Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Optizio Ltd (“Data Processor”) and the merchant using the Discount Kit application (“Data Controller”).
This DPA reflects the parties’ agreement regarding the processing of personal data in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Subject Matter, Nature, and Purpose of Processing
The Data Processor provides the Discount Kit Shopify application to the Data Controller. The purpose of processing is to enable discounting functionality on the Data Controller’s Shopify store.
Processing involves reading Shopify IDs (GIDs) for products, collections, and discounts, as well as customer tags used to determine discount eligibility. No end-user (shopper) personal data such as names, email addresses, or payment details are collected or processed for profiling or marketing.
2. Duration of Processing
This DPA shall remain in effect as long as the Data Controller has the Discount Kit app installed and the Terms and Conditions are in force.
3. Obligations of the Data Processor
The Data Processor shall:
- Process data only on documented instructions from the Data Controller, including with regard to transfers of personal data to a third country or an international organization.
- Ensure confidentiality: Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement security measures: Take all measures required pursuant to Article 32 of the GDPR (Security of Processing), detailed in Annex II (Technical and Organizational Measures - TOMs).
- Engage sub-processors only with authorization: The Data Controller grants a general authorization to engage the sub-processors listed in Annex I. The Processor will inform the Controller of any intended changes concerning the addition or replacement of other sub-processors.
- Assist with Data Subject Requests: Taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising the data subject’s rights.
- Assist with compliance: Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR (Security, Breach Notification, DPIA).
- Return or delete data: At the choice of the Controller, delete or return all the personal data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data.
- Audits and Inspections: Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 and allow for and contribute to audits.
4. Obligations of the Data Controller
The Data Controller is responsible for ensuring that they have a lawful basis for the processing of personal data and for complying with all applicable data protection laws.
Annex I: Authorized Sub-Processors
The following sub-processors are authorized:
- Cloudflare, Inc.: Session storage, caching, and infrastructure (Data Center locations may include EU and US).
- Mantle: Business operations platform, billing, and analytics (Merchant data only).
- Intercom, Inc.: Customer support services (Merchant data only).
- Functional Software, Inc. (Sentry): Application error monitoring and diagnostics (merchant and staff identifiers may appear in diagnostic events).
Annex II: Technical and Organizational Measures (TOMs)
The detailed Technical and Organizational Measures implemented by Optizio Ltd are set out in a separate document, available at https://policy.optiz.io/discount-kit-toms, which forms Annex II to this DPA.