Data Processing Addendum
Last updated 2 September 2026
This addendum governs Kepvia’s processing of personal data on your behalf and applies automatically to every merchant subject to the GDPR or comparable law — you do not need to sign or request it. It forms part of the Terms of Service.
1. Definitions
- Customer Personal Data — personal data contained in your store data that we process on your behalf, including data relating to your shoppers.
- Data Protection Laws — all privacy and data protection laws applicable to the processing, including the UK GDPR, the EU GDPR, and comparable laws elsewhere.
- SCCs — the Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum where applicable.
- Security Incident — a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Customer Personal Data.
- Sub-processor — a third party engaged by us to process Customer Personal Data.
- Controller, Processor, Data Subject and Processing have the meanings given in the GDPR.
2. Roles and responsibilities
For Customer Personal Data, you are the controller and TODO_LEGAL_ENTITY_NAME is the processor. We process it only on your documented instructions — which are: the Terms of Service, this addendum, and the actions you take in the app.
You are responsible for ensuring you have a lawful basis to collect the data and to have us process it, for giving your shoppers the notices their law requires, and for the accuracy of what you instruct us to capture. We will tell you if, in our opinion, an instruction infringes Data Protection Laws.
We process Customer Personal Data solely to provide the Service. We do not sell it, use it for our own purposes, or use it to train machine-learning models.
Where we process your own account and billing data, we act as a controller; that is covered by the Privacy Policy rather than this addendum.
3. Sub-processing
You give us general authorisation to engage sub-processors. The current list is in the Privacy Policy.
We will give you at least 30 days’ notice before adding or replacing a sub-processor that handles Customer Personal Data. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected part of the Service without penalty for the remainder of the paid period.
Each sub-processor is bound by written terms imposing protections no less onerous than these, and we remain fully liable to you for their performance.
4. Security
We implement appropriate technical and organisational measures to protect Customer Personal Data, described in Annex B. We may update them, but not in a way that materially reduces overall security.
Personnel with access are bound by confidentiality obligations and are granted access only to the extent needed to do their work.
On becoming aware of a Security Incident affecting Customer Personal Data, we will notify you without undue delay and within 72 hours where feasible, describing what we know, the likely consequences, and the steps taken. We will cooperate with you in responding, including any notification you must make to a regulator or to affected individuals.
You are responsible for your own use of the Service: keeping your Shopify account secure, controlling who has access to it, and choosing what to capture and where to export it.
5. Audits
On written request we will provide the information reasonably necessary to demonstrate compliance with this addendum. Where that is not sufficient for your obligations under Data Protection Laws, you may audit us once in any 12-month period, on at least 30 days’ written notice, during business hours, in a manner that does not disrupt the Service or compromise another customer’s data, subject to confidentiality, and at your cost. A regulator with authority over you may audit on the same terms.
6. International transfers
Customer Personal Data is processed in TODO_HOSTING_PROVIDER_AND_REGION. Where we transfer data protected by UK or EU law to a country without an adequacy decision, the SCCs are incorporated into this addendum and apply — module two (controller to processor), with you as data exporter and us as data importer — supplemented by the UK Addendum for UK transfers. If the SCCs are replaced or invalidated, we will adopt the replacement mechanism.
7. Deletion and return
You can export your data at any time from within the app. On termination, Customer Personal Data is retained for the history window of your plan so a reinstall can recover it, and is then deleted. You may instead ask us in writing to delete it immediately, and we will do so within 30 days of the request, except to the extent we are legally required to keep it — in which case we will continue to protect it and process it only for that purpose. Backups of our own systems are overwritten on their normal cycle.
8. Data subject rights and cooperation
The app lets you find, export and delete individual records yourself, which will satisfy most requests without our involvement. Where it does not, we will assist you in responding to data subject requests, taking into account the nature of the processing.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively; we will refer them to you and pass the request on.
We will also provide reasonable assistance with data protection impact assessments and prior consultations with regulators. Where assistance goes substantially beyond the app’s own functionality, we may charge a reasonable fee, agreed in advance.
9. Liability
Each party’s liability under this addendum is subject to the limitations and exclusions in the Terms of Service. Nothing here limits a data subject’s rights under Data Protection Laws, or liability that cannot lawfully be limited.
10. Relationship with the agreement
This addendum forms part of the Terms of Service and applies automatically where you are subject to Data Protection Laws — no signature is needed. In case of conflict, the SCCs prevail over this addendum, and this addendum prevails over the Terms of Service on matters of data protection. It replaces any earlier data processing terms between us.
11. Annex A — Details of processing
| Subject matter | Backup, storage, export, restoration and migration of Shopify store data. |
|---|---|
| Duration | For the term of the subscription, plus the retention period in section 7. |
| Nature and purpose | Copying store records via Shopify’s Admin API; storing them as versions; presenting them to you; writing them back to your store or to a destination store; exporting them to you or to a cloud account you connect. |
| Categories of data subject | The merchant’s shoppers and customers; the merchant’s staff and contractors with store accounts. |
| Categories of personal data | Names, email addresses, postal and billing addresses, phone numbers, order and transaction histories, customer notes, tags and segment membership, and any personal data the merchant has placed in metafields, metaobjects, pages or other store content. |
| Special category data | None is required or requested. Merchants should not place special category data in store records. |
| Frequency | Continuous — scheduled captures, incremental updates on store change events, and captures started manually. |
12. Annex B — Technical and organisational measures
- Encryption. TLS for all data in transit. Store, destination-store and cloud-account credentials encrypted at rest with a key held outside the database.
- Access control. Authentication through Shopify OAuth and session tokens; no passwords held by us. Production access limited to personnel who require it, under confidentiality obligations.
- Tenant isolation. Every record is scoped to the store that owns it, and requests are authorised against that scope.
- Storage. Backup storage is not publicly addressable; downloads are served through single-use, expiring links.
- Network. Application services are bound to the internal network and reached only through a hardened reverse proxy over HTTPS.
- Monitoring. Structured request and job logging, error tracking, and alerting on failures.
- Resilience. Long-running work runs on background workers with retries, so a failed run can be resumed rather than leaving partial data.
- Deletion. Automatic enforcement of plan retention windows, plus the Shopify redaction webhooks for shopper and shop erasure.
- Sub-processors. Bound by equivalent written obligations.
13. Contact
Questions about this addendum, or to submit a signed copy, contact privacy@kepvia.com. TODO_LEGAL_ENTITY_NAME, TODO_REGISTERED_ADDRESS.