Skip to main content

GDPR Compliance

iDeployed is a German company (UG, haftungsbeschränkt, registered in Leipzig) and is fully subject to the General Data Protection Regulation (GDPR / DSGVO).

Data storage and processing

All data is stored and processed in Germany. No data is transferred outside the EU. See Data Residency for details.

Data Processing Agreement (DPA / AVV)

If you process personal data of your customers through your JTL-Shop hosted on iDeployed (which is almost certainly the case for any e-commerce operation), you are required under GDPR Art. 28 to have a Data Processing Agreement (DPA) in place with iDeployed as your processor.

A DPA is available on request. Contact us at [email protected] to receive a copy.

Access to your data

Only authorised iDeployed personnel may access your infrastructure, and only for support or maintenance purposes. We do not access, share, or sell your shop data to third parties.

Your rights under GDPR

As a data subject, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (right to erasure)
  • Object to processing
  • Data portability

To exercise any of these rights, contact us at [email protected].

Your responsibilities as a shop operator

As the operator of a JTL-Shop, you are a data controller for the personal data of your customers. iDeployed acts as your data processor. You remain responsible for:

  • Your own shop privacy policy
  • Obtaining lawful bases for processing customer data
  • Cookie consent banners and tracking technologies in your shop