PRODEL · Three Button Trading

Data Processing Agreement

Last updated: 19 September 2026

This Agreement (“DPA”) is concluded between the Customer (“Controller”) and Three Button Trading Ltd (“Processor”) pursuant to article 28 of Regulation (EU) 2016/679 and forms an integral part of the Terms of Service. It is concluded in electronic form (article 28(9)) by confirmation of the Order Form under clause 2 of the Terms of Service and applies from the start date of the subscription or trial. The Controller’s details are those in the Order Form (Annex C). A signed copy with both parties’ details is provided on request. The Greek version prevails in case of discrepancy.

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller exclusively to provide the PRODEL service, for the duration of the subscription or trial and for 30 days after it ends (export and deletion period).

2. Nature, purpose and type of processing

ItemDescription
PurposePlanning, assignment, execution and documentation of the Controller’s last-mile deliveries; informing recipients of the progress of their delivery, when the Controller sends them the tracking link (clause 2A).
NatureStorage, organisation, display to authorised users, address geocoding, route and arrival-time calculation, sending of service email; display of limited details of a single stop, without sign-in, to whoever opens the delivery tracking link (clause 2A).
Data subjectsDelivery recipients (the Controller’s customers, natural persons or representatives of businesses); the Controller’s employees and contractors (drivers, dispatchers).
Categories of dataRecipients: name or company name, address and its coordinates, phone, free-text delivery notes, delivery window, parcel type and count, cash-on-delivery amount and declared amount collected, proof photo (which may show the item delivered, an entrance, people or number plates), driver’s note, failure reason, delivery time. The Controller’s employees: name, email, phone, role, latest device position during a route, route start/finish and break times, delivery times and outcomes, actions in the app. The Controller’s details shown to recipients: business name and contact phone (optional Settings fields). For both categories: IP addresses and technical connection details in server log files, for 90 days; for whoever opens the delivery tracking page, additionally the IP address in the request-limit counter, for up to 24 hours.
Special categoriesNot intended. The Controller does not enter special-category data (article 9) or criminal-conviction data (article 10) in free-text fields. If its activity means that the delivery itself reveals such data (e.g. medicines or medical supplies to individuals), it notifies the Processor in writing before starting, has its own legal basis under article 9(2), limits notes to what is necessary, and the parties agree any additional measures.
RetentionDetermined by the Controller, who can delete routes (with stops and photos) and users in the app. The Processor does not delete data during the subscription except under clause 10(5) of the Terms of Service (history beyond the Plan, with notice) and after termination under clause 7.

2A. Delivery tracking link

For every stop the service provides a web address of the form https://[application]/t/[stop id].[signature], which opens without an account or sign-in. The signature is computed on the server with a secret key (HMAC); the address cannot be guessed or derived from another address, and nothing new is stored in the database for the link itself. The data subjects of this processing are the delivery recipients; its purpose is to let a recipient see the progress and estimated time of their delivery. The Controller decides whether, to whom and by what means a link is sent; a recipient sees nothing unless one of the Controller’s users sends them the link.

ItemDescription
The page shows onlyThe business name and contact phone the Controller has entered in Settings (optional); the recipient’s name, as the Controller entered it for the stop; the status of the delivery or pickup (scheduled and for which day, on the way, next stop, the driver has arrived, completed, not completed); while the route is running, an estimated arrival window and how many stops come before; the agreed delivery window, if one was set; the cash-on-delivery amount, if any, while the delivery is pending; after delivery, its time.
The page never showsThe driver’s name, the driver’s location or any map; the recipient’s address or phone; delivery notes; proof photos; the failure reason; any other stop on the route.
Arrival estimateCalculated on the Processor’s server from the stop order, road travel times and, while the route is running, the last position sent by the driver’s device (the single “latest position” of Annex A). The position is not sent to the recipient; only the resulting time window is.
Sending the linkBy the Controller’s users (dispatcher or driver), from their own device, using the device’s SMS, WhatsApp, Viber or share sheet, or by copying the address. The Processor does not send SMS or chat messages, has no SMS provider, and does not learn whether or to whom the link was sent (clause 4A).
ValidityAnyone holding the address can open it until it expires. The page stops showing any data 48 hours after the stop is closed (completed or not completed), or 3 days after the route’s date if the stop was never closed; after that it only states that the link is not valid. A single link cannot be revoked earlier, other than by deleting the stop.
Recipient’s deviceThe page sets no cookies, stores nothing on the device and has no analytics; it carries a noindex tag and is excluded in robots.txt; it refreshes itself every 60 seconds while the delivery is pending. Requests are rate-limited per IP address with the request-limit counter and are recorded in the ordinary server log files (clause 2, “Categories of data”).

