Data processing agreement
This agreement applies whenever we process personal data on your behalf through reorderly, netterms, weighpoint or commissionly. You are the controller; we are your processor. It takes effect automatically when you install an app — you do not need to sign or request it. If your organisation requires a countersigned copy with our full registered details, email [email protected].
1. Roles and scope
For the store data we process through the apps — your orders, products, inventory, companies, staff and shoppers — you are the controller and we are the processor. For your own account and billing details, and for how you use our website, we are a controller in our own right and our privacy policy governs instead. Where a merchant is itself a processor for someone else, we act as sub-processor and this agreement reads accordingly.
“GDPR” means Regulation (EU) 2016/679 and, where relevant, the UK GDPR and the Data Protection Act 2018. Terms such as controller, processor, personal data, processing and personal data breach carry the meanings given in the GDPR.
2. Our instructions
We process personal data only on your documented instructions. Your instructions are: this agreement, the terms of service, the settings and rules you configure inside each app, and any further written instruction you give us. Installing an app and configuring it is an instruction to process as described in Annex 1.
We will tell you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law, and we may pause that processing until it is resolved. We will not process personal data for our own purposes, and we will not sell it, share it for advertising, or use it — or permit anyone else to use it — to create, train, fine-tune or improve any machine-learning or artificial-intelligence system.
3. Confidentiality of personnel
Everyone we authorise to process your personal data is bound by a written duty of confidentiality that survives the end of their engagement, is granted access only to what their role requires, and is subject to multi-factor authentication and access logging.
4. Security
We implement and maintain the technical and organisational measures set out in Annex 2, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR. We may update those measures over time, but not in a way that materially reduces the level of protection.
5. Sub-processors
You give us general written authorisation to engage the sub-processors listed in Annex 3. Each is bound by written terms imposing data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their performance.
We will give you at least 30 days’ notice by email to the store owner before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected app without further charge and receive a pro-rata refund of any prepaid fees for the unused period.
6. Assisting you with data subject requests
The apps let you find, export, correct and delete the records we hold for a given person, so most requests you can complete yourself. Where you cannot, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing, so you can respond within your statutory deadlines. If a data subject contacts us directly about data we process for you, we will not respond substantively — we will refer them to you and tell you promptly.
We also implement Shopify’s three mandatory compliance webhooks — customer data request, customer redact and shop redact — and act on them within the timeframes Shopify requires.
7. Personal data breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process for you. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of that at once, we will provide it in phases without further undue delay.
You are responsible for notifying your supervisory authority and affected individuals where the law requires it. We will provide reasonable assistance.
8. Data protection impact assessments
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority under Articles 35 and 36 GDPR.
9. Deletion and return
On uninstall, Shopify sends us a webhook. We stop processing immediately and delete or anonymise that store’s personal data within 48 hours, except where we are required by law to retain it — principally tax and accounting records, which are retained only for that purpose and remain subject to this agreement. Export your data before you uninstall; deletion is not reversible. We will confirm deletion in writing on request.
10. Audits and demonstrating compliance
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including the contents of this agreement and its annexes, and will respond to reasonable written security questionnaires no more than once a year. Where that is not sufficient for your regulator, we will permit an audit by you or a mutually agreed independent auditor, on at least 30 days’ notice, during business hours, no more than once in any twelve months except after a personal data breach, subject to confidentiality and to not disrupting our other customers. You bear the cost unless the audit reveals a material breach by us.
11. International transfers
We are based in Sweden, inside the EEA, and prefer EEA regions for every subprocessor. Where a subprocessor nevertheless processes personal data outside the EEA — see Annex 3 — that transfer is made under the European Commission’s Standard Contractual Clauses of 4 June 2021, Module Two (controller to processor), incorporated by reference and completed as follows:
- Clause 7 (docking) applies.
- Clause 9: Option 2, general written authorisation, with the 30-day notice period in section 5 above.
- Clause 11: the optional independent dispute resolution body does not apply.
- Clause 17: governed by the law of Sweden.
- Clause 18(b): the courts of Sweden.
- Annexes I, II and III of the Clauses are Annexes 1, 2 and 3 of this agreement.
