This Data Processing Agreement ("DPA") is entered into by and between Revnous (operating "Appdesh"), based in Berlin, Germany ("Processor"), and the App Founder / Customer utilizing the Appdesh services ("Controller").
This DPA applies exclusively to the processing of Shopify Partner API data, merchant metrics, and related platform analytics provided by the Controller to the Processor.
1. Definitions and Scope
- "Controller Data" means any data, including personal data relating to merchants, orders, subscriptions, or end-customers, pulled from the Shopify Partner API using credentials provided by the Controller.
- Scope: The Processor will process Controller Data solely for the purpose of generating analytical dashboards, managing business operations, and triggering Slack notifications as configured by the Controller within the Appdesh platform.
2. Roles and Instructions
- Roles: The parties acknowledge that the Customer is the Controller (or an intermediary Processor acting on behalf of a Shopify merchant) and Appdesh is the Processor (or Sub-processor).
- Compliance: The Processor shall process Controller Data strictly in accordance with the documented instructions of the Controller, including configurations set via the platform UI, and in strict compliance with Article 28 of the GDPR.
- Shopify Terms: Both parties agree to handle data in compliance with the Shopify Partner Program Agreement and Shopify's API Terms.
3. Data Minimization & Specification
- Data Minimization: The Processor commits to pulling only the minimum necessary API datasets required to perform the platform services.
- Categories of Data: Includes Shopify app statistics, transaction values, subscription states, shop identifiers, and non-sensitive operational event logs.
- Data Subjects: Shopify merchants, store owners, and end-consumers interacting with the Controller's apps.
4. Technical and Organizational Security Measures
The Processor shall implement appropriate technical and organizational measures to protect Controller Data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of Shopify API keys and Slack OAuth tokens at rest and in transit.
- Strict access controls limiting infrastructure availability to authorized personnel.
- Regular vulnerability patching and application state monitoring.
5. Sub-processors
The Controller grants generalized authorization to the Processor to engage sub-processors (such as infrastructure hosts or backend analytics tools like Mixpanel EU). The Processor ensures that all sub-processors are bound by written data protection obligations at least as restrictive as those outlined in this DPA.
6. Support for Shopify Compliance & Mandatory Webhooks
- Data Subject Requests: The Processor will, to a commercially reasonable extent, assist the Controller in fulfilling obligations to respond to data subjects exercising their rights under GDPR.
- Shopify Mandatory Webhooks: The Processor will not obstruct, and will actively assist the Controller in complying with, Shopify's mandatory privacy webhooks (e.g., Requests for Customer Data, Customer Data Deletion, and Shop Data Deletion). Upon receiving verified deletion hooks, relevant cached data will be erased across Appdesh sub-systems.
7. Data Return and Deletion
Upon termination of the service or upon the explicit disconnection of the Shopify Partner API integration by the Controller, the Processor shall delete all cached or stored Controller Data within 30 days, unless applicable European Union or German national law requires its continued storage.
8. Miscellaneous
This DPA is governed by the laws of the Federal Republic of Germany. The exclusive venue for disputes arising under this agreement shall be Berlin, Germany.