3. Obligations of the Processor

The Processor:

  1. processes the data only on documented instructions from the Controller — the Terms of Service, this Agreement and the use of the application by the Controller’s users constitute such instructions — unless required by EU or member-state law, in which case it informs the Controller beforehand unless prohibited;
  2. ensures that persons with access to the data are bound by confidentiality;
  3. implements the technical and organisational measures of Annex A (article 32);
  4. complies with clause 4 regarding sub-processors;
  5. assists the Controller, with appropriate measures, in responding to data-subject requests (articles 12–22), within 5 working days of a request;
  6. assists the Controller in complying with articles 32–36 (security, breach notification, impact assessment), taking into account the nature of the processing and the information available to it;
  7. at the end of the service, deletes or returns all data at the Controller’s choice, as set out in clause 7;
  8. makes available to the Controller all information necessary to demonstrate compliance and allows audits, as set out in clause 8;
  9. immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other EU or member-state law, without this constituting legal advice;
  10. if it receives a data-subject request directly, does not respond on the merits and forwards it to the Controller within 3 working days;
  11. maintains a record of the categories of processing carried out for the Controller (article 30(2)) and provides it on request;
  12. informs the Controller without delay if it can no longer comply with this Agreement, in which case the Controller may suspend processing or terminate the subscription.

Instructions. Instructions beyond the Terms of Service, this Agreement and the use of the application are given in writing by the Administrator to andreas@3buttontrading.com. The Processor may refuse an instruction requiring a material change to the service, or ask for a reasonable fee to carry it out.

4. Sub-processors

The Controller gives general authorisation for the use of the following sub-processors, which are bound by equivalent data-protection obligations:

Sub-processorCountryPurposeData
Hetzner Online GmbHGermany and Finland (EU)Hosting of the application, the database and proof photos; backupsAll service data
Amazon Web Services EMEA SARL (Amazon SES)Luxembourg (EU); processing in Frankfurt, Germany (region eu-central-1)Relay of service email to users (password reset, notifications)The recipient's email address and the message content
OpenStreetMap FoundationUnited Kingdom (adequacy decision)Map tiles on the driver and dispatcher screens; address geocoding (Nominatim)For tiles: the device's IP address and the map area. For geocoding: the address text, sent from our server, without user details

The Processor informs the Controller by email at least 30 days before adding or replacing a sub-processor. The Controller may object in writing within that period on reasonable data-protection grounds; if no solution is found, it may terminate the subscription without penalty.

4A. Independent providers

The following services are not sub-processors; they act as independent controllers under their own terms, and their use constitutes an instruction of the Controller (address search) or an action of its users (navigation, sending the delivery tracking link). The Controller may request in writing that Google search be disabled; OpenStreetMap is then used alone.

ServiceCountryWhenData
Google Ireland Ltd (Places API)Ireland (EU); possible onward transfer to Google LLC, USA (EU-US Data Privacy Framework)Address autocomplete when a stop is enteredThe address text being typed — sent from our server, without IP or user details
Waze / Google Maps / Apple Maps (navigation apps)On the driver's device, under each app's own termsNavigation to the stop, when the driver taps “Navigate” — opens the app the driver has chosenThe stop's coordinates — from the driver's device, not from our server
SMS / WhatsApp / Viber (the device's messaging apps)On the device of the customer's user (dispatcher or driver), under the terms of each app or mobile carrierSending the delivery tracking link to the recipient, when a dispatcher or driver of the customer chooses to send it — the messaging app on their own device opens and they send the message themselves; PRODEL sends no messages and has no SMS providerThe recipient's phone number and the message text containing the link address — from the user's device, not from our server, which does not learn whether or to whom it was sent

Channels used to send the tracking link. SMS, WhatsApp, Viber and any other app with which the Controller’s users send the link of clause 2A are the Controller’s own means: it chooses and uses them independently of the Processor, from its users’ devices and under the terms it has itself with each provider. They are not sub-processors. The Processor sends no messages, has no SMS provider, and no data is transmitted from its systems to those providers.

5. Transfers outside the EU/EEA

Storage and processing take place within the EU. Flows to third countries exist only: (a) to the United Kingdom (OpenStreetMap Foundation), under the European Commission’s adequacy decision; (b) possibly to the USA, for address search through Google (clause 4A), under the adequacy decision for the EU-US Data Privacy Framework and, in addition, Google’s standard contractual clauses. No other transfer is made without the Controller’s prior written instruction and appropriate Chapter V safeguards.

6. Data breaches

The Processor informs the Controller’s Administrator, by email and telephone, of any personal data breach concerning the Controller’s data, including breaches at sub-processors, without undue delay and at the latest within 48 hours of establishing with reasonable certainty that a breach occurred. The initial notice contains the information available (nature, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed, contact point) and is supplemented in phases, so that the Controller can meet the deadlines of articles 33–34. The Processor documents the incident and cooperates in its investigation. Notification does not constitute an admission of liability.

