Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Optizio Ltd (“Data Processor”) and the merchant using the Code Bulk application (“Data Controller”).
This DPA reflects the parties’ agreement regarding the processing of personal data in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Subject Matter, Nature, and Purpose of Processing
The Data Processor provides the Code Bulk Shopify application to the Data Controller. The purpose of processing is to enable bulk discount code generation, import, and management on the Data Controller’s Shopify store, and, where the Data Controller opts in, to mirror those codes into the Data Controller’s connected Klaviyo account.
Processing involves:
- Reading Shopify IDs (GIDs) for discounts.
- Generating, uploading, and storing discount redemption codes provided by or created for the Data Controller.
- Storing Shopify admin access tokens required to perform bulk operations on the Data Controller’s behalf.
- Recording merchant account details (store name, domain, primary email, Shopify plan, currency, and timezone) and the names and email addresses of store staff who interact with the App’s admin interface, in order to operate, support, and bill the service.
No end-user (shopper) personal data such as names, email addresses, or payment details are collected or processed. Discount redemption codes are treated as configuration data and are not used for profiling or marketing.
2. Duration of Processing
This DPA shall remain in effect as long as the Data Controller has the Code Bulk app installed and the Terms and Conditions are in force.
3. Obligations of the Data Processor
The Data Processor shall:
- Process data only on documented instructions from the Data Controller, including with regard to transfers of personal data to a third country or an international organization.
- Ensure confidentiality: Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement security measures: Take all measures required pursuant to Article 32 of the GDPR (Security of Processing), detailed in Annex II (Technical and Organizational Measures - TOMs).
- Engage sub-processors only with authorization: The Data Controller grants a general authorization to engage the sub-processors listed in Annex I. The Processor will inform the Controller of any intended changes concerning the addition or replacement of other sub-processors.
- Assist with Data Subject Requests: Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the data subject’s rights.
- Assist with compliance: Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR (Security, Breach Notification, DPIA).
- Return or delete data: At the choice of the Controller, delete or return all the personal data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data.
- Audits and Inspections: Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 and allow for and contribute to audits.
4. Obligations of the Data Controller
The Data Controller is responsible for ensuring that they have a lawful basis for the processing of personal data and for complying with all applicable data protection laws. Where the Data Controller connects a Klaviyo account, the Data Controller is responsible for its own relationship with, and instructions to, Klaviyo as its own processor.
Annex I: Authorized Sub-Processors
The following sub-processors are authorized:
- Cloudflare, Inc.: Application hosting, session storage, caching, and data storage across Workers, Durable Objects, D1, KV, and R2 (data center locations may include EU and US).
- Mantle: Business operations platform, billing, usage metering, and analytics (merchant data only).
- Intercom, Inc.: Customer support services (merchant data only).
- Functional Software, Inc. (Sentry): Application error monitoring and diagnostics (merchant and staff identifiers may appear in diagnostic events).
Merchant-authorized integration (not a sub-processor of Optizio): Where the Data Controller connects a Klaviyo account, discount redemption codes and related coupon data are transmitted to that account at the Data Controller’s direction. Klaviyo acts as the Data Controller’s own processor and is not engaged by Optizio.
Annex II: Technical and Organizational Measures (TOMs)
The detailed Technical and Organizational Measures implemented by Optizio Ltd are set out in a separate document, available at https://policy.optiz.io/code-bulk-toms, which forms Annex II to this DPA.