Optizio Policy Documents

Data Processing Agreement (DPA)

Version: 1.0
Issued: 31st July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Optizio Ltd (“Data Processor”) and the merchant using the Code Bulk application (“Data Controller”).

This DPA reflects the parties’ agreement regarding the processing of personal data in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

1. Subject Matter, Nature, and Purpose of Processing

The Data Processor provides the Code Bulk Shopify application to the Data Controller. The purpose of processing is to enable bulk discount code generation, import, and management on the Data Controller’s Shopify store, and, where the Data Controller opts in, to mirror those codes into the Data Controller’s connected Klaviyo account.

Processing involves:

No end-user (shopper) personal data such as names, email addresses, or payment details are collected or processed. Discount redemption codes are treated as configuration data and are not used for profiling or marketing.

2. Duration of Processing

This DPA shall remain in effect as long as the Data Controller has the Code Bulk app installed and the Terms and Conditions are in force.

3. Obligations of the Data Processor

The Data Processor shall:

  1. Process data only on documented instructions from the Data Controller, including with regard to transfers of personal data to a third country or an international organization.
  2. Ensure confidentiality: Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement security measures: Take all measures required pursuant to Article 32 of the GDPR (Security of Processing), detailed in Annex II (Technical and Organizational Measures - TOMs).
  4. Engage sub-processors only with authorization: The Data Controller grants a general authorization to engage the sub-processors listed in Annex I. The Processor will inform the Controller of any intended changes concerning the addition or replacement of other sub-processors, giving the Controller the opportunity to object to such changes. Notice will be given at least thirty (30) days before the intended change takes effect, except where a shorter period is necessary to address a security risk or to comply with a legal obligation, in which case notice will be given as early as reasonably practicable. If the Controller objects on reasonable data protection grounds within that period, the parties will discuss the objection in good faith; if it cannot be resolved, the Controller may terminate the affected services without penalty and without liability for fees relating to any unused period.
  5. Assist with Data Subject Requests: Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the data subject’s rights.
  6. Assist with compliance: Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR (Security, Breach Notification, DPIA).
  7. Return or delete data: At the choice of the Controller, delete or return all the personal data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data.
  8. Audits and Inspections: Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by the Controller or by another auditor mandated by the Controller. The parties agree that the following conditions are reasonable and proportionate to the nature of the processing:
    • (a) The Processor may satisfy an audit request in the first instance by providing its current Technical and Organizational Measures, a completed security questionnaire, and any third-party audit reports or certifications it holds.
    • (b) Where the Controller reasonably requires an on-site or system audit in addition to the above, such an audit may be carried out no more than once in any twelve (12) month period, except where required by a supervisory authority or following a personal data breach affecting the Controller’s data.
    • (c) The Controller shall give at least thirty (30) days’ prior written notice, conduct the audit during normal business hours, and take reasonable steps to avoid disruption to the Processor’s operations.
    • (d) Audits are carried out at the Controller’s cost, and any third-party auditor must be bound by confidentiality obligations no less protective than those in this DPA and must not be a competitor of the Processor.
    • (e) The Processor is not required to disclose information relating to its other customers, its own commercially sensitive information, or any information the disclosure of which would place it in breach of a legal or contractual obligation.

4. Obligations of the Data Controller

The Data Controller is responsible for ensuring that they have a lawful basis for the processing of personal data and for complying with all applicable data protection laws. Where the Data Controller connects a Klaviyo account, the Data Controller is responsible for its own relationship with, and instructions to, Klaviyo as its own processor.

5. International Data Transfers

5.1 The Data Processor is established in the United Kingdom. Transfers of personal data from the European Economic Area to the Data Processor are made on the basis of the European Commission’s adequacy decision in respect of the United Kingdom, renewed on 19 December 2025.

5.2 Where the Data Processor transfers personal data to a sub-processor located outside the United Kingdom or the European Economic Area, that transfer is made under one or more of the following safeguards:

5.3 The safeguard relied upon for each sub-processor is identified in Annex I. If a certification relied upon lapses or is invalidated, the Data Processor will transfer under an alternative safeguard listed in section 5.2 or will cease the transfer.

5.4 The Data Processor will not transfer personal data outside the United Kingdom or the European Economic Area other than as set out in Annex I without first informing the Data Controller in accordance with section 3.4.

6. Liability

6.1 The limitations and exclusions of liability set out in Section 12 (Limitation of Liability) of the Terms and Conditions apply to this DPA and to any claim arising out of or in connection with it. The parties’ aggregate liability under the Terms and Conditions and this DPA taken together shall not exceed the caps set out in that Section.

6.2 Nothing in this DPA limits or excludes either party’s liability to the extent that such limitation or exclusion is not permitted by applicable data protection law, including any liability owed directly to a data subject under Article 82 of the GDPR.

7. Relationship to the Terms and Conditions

This DPA supplements the Terms and Conditions. In the event of a conflict between this DPA and the Terms and Conditions in respect of the processing of personal data, this DPA prevails. In all other respects the Terms and Conditions continue in full force and effect.

Annex I: Authorized Sub-Processors

The following sub-processors are authorized:

Sub-processor Purpose Processing location Transfer safeguard (section 5.2)
Cloudflare, Inc. Application hosting, session storage, caching, and data storage across Workers, Durable Objects, D1, KV, and R2 EU and US data centre locations EU-U.S. Data Privacy Framework certification, including the UK Extension; EU Standard Contractual Clauses under Cloudflare’s customer DPA
Mantle Business operations platform, billing, usage metering, and analytics (merchant data only) US Being retired on 14 August 2026, after which these functions are performed in-house by Optizio Ltd in the United Kingdom. No new categories of data are shared with this sub-processor.
Intercom, Inc. Customer support services (merchant data only) Dublin, Ireland for EU customers EU-U.S. Data Privacy Framework certification, including the UK Extension
Functional Software, Inc. (Sentry) Application error monitoring and diagnostics (merchant and staff identifiers may appear in diagnostic events) US EU-U.S. Data Privacy Framework certification; Standard Contractual Clauses under Sentry’s Data Processing Addendum

Merchant-authorized integration (not a sub-processor of Optizio): Where the Data Controller connects a Klaviyo account, discount redemption codes and related coupon data are transmitted to that account at the Data Controller’s direction. Klaviyo acts as the Data Controller’s own processor and is not engaged by Optizio.

Annex II: Technical and Organizational Measures (TOMs)

The detailed Technical and Organizational Measures implemented by Optizio Ltd are set out in a separate document, which forms Annex II to this DPA. The version in force at the date of this DPA is version 1.0, issued 31st July 2026, published at https://policy.optiz.io/code-bulk-toms.

The Data Processor may update the Technical and Organizational Measures to reflect changes in technology, threats, or working practices, provided that no update materially reduces the overall level of security afforded to the personal data. Material changes are notified to the Data Controller in accordance with section 3.4.

Execution

Where the Data Controller has accepted the Terms and Conditions, this DPA applies as part of those Terms and no separate signature is required.

Where the parties wish to execute this DPA separately, it is entered into as follows:

Data Processor
Optizio Ltd, 124 City Road, London, EC1V 2NX, United Kingdom

   
Signature  
Name  
Title  
Date  

Data Controller

   
Company  
Registered address  
Signature  
Name  
Title  
Date  

Version History

Version Date Changes
1.0 31st July 2026 First published version. Supersedes the unversioned draft previously circulated on request. Added the Article 28(2) opportunity to object to sub-processor changes, with a notice period and a termination right, in section 3.4. Named the TOMs version in Annex II and added a covenant not to materially reduce the level of security.