Data Processing Agreement
This DPA forms part of, and is incorporated into, the Terms of Service (/legal/terms) (the "Agreement"). It is effective upon the Customer's acceptance of the Agreement, or upon first transmission of Merchant Personal Data to the service, whichever is earlier.
1. Definitions
- "Data Protection Law" — all laws applicable to the processing of personal data under this DPA, including, where applicable, Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and the Swiss FADP. "Controller", "processor", "data subject", "personal data", "personal data breach", and "processing" have the meanings given there.
- "Merchant" — a merchant store on which a dedicated app provisioned through the service is installed.
- "Merchant Personal Data" — personal data contained in storefront events emitted by a dedicated app's web pixel and sent to the DeploTeka data plane, as described in Annex I.
- "Sub-processor" — any third party engaged by DeploTeka to process Merchant Personal Data.
- "SCCs" — the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914, as amended or replaced.
2. Roles and scope
2.1 Roles. For Merchant Personal Data: the Merchant is the controller; the Customer acts as the Merchant's processor under its own arrangement with the Merchant; and DeploTeka processes Merchant Personal Data on the Customer's behalf as the Customer's (sub-)processor. DeploTeka's obligations in this DPA are those of a processor under Art. 28(3) GDPR regardless of its exact position in the chain.
2.2 Out of scope. This DPA does not cover data for which DeploTeka is a controller — the Customer's account data, the connected Shopify dashboard session, lead-form submissions, and operational metadata about the Customer's apps, stores, and setup runs. Those are governed by the Privacy Policy (/legal/privacy). Where operational metadata incidentally contains personal data of the Customer's or a Merchant's personnel (e.g. a store contact email), DeploTeka processes it only to provide the service.
2.3 Instructions. DeploTeka will process Merchant Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to do otherwise by law to which DeploTeka is subject — in which case DeploTeka will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. The Agreement, this DPA, and the Customer's configuration of the service (including which pixels are deployed and how the data plane is set) constitute the Customer's complete documented instructions at signature. Additional instructions require written agreement. DeploTeka will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
3. Details of processing
The subject matter, duration, nature and purpose of processing, the categories of data subjects and personal data, and the processing operations are set out in Annex I.
4. Customer obligations
4.1 The Customer warrants that its instructions are lawful and that it (or the relevant Merchant) has established a valid legal basis for the processing of Merchant Personal Data through the service.
4.2 The Customer is responsible for ensuring that each Merchant provides the storefront privacy notices and obtains any consents required for the pixel's operation, including under ePrivacy/cookie rules where they apply to storefront event collection.
4.3 The Customer will not instruct DeploTeka to process special categories of personal data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10) through the service, and will configure pixels so that such data is not sent.
4.4 The Customer will ensure its own arrangements with each Merchant permit DeploTeka's engagement as (sub-)processor on the terms of this DPA, and will flow down obligations no less protective than those here.
4.5 The Merchant relationship is the Customer's. As between the parties, the Customer — not DeploTeka — owns and operates the relationship with each Merchant and is solely responsible for that relationship and its compliance, including the Customer's and, as between the parties, each Merchant's compliance with their respective agreements with Shopify. DeploTeka has no contractual relationship with any Merchant and, except for obligations mandatorily imposed on processors by Data Protection Law, owes no duty to any Merchant. Nothing in this DPA transfers to DeploTeka any risk arising from Shopify's terms, policies, or enforcement, or qualifies §§5.3, 5.4, 14, or 15 of the Agreement.
5. DeploTeka's obligations
DeploTeka will:
- (a) Instructions — process Merchant Personal Data only as per §2.3;
- (b) Confidentiality — ensure that persons authorized to process Merchant Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- (c) Security — implement and maintain the technical and organizational measures described in Annex II, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing, as required by Art. 32 GDPR;
- (d) Sub-processors — engage Sub-processors only per §6;
- (e) Data-subject requests — taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's (or the Merchant's) obligation to respond to data-subject requests. If a data subject contacts DeploTeka directly, DeploTeka will not respond substantively except to direct them to the responsible controller, and will promptly notify the Customer;
- (f) Assistance — taking into account the nature of processing and the information available to it, assist the Customer in ensuring compliance with Arts. 32–36 GDPR (security, breach notification, DPIAs, prior consultation);
- (g) Return and deletion — comply with §9;
- (h) Information and audit — comply with §8.
6. Sub-processors
6.1 Authorization. The Customer gives general written authorization for DeploTeka to engage the Sub-processors listed in Annex III.
6.2 Changes. DeploTeka will give the Customer at least 30 days' written notice (email to the account address) before adding or replacing a Sub-processor. The Customer may object in writing on reasonable data-protection grounds within 14 days of notice. The parties will then discuss in good faith; if no resolution is found, the Customer may terminate the affected part of the service (and, if that part is not severable, the Agreement) with pro-rata refund of prepaid fees. Continued use after the notice period without objection constitutes acceptance.
6.3 Flow-down. DeploTeka will impose on each Sub-processor, by contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the Sub-processor's performance.
