StoreERP

Legal document

Data processing agreement

This agreement sets out the terms on which, and the safeguards with which, Storex processes the personal data of a customer business's clients and employees when the business enters that data into the Storex system.

Effective date
TODO: date of approval
Legal basis
Article 19 of the Law on Personal Data Protection
Related documents
Terms of service, Privacy policy

Version: storex-dpa-2026-09-29

This is an English translation provided for convenience. The Mongolian text is the authoritative version; where the two differ, the Mongolian governs.

Draft. This document has not been through legal review and has not been approved. It is not legally in force until it is.

Summary

The key provisions explained in plain language. This summary does not replace the agreement; where they differ, the clauses below govern.

  • You decide, we carry it out. Storex processes data only on your instructions (Article 2).
  • No use beyond the purpose. Storex does not use your clients' data for its own purposes (Article 3).
  • Advance notice of sub-processors. 30 days before a new one is added, with a right to object (Article 9).
  • Breaches notified within 24 hours. So you can make your legally required notifications on time (Article 11).
  • Help with rights requests. The system gives you the tools to fulfill data subjects' requests (Article 8).
  • Returned and deleted at the end. 60 days to export, then deletion, except records the law requires us to keep (Article 14).

1 Parties and definitions

  1. 1.1.

    Controller: the customer business that has accepted the Terms of Service. Processor: Storex (TODO: registered legal name, state registration number, registered address).

  2. 1.2.

    This agreement forms an integral part of the Terms of Service, and terms defined there have the same meaning here. "Personal data", "data subject" and "processing" have the meanings given to them in the Law on Personal Data Protection.

  3. 1.3.

    "Sub-processor" means a third party that accesses or processes personal data on the instructions of Storex.

2 Allocation of roles and instructions

  1. 2.1.

    The Controller determines the purposes and means of processing. Storex processes data only in accordance with the Controller's documented instructions. The Terms of Service, this agreement, and the settings the Controller configures and actions it takes in the system constitute such instructions.

  2. 2.2.

    If Storex considers that an instruction violates the law, it will promptly inform the Controller and may decline to carry out that instruction until it has been clarified.

  3. 2.3.

    Where the law requires Storex to process data, Storex will inform the Controller in advance, unless the law prohibits it from doing so.

3 Purpose of processing 19.2

Providing the Controller with point-of-sale, appointment booking, membership, online ordering, accounting and payroll services, together with the related technical support, backup and security. Storex will not use the data for its own marketing, for profiling, or to sell it to any other party.

4 Duration of processing 19.2

Data is processed for as long as the service agreement is in force and, after it terminates, for the return and deletion period set out in Article 14.

5 Data subjects and categories of data 19.2

Data subjectsData
The Controller's clients Name, phone number, email, appointments, purchase history, membership points, delivery address
The Controller's employees Name, job title, login access, hours worked, salary, bonus calculations, national registration number, bank account
Supplier representatives Name, phone number, email

The service is not designed for processing sensitive personal data. If the Controller enters such data (for example, a salon client's allergy information), the Controller is itself responsible for having the specific legal basis and consent the law requires.

6 Controller's obligations

  1. 6.1.

    To have a lawful basis for collecting the data, to obtain the data subject's consent where required, and to inform data subjects about the processing.

  2. 6.2.

    To ensure that the data entered into the system is accurate and limited to what the purpose requires.

  3. 6.3.

    To limit employees' access to what their work requires, and to revoke the access of departing employees promptly.

7 Processor's obligations

  1. 7.1.

    To limit the staff who access the data to those whose work requires it, and to bind them to confidentiality in writing.

  2. 7.2.

    To implement the security measures set out in Article 10 and keep them up to date.

  3. 7.3.

    To keep a record of the processing carried out on the Controller's behalf, and to provide the supervisory authority designated by law with the information it requires, through the Controller.

  4. 7.4.

    To assist the Controller, within reason, in meeting its legal obligations (risk assessments, breach notifications, dealings with the supervisory authority).

