Data processing agreement
The agreement under GDPR article 28 for customers who send their shoppers' addresses to RightDoor, with Passionate Talents B.V. as processor. Part of the Terms for every customer.
Last updated 8 October 2026.
1. Parties and how this agreement applies
This data processing agreement ("DPA") is between the customer who uses RightDoor (the controller, "you") and Passionate Talents B.V., Graan voor Visch 19905, 2132 WR Hoofddorp, the Netherlands, KvK 92791360 (the processor, "we").
It is part of the Terms of service and applies to every customer from the moment you send personal data to the service. No signature is needed. If you need a signed copy, ask at support@rightdoor.eu.
Words such as "personal data", "processing", "controller", "processor", "sub-processor" and "personal data breach" have the meaning the GDPR gives them.
2. Scope
This DPA covers the personal data you send to the RightDoor API to look up, validate or complete addresses, and the same data sent through access for AI agents (MCP) or a Shopify app if and when we offer them. It does not cover the data about your account, your users and your billing. For that data we are the controller and the privacy policy applies.
3. Details of the processing
| Item | Details |
|---|---|
| Subject matter | Checking postal addresses against the official Dutch and Belgian address registers (Kadaster BAG, BeST Address). |
| Nature | We receive an address in an API request, parse it, compare it with the registers in memory, return the result and discard the address. We count the distinct postcodes each customer looks up per day, to detect bulk extraction. |
| Purpose | To give you a verdict, a corrected address, suggestions and carrier-ready fields for the addresses you handle. |
| Duration | Each request, for as long as it takes to answer it. The only exceptions: postcodes stay in memory until the end of the day (UTC) for the distinct count, and with the address form the shopper's IP address stays in memory until then for its request limits. Only the count is stored. |
| Categories of personal data | Address details: street, house number, addition or box number, postcode, city, country. Any other text in the address lines, which may include a name or a company name. Free-form address text. An optional session id for suggestions, which you generate. With the address form: the shopper's IP address, in memory only. |
| Categories of data subjects | Your customers and the recipients of their shipments, and anyone else whose address you send. |
| Special categories | None. Don't send special categories of personal data or data about criminal convictions. |
4. Your instructions
We process the personal data only on your documented instructions. Each API request is an instruction to process the data in it as the documentation describes. The Terms, this DPA and the settings you choose in the dashboard are instructions too.
If the law requires us to process the data in another way, we tell you before we do, unless the law forbids that. If we believe an instruction breaks the GDPR, we tell you and may refuse to follow it.
You are responsible for having a legal basis for the processing and for informing your customers.
5. Confidentiality
Everyone who works on RightDoor for us is bound to confidentiality, by contract or by law. Only authorised RightDoor staff can access production systems, and only as far as their work needs. Because addresses are not stored, there is no store of your data for anyone to look into.
6. Security
We take the technical and organisational measures in Annex 1 to protect the personal data, taking into account the state of the art, the costs, and the risks for data subjects. We may change the measures, but never in a way that lowers the overall level of protection.
7. Sub-processors
You authorise us to use the sub-processors listed in Annex 2. We bind each of them by contract to data protection obligations that are at least as strict as this DPA. We remain responsible to you for their work.
We tell you by email, at least 30 days in advance, before we add or replace a sub-processor. You may object on reasonable data protection grounds within that period. If we can't resolve your objection, you may end the affected part of the service before the change, and we refund what you paid in advance for the time after that.
8. Requests from data subjects
We don't store the addresses you send, so we usually hold nothing that a request could concern. If a data subject contacts us about data you sent, we refer them to you, because we can't tell from our systems which customer sent it. We help you answer data subject requests where we reasonably can.
9. Data protection impact assessments
We give you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority. This DPA, its annexes and our documentation describe the processing; ask us at support@rightdoor.eu for anything else.
10. Personal data breaches
We notify you of a personal data breach that affects your data without undue delay, and at the latest within 48 hours after we become aware of it. We send the notice to the email address of your account.
The notice describes, as far as we know at that point, what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we took or propose. We add information as we learn more, and we take reasonable steps to contain the breach and limit its effects.
