Exhibit A to the Master Services Agreement / Platform Services Agreement
Last updated: June 25, 2026
PARTIES
This Data Processing Agreement ("DPA") is entered into between:
Controller:
[Customer name]
[Address]
[Registration number]
("Customer" or "Controller")
Processor:
Stack ehf.
Laugavegur 178, 105 Reykjavík, Iceland
Reg. 641019-1270
("Stack" or "Processor")
Each a "Party" and together the "Parties."
This DPA forms part of and is incorporated into the Master Services Agreement between the Parties ("MSA"). Capitalized terms not defined herein have the meaning given in the MSA.
1. SUBJECT MATTER AND DURATION
1.1 This DPA governs Processor's processing of Personal Data on behalf of Controller in connection with the provision of the Services under the MSA.
1.2 This DPA commences on the Effective Date of the MSA and continues until Processor ceases to process Personal Data on behalf of Controller, including following termination or expiration of the MSA, subject to Section 12 (Return and Deletion).
1.3 The details of processing are set out in Annex I.
2. DEFINITIONS
2.1 In this DPA:
"Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 (to the extent applicable), the Icelandic Act on Data Protection and the Processing of Personal Data (Act No. 90/2018), and any implementing or supplementary legislation.
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
"Personal Data" means any information relating to a Data Subject that is processed by Processor on behalf of Controller in connection with the Services.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Processor on behalf of Controller.
"Processing" (and "Process") has the meaning given in Data Protection Laws.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
"Sub-processor" means any third party engaged by Processor to Process Personal Data on behalf of Controller.
2.2 The terms "controller," "processor," "data subject," and "supervisory authority" have the meanings given in the GDPR.
3. ROLES OF THE PARTIES
3.1 The Parties acknowledge that, with regard to Personal Data processed in connection with the Services, Controller is the controller and Processor is the processor.
3.2 Controller determines the purposes and means of Processing. Processor Processes Personal Data only on documented instructions from Controller, as set out in the MSA, this DPA, and Annex I, unless required to do so by applicable law (in which case Processor shall inform Controller of that legal requirement before Processing, unless prohibited by law).
3.3 Where Controller acts as a processor for its own customers and engages Stack to Process Personal Data on its behalf, Controller represents that it has a lawful basis and valid instructions to engage Stack as a sub-processor, and Controller's customer terms shall govern the relationship between Controller and its customers.
4. PROCESSOR OBLIGATIONS
Processor shall:
4.1 Instructions. Process Personal Data only on Controller's documented instructions, including with regard to transfers of Personal Data to a third country, unless required by applicable law.
4.2 Confidentiality. Ensure that persons authorized to Process Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
4.3 Security. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex II and in accordance with Article 32 GDPR.
4.4 Sub-processors. Not engage another processor without Controller's prior specific or general written authorization, subject to Section 5.
4.5 Assistance — Data Subject rights. Taking into account the nature of Processing, assist Controller by appropriate technical and organizational measures, insofar as possible, for the fulfillment of Controller's obligation to respond to Data Subject requests under Chapter III GDPR.
4.6 Assistance — compliance. Assist Controller in ensuring compliance with Articles 32–36 GDPR, taking into account the nature of Processing and information available to Processor, including:
a) security of Processing (Article 32);
b) notification of Personal Data Breaches to supervisory authorities (Article 33);
c) communication of Personal Data Breaches to Data Subjects (Article 34);
d) data protection impact assessments (Article 35); and
e) prior consultation with supervisory authorities (Article 36).
4.7 Deletion and return. At Controller's choice, delete or return all Personal Data to Controller after the end of the provision of Services, and delete existing copies unless applicable law requires storage, as further described in Section 12.
4.8 Audit and information. Make available to Controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits and inspections conducted by Controller or an auditor mandated by Controller, subject to Section 11.
4.9 Records. Maintain records of Processing activities as required under Article 30(2) GDPR.
5. SUB-PROCESSORS
5.1 General authorization. Controller provides general written authorization for Processor to engage Sub-processors listed in Annex III, subject to the conditions in this Section 5.
5.2 New Sub-processors. Processor shall notify Controller of any intended changes concerning the addition or replacement of Sub-processors at least thirty (30) days in advance, giving Controller the opportunity to object on reasonable grounds relating to data protection. If Controller objects in writing within fifteen (15) days and the Parties cannot resolve the objection, Controller may terminate the affected Services in accordance with the MSA.
5.3 Sub-processor obligations. Processor shall impose on each Sub-processor data protection obligations equivalent to those in this DPA by way of a written contract. Processor remains fully liable to Controller for the performance of each Sub-processor's obligations.
5.4 Current Sub-processors. The Sub-processors authorized as of the date of this DPA are listed in Annex III.
6. PERSONAL DATA BREACHES
6.1 Processor shall notify Controller without undue delay and in any event within seventy-two (72) hours after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of Controller.
6.2 The notification shall, to the extent available, include:
a) a description of the nature of the Personal Data Breach, including categories and approximate number of Data Subjects and records concerned;
b) the name and contact details of Processor's point of contact;
c) a description of the likely consequences; and
d) a description of measures taken or proposed to address the breach, including measures to mitigate possible adverse effects.
