Skip to content
DocumentationSupportSecurityService status
SK EN
TOREVO
Products Shopify solutions Integrations Projects About
Discuss a project
Primary navigation
Products Shopify solutions Integrations Projects About
Slovenčina English
DocumentationSupportSecurityService status
Discuss a project
Legal
PrivacyTermsDPASubprocessors
Contact
Torevo Legal

Subprocessors and external services

This overview describes services used by mespi s.r.o. as the operator of the Torevo brand and distinguishes our subprocessors from platforms and recipients connected by the merchant. A provider receives data only to the extent required for an enabled service.

Last updated: 29 July 2026
ProviderRolePurpose and scopeLocation and contractual basis
DigitalOcean, LLCSubprocessorHosting of applications, databases, encrypted documents and operational monitoring.Primary data centre Frankfurt (FRA1). The DPA dated 6 February 2026 covers GDPR, the Data Privacy Framework and fallback Standard Contractual Clauses.
Sendinblue SAS (Brevo)SubprocessorTransactional delivery of public contact-form messages: name, email, topic and message.Sendinblue SAS, Paris, France. The DPA is an appendix to the Brevo Terms. Exact location and further providers follow the current Brevo account and DPA.
Websupport s. r. o.SubprocessorOperation of the torevo@torevo.tech mailbox and related delivery of business, support and privacy correspondence.Websupport s. r. o., Slovakia/EU. Article 16.11 of the current Terms contains Article 28 GDPR processor terms.
ShopifyMerchant-selected platformSource of store identity, permissions, orders, transactions, subscription and administration context.Shopify processes data under its own agreement with the merchant. Torevo uses only approved permissions, APIs and webhooks required by the installed app.
KROS a. s.Merchant-connected recipient and providerCreation or reconciliation of invoice documents, payments, operation state and PDFs.Used only after the merchant connects its own KROS account. Data is sent on its instruction over HTTPS with a dedicated API token under the KROS OpenAPI terms.
Packeta GroupMerchant-selected recipient and carrierPickup points, shipment creation, labels and delivery status.Used only by an installed Torevo • Packeta SK or Torevo • Zasilkovna app and only for data required for the requested delivery.

How this list is used

  • A carrier or invoicing provider receives no data until the merchant connects and enables the relevant app or integration.
  • Torevo does not send one provider the API secrets of another provider or another merchant’s data.
  • Retention, export and deletion follow the service purpose, contract, legal obligations and a technically verified deletion procedure.
  • Torevo maintains a control register of public DPAs, terms, review dates and transfer mechanisms. We do not have a separately negotiated DPA with DigitalOcean, Brevo or Websupport. We rely on their current published documents.
  • If a new subprocessor is added, this overview and contractual documentation are updated before production use. Active customers receive appropriate notice and may raise a reasoned objection.

Send questions about providers, transfers or a specific DPA to torevo@torevo.tech.

TOREVO

Torevo builds Shopify apps, integrations and e-commerce systems for day-to-day commerce operations.

Slovenčina · English

Products

KROS InvoicingTorevo ShippingTorevo • Packeta SKTorevo • ZasilkovnaLocalisations

Shopify solutions

Custom appsIntegrationsAutomationStorefront and UXTechnical audit

Resources and support

DocumentationSupportSecurityService statusChangelog

Torevo

AboutProjectsContactLegal

© 2026 Torevo. All rights reserved.