WPXFacets Data Processing Agreement

This Data Processing Agreement (the DPA) forms part of the agreement between the Customer and SC WEBIXKIT SOLUTIONS S.R.L., trading as WPXFacets, for the WPXFacets managed Elasticsearch service (the Service). It applies where WPXFacets processes personal data on behalf of the Customer in connection with the Service.

The Customer is the controller and WPXFacets is the processor for the processing described in Annex II. WPXFacets remains an independent controller for its own account, billing, security, support, and legal-compliance processing; that separate processing is governed by the WPXFacets Privacy Policy and is not covered by this DPA.

1. Contract documents

The parties adopt the European Commission’s standard contractual clauses between controllers and processors contained in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (the Clauses).

The complete DPA consists of:

  1. the unmodified English Official Journal PDF of Decision (EU) 2021/915, supplied with this DPA and identified by SHA-256 a4517774d1427c3c72b76aa3882e5242d26544296bded6033dadfc7fd8b27ee3;
  2. the permitted selections in section 2 below; and
  3. Annexes I, II, III, and IV below.

The English text governs. Any Romanian or German copy supplied by WPXFacets is for reference only. If this DPA or another agreement between the parties conflicts with the Clauses, the Clauses prevail.

The Clauses under Decision (EU) 2021/915 concern the controller-processor relationship under Article 28 GDPR. They are not the separate standard contractual clauses for transfers of personal data outside the EEA.

2. Permitted selections in the Clauses

The parties make the following selections without otherwise modifying the Clauses:

  • In Clause 1(a), the parties select Option 1, Article 28(3) and (4) of Regulation (EU) 2016/679 (GDPR).
  • The optional Clause 5 (Docking clause) is not included.
  • In Clause 7.7, the parties select Option 2, general written authorisation for sub-processors.
  • Under Clause 7.7 Option 2, WPXFacets must give the Customer at least 30 days’ written notice before a new or replacement sub-processor begins processing personal data. The Customer may object on reasonable data-protection grounds during that notice period.

3. Documented instructions

The Customer instructs WPXFacets to process Customer Data only as necessary to provide, secure, support, retain, and delete the Service as described in this DPA, the parties’ agreement, and the Customer’s use of the Service controls.

Documented instructions include the Customer’s configuration and use of the Service, selection of an available EU hosting location, indexing and deletion requests, Search Analytics enable or disable actions, complete Search Analytics dataset deletion, support requests, and service cancellation. An instruction outside the agreed Service scope may require a separate agreement and reasonable fees. WPXFacets will inform the Customer immediately if, in its opinion, an instruction infringes applicable data-protection law, as required by the Clauses.

4. Sub-processor authorisation and notice

The Customer gives WPXFacets general written authorisation to use the sub-processors in Annex IV. The current list and dated change history are maintained on the WPXFacets Subprocessors page.

WPXFacets will send notice of an intended addition or replacement to the account email address at least 30 days before the change takes effect. The notice will identify the sub-processor, its role, processing location, intended start date, and how to object. If the parties cannot resolve a timely, reasonable objection, the rights available under Clause 7.7 and Clause 10 apply.

5. Electronic execution and versions

This DPA is concluded electronically. The person accepting it confirms that they are authorised to bind the Customer identified in the applicable WPXFacets subscription.

Each published version has a stable version label, an effective UTC date, canonical document bytes, and a SHA-256 hash. The acceptance record identifies the subscription, Customer, representative, version label, document hash, and server-recorded UTC acceptance time. A published version that has been accepted is not edited in place.

Acceptance makes the subscription eligible to use optional Search Analytics. It does not enable collection. An authorised Customer administrator must enable Search Analytics separately on the Customer’s connected Main environment after completing the Customer’s own lawful-basis and shopper-notice review.


Annex I — List of Parties

A. Controller

The Customer identified in the WPXFacets subscription and billing record:

Field Contract value
Name Customer’s legal company name captured at B2B checkout
Address Customer’s complete billing address captured at checkout
Contact person WPXFacets account holder name and work email
Business identifier Validated EU VAT ID or non-EU business tax or registration ID
Activities relevant to the processing Operation of a WooCommerce storefront using the Service
Signature and accession date Electronic acceptance record for the applicable subscription and DPA version

B. Processor

Field Contract value
Legal name SC WEBIXKIT SOLUTIONS S.R.L.
Trading name WPXFacets
Romanian tax identification number (CUI) 45239327
EU VAT ID for intra-Community transactions RO45267408
Trade Registry number (current ONRC format) J2021003824130
Historic Trade Registry reference J13/3824/17.11.2021
European Unique Identifier (EUID) ROONRC.J2021003824130
Registered address Str. Arțarului, nr. 25, Camera nr. 4, Sat Siminoc, Oraș Murfatlar, Județul Constanța, Romania
Data-protection contact support@wpxfacets.com
Activities relevant to the processing Provision and operation of the dedicated managed Elasticsearch Service, including optional Search Analytics
Legal representative Gavrilov Alexandru-Gabriel
Signature Countersigned electronically by Gavrilov Alexandru-Gabriel, legal representative of SC WEBIXKIT SOLUTIONS S.R.L., on 25 August 2026 for version 2026-08-25-v1.

