Version: 1.0
Issued: 31st July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Optizio Ltd (“Data Processor”) and the merchant using the Code Bulk application (“Data Controller”).
This DPA reflects the parties’ agreement regarding the processing of personal data in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
The Data Processor provides the Code Bulk Shopify application to the Data Controller. The purpose of processing is to enable bulk discount code generation, import, and management on the Data Controller’s Shopify store, and, where the Data Controller opts in, to mirror those codes into the Data Controller’s connected Klaviyo account.
Processing involves:
No end-user (shopper) personal data such as names, email addresses, or payment details are collected or processed. Discount redemption codes are treated as configuration data and are not used for profiling or marketing.
This DPA shall remain in effect as long as the Data Controller has the Code Bulk app installed and the Terms and Conditions are in force.
The Data Processor shall:
The Data Controller is responsible for ensuring that they have a lawful basis for the processing of personal data and for complying with all applicable data protection laws. Where the Data Controller connects a Klaviyo account, the Data Controller is responsible for its own relationship with, and instructions to, Klaviyo as its own processor.
5.1 The Data Processor is established in the United Kingdom. Transfers of personal data from the European Economic Area to the Data Processor are made on the basis of the European Commission’s adequacy decision in respect of the United Kingdom, renewed on 19 December 2025.
5.2 Where the Data Processor transfers personal data to a sub-processor located outside the United Kingdom or the European Economic Area, that transfer is made under one or more of the following safeguards:
5.3 The safeguard relied upon for each sub-processor is identified in Annex I. If a certification relied upon lapses or is invalidated, the Data Processor will transfer under an alternative safeguard listed in section 5.2 or will cease the transfer.
5.4 The Data Processor will not transfer personal data outside the United Kingdom or the European Economic Area other than as set out in Annex I without first informing the Data Controller in accordance with section 3.4.
6.1 The limitations and exclusions of liability set out in Section 12 (Limitation of Liability) of the Terms and Conditions apply to this DPA and to any claim arising out of or in connection with it. The parties’ aggregate liability under the Terms and Conditions and this DPA taken together shall not exceed the caps set out in that Section.
6.2 Nothing in this DPA limits or excludes either party’s liability to the extent that such limitation or exclusion is not permitted by applicable data protection law, including any liability owed directly to a data subject under Article 82 of the GDPR.
This DPA supplements the Terms and Conditions. In the event of a conflict between this DPA and the Terms and Conditions in respect of the processing of personal data, this DPA prevails. In all other respects the Terms and Conditions continue in full force and effect.
The following sub-processors are authorized:
| Sub-processor | Purpose | Processing location | Transfer safeguard (section 5.2) |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting, session storage, caching, and data storage across Workers, Durable Objects, D1, KV, and R2 | EU and US data centre locations | EU-U.S. Data Privacy Framework certification, including the UK Extension; EU Standard Contractual Clauses under Cloudflare’s customer DPA |
| Mantle | Business operations platform, billing, usage metering, and analytics (merchant data only) | US | Being retired on 14 August 2026, after which these functions are performed in-house by Optizio Ltd in the United Kingdom. No new categories of data are shared with this sub-processor. |
| Intercom, Inc. | Customer support services (merchant data only) | Dublin, Ireland for EU customers | EU-U.S. Data Privacy Framework certification, including the UK Extension |
| Functional Software, Inc. (Sentry) | Application error monitoring and diagnostics (merchant and staff identifiers may appear in diagnostic events) | US | EU-U.S. Data Privacy Framework certification; Standard Contractual Clauses under Sentry’s Data Processing Addendum |
Merchant-authorized integration (not a sub-processor of Optizio): Where the Data Controller connects a Klaviyo account, discount redemption codes and related coupon data are transmitted to that account at the Data Controller’s direction. Klaviyo acts as the Data Controller’s own processor and is not engaged by Optizio.
The detailed Technical and Organizational Measures implemented by Optizio Ltd are set out in a separate document, which forms Annex II to this DPA. The version in force at the date of this DPA is version 1.0, issued 31st July 2026, published at https://policy.optiz.io/code-bulk-toms.
The Data Processor may update the Technical and Organizational Measures to reflect changes in technology, threats, or working practices, provided that no update materially reduces the overall level of security afforded to the personal data. Material changes are notified to the Data Controller in accordance with section 3.4.
Where the Data Controller has accepted the Terms and Conditions, this DPA applies as part of those Terms and no separate signature is required.
Where the parties wish to execute this DPA separately, it is entered into as follows:
Data Processor
Optizio Ltd, 124 City Road, London, EC1V 2NX, United Kingdom
| Signature | |
| Name | |
| Title | |
| Date |
Data Controller
| Company | |
| Registered address | |
| Signature | |
| Name | |
| Title | |
| Date |
| Version | Date | Changes |
|---|---|---|
| 1.0 | 31st July 2026 | First published version. Supersedes the unversioned draft previously circulated on request. Added the Article 28(2) opportunity to object to sub-processor changes, with a notice period and a termination right, in section 3.4. Named the TOMs version in Annex II and added a covenant not to materially reduce the level of security. |