DataXDATAX
PrivacyTermsDPA

Data Processing Agreement (DPA) pursuant to Art. 28 GDPR

between

the customer (merchant / shop operator) — hereinafter the "Controller" —

and

DataX GmbH, Waldstr. 4, 04105 Leipzig, Germany (Managing Director: Jakob Gerzen; VAT ID: DE356231862; commercial register: Local Court of Leipzig, HRB 40755) — hereinafter the "Processor" —

— together the "Parties" —

This DPA specifies the data protection obligations of the Parties for the processing of personal data that the Processor performs for the Controller in the course of using the DataX Services (DataX Analytics, DataX Influencer Tracking; hereinafter the "Services"). It applies upon activation of the Services and supplements the Terms of Service.

1. Subject matter, nature, purpose and duration

1.1 The subject matter of the processing is the provision of the Services, in particular the collection, storage, analysis and presentation of shop and order data to provide analytics and influencer-tracking reports for the Controller.

1.2 Nature of the processing: automated retrieval via the Shopify Admin API, storage in an encrypted database, aggregation/analysis, display in the Controller's DataX account.

1.3 Purpose: solely the performance of the analytics/reporting services commissioned by the Controller (no own purposes, no sale of data, no marketing dispatch to end customers).

1.4 Duration: for the term of the main contract (Terms of Service). After termination, section 9 applies.

2. Type of data and categories of data subjects

2.1 Categories of data subjects: end customers and visitors of the Controller's shop.

2.2 Types of personal data (see Annex 1):

  • order data (order ID, date, amounts, discount codes, items/quantities, status),
  • the customers' email address and phone number — stored by the Processor

exclusively in hashed/pseudonymised form (matching/deduplication).

No clear names, plain-text addresses or payment data are stored for processing purposes (data minimisation, Art. 5(1)(c) GDPR).

3. Obligations of the Processor

The Processor

3.1 processes personal data exclusively on documented instructions of the Controller (this DPA and the use of the Services constitute instructions), unless a legal obligation requires otherwise;

3.2 ensures confidentiality; persons authorised to process are bound to confidentiality;

3.3 takes the technical and organisational measures (TOMs) under Art. 32 GDPR (Annex 2);

3.4 supports the Controller as far as possible in fulfilling data subject rights (access, erasure, restriction) — erasure/access requests are processed via the Shopify compliance webhooks (customers/redact, customers/data_request, shop/redact);

3.5 supports the Controller in complying with Art. 32–36 GDPR (data security, breach notification, data protection impact assessment);

3.6 notifies the Controller of personal data breaches without undue delay after becoming aware of them (Art. 33 GDPR);

3.7 at the Controller's choice, deletes or returns all data after termination (section 9);

3.8 provides the Controller with the information necessary to demonstrate compliance and enables audits (section 8).

4. Obligations of the Controller

4.1 The Controller is responsible for the lawfulness of the processing and the legal basis (Art. 6 GDPR).

4.2 The Controller generally issues instructions in text form; verbal instructions are confirmed without undue delay.

5. Sub-processors

5.1 The Controller grants a general authorisation for the use of sub-processors. Those currently engaged are listed in Annex 3.

5.2 The Processor informs the Controller of intended changes; the Controller may object on reasonable grounds.

5.3 The Processor binds sub-processors to equivalent data protection obligations (Art. 28(4) GDPR).

6. Third-country transfer

Processing takes place within the EU/EEA. Should a transfer to a third country occur, this happens only on the basis of an adequacy decision or appropriate safeguards (in particular EU Standard Contractual Clauses, Art. 46 GDPR).

7. Data breaches

Notifications under section 3.6 contain — to the extent available — the nature of the breach, the data categories/scope affected, the likely consequences and the measures taken.

8. Evidence and audits

The Processor demonstrates compliance on request (e.g. by documenting the TOMs). On-site inspections are permitted with reasonable advance notice, during business hours and without disrupting operations.

9. Termination

After termination of the main contract, the Processor deletes the personal data within

30 days or returns it on request, unless a statutory retention obligation precludes this.

10. Liability and final provisions

10.1 Liability is governed by Art. 82 GDPR and the main contract.

10.2 Amendments require text form.

10.3 German law applies; the place of jurisdiction is, to the extent permissible, Leipzig.

10.4 Should a provision be invalid, the remainder of the contract remains effective.


Annex 1 — Data processed, purposes, data subjects

CategoryDataPurpose
Order dataorder ID, date, amounts, items/quantities, discount codes, statusrevenue/order analytics, influencer attribution
Customer identifieremail, phone (hashed)deduplication / attribution of orders

Data subjects: end customers/visitors of the shop. Retention: for the term of the contract; deletion per section 9 and upon redact requests.

Annex 2 — Technical and organisational measures (Art. 32 GDPR)

  • Encryption: data at rest (database encryption/TDE) and in transit (TLS);

encrypted backups.

  • Pseudonymisation: email/phone are stored hashed.
  • Access control: role-based access limited to what is necessary; strong

authentication; administrative access separately protected.

  • Separation: separate development and production environments/databases;

tenant-separated data storage per shop.

  • Logging: access/change logs (audit trails, page-visit logs).
  • Availability/recoverability: automated backups, point-in-time recovery.
  • Resilience & incident response: procedures for handling security incidents.

Annex 3 — Sub-processors

Sub-processorServicePlace of processing
Oracle Corporation (Oracle Cloud Infrastructure, OCI)Hosting of the database (Autonomous Database) and email deliveryEU (Frankfurt region, Germany)