For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies to those Clauses, with Tables 1 to 3 completed by reference to the same annexes and Table 4 selecting “Importer”. For Swiss transfers, the Clauses apply with references to the GDPR read as references to the Swiss FADP, the competent authority read as the Swiss FDPIC, and “member state” read so as not to deprive data subjects in Switzerland of the right to sue in their place of habitual residence.
If a transfer mechanism we rely on is invalidated, we will adopt a valid alternative without undue delay rather than continuing the transfer.
12. United States state privacy law
Where the California Consumer Privacy Act as amended, or a comparable US state privacy law, applies to personal information we process for you, we act as a service provider (or processor, as that law terms it). We will not sell or share that personal information, retain, use or disclose it outside the direct business relationship with you, or combine it with personal information from another source except as that law permits. We will notify you if we determine we can no longer meet those obligations.
13. Liability and precedence
Each party’s liability under this agreement is subject to the limitations and exclusions in the terms of service, except where the GDPR provides otherwise as between controller and processor or in respect of a data subject’s claim. If this agreement conflicts with the terms of service on a data protection matter, this agreement prevails; if it conflicts with the Standard Contractual Clauses, the Clauses prevail.
14. Term
This agreement takes effect when you install an app and continues while we process personal data for you. Sections 3, 4, 9, 10, 11, 12 and 13 survive its end for as long as we hold any personal data of yours.
Annex 1 — Details of processing
Subject matter: provision of the apps you have installed. Duration: for as long as the app is installed, plus the deletion window in section 9. Nature and purpose: collection, storage, organisation, retrieval, use, disclosure to sub-processors, erasure — in order to provide the functions described below. Frequency: continuous.
| App | Purpose of processing | Categories of data subject | Categories of personal data |
|---|---|---|---|
| reorderly | Demand forecasting, purchase orders, receiving, supplier communication | Your staff; supplier contacts | Name, business email, business phone; no shopper records are accessed |
| netterms | Credit limits, invoicing, A/R aging, collections correspondence, checkout enforcement | Your B2B customers’ company contacts; your staff | Name, email, phone, billing address, company affiliation, order and payment history, credit limit and status |
| weighpoint | Price computation at the point of sale, fractional inventory, receipts | Your staff; shoppers indirectly via order records | Staff identifier and role for override and PIN logging; order line data |
| commissionly | Sale attribution, commission calculation, payout periods and exports | Your retail staff; shoppers indirectly via order records | Staff name, email, Shopify staff ID, role, home location, pay type, PIN hash; order and refund data attributed to them |
No special categories of personal data under Article 9 GDPR are required by any app, and none should be entered into free-text fields.
Annex 2 — Technical and organisational measures
- Encryption. TLS 1.2 or better in transit; AES-256 at rest for databases and backups.
- Access control. The number of people who can reach production is kept minimal by design; that access requires multi-factor authentication, is reviewed on any role change, revoked on departure, and logged.
- Tenant isolation. Every record is scoped to a shop identifier and every query is filtered by the authenticated session’s shop; API access is authenticated by Shopify session token or a signed webhook HMAC.
- Least-privilege scopes. Each app requests only the Shopify OAuth scopes its features need; the per-app list is published in the privacy policy.
- Auditability. Automated writes to your store are attributable and, where applicable, reversible — inventory receipts carry a reference document, credit events record before and after values, commission lines carry their calculation, and overrides record the actor.
- Resilience. Encrypted daily backups with tested restoration; idempotency keys on all inventory and order-derived writes so that a replay cannot double-apply.
- Secure development. Version control with review, dependency vulnerability scanning, secrets held in a managed secret store and never in source, changes tested before release.
- Deletion. Automated erasure on the Shopify uninstall and redact webhooks, within 48 hours.
- Incident response. A documented process for detection, containment, assessment and notification, with the 48-hour controller notification in section 7.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify Inc. | Platform, OAuth, billing, app distribution | Canada / US |
| Cloud hosting and managed database provider | Application hosting and managed database | EEA |
| Error and log monitoring provider | Fault diagnosis and error reporting | EEA |
| Transactional email provider | Service notices, invoices and collection reminders | EEA |
| Support desk provider | Support correspondence | EEA |
Contact
[email protected] · Flotelligent, Sweden. Our registered business details are provided on request. Our supervisory authority is Integritetsskyddsmyndigheten (IMY), Sweden.