11. Deletion and return
We discard the personal data in each request as soon as we have answered it. When the agreement ends there is therefore nothing to return or delete. Error reports are scrubbed before they leave the service and contain no data from your requests.
12. Information and audits
We give you the information you need to show that this DPA is met, on request: for example a description of our measures and of our sub-processors' safeguards.
If that isn't enough, you may have an audit done, at your own cost, by yourself or by an independent auditor bound to confidentiality. Give us at least 30 days' notice. Audits take place during business hours, at most once a year unless a breach or a supervisory authority makes another one necessary, and must not disrupt the service or expose other customers' data.
13. International transfers
The API processes your data in the EU, in Frankfurt, Germany. Some sub-processors are US companies. Where personal data is transferred outside the European Economic Area, or accessed from outside it, we make sure an adequate safeguard applies: the EU-US Data Privacy Framework for certified companies, or the EU Standard Contractual Clauses. Annex 2 names the safeguard for each sub-processor.
14. Liability
The liability provisions of the Terms (section 17 of the Terms) apply to this DPA, as far as the GDPR allows. Article 82 GDPR, on the rights of data subjects to compensation, is not limited by this DPA.
15. Term and order of precedence
This DPA applies as long as we process personal data for you. On personal data, this DPA prevails over the Terms. A data processing agreement signed as part of an Enterprise contract prevails over this one. Dutch law applies and disputes go to the court named in section 22 of the Terms.
Annex 1: Security measures
- No storage of request data. Addresses are processed in memory and never written to the database, logs or error reports. Logs hold only the route, status, response time, key or account id and request id; query strings and request bodies are never logged.
- Scrubbed error reports. Only an allow-list of fields leaves the service. Request bodies, query strings, headers, addresses and credentials are removed.
- Encryption in transit. TLS on every connection to the API and the dashboard; HTTPS enforced with HSTS.
- EU hosting. The API and its database run in Frankfurt, Germany.
- Authentication. API keys are stored as a keyed hash (HMAC-SHA256 with a secret) and checked in constant time. Keys are accepted only in the Authorization header, never in URLs. Passwords are stored as hashes; two-factor secrets are encrypted.
- Account protection. Two-factor authentication is available for every account and required to create or rotate live keys and to change billing. Security and billing actions are recorded in an audit log.
- Abuse protection. Rate limits per account, limits on request sizes, and alerts when an account looks up an unusual number of distinct postcodes.
- Access control. Only authorised RightDoor staff can access production, each with a personal account and two-factor authentication. Staging and production use separate databases.
- Secure development. Automated tests and a dependency audit on every change, and security headers on every response.
- Incident handling. Security reports go to support@rightdoor.eu (also listed in /.well-known/security.txt). Incidents are investigated and notified as section 10 describes.
Annex 2: Sub-processors
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Prisma Compute and Prisma PostgresPrisma Data, Inc., Wilmington, Delaware, United States | Application hosting and database. Processes the addresses in API requests, in memory only. | Frankfurt, Germany | EU-US Data Privacy Framework (Prisma Data, Inc. is certified). |
| PostHog (EU Cloud)PostHog, Inc., San Francisco, United States | Error tracking. Receives scrubbed error reports, which contain no data from your requests. | Frankfurt, Germany (EU Cloud) | EU-US Data Privacy Framework and EU Standard Contractual Clauses, for any access from outside the EU. |
| Google WorkspaceGoogle Cloud EMEA Limited, Dublin, Ireland | Company email. Sees personal data only if you send it to us, for example in a support request. | EU and United States | EU-US Data Privacy Framework (Google LLC) and EU Standard Contractual Clauses. |
Only Prisma is in the request path. Stripe, Resend, Better Stack, Cloudflare and GitHub never receive the content of API requests. They handle our own account and billing data, as the privacy policy describes.
Passionate Talents B.V., Graan voor Visch 19905, 2132 WR Hoofddorp, the Netherlands. KvK 92791360 · VAT NL866173882B01. Questions: support@rightdoor.eu.