6.3 Processor shall cooperate with Controller and take reasonable steps to assist Controller in meeting Controller's obligations under Articles 33 and 34 GDPR.
6.4 Processor shall document all Personal Data Breaches, including facts, effects, and remedial action taken.
7. INTERNATIONAL TRANSFERS
7.1 Processor shall not transfer Personal Data to a country outside the EEA/UK unless:
a) the European Commission (or UK authorities, as applicable) has issued an adequacy decision for that country;
b) appropriate safeguards are in place, including the SCCs; or
c) a derogation under Article 49 GDPR applies and Controller has provided documented instructions.
7.2 SCCs. Where Personal Data is transferred to a Sub-processor or Processor affiliate in a country without an adequacy decision, the Parties agree that the Module Two (Controller to Processor) SCCs set out in Annex IV are incorporated into and form part of this DPA. The optional clauses and appendices in Annex IV shall apply.
7.3 If SCCs are amended, replaced, or invalidated, the Parties shall cooperate in good faith to implement an alternative transfer mechanism permitted under Data Protection Laws.
8. DATA SUBJECT REQUESTS
8.1 Processor shall promptly notify Controller if Processor receives a request from a Data Subject to exercise rights under Data Protection Laws with respect to Personal Data processed on behalf of Controller.
8.2 Processor shall not respond to such request except on Controller's documented instructions or as required by applicable law.
8.3 Processor shall provide reasonable assistance to Controller in responding to Data Subject requests, at Controller's expense where permitted by law.
9. CONTROLLER OBLIGATIONS
Controller shall:
a) ensure it has a lawful basis for Processing and for instructing Processor to Process Personal Data;
b) provide documented instructions that comply with Data Protection Laws;
c) inform Processor without undue delay of any inaccuracy in Personal Data or change in Processing instructions;
d) ensure Data Subjects are provided with appropriate privacy notices; and
e) be responsible for the accuracy, quality, and legality of Personal Data and the means by which Controller acquired Personal Data.
10. LIABILITY
10.1 Each Party's liability under this DPA is subject to the limitations and carve-outs set forth in Section 15 of the MSA, except that nothing in the MSA limits either Party's liability for breaches of Data Protection Laws to the extent such limitation is prohibited by mandatory applicable law.
10.2 Where Processor has paid compensation, damages, or fines in respect of Processing that Controller has instructed, Controller shall indemnify Processor for the portion attributable to Controller's instructions or breach of this DPA, to the extent permitted by Data Protection Laws.
11. AUDITS
11.1 Processor shall make available information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by Controller or an independent auditor appointed by Controller.
11.2 Audits shall be conducted:
a) upon at least thirty (30) days' prior written notice;
b) during normal business hours;
c) no more than once per twelve (12) month period, except following a Personal Data Breach or regulatory request; and
d) subject to reasonable confidentiality and security requirements.
11.3 Controller shall bear its own costs and reimburse Processor for reasonable costs of assistance unless the audit reveals material non-compliance by Processor.
11.4 Processor may satisfy audit obligations by providing current third-party certifications or audit reports (e.g., SOC 2, ISO 27001) where they cover the relevant Processing.
12. RETURN AND DELETION
12.1 Upon termination or expiration of the MSA, Controller may export Personal Data during the Export Window defined in Section 13 of the MSA.
12.2 Following the Export Window, Processor shall, at Controller's election communicated in writing, delete or return all Personal Data Processed on behalf of Controller, unless applicable law requires continued storage.
12.3 Processor may retain Personal Data to the extent required by applicable law, but only for the period required and subject to continued confidentiality and data protection obligations.
12.4 Backup copies containing Personal Data may be retained for up to ninety (90) days in secure backup systems before automated deletion, provided such copies are isolated from active Processing and protected by appropriate security measures.
12.5 Upon request, Processor shall provide written confirmation of deletion in accordance with this Section 12.
13. GENERAL
13.1 In the event of conflict between this DPA and the MSA with respect to the Processing of Personal Data, this DPA prevails.
13.2 This DPA is governed by the laws of Iceland. Disputes arising under this DPA are subject to the dispute resolution clause in the MSA.
13.3 This DPA may be amended only in writing signed by both Parties, or as permitted under the MSA amendment provisions where such amendments do not materially reduce Processor's data protection obligations without Controller's consent.