7. International transfers
7.1 DeploTeka will not transfer Merchant Personal Data outside the EEA/UK/Switzerland (where the data originates there) except in compliance with Chapter V GDPR (or the UK/Swiss equivalents).
7.2 Where such a transfer is made to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses, Module Three (processor → sub-processor) or Module Two as the chain requires, are incorporated by reference, with: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 30 days); Clause 11 optional redress not selected; Clause 17/18 law and forum = an EU member state; Annexes populated from Annexes I–III of this DPA. The UK International Data Transfer Addendum and the Swiss FADP adaptations apply where UK/Swiss data is in scope.
8. Audit
8.1 DeploTeka will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer (or, where required, by a Merchant exercising audit rights through the Customer).
8.2 Audit mechanics: first by written questionnaire and documentation review; an inspection on 30 days' notice, at most once per 12 months, during business hours, without disrupting production, under confidentiality, and at the Customer's cost — except that these limits do not apply where an audit is required by a supervisory authority or follows a personal data breach affecting the Customer's Merchant Personal Data.
9. Return and deletion
9.1 Upon termination of the Agreement, or upon the Customer's written request for a given Merchant (e.g. when a Merchant offboards), DeploTeka will, at the Customer's choice, delete or return the relevant Merchant Personal Data within 30 days, and delete existing copies, including from backup rotation, unless and to the extent storage is required by law — in which case DeploTeka will protect the retained data per this DPA and process it for no other purpose.
9.2 On request, DeploTeka will confirm deletion in writing.
10. Personal data breach
DeploTeka will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Merchant Personal Data. The notification will describe, to the extent then known: the nature of the breach, the categories and approximate volumes of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point — and will be supplemented as information becomes available. DeploTeka's notification is not an admission of fault. The Customer is responsible for onward notification to Merchants, supervisory authorities, and data subjects as Data Protection Law requires.
11. Liability and precedence
11.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement — including the Customer's indemnity in §14 of the Agreement and the exclusions in §15 — and liability under the Agreement and this DPA is a single aggregate cap, not separate caps.
11.2 In the event of conflict between this DPA and the Agreement with respect to the processing of Merchant Personal Data, this DPA prevails. Where the SCCs apply, the SCCs prevail over both to the extent of any conflict. For all other matters — in particular the allocation of Shopify platform risk — the Agreement (including §§5.3, 5.4, 14, and 15) prevails, and nothing in this DPA is a conflict with it.
11.3 Platform risk unaffected. Nothing in this DPA — including the assistance, audit, and breach-notification obligations in §§5, 8, and 10 — makes DeploTeka responsible for any act or omission of Shopify, creates any DeploTeka obligation or liability in respect of the Customer's or any Merchant's Shopify accounts, apps, or Partner status, or limits or overrides the platform-risk allocation, Customer indemnity, and liability exclusions in §§5.4, 14, and 15 of the Agreement, which apply with full force to this DPA and to the processing under it. For clarity: a Shopify Action (as defined in the Agreement) — including suspension or termination of a dedicated app, of the pixel's operation, or of the Customer's accounts, and any resulting unavailability or loss of Merchant Personal Data collection — is not a personal data breach by DeploTeka, is not a breach of this DPA, and gives rise to no DeploTeka liability.
12. Term
This DPA runs for as long as DeploTeka processes Merchant Personal Data under the Agreement, and §§8–11 survive until deletion is complete.
Annex I — Details of processing
Subject matter: collection, storage, and processing of storefront events emitted by the web pixel of the Customer's dedicated apps installed on Merchant storefronts, and monitoring of those apps' health.
Duration: the term of the Agreement plus the deletion window in §9.
Nature and purpose: receipt of events at the data-plane collection endpoint; storage; structuring; aggregation and analysis to deliver the analytics/data-plane functionality enabled for the Merchant; operational monitoring of app health. No use for DeploTeka's own purposes; no sale; no advertising use.
Categories of data subjects: visitors and shoppers of Merchant storefronts on which a dedicated app is installed.
Categories of personal data: storefront event data collected by the pixel, as configured for the Merchant.
Special categories: none intended or permitted; see §4.3.
Frequency: continuous, for as long as the pixel is active.
Annex II — Technical and organizational measures (Art. 32)
- Encryption in transit: TLS for all traffic, including pixel-to-endpoint.
- Credential protection: Shopify dashboard sessions sealed in an encrypted vault; never written to logs or rendered to clients; used server-side only.
- Tenant isolation: all cabinet reads are tenant-scoped at the query layer.
- Ingress integrity: lifecycle webhooks are HMAC-verified; unauthenticated or malformed input is rejected; public endpoints are rate-limited with input validation and size caps.
- Least privilege: scope intersection on deploy prevents silent broadening of an app's access; install links are fetched on demand via audited server round-trips, never embedded or logged.
- Change management: configuration changes are applied server-side and recorded per change.
Annex III — Authorized Sub-processors
| Sub-processor | Purpose | Location / region | Transfer mechanism |
|---|---|---|---|
| EU-based cloud infrastructure provider | Hosting & infrastructure for the control plane and data plane | European Union | N/A — in-region |
Acceptance: this DPA is accepted electronically together with the Terms of Service.