Data Processing Addendum
The terms governing Shoppio's processing of personal data on behalf of merchants.
1. Scope
This Data Processing Addendum ("DPA") forms part of the Terms when Shoppio processes Personal Data on behalf of the Customer as Processor.
2. Definitions
"Personal Data", "Processing", "Controller", "Processor" and "Data Subject" have the meanings given in GDPR Art. 4.
3. Processing details
Subject-matter, duration, nature, purpose, categories of data subjects and personal data are described in Annex 1 of the Service Order.
4. Customer instructions
Shoppio will process Personal Data only on documented instructions of the Customer.
5. Confidentiality
Persons authorized to process Personal Data are bound by appropriate confidentiality obligations.
6. Security measures
Technical & organizational measures: encryption at rest (AES-256) and in transit (TLS 1.3), least-privilege access, audit logging, intrusion detection, regular penetration testing.
7. Sub-processors
Customer authorizes the engagement of the following sub-processors. Shoppio will notify Customer of any addition or replacement (30-day objection right).
| Sub-processor | Service | Location |
|---|---|---|
| Google Cloud | Hosting & storage | Iowa, Belgium, Sydney |
| Stripe | Card processing | United States |
| Cloudflare | CDN & DDoS | Global |
| Sentry | Error logging | United States |
| Segment | Event pipeline | United States |
| Twilio | SMS delivery | United States |
| Postmark | Transactional email | United States |
8. Data Subject rights
Shoppio will assist Customer in fulfilling requests by Data Subjects to exercise rights under applicable data protection law.
9. Personal Data Breach notification
Shoppio will notify Customer without undue delay (within 72 hours) of becoming aware of a Personal Data Breach.
10. International transfers
Transfers from the EU/EEA, UK or Switzerland are governed by the EU Standard Contractual Clauses (2021/914) and the UK Addendum.
11. Audits
Customer (or its representative) may audit Shoppio's compliance once per year on 30 days' notice, subject to standard confidentiality.
12. Return & deletion
On termination, Shoppio will delete or return Personal Data within 60 days unless retention is required by law.