Data Processing Agreement (DPA) pursuant to Art. 28 GDPR
between
the customer (merchant / shop operator) — hereinafter the "Controller" —
and
DataX GmbH, Waldstr. 4, 04105 Leipzig, Germany (Managing Director: Jakob Gerzen; VAT ID: DE356231862; commercial register: Local Court of Leipzig, HRB 40755) — hereinafter the "Processor" —
— together the "Parties" —
This DPA specifies the data protection obligations of the Parties for the processing of personal data that the Processor performs for the Controller in the course of using the DataX Services (DataX Analytics, DataX Influencer Tracking; hereinafter the "Services"). It applies upon activation of the Services and supplements the Terms of Service.
1. Subject matter, nature, purpose and duration
1.1 The subject matter of the processing is the provision of the Services, in particular the collection, storage, analysis and presentation of shop and order data to provide analytics and influencer-tracking reports for the Controller.
1.2 Nature of the processing: automated retrieval via the Shopify Admin API, storage in an encrypted database, aggregation/analysis, display in the Controller's DataX account.
1.3 Purpose: solely the performance of the analytics/reporting services commissioned by the Controller (no own purposes, no sale of data, no marketing dispatch to end customers).
1.4 Duration: for the term of the main contract (Terms of Service). After termination, section 9 applies.
2. Type of data and categories of data subjects
2.1 Categories of data subjects: end customers and visitors of the Controller's shop.
2.2 Types of personal data (see Annex 1):
- order data (order ID, date, amounts, discount codes, items/quantities, status),
- the customers' email address and phone number — stored by the Processor
exclusively in hashed/pseudonymised form (matching/deduplication).
No clear names, plain-text addresses or payment data are stored for processing purposes (data minimisation, Art. 5(1)(c) GDPR).
3. Obligations of the Processor
The Processor
3.1 processes personal data exclusively on documented instructions of the Controller (this DPA and the use of the Services constitute instructions), unless a legal obligation requires otherwise;
3.2 ensures confidentiality; persons authorised to process are bound to confidentiality;
3.3 takes the technical and organisational measures (TOMs) under Art. 32 GDPR (Annex 2);
3.4 supports the Controller as far as possible in fulfilling data subject rights (access, erasure, restriction) — erasure/access requests are processed via the Shopify compliance webhooks (customers/redact, customers/data_request, shop/redact);
3.5 supports the Controller in complying with Art. 32–36 GDPR (data security, breach notification, data protection impact assessment);
3.6 notifies the Controller of personal data breaches without undue delay after becoming aware of them (Art. 33 GDPR);
3.7 at the Controller's choice, deletes or returns all data after termination (section 9);
3.8 provides the Controller with the information necessary to demonstrate compliance and enables audits (section 8).
4. Obligations of the Controller
4.1 The Controller is responsible for the lawfulness of the processing and the legal basis (Art. 6 GDPR).
4.2 The Controller generally issues instructions in text form; verbal instructions are confirmed without undue delay.
5. Sub-processors
5.1 The Controller grants a general authorisation for the use of sub-processors. Those currently engaged are listed in Annex 3.
5.2 The Processor informs the Controller of intended changes; the Controller may object on reasonable grounds.
5.3 The Processor binds sub-processors to equivalent data protection obligations (Art. 28(4) GDPR).
6. Third-country transfer
Processing takes place within the EU/EEA. Should a transfer to a third country occur, this happens only on the basis of an adequacy decision or appropriate safeguards (in particular EU Standard Contractual Clauses, Art. 46 GDPR).
7. Data breaches
Notifications under section 3.6 contain — to the extent available — the nature of the breach, the data categories/scope affected, the likely consequences and the measures taken.
8. Evidence and audits
The Processor demonstrates compliance on request (e.g. by documenting the TOMs). On-site inspections are permitted with reasonable advance notice, during business hours and without disrupting operations.
9. Termination
After termination of the main contract, the Processor deletes the personal data within
30 days or returns it on request, unless a statutory retention obligation precludes this.
10. Liability and final provisions
10.1 Liability is governed by Art. 82 GDPR and the main contract.
10.2 Amendments require text form.
10.3 German law applies; the place of jurisdiction is, to the extent permissible, Leipzig.
10.4 Should a provision be invalid, the remainder of the contract remains effective.
Annex 1 — Data processed, purposes, data subjects
Data subjects: end customers/visitors of the shop. Retention: for the term of the contract; deletion per section 9 and upon redact requests.
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
- Encryption: data at rest (database encryption/TDE) and in transit (TLS);
encrypted backups.
- Pseudonymisation: email/phone are stored hashed.
- Access control: role-based access limited to what is necessary; strong
authentication; administrative access separately protected.
- Separation: separate development and production environments/databases;
tenant-separated data storage per shop.
- Logging: access/change logs (audit trails, page-visit logs).
- Availability/recoverability: automated backups, point-in-time recovery.
- Resilience & incident response: procedures for handling security incidents.
