1. Parties and status
This Data Processing Agreement (DPA) forms part of the agreement between the merchant as controller and the Service operator as processor. The operator's complete legal identity and contact details must be inserted before this DPA can be executed or relied upon. Installation alone does not cure that omission.
2. Scope, purpose and duration
The processor handles Shopify customer data only to authenticate, import, match, synchronize, troubleshoot, secure and delete data for Bidson CRM Sync. Processing continues for the installation term and any limited deletion, backup or legal-retention period afterward.
3. Documented instructions
The processor acts only on documented instructions in the agreement, app configuration, authorized actions and written support requests, including instructions about transfers. It will inform the controller if an instruction appears to violate data-protection law, unless legally prohibited, and may pause the affected processing.
4. Processing details
- Data subjects: the merchant's customers, prospects and relevant store users.
- Data: names, email addresses, phone numbers, tags, marketing-consent status, Shopify identifiers, linkage identifiers and aggregated order count, spend, currency and latest-order information.
- Operations: retrieval, transmission, matching, transformation, temporary handling, limited storage, support, deletion and redaction.
- Frequency: initial imports and event-driven or merchant-requested updates.
- Restricted data: special-category data, criminal-offence data, payment-card data, government IDs, medical data and children's data are not intended for the Service and must not be submitted.
5. Confidentiality and personnel
The processor will limit access to personnel who need it to operate or support the Service and who are bound by confidentiality obligations. Access must be removed when no longer required.
6. Security measures
The processor will maintain measures appropriate to risk under GDPR Article 32 and may improve them without materially reducing overall protection.
- Encryption in transit and encryption of Attio access and refresh tokens at rest.
- Data minimization: complete raw Shopify customer, order and webhook payloads are not intentionally persisted.
- Restricted logging that excludes access tokens and customer payloads.
- Logical separation by shop identifiers, controlled retries, idempotent synchronization, backups and provider infrastructure controls.
- Deletion workflows for uninstallation and Shopify privacy requests.
7. Subprocessors
The controller grants general written authorization for the subprocessors on the current subprocessor list. The processor will impose substantially equivalent data-protection duties on each subprocessor and remain responsible for its processing as required by law.
The processor will provide reasonable advance notice of a new or replacement subprocessor. The controller may object on documented data-protection grounds. The parties will seek a reasonable solution; if none is available, either party may terminate the affected Service. The required notification mechanism must be operational before external production use.
8. International transfers
The processor will use a lawful Chapter V transfer mechanism for restricted transfers, such as an adequacy decision or the EU Standard Contractual Clauses, and supplementary measures where required. The controller authorizes transfers inherent in the listed subprocessors subject to those safeguards.
9. Assistance to the controller
Taking account of the nature of processing and available information, the processor will reasonably assist with data-subject requests, security obligations, breach assessments, data-protection impact assessments and supervisory-authority consultations. The controller remains responsible for responding to individuals and demonstrating the lawfulness of its instructions.
10. Personal data breaches
The processor will notify the controller without undue delay after becoming aware of a personal data breach affecting controller data and will provide available information reasonably needed for the controller's assessment and notification duties. Notification is not an admission of fault.
11. Return and deletion
At the controller's choice and subject to product functionality, the processor will delete or return personal data after the Services end and delete remaining copies, unless law requires retention. Data in backups may remain until normal rotation, protected from ordinary use. The controller should export any data it needs before termination.
12. Information and audits
The processor will provide information reasonably necessary to demonstrate Article 28 compliance. Where documentation is insufficient, the controller may conduct or appoint an independent auditor for a proportionate audit on reasonable advance notice, no more than once annually unless an incident or authority requires otherwise, without accessing other customers' data or compromising security. The controller bears its audit costs unless material non-compliance is found.
13. Controller obligations
The controller determines lawful purposes and means, has a valid legal basis, provides required notices, configures Shopify and Attio appropriately, submits only permitted data, handles individuals' requests and ensures its instructions comply with law.
14. Precedence and governing terms
This DPA takes precedence over conflicting service terms on personal-data processing. Liability and governing law follow the main agreement except where mandatory data-protection law requires otherwise. The English version prevails over translations in case of inconsistency.