Saltar al contenido
ServiciosCasos
Agenda tu diagnósticoAgendar
Legal center/Data

Data Processing Addendum

Leer este documento en español

On this page

  • 1. Scope and order of precedence
  • 2. Definitions
  • 3. Instructions and details of processing
  • 4. Confidentiality
  • 5. Security
  • 6. Subprocessors
  • 7. Data-subject requests
  • 8. Assistance and compliance
  • 9. Personal-data incidents
  • 10. Return and deletion
  • 11. Audit
  • 12. International transfers
  • 13. Liability and termination
  • Annex I — Processing description
  • Annex II — Technical and organizational measures
  • Annex III — Subprocessors
Version
July 27, 2026
Parties
The Shopify merchant accepting the Merchant Terms (“Controller”) and DIGIT DECK AGENCY S.A.S. (“Processor” or “Digitdeck”).

1. Scope and order of precedence

This Data Processing Addendum (“DPA”) forms part of the Merchant Terms and applies when Digitdeck processes personal data on the Controller’s behalf. If this DPA conflicts with the Merchant Terms on personal-data processing, this DPA controls. Applicable mandatory data-protection law controls over both.

2. Definitions

“Personal Data,” “Controller,” “Processor,” “Data Subject,” “Processing,” and “Supervisory Authority” have the meanings in applicable data-protection law. “Customer Data” means personal data received from Shopify or collected through a Digitdeck feature for the Controller. “Subprocessor” means a third party engaged by Digitdeck to process Customer Data.

3. Instructions and details of processing

Digitdeck will process Customer Data only on documented instructions in the Merchant Terms, module configuration, support requests, and Controller use of the Service, unless law requires otherwise. Digitdeck will inform the Controller if an instruction appears unlawful, unless prohibited.

The processing subject, duration, nature, purposes, data categories, and data subjects are listed in Annex I. The Controller is responsible for lawful instructions, notices, consents, and the accuracy of data supplied.

4. Confidentiality

Digitdeck will ensure persons authorized to process Customer Data are bound by confidentiality and receive access only as needed for assigned duties.

5. Security

Digitdeck will implement and maintain risk-appropriate technical and organizational measures, including those in Annex II. Digitdeck may update controls as technology and risk evolve, provided the overall protection is not materially reduced.

6. Subprocessors

The Controller grants general authorization for the subprocessors in the published Subprocessor List. Digitdeck will impose data-protection obligations at least as protective as this DPA and remains responsible for their performance to the extent required by law.

Digitdeck will provide reasonable advance notice of a new subprocessor that materially processes Customer Data. The Controller may object on documented data-protection grounds within fifteen days. The parties will attempt a reasonable alternative; if none is available, either party may terminate the affected feature without penalty.

7. Data-subject requests

Taking into account the nature of processing, Digitdeck will reasonably assist the Controller with requests to access, correct, delete, restrict, object, or export Personal Data. Digitdeck may direct requesters to the Controller and will not independently respond on the Controller’s behalf unless authorized or legally required. Shopify privacy webhooks are processed as described in the Privacy Policy.

8. Assistance and compliance

Digitdeck will reasonably assist with security, breach notification, data-protection impact assessments, regulator consultations, and evidence of compliance, considering the processing and information available. Requests requiring exceptional effort may be subject to reasonable fees agreed in advance, except where the assistance is required because of Digitdeck’s breach.

9. Personal-data incidents

Digitdeck will notify the Controller without undue delay after confirming a Personal Data Breach affecting Customer Data and will provide available information about nature, categories, likely consequences, containment, and remediation. Notification is not an admission of fault. The Controller is responsible for regulatory and data-subject notices unless law assigns that duty to Digitdeck.

10. Return and deletion

At termination or valid instruction, Digitdeck will delete or return Customer Data, unless law requires retention. Data in backups will remain protected and be deleted under the backup cycle. Shopify mandatory redaction events take precedence where applicable.

11. Audit

Digitdeck will provide current policies, summaries, or independent evidence reasonably sufficient to demonstrate compliance. If that is insufficient, the Controller may request one audit per year with at least thirty days’ notice, during normal hours, under confidentiality, without accessing other tenants’ data or disrupting operations. Additional audits are permitted after a confirmed material incident or regulator request. The Controller bears reasonable costs unless the audit finds a material Digitdeck breach.

12. International transfers

Where Customer Data is transferred from the EEA, United Kingdom, Switzerland, or another jurisdiction requiring safeguards to a country without an adequate level of protection, the parties will use the legally applicable transfer mechanism. For EEA transfers, the unmodified European Commission Standard Contractual Clauses, Module 2 (Controller to Processor), are incorporated where required; Annexes I–III of this DPA complete the corresponding annex information. The parties will execute additional forms reasonably required by law.

13. Liability and termination

Liability under this DPA is subject to the Merchant Terms except where applicable law prohibits that limitation. A material uncured breach of this DPA is a material breach of the Merchant Terms.

Annex I — Processing description

Item Description
Subject Hosting and operating enabled Digitdeck Shopify modules
Duration Subscription term plus limited deletion, backup, security, and legal-retention periods
Nature Collection, receipt, organization, storage, lookup, analysis, transmission, display, modification, deletion
Purposes Back-in-stock notices, bundles, referrals, reviews, experimentation, analytics, AI drafts, support, security, billing limits
Data subjects Merchant staff, shoppers, customers, reviewers, subscribers, referral participants
Data Store IDs/config; catalog/inventory; order/customer IDs and email where needed; review content; referral records; pseudonymous events; prompts and generated drafts; logs
Sensitive data Not intended or authorized
Frequency Continuous while relevant modules are enabled

Annex II — Technical and organizational measures

  • Tenant isolation keyed by verified Shopify store domain.
  • OAuth and least-privilege scopes; encrypted offline access tokens.
  • TLS in transit and provider encryption at rest.
  • HMAC and timestamp verification for webhooks; signed app-proxy validation.
  • Named access, MFA where supported, least privilege, secret management, and audit logging.
  • Rate limiting, fail-closed entitlements, idempotent queues, monitoring, and tested recovery.
  • Secure development review, dependency updates, backups, incident response, and redaction workflows.
  • Data minimization, synthetic QA data, restricted support evidence, and confidentiality obligations.

Annex III — Subprocessors

The current Subprocessor List is incorporated by reference and maintained with provider, purpose, data categories, location, and transfer safeguard.

Explorar

  • Servicios
  • Casos
  • Método
  • Nosotros
  • Contacto

Contacto

  • +57 300 295 4442
  • digitdeck.servicios@gmail.comCorreo copiado
  • Medellín, Colombia
  • Escribirnos
  • Agenda tu diagnóstico

Legal

  • Política de privacidad
  • Términos del servicio
  • Cookies y tracking
  • Centro legal

La app

  • Digitdeck en la Shopify App Store ↗
  • Privacidad de la Plataforma ↗

DIGIT DECK AGENCY S.A.S. · NIT 901731429-0 · Carrera 64 C # 48-43, Medellín, Antioquia, Colombia

© 2026 DigitDeck. Todos los derechos reservados.

Escribir por WhatsApp