Data Processing Agreement
Updated October 6, 2026
This agreement is part of the sild Terms of Service (sild.cloud/terms). It applies whenever sild processes personal data for a customer, as required by Article 28 of the GDPR (Regulation (EU) 2016/679).
- Controller: the customer who connected a store to sild ("you").
- Processor: Illia Kirieiev, NIP 8513342075, ul. Małe Błonia 31/2, 71-779 Szczecin, Poland ("we").
If this agreement and the Terms conflict on data protection, this agreement wins.
1. Subject and duration
We process personal data to provide the Service described in the Terms. Annex 1 describes the processing. This agreement lasts as long as we process personal data for you.
2. Your instructions
- We process personal data only on your documented instructions. Your instructions are these terms, the settings you choose in the Plugin and requests you send us in writing.
- If an instruction seems to break data protection law, we tell you and may refuse to carry it out.
- If EU or member state law requires us to process data in another way, we tell you first, unless that law forbids it.
3. Confidentiality
Only people who need the data to run the Service have access to it. They are bound to keep it confidential.
4. Security
We take the technical and organisational measures in Annex 2 (sild.cloud/security). We may improve them over time but will not lower the overall level of protection.
5. Subprocessors
- You give general authorisation for the subprocessors listed at sild.cloud/subprocessors.
- We tell you by email at least 30 days before we add or replace a subprocessor. If you object on reasonable data protection grounds and we cannot solve it, you may end the contract before the change takes effect and get back any prepaid fees for the unused time.
- Each subprocessor is bound by data protection terms at least as protective as these. We remain responsible to you for their work.
6. Transfers outside the EEA
We transfer personal data outside the EEA only with a valid safeguard under Chapter V of the GDPR, such as an adequacy decision (including the EU-US Data Privacy Framework) or the standard contractual clauses.
7. Helping you
- Requests from people. If a buyer contacts us directly, we forward the request to you and do not answer it ourselves. We help you answer requests for access, correction, deletion and the other GDPR rights. Most of the data also lives in your WooCommerce store and your Merit company, where you can act on it directly.
- Other duties. We give you the information you reasonably need for data protection impact assessments and consultations with an authority.
8. Personal data breaches
We tell you without undue delay, and in any case within 48 hours after we become aware of a breach that affects your data. We include what we know: what happened, which data and people are affected, likely consequences and what we did. We send updates as we learn more.
9. End of processing
- When a store disconnects, it stops sending data. When the last store of an account disconnects, we delete the Merit API key at once.
- Within 30 days after the contract ends we delete the remaining personal data, unless the law requires us to keep it. Encrypted backups roll over within 14 more days.
- The documents created by the Service are already in your Merit company and stay there. On request, before the contract ends, we export the sync records of your account.
10. Audits
- On request we give you the information needed to show that we meet this agreement.
- If that is not enough, you or an independent auditor bound to confidentiality may audit us once a year with 30 days' notice, at your cost, without access to other customers' data.
11. Liability
Liability under this agreement follows the Terms of Service, except where the GDPR does not allow it to be limited.
Annex 1. Description of the processing
People concerned
- Buyers of your store (persons and contact people of businesses).
- Your staff whose email address you enter for alerts.
Personal data
- Buyer name, company name, email address, phone number, billing address, shipping country.
- Company registry code, VAT number and the result of its check in the EU VIES register.
- Order contents: items, quantities, prices, discounts, taxes, payment method, order dates, refunds, WordPress customer ID.
- Data read from your Merit company: customers, sales invoices, credit invoices, payments, items and stock.
- Alert email addresses.
No special categories of data (GDPR art. 9) are intended. Do not put them into order fields that reach sild.
What we do with it
- Receive order events from your store and keep them encrypted.
- Build sales invoices, credit invoices and payments, and create them in your Merit company (Live mode).
- Read your Merit data to compare results (Preview mode), avoid duplicates, find payments, check that invoices still exist and read stock.
- Check VAT numbers in the EU VIES register when your settings ask for it.
- Send you emails about failures and daily checks.
How long
- Order and refund payloads: deleted 60 days after the last change of a finished order.
- Sync records (order number, state, Merit document numbers, amounts, dates): while the account exists, then as in section 9.
- Merit API key: until the last store of the account disconnects.
- Backups: up to 14 days.
Where
- Servers in Poland (EU). Subprocessors as listed at sild.cloud/subprocessors.
Annex 2. Security measures
See sild.cloud/security. The version in force when this agreement was accepted applies, as improved since.
Annex 3. Subprocessors
See sild.cloud/subprocessors.