranties, purpose limitation, CCPA service provider terms, transfer mechanisms (SCCs Module 3 and 4, UK Addendum, Swiss FADP, fallback if the Data Privacy Framework ends), deletion within 30 days of uninstalling with backups gone within 35 days (with a stated exception for Progus COD Form), e-mail notice of sub-processor changes to signatories, rules on amendments and versions, governing law and jurisdiction. Annex I and Annex III now describe every Progus application (Store Locator, Subscriptions, InPost, AI Studio, COD Form, Upsell, Sticky Add to Cart, Trust Badges), and Annex III separates sub-processors engaged by Progus from integrations the Merchant selects with its own account. Annex III changes: added Google Workspace, OpenStreetMap Foundation map tiles, Mapbox (text support), unpkg, Google Places and Fonts on the dealer form, Cloudflare R2, MSG91, NexusAI Services LLC (Kie.ai) with the model likeness; removed MapTiler, TomTom and Mapbox as map styles and Brevo (used only for Progus's own e-mails to merchants).
- 25.09.2026: Annex III: Heroku (Salesforce) application hosting for Progus Store Locator is located in the United States only.
- 24.09.2026: Annex II split into measures for all applications and additional measures for Progus Store Locator, with the actual log retention periods (Fly.io, Better Stack, Sentry). Annex I and Annex III completed for Progus Subscriptions, InPost by Progus and Progus AI Studio; support chat and support AI tools listed for all applications. The IP-based position in Progus Store Locator is determined by Cloudflare, so ip-api.com is no longer a sub-processor.
- 23.09.2026: First published version.