Legal

Data Processing Agreement

The terms under which Tachyprint processes your end customers' personal data on your behalf.

Last updated: 2026-09-25

1. Subject Matter and Duration

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service between Tachyprint ("Processor") and the print shop business that operates a Tachyprint shop ("Controller"). By accepting the Terms of Service, the Controller also accepts this DPA. It applies for as long as Tachyprint processes personal data on the Controller's behalf under the Terms.

2. Roles of the Parties

The Controller determines the purposes and means of processing personal data belonging to its own end customers. Tachyprint acts solely as a Processor, processing that personal data only on the Controller's documented instructions, as set out in this DPA and the Terms of Service.

3. Nature and Purpose of Processing

Tachyprint processes personal data to provide the ordering, order-tracking, admin dashboard, and notification functions of the Service: accepting orders, storing uploaded print files, calculating price estimates, and sending status-update emails on the Controller's behalf.

4. Categories of Data Subjects and Personal Data

Data subjects: the Controller's own end customers who place orders through the Controller's shop.

Personal data: names, email addresses, phone numbers, order details, and files uploaded for printing, which may themselves contain personal data depending on their content.

5. Controller Instructions

Tachyprint will process personal data only as necessary to provide the Service and in accordance with the Controller's instructions as reflected in the Controller's shop configuration and use of the Service, unless required to do otherwise by EU or Greek law. If we believe an instruction infringes applicable data-protection law, we will inform the Controller before carrying it out.

6. Confidentiality

Tachyprint ensures that personnel authorized to process personal data under this DPA are bound by an appropriate obligation of confidentiality, whether contractual or statutory.

7. Security Measures

Tachyprint implements appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including encryption of data in transit, access controls, and regular software updates to the infrastructure hosting the Service.

8. Sub-processors

The Controller authorizes Tachyprint to engage the following sub-processors to provide the Service: Vercel (website hosting), Supabase (database), Cloudflare (DNS, custom domains, network security), Resend (transactional email delivery), Sentry (error tracking), Render (back-office hosting), Upstash (rate limiting), Google Places (business verification), and Slack (internal account notifications).

Tachyprint will impose data-protection obligations on any sub-processor that are no less protective than those in this DPA, and remains responsible for each sub-processor's compliance. We will provide reasonable notice before adding or replacing a sub-processor materially involved in processing the Controller's end-customer data.

9. Assistance with Data Subject Requests

Taking into account the nature of the processing, Tachyprint will provide the Controller with reasonable assistance, through the Service's own tools where available, to respond to requests from the Controller's end customers to exercise their data-subject rights.

10. Personal Data Breach Notification

Tachyprint will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's end-customer data, and will provide the information reasonably available to us to help the Controller meet its own breach-notification obligations.

11. Deletion or Return of Data on Termination

On termination of the Service, Tachyprint will, at the Controller's choice, delete or make available for export the personal data processed on the Controller's behalf, except to the extent retention is required by law.

12. Audit Rights

On reasonable request, Tachyprint will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, subject to reasonable notice and confidentiality safeguards.

13. International Transfers

Where a sub-processor engaged under this DPA processes personal data outside the European Economic Area, Tachyprint ensures that appropriate safeguards under GDPR, such as Standard Contractual Clauses or an equivalent certified mechanism, are in place before the transfer occurs.

14. Acceptance

Accepting the Tachyprint Terms of Service, including at trial signup or on converting to a paid plan, constitutes acceptance of this DPA in full.

Company details

Legal entity:
<<FILL: legal entity name>>
Trading name:
Tachyprint
Registered address:
<<FILL: registered address>>
VAT number:
<<FILL: VAT number (ΑΦΜ)>>
Company registry number (ΓΕΜΗ):
<<FILL: company registry number (ΓΕΜΗ)>>
Contact:
support@tachyprint.com