13.4 If any provision of this DPA is invalid or unenforceable, the remaining provisions remain in effect.
ANNEX I — DETAILS OF PROCESSING
A. List of Parties
| Controller | Processor | |
|---|---|---|
| Name | [Customer name] | Stack ehf. |
| Address | [Address] | Laugavegur 178, 105 Reykjavík, Iceland |
| Contact | [Contact person and email] | Data Protection Officer, support@fast-track.io |
| Role | Controller | Processor |
B. Description of Processing
| Field | Details |
|---|---|
| Subject matter | Provision of the FastTrack Platform SaaS services under the MSA |
| Duration | For the Subscription Term and any Export Window / retention periods in Sections 12 of the MSA and DPA |
| Nature and purpose | Hosting, storage, retrieval, organization, analysis, transmission, and deletion of Personal Data as necessary to provide point-of-sale, payment processing, inventory, analytics, and related retail operations services |
| Categories of Data Subjects | Customer's employees and authorized Users; Customer's end customers (shoppers); delivery recipients and pickup contacts; loyalty and marketing program members |
| Categories of Personal Data | Identity and contact data; account credentials; employment and store identifiers; transaction, order, basket, and receipt data; payment metadata (card type, last four digits, authorization status — not full PAN); device identifiers, IP addresses, logs, and usage telemetry; loyalty and marketing preferences where enabled by Customer |
| Special categories (if any) | None intended. Controller shall not instruct Processor to Process special categories of data unless agreed in writing with appropriate safeguards |
| Frequency of transfer | Continuous for the duration of the Services |
| Retention | For the Subscription Term plus Export Window and backup retention per Section 12 of the DPA, unless longer retention is required by law or agreed in writing |
ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES
Processor implements the following measures, appropriate to the nature of the Personal Data and the risks of Processing:
1. Access control
- Role-based access control (RBAC) for production systems
- Multi-factor authentication for administrative access
- Unique user accounts; no shared credentials
- Access reviews and revocation upon role change or termination
- Principle of least privilege
2. Data encryption
- Encryption in transit (TLS 1.2+) for all external communications
- Encryption at rest for databases and object storage (AES-256 or equivalent)
- Secure key management via AWS KMS
3. Infrastructure security
- Hosting on Amazon Web Services (AWS) in eu-west-1 (Ireland)
- Network segmentation and firewalls
- Regular security patching and vulnerability management
- DDoS protection and web application firewall where applicable
4. Application security
- Secure software development lifecycle (SDLC)
- Code review and dependency scanning
- Separation of development, staging, and production environments
- Malicious code screening per MSA Section 5.1
5. Backup and recovery
- Regular automated database backups per MSA Section 5.1
- Backup encryption and access controls
- Disaster recovery and business continuity procedures
- Backup retention aligned with Section 12.4 of this DPA
6. Logging and monitoring
- Centralized logging of access and security events
- Monitoring for unauthorized access and anomalies
- Log retention for 12 months
7. Personnel and organizational measures
- Confidentiality obligations for all personnel with access to Personal Data
- Security awareness training
- Background checks for personnel with production access where permitted by law
- Documented information security policies
8. Incident response
- Documented incident response plan
- Personal Data Breach notification per Section 6 of this DPA
- Post-incident review and remediation
9. Sub-processor management
- Due diligence on Sub-processors
- Contractual data protection obligations equivalent to this DPA
- Sub-processor list maintained in Annex III
10. Physical security
- AWS data center physical security (Processor does not operate own data centers)
- Secure disposal of hardware where Processor manages physical devices
Measures are reviewed periodically and updated as the Platform evolves.
ANNEX III — APPROVED SUB-PROCESSORS
As of the date of this DPA, Controller authorizes the following Sub-processors:
| Sub-processor | Service provided | Location / data region | Processing activity |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (compute, storage, database, networking) | EU (Ireland) — eu-west-1 | Hosting and storage of Customer Data and Personal Data |
| Payment service providers (Adyen, Stripe, Teya, Rapyd, Verifone, Vipps, Blikk, Swish, and others integrated per Customer Order) | Payment processing | Primarily EU; global where required by provider or transaction | Processing payment transaction data |
Processor shall maintain an up-to-date sub-processor list at https://www.fast-track.io/legal/privacy (Section 5) and notify Controller of changes per Section 5.2.
ANNEX IV — STANDARD CONTRACTUAL CLAUSES (MODULE TWO: CONTROLLER TO PROCESSOR)
The Parties agree to incorporate the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Two: Transfer controller to processor, with the following selections and appendices completed:
Clause selections
| Clause | Selection |
|---|---|
| Clause 7 — Docking clause | Used — optional docking clause applies |
| Clause 9 — Use of sub-processors | Option 2: General written authorization with notice period per DPA Section 5.2 |
| Clause 11 — Redress | Used — optional redress clause applies |
| Clause 17 — Governing law | Laws of Ireland (EU Member State) |
| Clause 18(b) — Competent courts | Courts of Ireland |
| Annex I.A — Data exporter | Controller (Customer) — details per Annex I above |
| Annex I.B — Data importer | Processor (Stack ehf.) — details per Annex I above |
| Annex I.C — Description of transfer | As set out in Annex I of this DPA |
| Annex II — TOMs | As set out in Annex II of this DPA |
| Annex III — Sub-processors | As set out in Annex III of this DPA |
Execution of this DPA in the SIGNATURES section below constitutes acceptance of the Standard Contractual Clauses on the terms set out in this Annex IV, with Appendices I–III completed using Annex I–III of this DPA.
SIGNATURES
Controller:
Name: ********___********
Title: ********___********
Date: ********___********
Signature: ********___********
Processor (Stack ehf.):
Name: ********___********
Title: ********___********
Date: ********___********
Signature: ********___********
