Data Processing Terms
Version: 12 September 2026
These terms govern Dozenfold’s processing of personal data on behalf of a merchant when incorporated into the merchant’s agreement with Dozenfold. They take priority over conflicting service terms on data protection.
Roles and instructions
The merchant is the controller of store data and Dozenfold acts as its processor. We process that data only on documented instructions to provide storefront monitoring, diagnose errors and performance, and explain observed shopping outcomes. The merchant is responsible for its notices, lawful basis and required visitor permissions. We will inform the merchant if we believe an instruction infringes applicable data protection law.
Data and duration
Processing concerns store visitors and includes session and event identifiers, page and device context, diagnostic events, shopping stages, purchase amount and currency. We do not request shopper name, email, phone or address fields, or record input values. Screen or DOM replay is captured only when a merchant turns on error-session replay: then a masked page reconstruction is stored for sessions with an error, for 30 days. Session-linked data is treated as potentially personal data.
Processing lasts for the service and the applicable deletion period. Public paid plans provide 30 days of event history. Account and billing records have separate purposes; minimal usage records remain with store billing history until the store record is deleted. Uninstalling stops new collection and does not immediately erase all records. On termination, we will return or delete personal data at the merchant’s choice, unless applicable law requires retention. Backup copies are restricted to recovery and removed under the applicable backup retention schedule; restored data remains subject to deletion instructions.
Protection and assistance
We will apply appropriate technical and organizational measures, including encryption in storage and transit, access restrictions, confidentiality duties, and recovery procedures. We will notify the merchant without undue delay after becoming aware of a personal data breach and provide available information and reasonable assistance with the response.
We will reasonably assist with access, correction and deletion requests, security obligations, impact assessments and regulatory consultations. Requests received from store visitors will be referred to the merchant unless we are instructed or legally required to respond.
Service providers and transfers
The merchant authorizes Hetzner for hosting and Cloudflare for network and storage services as subprocessors. They must be bound by data protection obligations appropriate to their work. We remain responsible for their performance of those obligations. We will notify the merchant before adding or replacing a subprocessor and allow a reasonable opportunity to object on data protection grounds.
Data may be processed outside the merchant’s country, including through access from Türkiye. Transfers subject to legal restrictions require an applicable transfer mechanism and safeguards, including standard contractual clauses where required. These terms do not themselves replace any required international transfer clauses.
Accountability and changes
We will provide information reasonably necessary to demonstrate compliance and allow appropriate audits, subject to confidentiality and protection of other merchants’ data. Material changes to these terms will be notified directly to the merchant for acceptance before taking effect.
Service provider and contact
Dozenfold is operated by LEVENT ANIL ÖZEN, a sole proprietor in Türkiye.
Ritim İstanbul AVM, Cevizli Mah. Zühal Cad. A Ticari Blok Apt. No:46/50, Maltepe / İstanbul.
Data protection requests: privacy@dozenfold.com. See our Privacy Policy for website, support and account processing.