7. Deletion, return and backups

  • During the subscription, the Controller may delete data itself in the app and request an export under clause 8 of the Terms of Service.
  • After termination, the data is kept for 30 days for export and then deleted from active systems, together with proof photos.
  • Backups are rotated as described in Annex A; monthly backups are kept, encrypted, for up to 13 months. They are not used to restore the Controller’s data after termination, except on its written request.
  • If the database or photo storage is restored from a backup, the Processor informs the Administrator within 24 hours, stating the point in time of the backup. Deletions the Controller had made after that point are re-applied by the Processor within 72 hours of the Controller notifying the records concerned. If the restore takes place after the subscription has ended, the Processor deletes all the Controller’s data again within 72 hours, without request.
  • Data that the Processor is legally required to retain (e.g. invoices) is excepted.

8. Audits

The Processor answers reasonable security questionnaires from the Controller in writing within 15 working days and provides the documentation of Annex A. Where that is insufficient, the Controller or an independent auditor it appoints (not a competitor of the Processor, bound by confidentiality) may carry out an audit, remote or on site, once a year or after a breach, with 30 days’ notice, during working hours, without access to other customers’ data. Each party bears its own costs; if the audit finds material non-compliance by the Processor, the Processor bears the reasonable costs of the audit and remedies the non-compliance without delay. The above does not limit the powers of the supervisory authority.

9. Obligations of the Controller

  • Ensures a legal basis for the data it enters and informs data subjects under articles 13–14; in particular, it informs drivers in writing before their first route about the sending of position, its duration, retention and recipients (template on the Driver notice page), and carries out an impact assessment where required, with the Processor’s assistance under clause 3(6).
  • Enters only the data necessary for the delivery; does not enter special-category data, door codes or other security details without need; ensures that proof photos show the item or the delivery point and not people.
  • Manages its users’ accounts and devices and removes access from those who leave.
  • Its instructions to the Processor comply with the GDPR.

10. Liability and governing law

Between the parties, clause 16 of the Terms of Service applies. Each party is liable for the damage caused by its own breach of the GDPR or of this Agreement and has a right of recourse against the other under article 82(5) for what it paid beyond its share. Administrative fines are borne by the party on which they were imposed. Governing law is the law of the Republic of Cyprus; the courts of Nicosia have jurisdiction. Supervisory authority: Office of the Commissioner for Personal Data Protection.

11. Duration, precedence, amendments

This Agreement applies for as long as the Processor processes personal data on behalf of the Controller, i.e. until deletion under clause 7 is complete, and survives the termination of the Terms of Service. In case of conflict between this Agreement and the Terms of Service, this Agreement prevails on data-protection matters and the Terms of Service on all other matters. Amendments to this Agreement are made as amendments to the Terms of Service (clause 18 thereof); amendments reducing the guarantees to the Controller require its express consent.

Annex A — Technical and organisational measures

  • Encryption of communication between users’ devices and the service with TLS (HTTPS, HSTS); internal connections between the Processor’s systems do not leave the server or its private network.
  • Authentication by email and password; passwords are stored only as bcrypt hashes; changing a password revokes all active sessions.
  • Role and ownership checks: a driver sees only the routes assigned to them; the role is re-checked against the database on every user-management action and at least every 60 seconds otherwise.
  • A separate installation per customer, with its own database and photo storage.
  • Proof photos in private object storage, without public links; access passes an authorisation check.
  • Driver position only during a route and not during breaks; only the latest position is kept, and it is deleted when the route is finished.
  • Delivery tracking page (clause 2A): addresses signed by the server with a secret key (HMAC), which cannot be guessed or derived from one another; automatic expiry 48 hours after the stop is closed, or 3 days after the route’s date if the stop was never closed; data minimisation — the page contains no address, recipient phone, notes, photos, failure reason, other stops, or driver identity or position; the position is used only on the server to calculate the arrival estimate; no cookies, device storage or analytics; a noindex tag and exclusion in robots.txt; a request limit per IP address.
  • Rate limits against automated attacks on sign-in, password reset, forms and the delivery tracking page.
  • Backups: database every hour during working hours and every night, photos every night; kept in Germany and, encrypted, in Finland; daily for 14 days, monthly for up to 13 months; server images for 7 days.
  • A deletion ledger kept outside the database, so that deletions made before a restore are re-applied automatically (today for contact-form leads; for other data see clause 7).
  • Servers in Hetzner data centres (Germany, Finland), with administrative access held only by the Processor’s management, over an encrypted connection with personal keys.
  • Regular security updates of the operating system and the application; software development in a separate environment with fictitious data.
  • The driver’s device temporarily stores, for offline operation, the pages of the current route and pending deliveries; they are deleted on sign-out and on synchronisation respectively. Physical security and management of devices rest with the Controller; the Processor revokes a user’s active sessions on request within 4 working hours.

Annex B — Processor’s details

Three Button Trading Ltd

Reg. no. HE 426226 · VAT CY10426226N · Registered office: 4 Makedonias Street, Troulloi, 7505 Larnaca, Cyprus · andreas@3buttontrading.com · +357 99 606664

Annex C — Controller’s details

As recorded in the Order Form: legal name, registration number, VAT number, address, Administrator and their email, start date.

For a signed copy of this Agreement with your business’s details, email andreas@3buttontrading.com. This text is a draft prepared by the Company and has not yet been reviewed by a lawyer.