Data Processing Addendum
When a shopper types their name into one of your kiosks, you are the controller of that data and we are your processor. This is the Article 28 contract that governs it — already in force, with nothing for you to sign.
- Effective
- July 25, 2026
- Applies to
- www.kioskwizard.com
1. Scope and roles
This Addendum forms part of the Terms of Service between you (the “Controller”) and Web Wiz LLC (the “Processor”), and applies whenever we process personal data on your behalf that is subject to the EU General Data Protection Regulation, the UK GDPR, or a US state privacy law imposing equivalent processor obligations.
It is incorporated automatically — you do not need to sign or request it. If your organisation requires a countersigned copy, email support@kioskwizard.com.
Where we process personal data for our own purposes — your account email, your billing details, our server logs — we act as a controller, not a processor, and the Privacy Policy governs instead. This Addendum covers only shopper data flowing through your kiosks.
2. Particulars of processing
Required by GDPR Article 28(3). These are the complete particulars — there is no other processing we do on your behalf.
- Subject matter
- Operating touchscreen kiosks that display your WooCommerce catalogue and submit orders back into your store.
- Duration
- For as long as you hold an active Kiosk Wizard account, plus the short deletion window in section 9.
- Nature and purpose
- Collection and onward transmission. A shopper’s details are received by our server, attached to the order, and posted to your store’s Store API. We perform no analysis, profiling, enrichment, or secondary use of any kind.
- Categories of data subject
- Shoppers who place an order at one of your kiosks.
- Types of personal data
- First name, last name, email address, and any free-text order note the shopper chooses to write. Nothing else is requested. No payment data is collected — kiosk orders are paid at your register.
- Special categories
- None requested or required. A shopper could type anything into a free text note, so we treat note content as potentially sensitive and never read, index, or retain it.
- Retention by the Processor
- None. Shopper data is held in memory only for the duration of the request that forwards the order, and is never written to our database.
3. Processing on documented instructions
We process shopper personal data only on your documented instructions, which for these purposes are: the Terms, this Addendum, the configuration you set in your dashboard, and the ordinary operation of the kiosk. We will not process it for any other purpose, and will never sell, share, or use it for our own analytics, product development, or model training.
If we are required by law to process it otherwise, we will tell you before doing so unless that law forbids it. If we believe an instruction infringes data protection law, we will tell you promptly and may pause that processing.
4. Confidentiality
Access to personal data is restricted to personnel who need it to deliver or support the service. Everyone with access is bound by a confidentiality obligation that survives the end of their engagement, and access is removed when it is no longer needed.
5. Security measures
We implement the technical and organisational measures required by GDPR Article 32, in proportion to the risk. In particular:
- encryption of all data in transit using TLS 1.2 or above;
- encryption of stored WooCommerce API credentials at rest using AES-256-GCM, with the key held in the server environment and never in the database;
- logical isolation between tenants enforced at the database layer by row-level security and narrowly scoped, access-checked functions;
- data minimisation by design — shopper data is never persisted, so there is no store of it to breach;
- multi-factor authentication on all administrative and vendor accounts, with least-privilege access;
- managed, encrypted, point-in-time-recoverable backups of the application database held by our hosting providers;
- dependency and platform patching, and periodic review of these measures.
We may update these measures over time provided the level of security is not reduced.
6. Sub-processors
You give general written authorisation for us to engage sub-processors. The current list is published at kioskwizard.com/subprocessors.
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, tell us and we will work in good faith to offer an alternative; if we cannot, you may terminate the affected subscription without penalty and receive a pro-rata refund of any prepaid fees.
Every sub-processor is engaged under a written contract imposing obligations no less protective than this Addendum, and we remain fully liable to you for their performance.
7. International transfers
We and our sub-processors are located in the United States. Where personal data is transferred out of the EEA or the UK, the transfer is made under the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor) as between us and our sub-processors, and Module Two (controller to processor) as between you and us, together with the UK International Data Transfer Addendum where UK data is involved. Those clauses are incorporated into this Addendum by reference and, in the event of conflict, take precedence.
Given the categories involved — a name and an email address, held in transit only — we consider the risk of the transfer low, and we commit to challenging any government access request that appears unlawful and to notifying you where we are permitted to.
8. Assisting you
Taking into account the nature of the processing, we will:
- assist you in responding to data subject requests under GDPR Articles 12–23. In practice this is rarely needed: because we retain nothing, the record a shopper is asking about lives in your WooCommerce store, not with us. If a shopper contacts us directly we will not act on the request ourselves — we will refer them to you and tell you within 5 business days;
- assist you with data protection impact assessments and prior consultation under Articles 35 and 36, at your reasonable request;
- notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data, with the information you need for your own Article 33 notification, and cooperate in your investigation and remediation.
9. Return and deletion
Because shopper data is never stored, there is nothing to return or delete at the end of the service. Your account and kiosk configuration are deleted as set out in section 9 of the Privacy Policy: immediately from live systems on account deletion, and from encrypted backups within 30 days as those backups expire. Stored WooCommerce credentials are destroyed with the kiosk, and can additionally be revoked by you at any time from your own wp-admin.
10. Audits
We will make available the information reasonably necessary to demonstrate compliance with Article 28, and will respond to a written security questionnaire once in any 12-month period at no charge. Where you reasonably require an on-site audit, we will agree scope and timing in advance so as not to disrupt the service, and you will bear the cost unless the audit reveals a material breach of this Addendum. Audit rights may not be exercised in a way that compromises the security or confidentiality of other customers’ data.
11. Liability and precedence
Each party’s liability under this Addendum is subject to the limitations in section 13 of the Terms, except where the applicable data protection law does not permit that limitation. Where this Addendum conflicts with the Terms, this Addendum governs for matters of data protection; where it conflicts with the Standard Contractual Clauses, those Clauses govern.
12. Contact
Data protection matters, including breach notifications and sub-processor objections: support@kioskwizard.com, Web Wiz LLC, 2108 N ST STE N, Sacramento, CA 95816, United States.