8 Safeguarding data subjects' rights 19.2

  1. 8.1.

    Storex provides the Controller, through the system, with tools to search for, view, correct, export and delete a data subject's data.

  2. 8.2.

    If a data subject submits a request directly to Storex, Storex will forward it to the Controller within 5 business days and help fulfill it as the Controller instructs. Storex will not respond to the request directly without the Controller's authorization.

9 Sub-processors 19.3

  1. 9.1.

    By accepting this agreement, the Controller authorizes the use of the sub-processors listed below. TODO: list of sub-processors

    Sub-processorServiceLocation
    TODOServers, data centerTODO
    TODOBackupTODO
    TODOSending text messages and emailTODO
  2. 9.2.

    Storex will give 30 days' notice before adding or replacing a sub-processor. If the Controller objects on reasonable grounds and the parties do not reach agreement, the Controller may terminate the service agreement without penalty and receive a refund of fees for the unused period.

  3. 9.3.

    Storex will enter into a written agreement with each sub-processor imposing data protection obligations no less protective than those in this agreement, and is liable for the sub-processor's acts as for its own.

  4. 9.4.

    Services that the Controller itself chooses and contracts with directly, such as the e-Barimt system, banks and QPay, are not sub-processors of Storex; transmitting data to them is done on the Controller's instructions.

10 Confidentiality and security measures

  1. 10.1.

    Storex implements at least the following technical and organizational measures:

    • encrypting data in transit with TLS;
    • isolating each Controller's data at the database level;
    • granting access on the principle of least privilege and logging every access;
    • storing passwords only in one-way hashed form;
    • backing up regularly and testing the ability to restore every year;
    • patching software vulnerabilities regularly;
    • training staff in data protection regularly.
  2. 10.2.

    Storex may update these measures in line with technological developments, provided the level of protection is not reduced.

11 Personal data breach notification

  1. 11.1.

    On becoming aware of a personal data breach affecting the Controller's data, Storex will notify the Controller without undue delay, and within 24 hours of becoming aware of it.

  2. 11.2.

    The notification will describe the nature of the breach, the data subjects affected, the categories and approximate number of records, the likely consequences, and the measures taken or proposed. Information not available at the time will be provided as soon as it becomes available.

  3. 11.3.

    The Controller is responsible for notifying the supervisory authority and data subjects, and Storex will provide the information required to do so.

12 Storage location and cross-border transfer

Data is stored in TODO: server location. Storex will not transfer data outside the territory of Mongolia without notifying the Controller in advance and ensuring the safeguards required by law.

13 Audits

  1. 13.1.

    On the Controller's request, Storex will provide information demonstrating its compliance with this agreement.

  2. 13.2.

    No more than once a year, and on 30 days' notice, the Controller may conduct an audit at its own expense, or have one conducted by an independent auditor bound by confidentiality. This limit does not apply to audits prompted by a breach or required by the supervisory authority.

  3. 13.3.

    An audit must not affect the data or security of Storex's other customers, and must take place during business hours.

14 Return and deletion on termination 19.4.5

  1. 14.1.

    For 60 days after termination, the Controller may export its data in common machine-readable formats (CSV, XLSX).

  2. 14.2.

    When that period ends, Storex will delete the data within 30 days, and it will be fully deleted from backup copies through routine rotation within 90 days. On the Controller's request, Storex will confirm the deletion in writing.

  3. 14.3.

    Records that the law requires to be retained are not deleted — processing of them stops, and they are moved to archival storage for the period the law prescribes.

15 Liability

The parties' liability under this agreement is governed by Article 15 of the Terms of Service. That limitation does not apply to liability that the law does not permit to be limited.

16 Term and order of precedence

  1. 16.1.

    This agreement takes effect together with the Terms of Service and remains in force for as long as Storex processes the Controller's data.

  2. 16.2.

    In matters concerning personal data, where this agreement conflicts with the Terms of Service, this agreement prevails.