Version: 1.0 Effective date: 23 September 2026
This Data Processing Agreement (“DPA”) forms part of the agreement under which Optizio Ltd, of 124 City Road, London, EC1V 2NX, United Kingdom (“Optizio”, “Processor”, “we”, “us”) provides the Stackable: Combined Discounts Shopify application (“Stackable” or the “Service”) to the merchant using the Service (“Controller”, “you”).
This DPA applies where Optizio processes Personal Data on the Controller’s behalf. It reflects the parties’ agreement under Article 28 of Regulation (EU) 2016/679 (“EU GDPR”) and, where applicable, the UK GDPR.
The Controller determines the purposes and means of the Personal Data processed through its Shopify store. Optizio acts as Processor when it processes that Personal Data to provide the Service under the Controller’s documented instructions, including this DPA and the Controller’s use of the Service.
Optizio may act as an independent controller where it processes Personal Data for its own legitimate business purposes, such as managing its legal obligations, protecting the security of its services, or administering its direct contractual relationship with the Controller. That processing is governed by the Stackable Privacy Policy, rather than this DPA.
| Item | Description |
|---|---|
| Subject matter | Provision, support, security, and operation of the Stackable Shopify application. |
| Duration | For the duration of the Controller’s use of the Service and afterwards only for the periods stated in section 7 and Annex I. |
| Nature | Collection, receipt, retrieval, consultation, storage, use, transmission, restriction, deletion, and destruction of Personal Data as needed to provide the Service. |
| Purpose | To configure and operate discounts, linked discount codes, code blocking, checkout upsells, and point-of-sale functionality; administer the merchant account; provide support; protect the Service; and meet applicable legal obligations. |
The categories of data subjects and Personal Data are set out in Annex I. The Service is not intended to process special-category Personal Data, payment-card data, or customer profiles.
Optizio shall:
The Controller shall:
Optizio will restrict access to Personal Data to authorised personnel who need it to provide, secure, or support the Service. Optizio will maintain the safeguards in Annex II and may update them provided that the update does not materially reduce the overall level of protection for Personal Data.
The Controller grants Optizio general authorisation to use the sub-processors listed in Annex III.
Optizio will provide at least 30 days’ prior notice of a new or replacement sub-processor by updating Annex III or otherwise notifying the Controller, except where a shorter period is necessary to address a security risk or comply with law. The Controller may object on reasonable data-protection grounds within that period. The parties will discuss the objection in good faith; if they cannot resolve it, the Controller may terminate the affected Service without penalty for the unused portion of that Service.
Optizio will impose written data-protection obligations on sub-processors that are no less protective than the obligations in this DPA.
Optizio is established in the United Kingdom. Where Personal Data is transferred outside the United Kingdom or the European Economic Area, Optizio will ensure that the transfer is subject to an appropriate recognised transfer mechanism, such as:
The safeguard used for each sub-processor is identified in Annex III.
On termination of the Service, Optizio will delete or return Personal Data processed on the Controller’s behalf, unless applicable law requires retention.
The following exceptions and operational limits apply:
On reasonable written request, Optizio will make available its current technical and organisational measures, relevant security questionnaires, and third-party audit reports or certifications that it is entitled to share.
Where that information is insufficient to demonstrate compliance, the Controller may conduct an audit no more than once in any 12-month period, unless required by a supervisory authority or following a Personal Data Breach affecting the Controller’s Personal Data. The Controller must:
Optizio is not required to disclose information relating to other customers, confidential security information that would create a material security risk if disclosed, or information whose disclosure would breach a legal or contractual obligation.
This DPA prevails over any conflicting term in the parties’ agreement relating to the processing of Personal Data. Liability under this DPA is subject to the liability provisions of the parties’ agreement, except to the extent that applicable data-protection law does not permit a limitation or exclusion.
orders/create webhook delivered for an upsell-attributed order.myshopify domain, contact email, Shopify plan, currency, time zone, locale, staff user identifiers, names, email addresses, verification/account-owner flags, and installation/activity timestamps;Processing occurs when the Controller installs or uses the Service, changes configuration, receives support, or where Shopify delivers a filtered upsell-attribution webhook. Billing and subscription processing occurs as necessary to administer the Service.
The Technical and Organisational Measures that apply to Stackable are published at policy.optiz.io/stackable-toms and form part of this DPA.
| Sub-processor | Purpose | Processing location | Transfer safeguard |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting, session storage, caching, and data storage across Workers, KV, and D1 | EU and US data-centre locations | EU-US Data Privacy Framework certification, including the UK Extension; EU Standard Contractual Clauses under Cloudflare’s customer DPA |
| Functional Software, Inc. (Sentry) | Application error monitoring and diagnostics. Merchant and staff identifiers may appear in diagnostic events. | United States | EU-US Data Privacy Framework certification and Standard Contractual Clauses under Sentry’s Data Processing Addendum |
| Intercom, Inc. | Customer-support correspondence. Information is processed only when the Controller contacts Optizio through a channel routed to Intercom. | Dublin, Ireland for EU customers | EU-US Data Privacy Framework certification, including the UK Extension |
This DPA applies when the Controller accepts the agreement governing its use of Stackable. It may also be executed separately.
Processor Optizio Ltd, 124 City Road, London, EC1V 2NX, United Kingdom
| Signature | |
| Name | |
| Title | |
| Date |
Controller
| Company | |
| Registered address | |
| Signature | |
| Name | |
| Title | |
| Date |
| Version | Date | Changes |
|---|---|---|
| 1.0 | 23 September 2026 | Initial Stackable-specific DPA. |