CommerceGorilla
ENEL
Back to website
Client services

Data Processing Agreement

Article 28 GDPR terms for Client personal data processed by CommerceGorilla on behalf of a business Client.

Last updated: 5 October 2026 · Version CG-DPA-2026-10-05-v1.0

1. Parties and purpose

This Data Processing Agreement ("DPA") applies where a business Client (the "Controller") engages VEDINOGLOU THEODORA, trading as CommerceGorilla (the "Processor") to process personal data on the Controller's behalf in connection with an accepted Proposal/SOW.

VEDINOGLOU THEODORA
Sole Proprietorship, operating under the commercial brand CommerceGorilla

VAT Number: EL116187459
G.E.MI. Number: 159799603000
Registered Address: Souliou 149, 13231, Petroupoli, Athens, Greece
Email: hello@commercegorilla.gr
Telephone: +30 698 738 3570

This DPA supplements the applicable CommerceGorilla Terms of Service and is intended to satisfy Article 28(3) and (4) GDPR. It does not by itself authorise any processing beyond the Services and documented instructions agreed with the Controller.

2. Scope and documented instructions

The Processor will process personal data only on documented instructions from the Controller, including as set out in the Proposal, Integration Schedule, support request or other written instruction, unless Union or Member State law requires otherwise. Where legally permitted, the Processor will inform the Controller before processing required by law.

If the Processor reasonably believes an instruction infringes applicable data-protection law, it will inform the Controller without undue delay and may suspend the affected instruction while the parties clarify it.

3. Processing details

The subject matter, duration, nature and purpose of processing, types of personal data and categories of data subjects are set out in Schedule 1 below and/or the applicable Proposal. The Controller is responsible for ensuring that its instructions and disclosure of personal data to the Processor are lawful.

4. Confidentiality

The Processor will ensure that persons authorised to process Controller personal data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality and receive access only as necessary for their tasks.

5. Security of processing

Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, the Processor will implement appropriate technical and organisational measures designed to provide a level of security appropriate to the risk. Baseline measures are described in Schedule 2 and may be adapted to the actual project and platforms.

6. Subprocessors

The Controller grants general written authorisation for the Processor to use subprocessors where reasonably necessary to provide the Services. A project-specific subprocessor list will be made available in the Proposal, DPA Schedule, or other durable written record before the relevant subprocessor processes Controller personal data.

The Processor will impose data-protection obligations on an authorised subprocessor that provide protection equivalent in substance to the relevant obligations in this DPA. The Processor remains responsible to the Controller for performance of the subprocessor's data-protection obligations to the extent required by Article 28 GDPR.

Where the Processor intends to add or replace a subprocessor processing Controller personal data, it will provide reasonable advance notice where practicable, giving the Controller an opportunity to raise a reasoned data-protection objection. The parties will work in good faith to resolve a substantiated objection; if no reasonable alternative is available, either party may terminate the affected Service without penalty for the unperformed portion.

7. International transfers

The Processor will not knowingly transfer Controller personal data to a country outside the EEA except where the transfer is permitted under Chapter V GDPR. Where required, the parties or relevant provider will rely on an applicable adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism, together with supplementary measures where required.

The Controller acknowledges that this DPA alone does not constitute the EU Standard Contractual Clauses for international transfers.

8. Data-subject rights

Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller, through appropriate technical and organisational measures where possible, to enable the Controller to respond to requests exercising data-subject rights. If the Processor receives a request relating to Controller data, it will forward the request to the Controller unless legally prohibited and will not respond on the Controller's behalf except on documented instruction or where required by law.

9. Personal-data breaches

The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller personal data and, where reasonably practicable, will provide an initial notification within 24 hours. The notification will include information reasonably available to the Processor concerning the nature of the incident, affected data/categories, likely consequences and mitigation taken or proposed. Information may be supplied in phases where not immediately available.

The 24-hour target is an operational notification target and does not alter the legal standards or allocate responsibility for regulatory notification decisions. The Controller remains responsible for determining whether notification to an authority or data subjects is legally required.

10. Assistance and compliance information

Taking into account the nature of processing and information available to it, the Processor will provide reasonable assistance with the Controller's obligations concerning security, breach response, data-protection impact assessments and prior consultation where Article 28(3)(f) GDPR applies.

