GDPR Compliance Summary

Your organization is the controller of the personal data in its store and decides why it is processed. Jaapi AB, a Swedish company, is its processor and acts on its instructions under the Data Processing Agreement. The full notice is the privacy policy.

Data Location: EU by default, one home region per store
Legal Basis: Contract performance, legal obligation, legitimate interest
Sign-in: Email link or your organization's SSO, no passwords
Last Updated: September 6, 2026

Data Processing Overview

What personal data the store holds and on what legal basis it is processed. Your organization sets the purposes for its store's data; the bases below are Jaapi's own, for the processing it does to run the service.

Data We Process

  • Account Data: Name, email address, role
  • Shipping Data: The addresses you enter
  • Order Data: Order history, credit balance and its history
  • Support Data: Support correspondence
  • Request Logs: IP address, page requested and browser identification, kept 30 days

Legal Basis

  • Contract Performance: Running the store for your organization: sign-in, orders, payment, fulfillment, support
  • Legal Obligation: Keeping the order records behind an invoice under the Swedish Bookkeeping Act
  • Legitimate Interest: Keeping the platform secure and running

Data Storage & Security

Each store has one home region: the EU by default, or the US where the customer chose it. Backups for every store are stored in the EU, and store data is never copied to another region. A customer that requires EU-only hosting gets it as a contractual commitment. Sub-processors outside the EU receive personal data only under the European Commission's standard contractual clauses or an adequacy decision.

Data Location

Where a store's personal data lives:

  • Application and database, EU stores: Nuremberg, Germany (Hetzner)
  • Application and database, US stores: Ashburn, Virginia (Hetzner)
  • Backups: Falkenstein, Germany (Hetzner), encrypted
  • Payments: Ireland (Stripe)
  • Email delivery: Belgium (MailerSend)
  • Our own email and team communication: EU (Google Workspace) and US (Slack)
  • Stores on a customer-owned domain that still points at our previous edge network: traffic passes through the US (Vercel) in transit and is not stored there

Security Measures

  • Every connection encrypted and authenticated
  • Backups and secrets encrypted; each database reachable only from its own server
  • Data separated per store; a session is bound to one store
  • No write channel to customer data outside the service APIs and an audited mutation lane
  • ISO 27001:2022 certified; annual external penetration test

The full list is on the security page.

Data Subject Rights

You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive the data you gave in a portable format. Requests are answered within one month, as GDPR Article 12 requires.

Your organization is the controller, and its administrators can view and correct your data and close your account with the store's own tools, so start with them. Jaapi erases what remains at your organization's request. A request sent to lynn@jaapi.store is passed on to your organization, and Jaapi helps with anything the tools do not cover. You can also complain to Integritetsskyddsmyndigheten (IMY), the Swedish supervisory authority.

Access: Request a copy of your personal data
Rectification: Correct inaccurate data
Erasure: Request deletion of your data
Data Portability: Receive data in machine-readable format
Object: Object to processing based on legitimate interest
Restrict Processing: Limit how we process your data

Data Retention

Store data is kept for as long as your organization uses the service, and after that only what Swedish law requires. The full retention table is in the privacy policy.

Account Data

Kept until your organization's store is deleted. Within 30 days of the end of the service, Jaapi exports the store's data on request, deletes its personal data and confirms the deletion.

Order Data

The order records behind an invoice, with the recipient's name and address, are kept for seven years after the end of the financial year, as the Swedish Bookkeeping Act requires.

Request Logs

Deleted after 30 days.

Session Data

Expired sessions are deleted 30 days after they expire.

Backups

Daily backups expire after 30 days and monthly backups after 24 months. Deleted data remains in them until then; backups are restored only to recover the platform.

Third-Party Processors

The vendors that process personal data on Jaapi's behalf are published, with location and the data each holds, on the vendors page. Each is under a data processing agreement.

Fulfillment Suppliers

Orders are produced and shipped by a curated network of approved on-demand manufacturing suppliers, usually one near the recipient. A supplier receives only what the order needs (recipient name, shipping address, contact details, any customs tax identifier, product specification), under order terms that limit its use to producing and shipping that order. Suppliers whose systems accept orders automatically are under data processing agreements; the rest are small local producers that take orders manually and are bound by the order terms alone. On request your store can be restricted to suppliers under data processing agreements.

Supplier identities are commercially confidential, so the current list, and which suppliers are under agreements, is disclosed to customers on request rather than published. Ask lynn@jaapi.store, and treat the list as confidential.

Sub-processor Changes: The vendors page is the current register. Your organization may object to a sub-processor on reasonable data protection grounds.

Contact & Compliance

Questions about privacy, data subject requests and security incidents go to Jaapi's data protection contact. Jaapi has not appointed a data protection officer, as the conditions of Article 37 GDPR do not apply.

Data Protection Contact

Lynn Smeria, Security Officer
lynn@jaapi.store

Incident Reporting

Monitoring is alert-driven, and both founders receive every alert. As your processor, Jaapi notifies your organization of a personal data breach without undue delay, and within 48 hours, of becoming aware of it, with the nature of the breach, the data and people affected, the likely consequences and the measures taken, so that it can meet its own 72-hour obligation. Every incident is recorded.

Audit Rights: Customer administrators and their auditors read Jaapi's policies and evidence on the signed-in pages of this trust center. Audits beyond that follow the data processing terms of the service agreement.