Optizio Policy Documents

Data Processing Agreement, Stackable

Version: 1.0 Effective date: 23 September 2026

This Data Processing Agreement (“DPA”) forms part of the agreement under which Optizio Ltd, of 124 City Road, London, EC1V 2NX, United Kingdom (“Optizio”, “Processor”, “we”, “us”) provides the Stackable: Combined Discounts Shopify application (“Stackable” or the “Service”) to the merchant using the Service (“Controller”, “you”).

This DPA applies where Optizio processes Personal Data on the Controller’s behalf. It reflects the parties’ agreement under Article 28 of Regulation (EU) 2016/679 (“EU GDPR”) and, where applicable, the UK GDPR.

1. Scope and Roles

1.1 Controller and Processor

The Controller determines the purposes and means of the Personal Data processed through its Shopify store. Optizio acts as Processor when it processes that Personal Data to provide the Service under the Controller’s documented instructions, including this DPA and the Controller’s use of the Service.

Optizio may act as an independent controller where it processes Personal Data for its own legitimate business purposes, such as managing its legal obligations, protecting the security of its services, or administering its direct contractual relationship with the Controller. That processing is governed by the Stackable Privacy Policy, rather than this DPA.

1.2 Subject Matter, Duration, Nature, and Purpose

Item Description
Subject matter Provision, support, security, and operation of the Stackable Shopify application.
Duration For the duration of the Controller’s use of the Service and afterwards only for the periods stated in section 7 and Annex I.
Nature Collection, receipt, retrieval, consultation, storage, use, transmission, restriction, deletion, and destruction of Personal Data as needed to provide the Service.
Purpose To configure and operate discounts, linked discount codes, code blocking, checkout upsells, and point-of-sale functionality; administer the merchant account; provide support; protect the Service; and meet applicable legal obligations.

1.3 Categories of Data Subjects and Personal Data

The categories of data subjects and Personal Data are set out in Annex I. The Service is not intended to process special-category Personal Data, payment-card data, or customer profiles.

2. Processor Obligations

Optizio shall:

  1. process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law;
  2. ensure that persons authorised to process Personal Data are bound by confidentiality obligations;
  3. implement the technical and organisational measures in Annex II;
  4. taking account of the nature of processing, assist the Controller through appropriate technical and organisational measures with data-subject requests;
  5. assist the Controller, taking account of the nature of processing and information available to Optizio, with its obligations under Articles 32 to 36 of the EU GDPR;
  6. notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA;
  7. make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the EU GDPR; and
  8. not sell, rent, or use Controller Personal Data for advertising or profiling.

3. Controller Obligations

The Controller shall:

  1. ensure that it has a valid legal basis for the processing and for the instructions it gives to Optizio;
  2. provide lawful, documented instructions and ensure that its use of the Service complies with applicable data-protection law;
  3. remain responsible for the accuracy, quality, and legality of Personal Data made available through Shopify or otherwise provided to Optizio; and
  4. promptly notify Optizio if an instruction no longer complies with applicable data-protection law.

4. Confidentiality and Security

Optizio will restrict access to Personal Data to authorised personnel who need it to provide, secure, or support the Service. Optizio will maintain the safeguards in Annex II and may update them provided that the update does not materially reduce the overall level of protection for Personal Data.

5. Sub-processors

The Controller grants Optizio general authorisation to use the sub-processors listed in Annex III.

Optizio will provide at least 30 days’ prior notice of a new or replacement sub-processor by updating Annex III or otherwise notifying the Controller, except where a shorter period is necessary to address a security risk or comply with law. The Controller may object on reasonable data-protection grounds within that period. The parties will discuss the objection in good faith; if they cannot resolve it, the Controller may terminate the affected Service without penalty for the unused portion of that Service.

Optizio will impose written data-protection obligations on sub-processors that are no less protective than the obligations in this DPA.

6. International Transfers

Optizio is established in the United Kingdom. Where Personal Data is transferred outside the United Kingdom or the European Economic Area, Optizio will ensure that the transfer is subject to an appropriate recognised transfer mechanism, such as:

The safeguard used for each sub-processor is identified in Annex III.

7. Return and Deletion

On termination of the Service, Optizio will delete or return Personal Data processed on the Controller’s behalf, unless applicable law requires retention.

The following exceptions and operational limits apply:

8. Audits

On reasonable written request, Optizio will make available its current technical and organisational measures, relevant security questionnaires, and third-party audit reports or certifications that it is entitled to share.

Where that information is insufficient to demonstrate compliance, the Controller may conduct an audit no more than once in any 12-month period, unless required by a supervisory authority or following a Personal Data Breach affecting the Controller’s Personal Data. The Controller must:

Optizio is not required to disclose information relating to other customers, confidential security information that would create a material security risk if disclosed, or information whose disclosure would breach a legal or contractual obligation.

9. Order of Precedence and Liability

This DPA prevails over any conflicting term in the parties’ agreement relating to the processing of Personal Data. Liability under this DPA is subject to the liability provisions of the parties’ agreement, except to the extent that applicable data-protection law does not permit a limitation or exclusion.

Annex I: Processing Details

Data Subjects

Personal Data

Processing Frequency

Processing occurs when the Controller installs or uses the Service, changes configuration, receives support, or where Shopify delivers a filtered upsell-attribution webhook. Billing and subscription processing occurs as necessary to administer the Service.

Annex II: Technical and Organisational Measures

The Technical and Organisational Measures that apply to Stackable are published at policy.optiz.io/stackable-toms and form part of this DPA.

Annex III: Authorised Sub-processors

Sub-processor Purpose Processing location Transfer safeguard
Cloudflare, Inc. Application hosting, session storage, caching, and data storage across Workers, KV, and D1 EU and US data-centre locations EU-US Data Privacy Framework certification, including the UK Extension; EU Standard Contractual Clauses under Cloudflare’s customer DPA
Functional Software, Inc. (Sentry) Application error monitoring and diagnostics. Merchant and staff identifiers may appear in diagnostic events. United States EU-US Data Privacy Framework certification and Standard Contractual Clauses under Sentry’s Data Processing Addendum
Intercom, Inc. Customer-support correspondence. Information is processed only when the Controller contacts Optizio through a channel routed to Intercom. Dublin, Ireland for EU customers EU-US Data Privacy Framework certification, including the UK Extension

Execution

This DPA applies when the Controller accepts the agreement governing its use of Stackable. It may also be executed separately.

Processor Optizio Ltd, 124 City Road, London, EC1V 2NX, United Kingdom

   
Signature  
Name  
Title  
Date  

Controller

   
Company  
Registered address  
Signature  
Name  
Title  
Date  

Version History

Version Date Changes
1.0 23 September 2026 Initial Stackable-specific DPA.