Last updated 1 October 2026
Data Processing Addendum (DPA)
This addendum forms part of the Terms of service between the Operator (controller) and Nordera Works Teknoloji ve Danışmanlık A.Ş. (processor) and reflects Art. 28 GDPR.
1. Subject matter and duration
Processing of order, inventory and courier-pickup data to provide the PickVend service, for the term of the service agreement.
2. Nature and purpose
Receiving orders from delivery platforms, checking and reserving stock, unlocking machines for couriers, verifying picked items, synchronising inventory, logging events, and reporting to the Operator.
3. Categories of data and data subjects
- Couriers: order code entered, timestamp, IP address, machine. No names.
- Operator staff: contact details, login activity.
- End customers: none directly. The delivery platform does not share customer names, addresses or payment data with PickVend. Order IDs are pseudonymous.
4. Processor obligations
- Process only on documented instructions from the Operator (the service configuration counts as instructions).
- Ensure staff with access are bound by confidentiality.
- Implement the technical and organisational measures in Section 6.
- Assist the Operator with data-subject requests, security incidents and impact assessments.
- Delete or return all data at the end of the service, unless law requires retention.
- Make available the information needed to demonstrate compliance and allow audits on reasonable notice.
5. Sub-processors
| Sub-processor | Role | Location |
|---|
| Vercel Inc. | Hosting, serverless compute | Frankfurt, Germany (fra1) |
| Neon Inc. | PostgreSQL database | Frankfurt, Germany (AWS eu-central-1) |
| Delivery platform (as configured, e.g. Wolt Enterprises Oy) | Receives order status and inventory | Finland / EU |
| Machine cloud (as configured, e.g. Selfly Store Oy / Husky) | Receives unlock commands, provides inventory | Finland / EU |
We notify the Operator at least 30 days before adding or replacing a sub-processor; the Operator may object on reasonable grounds.
6. Technical and organisational measures
- TLS 1.2+ for all connections; webhooks authenticated by HMAC signature or secret header.
- Machine and platform credentials encrypted at rest (AES-256-GCM) with keys held outside the database.
- Role-based access to the dashboard; audit log of all API calls and webhooks.
- Data stored exclusively in EU data centres; daily backups by the database provider.
- Security incidents notified to the Operator without undue delay and within 48 hours of becoming aware.
7. International transfers
Data stays in the EU. Remote support access from Türkiye, where it occurs, is covered by EU standard contractual clauses (2021/914, module 2) which form part of this addendum on request.
Contact for this addendum: hello@norderaworks.com