Version: 1.1
Issued: 31st July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Optizio Ltd (“Data Processor”) and the merchant using the Discount Kit application (“Data Controller”).
This DPA reflects the parties’ agreement regarding the processing of personal data in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
The Data Processor provides the Discount Kit Shopify application to the Data Controller. The purpose of processing is to enable discounting functionality on the Data Controller’s Shopify store. Processing involves reading Shopify IDs (GIDs) for products, collections, and discounts, as well as customer tags used to determine discount eligibility. No end-user (shopper) personal data such as names, email addresses, or payment details are collected or processed for profiling or marketing.
This DPA shall remain in effect as long as the Data Controller has the Discount Kit app installed and the Terms and Conditions are in force.
The Data Processor shall:
The Data Controller is responsible for ensuring that they have a lawful basis for the processing of personal data and for complying with all applicable data protection laws.
5.1 The Data Processor is established in the United Kingdom. Transfers of personal data from the European Economic Area to the Data Processor are made on the basis of the European Commission’s adequacy decision in respect of the United Kingdom, renewed on 19 December 2025.
5.2 Where the Data Processor transfers personal data to a sub-processor located outside the United Kingdom or the European Economic Area, that transfer is made under one or more of the following safeguards:
5.3 The safeguard relied upon for each sub-processor is identified in Annex I. If a certification relied upon lapses or is invalidated, the Data Processor will transfer under an alternative safeguard listed in section 5.2 or will cease the transfer.
5.4 The Data Processor will not transfer personal data outside the United Kingdom or the European Economic Area other than as set out in Annex I without first informing the Data Controller in accordance with section 3.4.
6.1 The limitations and exclusions of liability set out in Section 12 (Limitation of Liability) of the Terms and Conditions apply to this DPA and to any claim arising out of or in connection with it. The parties’ aggregate liability under the Terms and Conditions and this DPA taken together shall not exceed the caps set out in that Section.
6.2 Nothing in this DPA limits or excludes either party’s liability to the extent that such limitation or exclusion is not permitted by applicable data protection law, including any liability owed directly to a data subject under Article 82 of the GDPR.
This DPA supplements the Terms and Conditions. In the event of a conflict between this DPA and the Terms and Conditions in respect of the processing of personal data, this DPA prevails. In all other respects the Terms and Conditions continue in full force and effect.
The following sub-processors are authorized:
| Sub-processor | Purpose | Processing location | Transfer safeguard (section 5.2) |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting, session storage, caching, and infrastructure | EU and US data centre locations | EU-U.S. Data Privacy Framework certification, including the UK Extension; EU Standard Contractual Clauses under Cloudflare’s customer DPA |
| Mantle | Business operations platform, billing, and analytics (merchant data only) | US | Being retired on 14 August 2026, after which these functions are performed in-house by Optizio Ltd in the United Kingdom. No new categories of data are shared with this sub-processor. |
| Intercom, Inc. | Customer support services (merchant data only) | Dublin, Ireland for EU customers | EU-U.S. Data Privacy Framework certification, including the UK Extension |
| Functional Software, Inc. (Sentry) | Application error monitoring and diagnostics (merchant and staff identifiers may appear in diagnostic events) | US | EU-U.S. Data Privacy Framework certification; Standard Contractual Clauses under Sentry’s Data Processing Addendum |
The detailed Technical and Organizational Measures implemented by Optizio Ltd are set out in a separate document, which forms Annex II to this DPA. The version in force at the date of this DPA is version 1.0, issued 31st July 2026, published at https://policy.optiz.io/discount-kit-toms.
The Data Processor may update the Technical and Organizational Measures to reflect changes in technology, threats, or working practices, provided that no update materially reduces the overall level of security afforded to the personal data. Material changes are notified to the Data Controller in accordance with section 3.4.
Where the Data Controller has accepted the Terms and Conditions, this DPA applies as part of those Terms and no separate signature is required.
Where the parties wish to execute this DPA separately, it is entered into as follows:
Data Processor
Optizio Ltd, 124 City Road, London, EC1V 2NX, United Kingdom
| Signature | |
| Name | |
| Title | |
| Date |
Data Controller
| Company | |
| Registered address | |
| Signature | |
| Name | |
| Title | |
| Date |
| Version | Date | Changes |
|---|---|---|
| 1.1 | 31st July 2026 | Added Sentry to Annex I. Added international transfer safeguards (section 5), liability (section 6), and precedence over the Terms and Conditions (section 7). Scoped the audit right in section 3.8. Added transfer safeguards and processing locations to Annex I. Added an execution block. Added the Article 28(2) opportunity to object to sub-processor changes, with a notice period and a termination right, in section 3.4. Named the TOMs version in Annex II and added a covenant not to materially reduce the level of security. |
| 1.0 | 30th April 2026 | Initial version. |