1. Scope and order of precedence
This Data Processing Addendum (“DPA”) forms part of the Merchant Terms and applies when Digitdeck processes personal data on the Controller’s behalf. If this DPA conflicts with the Merchant Terms on personal-data processing, this DPA controls. Applicable mandatory data-protection law controls over both.
2. Definitions
“Personal Data,” “Controller,” “Processor,” “Data Subject,” “Processing,” and “Supervisory Authority” have the meanings in applicable data-protection law. “Customer Data” means personal data received from Shopify or collected through a Digitdeck feature for the Controller. “Subprocessor” means a third party engaged by Digitdeck to process Customer Data.
3. Instructions and details of processing
Digitdeck will process Customer Data only on documented instructions in the Merchant Terms, module configuration, support requests, and Controller use of the Service, unless law requires otherwise. Digitdeck will inform the Controller if an instruction appears unlawful, unless prohibited.
The processing subject, duration, nature, purposes, data categories, and data subjects are listed in Annex I. The Controller is responsible for lawful instructions, notices, consents, and the accuracy of data supplied.
4. Confidentiality
Digitdeck will ensure persons authorized to process Customer Data are bound by confidentiality and receive access only as needed for assigned duties.
5. Security
Digitdeck will implement and maintain risk-appropriate technical and organizational measures, including those in Annex II. Digitdeck may update controls as technology and risk evolve, provided the overall protection is not materially reduced.
6. Subprocessors
The Controller grants general authorization for the subprocessors in the published Subprocessor List. Digitdeck will impose data-protection obligations at least as protective as this DPA and remains responsible for their performance to the extent required by law.
Digitdeck will provide reasonable advance notice of a new subprocessor that materially processes Customer Data. The Controller may object on documented data-protection grounds within fifteen days. The parties will attempt a reasonable alternative; if none is available, either party may terminate the affected feature without penalty.
7. Data-subject requests
Taking into account the nature of processing, Digitdeck will reasonably assist the Controller with requests to access, correct, delete, restrict, object, or export Personal Data. Digitdeck may direct requesters to the Controller and will not independently respond on the Controller’s behalf unless authorized or legally required. Shopify privacy webhooks are processed as described in the Privacy Policy.
8. Assistance and compliance
Digitdeck will reasonably assist with security, breach notification, data-protection impact assessments, regulator consultations, and evidence of compliance, considering the processing and information available. Requests requiring exceptional effort may be subject to reasonable fees agreed in advance, except where the assistance is required because of Digitdeck’s breach.
9. Personal-data incidents
Digitdeck will notify the Controller without undue delay after confirming a Personal Data Breach affecting Customer Data and will provide available information about nature, categories, likely consequences, containment, and remediation. Notification is not an admission of fault. The Controller is responsible for regulatory and data-subject notices unless law assigns that duty to Digitdeck.
10. Return and deletion
At termination or valid instruction, Digitdeck will delete or return Customer Data, unless law requires retention. Data in backups will remain protected and be deleted under the backup cycle. Shopify mandatory redaction events take precedence where applicable.
11. Audit
Digitdeck will provide current policies, summaries, or independent evidence reasonably sufficient to demonstrate compliance. If that is insufficient, the Controller may request one audit per year with at least thirty days’ notice, during normal hours, under confidentiality, without accessing other tenants’ data or disrupting operations. Additional audits are permitted after a confirmed material incident or regulator request. The Controller bears reasonable costs unless the audit finds a material Digitdeck breach.
12. International transfers
Where Customer Data is transferred from the EEA, United Kingdom, Switzerland, or another jurisdiction requiring safeguards to a country without an adequate level of protection, the parties will use the legally applicable transfer mechanism. For EEA transfers, the unmodified European Commission Standard Contractual Clauses, Module 2 (Controller to Processor), are incorporated where required; Annexes I–III of this DPA complete the corresponding annex information. The parties will execute additional forms reasonably required by law.
13. Liability and termination
Liability under this DPA is subject to the Merchant Terms except where applicable law prohibits that limitation. A material uncured breach of this DPA is a material breach of the Merchant Terms.
Annex I — Processing description
| Item | Description |
|---|---|
| Subject | Hosting and operating enabled Digitdeck Shopify modules |
| Duration | Subscription term plus limited deletion, backup, security, and legal-retention periods |
| Nature | Collection, receipt, organization, storage, lookup, analysis, transmission, display, modification, deletion |
| Purposes | Back-in-stock notices, bundles, referrals, reviews, experimentation, analytics, AI drafts, support, security, billing limits |
| Data subjects | Merchant staff, shoppers, customers, reviewers, subscribers, referral participants |
| Data | Store IDs/config; catalog/inventory; order/customer IDs and email where needed; review content; referral records; pseudonymous events; prompts and generated drafts; logs |
| Sensitive data | Not intended or authorized |
| Frequency | Continuous while relevant modules are enabled |
Annex II — Technical and organizational measures
- Tenant isolation keyed by verified Shopify store domain.
- OAuth and least-privilege scopes; encrypted offline access tokens.
- TLS in transit and provider encryption at rest.
- HMAC and timestamp verification for webhooks; signed app-proxy validation.
- Named access, MFA where supported, least privilege, secret management, and audit logging.
- Rate limiting, fail-closed entitlements, idempotent queues, monitoring, and tested recovery.
- Secure development review, dependency updates, backups, incident response, and redaction workflows.
- Data minimization, synthetic QA data, restricted support evidence, and confidentiality obligations.
Annex III — Subprocessors
The current Subprocessor List is incorporated by reference and maintained with provider, purpose, data categories, location, and transfer safeguard.