Legal · Effective May 1, 2026

Data Processing Addendum

The terms governing Shoppio's processing of personal data on behalf of merchants.

Template notice. This document is provided as a reference and does not constitute legal advice. Adapt it with your legal counsel before relying on it for production use.

1. Scope

This Data Processing Addendum ("DPA") forms part of the Terms when Shoppio processes Personal Data on behalf of the Customer as Processor.

2. Definitions

"Personal Data", "Processing", "Controller", "Processor" and "Data Subject" have the meanings given in GDPR Art. 4.

3. Processing details

Subject-matter, duration, nature, purpose, categories of data subjects and personal data are described in Annex 1 of the Service Order.

4. Customer instructions

Shoppio will process Personal Data only on documented instructions of the Customer.

5. Confidentiality

Persons authorized to process Personal Data are bound by appropriate confidentiality obligations.

6. Security measures

Technical & organizational measures: encryption at rest (AES-256) and in transit (TLS 1.3), least-privilege access, audit logging, intrusion detection, regular penetration testing.

7. Sub-processors

Customer authorizes the engagement of the following sub-processors. Shoppio will notify Customer of any addition or replacement (30-day objection right).

Sub-processorServiceLocation
Google CloudHosting & storageIowa, Belgium, Sydney
StripeCard processingUnited States
CloudflareCDN & DDoSGlobal
SentryError loggingUnited States
SegmentEvent pipelineUnited States
TwilioSMS deliveryUnited States
PostmarkTransactional emailUnited States

8. Data Subject rights

Shoppio will assist Customer in fulfilling requests by Data Subjects to exercise rights under applicable data protection law.

9. Personal Data Breach notification

Shoppio will notify Customer without undue delay (within 72 hours) of becoming aware of a Personal Data Breach.

10. International transfers

Transfers from the EU/EEA, UK or Switzerland are governed by the EU Standard Contractual Clauses (2021/914) and the UK Addendum.

11. Audits

Customer (or its representative) may audit Shoppio's compliance once per year on 30 days' notice, subject to standard confidentiality.

12. Return & deletion

On termination, Shoppio will delete or return Personal Data within 60 days unless retention is required by law.

Questions? Email legal@shoppio.pro.