The Processor will make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. Audits should normally begin with documentary evidence and questionnaires. On-site or intrusive audits must be reasonable, proportionate, subject to confidentiality/security restrictions, and normally conducted during business hours with reasonable notice, unless a regulator or material incident requires otherwise.

11. Return and deletion

At the end of the relevant Services, the Processor will, at the Controller's choice and subject to the technical capabilities of the relevant systems, return or delete Controller personal data under its control, unless Union or Member State law requires retention. Routine backup copies may remain until overwritten under ordinary retention cycles, provided they remain protected and are not restored except for legitimate continuity/security purposes.

12. Controller obligations

The Controller is responsible for establishing a lawful basis, providing required transparency notices, respecting data-subject rights, limiting data to what is necessary, issuing lawful instructions, maintaining appropriate account permissions and ensuring that special-category or high-risk data is not provided unless expressly agreed and appropriately protected.

13. Liability and precedence

Liability under this DPA is subject to the applicable CommerceGorilla Terms of Service to the extent permitted by law, but no contractual limitation overrides data-subject rights, regulatory powers or liability that cannot legally be limited. If this DPA conflicts with the Terms of Service on data-processing matters, this DPA prevails for those matters.

14. Governing law

This DPA is governed by Greek law. The jurisdiction clause in the applicable B2B Terms of Service applies, subject to mandatory GDPR rules concerning supervisory authorities and data-subject rights.

Schedule 1. Processing description

Subject matterProcessing necessary to perform the specific ecommerce, migration, integration, automation, analytics-configuration, support or related Services identified in the accepted Proposal.
DurationFor the duration of the relevant Services plus the limited period reasonably necessary for secure return/deletion and legally required retention.
Nature/purposeAccess, retrieval, organisation, migration, mapping, transmission, troubleshooting, configuration, support and other operations strictly necessary for the agreed Services and Controller instructions.
Typical data subjectsClient customers/prospects, Client staff/admin users, suppliers or other persons whose data is present in systems included in the project.
Typical personal dataContact details, account/customer identifiers, order/transaction metadata, shipping/billing details, support or CRM data, technical identifiers and other fields expressly required for the project.
Special-category dataNot intentionally required. The Controller must not provide special-category or criminal-offence data unless expressly agreed in writing and appropriate safeguards are defined.

Schedule 2. Baseline technical and organisational measures

  • Role-based or least-privilege access where supported.
  • Use of collaborator/delegated accounts instead of shared master credentials where available.
  • Multi-factor authentication on supported business systems where reasonably practicable.
  • Confidentiality obligations for authorised personnel.
  • Secure transfer methods appropriate to the data and platform.
  • Reasonable endpoint and account-security practices.
  • Access removal/review at project completion where applicable.
  • Incident escalation and documented breach-response process.
  • Data minimisation: access only to data reasonably necessary for the agreed task.
  • Use of reputable service providers and subprocessor due diligence proportionate to risk.

Schedule 3. Project-specific subprocessors

Complete for each project where CommerceGorilla appoints a provider to process Client personal data on its behalf. Client-selected platforms contracted directly by the Client are not automatically CommerceGorilla subprocessors.

ProviderService / processingLocation / transfer mechanism
To be completed in the Proposal/DPA record before relevant processing begins.

Acceptance

This DPA becomes binding when incorporated into an accepted Proposal/SOW, electronically accepted by both parties, or signed separately. The parties should retain a durable copy of the applicable version and completed schedules.

Legal & privacy Privacy Policy Cookie Policy Terms of Use Terms of Service Data Processing Agreement hello@commercegorilla.gr
© 2026 CommerceGorilla. All rights reserved.
PrivacyCookiesTermsTerms of Service Data Processing Agreement

Your privacy, your choice

We use necessary technologies to keep the site working. With your permission, optional analytics and marketing technologies may be used. Read our Cookie Policy.

Cookie preferences

Choose which optional technologies Gorilla may use. Necessary storage remains active because it supports core site functions and your privacy choices.

Necessary

Required for core functions and for remembering your privacy choice for up to six months.

Always on
Analytics

Helps us understand website performance and usage. Optional analytics must remain blocked until you allow this category.

Marketing

May be used for advertising measurement, audiences or remarketing. Marketing technologies must remain blocked until you allow this category.