Annex II — Description of the Processing

A. Subject matter

Operation of the Customer’s dedicated managed Elasticsearch Service for product search and filtering and, where separately enabled by the Customer, Search Analytics.

B. Duration

Product catalogue processing continues for the Service subscription term and the controlled service-deletion period after entitlement ends.

Search Analytics processing continues only while the feature is enabled, subject to a rolling maximum retention of 90 UTC calendar days. The Customer may stop new collection or instruct deletion of the complete Search Analytics dataset earlier through the Service controls.

Disabling Search Analytics or disconnecting a site stops new collection but does not by itself delete data still within the retention period. Ending the Service triggers the return-or-deletion obligations in Clause 10. WPXFacets does not retain a managed backup copy of the indexes.

C. Nature and frequency

Depending on the Customer’s instructions: receipt, validation, minimisation, normalisation, aggregation, storage, indexing, retrieval, reporting, securing, retention, and deletion. Processing is continuous while the Service is active, except that Search Analytics collection occurs only after the Customer separately enables it.

D. Purpose

  • Operating product search and filtering for the Customer’s storefront.
  • Where separately enabled, producing store-specific search-quality reporting so the Customer can identify repeated searches that return no products.
  • Securing, supporting, retaining, and deleting the Service in accordance with documented instructions and applicable law.

WPXFacets does not use Customer Data for another customer, a shared corpus, advertising, profiling, or automatic relevance changes, and does not determine an independent purpose for the Customer Data covered by this DPA.

E. Categories of data subjects

  • Storefront visitors who submit a search on the Customer’s site.
  • Customer administrators authorised to access the Search Analytics report.
  • Individuals whose personal data the Customer chooses to include in its product catalogue. WPXFacets does not require or expect personal data in catalogue fields.

F. Categories of personal data

Product catalogue data

Data selected and submitted by the Customer for indexing. Product catalogue data ordinarily does not contain personal data, but the Customer controls its catalogue fields and content.

Search Analytics data

Only when Search Analytics is separately enabled:

  • readable normalised and display search terms, which may incidentally contain personal data;
  • a SHA-256 hash of the normalised term used as an aggregation key, not as anonymisation;
  • UTC calendar day and normalised language;
  • search, zero-result, and filtered-zero-result counters;
  • result-count sum, minimum, and maximum; and
  • document schema version.

No visitor, customer-account, session, cookie, IP-address, or user-agent identifier is stored with a Search Analytics record.

G. Sensitive data and safeguards

No special-category or criminal-conviction data is intentionally processed. Visitor-supplied search text may nevertheless contain such data incidentally. The additional safeguards are conservative pattern rejection before storage, no visitor identifier, daily aggregation instead of event-level storage, the 90-day retention ceiling, access restricted to authorised administrators of the same store, and single-store isolation.

The Customer must not intentionally submit special-category or criminal-conviction data through the Service unless the parties first document the instruction and agree appropriate additional safeguards.

H. Processing locations and transfers

For the initial Service, processing is restricted to the EU hosting location selected for the subscription: Nuremberg or Falkenstein in Germany, or Helsinki in Finland. Search terms are not sent to the WPXFacets WordPress control plane; they are processed through the per-server gateway on the Customer’s dedicated managed node.

The Service described by this DPA does not offer a non-EEA processing location. A later non-EEA location would require separate advance disclosure, a valid Chapter V transfer mechanism, and any required transfer assessment and supplementary measures before use.

I. Controller rights and obligations

The Customer determines the purposes and means of its storefront processing and remains responsible for the accuracy and lawfulness of its documented instructions, its lawful basis, required notices to data subjects, and authorising access by its administrators. The Customer must not use the Search Analytics enable control as a substitute for its own lawful-basis or transparency review.

J. Assistance with data-subject requests

The Customer receives and assesses data-subject requests as controller. WPXFacets assists using the data and technical capabilities available under the Service.

Search Analytics deliberately stores no visitor identifier. The parties therefore may be unable to link a record reliably to a particular person, and the Service does not support deletion of one individual query row. Where deletion is required and a row cannot be reliably isolated, the supported technical operation is deletion of the Customer’s complete Search Analytics dataset.


Annex III — Technical and Organisational Measures

A. Isolation and tenancy

  • One subscription maps to one dedicated virtual server; Customer Data is not co-tenanted with another customer’s data on the same Elasticsearch node.
  • Each connected site writes only to its assigned indexes. There is no central analytics ingestion or cross-customer search corpus.
  • Search Analytics collection is available only on the subscription’s unique Main environment and is enforced by the control plane and per-server gateway.

B. Network and administrative access

  • Elasticsearch binds to 127.0.0.1:9200 and is not exposed publicly.
  • Hetzner Cloud Firewall and host-level UFW rules both restrict inbound access. Elasticsearch, database, Redis, and container-only ports are not publicly exposed.
  • Administrative SSH access reaches managed nodes only through a hardened bastion from an allow-listed source. Root login and password authentication are disabled; access uses passphrase-protected ED25519 keys.
  • Dedicated least-privilege Elasticsearch identities are used for client and monitoring access. Bootstrap credentials are removed at provisioning.

C. Application and transport security

  • HTTP transport uses TLS.
  • The Customer plugin does not store Elasticsearch credentials or submit Elasticsearch query DSL; access is mediated by a semantic per-server gateway.
  • The control plane issues short-lived signed entitlement tokens. The gateway derives the exact index target from the authenticated slot assignment; the client cannot submit a physical index name.
  • Without a valid assignment or capability, the system fails closed before forwarding a request to Elasticsearch.

D. Confidentiality and access limitation

  • Access to Customer Data is limited to personnel who need it to provide, secure, monitor, or support the Service and who are subject to confidentiality obligations.
  • Customer-side report access is restricted to authorised administrators of the same store.
  • Operational logs and stored task state are query-free; search terms are not written to them.

E. Minimisation, retention, and deletion

  • Search Analytics stores no visitor, account, session, cookie, IP-address, or user-agent identifier.
  • Search terms are normalised, length-bounded, and screened for common sensitive patterns before storage.
  • Analytics is stored as daily aggregates rather than individual events.
  • A scheduled cleanup enforces the rolling 90-day maximum retention.
  • An authorised Customer administrator may delete the complete Search Analytics dataset on demand while the Service is reachable.
  • Confirmed deletion removes the analytics index and recreates a verified empty index only if collection remains enabled.
  • Plugin uninstall does not send a remote destructive request.
  • After entitlement ends, new authorisation is rejected and server power-off is requested. Final server destruction is a controlled operation completed only when the infrastructure provider confirms exact remote absence.

F. Incident, continuity, and effectiveness measures

  • Security events are investigated through the operational support and infrastructure access channels, and personal data breaches are handled under Clause 9.
  • Provisioning verifies required network, service, and access-control state before a managed node is placed in service.
  • The infrastructure layer is operated by Hetzner Online GmbH under the sub-processor agreement described in Annex IV.

G. Disclosed limitations

  • WPXFacets provides no managed snapshot or backup facility for the Elasticsearch indexes. Final destruction of the dedicated server permanently removes the only managed index copies on that node.
  • WPXFacets does not hold ISO 27001, SOC 2, or an equivalent third-party security certification. Certifications and independent reports held by Hetzner apply to Hetzner’s infrastructure layer, not to WPXFacets.
  • Data on the dedicated server is not encrypted at rest. Data in transit is protected by TLS, and the node is isolated and access-controlled as described above.
  • WPXFacets does not currently offer an independently audited recurring control-effectiveness programme. Provisioning-time verification and operational checks are the current evidence.

Annex IV — List of Sub-processors

The Customer generally authorises the following initial sub-processor under Clause 7.7 Option 2:

Hetzner Online GmbH

Address: Industriestr. 25, 91710 Gunzenhausen, Germany

Processing activities: Physical infrastructure, virtual-server and storage hosting for the Customer’s dedicated managed node.

Processing location: The EU location selected for the subscription: Nuremberg or Falkenstein, Germany, or Helsinki, Finland.

Hetzner operates the physical infrastructure, hypervisor, and network. WPXFacets operates the guest operating system, Elasticsearch, per-server gateway, and application-level access controls.

The current list and dated change history are maintained at https://www.wpxfacets.com/subprocessors/. An addition or replacement is governed by the notice and objection procedure in section 4 and Clause 7.7. The initial list above remains part of the exact DPA version accepted by the Customer.