Legal

Data Processing Agreement

Last updated: Aug 26, 2026

Data Processing Agreement

Emersoft Books Shopify Application | Version 1.1

Effective date: August 26, 2026

How this DPA applies

This Data Processing Agreement applies when Emersoft processes Merchant Personal Data on behalf of a Shopify merchant. The Processor is the Emersoft entity identified in the applicable Shopify billing record, invoice, order form or other Services Agreement. The Controller should confirm the relevant entity before requesting a separately signed copy.

DPA Particulars

Item

Details

Controller

The Shopify merchant or other customer identified in the Services Agreement.

Processor

The Emersoft Contracting Entity identified in the Services Agreement: EMERSOFT LLC or EMERSOFT LTD.

EMERSOFT LLC

EIN 92-1707678; 9620 Las Vegas Blvd S, Ste E4 #612, Las Vegas, Nevada 89123, United States.

EMERSOFT LTD

Company number 10977747; 21 Navigation Business Village, Navigation Way, Preston, Lancashire, England, PR2 2YP.

Services

Emersoft Books, including supported Shopify integrations, catalogue, inventory, Pubnet EDI, fulfilment and support functions.

Effective date

The earlier of the date this DPA is accepted, the date the Services Agreement begins, or the date Emersoft first processes Merchant Personal Data for the Controller.

Contact

[email protected] or https://emersoft.co/contact.

1. Scope and Order of Precedence

1.1 This DPA forms part of the agreement governing the Controller’s use of the Services, including the Emersoft Books Terms of Service, an order form, Shopify billing approval or other written agreement (the “Services Agreement”).

1.2 This DPA applies only to Merchant Personal Data processed by Emersoft as a processor, service provider or contractor on behalf of the Controller. It does not apply to personal data for which Emersoft determines independent purposes and means, such as its own billing, account administration, security, legal compliance and direct business communications. That processing is covered by the Emersoft Privacy Policy.

1.3 If there is a conflict concerning the processing of Merchant Personal Data, the following order of precedence applies: mandatory transfer clauses; this DPA; the Services Agreement; and other incorporated policies. Commercial limitations in the Services Agreement remain applicable unless prohibited by Data Protection Law or mandatory transfer clauses.

2. Definitions

Applicable Data Protection Law: means laws applicable to the processing under this DPA, including where relevant the UK GDPR, Data Protection Act 2018, EU GDPR, applicable US state privacy laws, PIPEDA and Australian privacy laws.

Controller: means the merchant or customer that determines the purposes and essential means of processing Merchant Personal Data.

Data Subject: means an identified or identifiable person to whom Merchant Personal Data relates.

Merchant Personal Data: means personal data contained in Shopify orders, fulfilment orders, merchant instructions or related records that Emersoft processes on behalf of the Controller.

Personal Data Breach: means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Merchant Personal Data.

Processor: means the Emersoft Contracting Entity identified in the Services Agreement.

Restricted Transfer: means a transfer that requires an adequacy mechanism, appropriate safeguard or other valid transfer basis under Applicable Data Protection Law.

Subprocessor: means a third party engaged by Emersoft to process Merchant Personal Data on behalf of the Controller.

Services: means the Emersoft Books Shopify application and related support and integration services.

Terms such as “personal data”, “processing”, “controller”, “processor” and “supervisory authority” have the meanings given by Applicable Data Protection Law.

3. Roles, Instructions and Compliance

3.1 The Controller is the controller of Merchant Personal Data. Emersoft is the processor, service provider or contractor for the processing described in Schedule 1.

3.2 The Controller instructs Emersoft to process Merchant Personal Data to provide, secure, maintain and support the Services; to transmit fulfilment instructions to providers selected or enabled by the Controller; to process documented instructions submitted through the Services or in writing; and to comply with applicable law.

3.3 Emersoft will process Merchant Personal Data only on documented instructions from the Controller, including instructions in the Services Agreement, this DPA, configuration choices, supplier selections, support requests and other written communications, unless Emersoft is required to process the data by law. Where legally permitted, Emersoft will notify the Controller before processing required by law.

3.4 If Emersoft reasonably believes an instruction infringes Applicable Data Protection Law, it will notify the Controller and may pause the affected processing while the parties resolve the issue. Emersoft is not required to provide legal advice or follow unlawful instructions.

3.5 Emersoft will comply with direct obligations imposed on processors and will promptly notify the Controller if it can no longer meet applicable obligations.

4. Controller Responsibilities

The Controller is responsible for:

  • ensuring that its collection, use and disclosure of Merchant Personal Data is lawful, fair and transparent;

  • providing legally required privacy information to customers and other Data Subjects;

  • having a valid legal basis for processing and for disclosing order and delivery information to Emersoft and selected fulfilment providers;

  • ensuring that its instructions are lawful and that Merchant Personal Data is accurate, relevant and limited to what is necessary;

  • not submitting special-category data, highly sensitive data, full payment-card data or children’s data unless expressly supported, necessary and lawfully authorised;

  • responding to Data Subjects and regulators, with assistance from Emersoft as described below; and

  • maintaining appropriate Shopify, supplier and user security, including access control and credential protection.

5. Confidentiality and Personnel

5.1 Emersoft will ensure that personnel authorised to process Merchant Personal Data are subject to an appropriate duty of confidentiality and are given access only where necessary for their responsibilities.

5.2 Emersoft will restrict administrative and production access to authorised personnel and technical processes. The current access model is described in Schedule 2.

5.3 Emersoft remains responsible for the acts and omissions of its personnel in relation to Merchant Personal Data, subject to the Services Agreement and Applicable Data Protection Law.

6. Security

6.1 Taking into account the state of the art, implementation costs, nature, scope, context and purposes of processing, and the risk to individuals, Emersoft will maintain appropriate technical and organisational measures designed to protect Merchant Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

6.2 The measures currently confirmed by Emersoft are set out in Schedule 2. Emersoft may update measures where this does not materially reduce the overall security of the Services.

6.3 The Controller acknowledges that security is a shared responsibility. Emersoft is not responsible for a breach caused solely by the Controller’s insecure Shopify account, supplier credentials, user access, devices or instructions, except to the extent Emersoft contributed to the breach.

7. Subprocessors

7.1 The Controller gives Emersoft general written authorisation to engage the Subprocessors identified in Schedule 3 and in the current published Subprocessor List.

7.2 Emersoft will enter into a written agreement with each Subprocessor that imposes data-protection obligations providing an equivalent level of protection for Merchant Personal Data, to the extent required by Applicable Data Protection Law.

7.3 Emersoft will remain responsible to the Controller for a Subprocessor’s performance of its data-protection obligations to the extent required by law.

7.4 Emersoft will provide reasonable advance notice, normally at least 30 days where practicable, before appointing a new Subprocessor that will materially process Merchant Personal Data. The Controller may object on reasonable data-protection grounds during the notice period.

7.5 If the parties cannot resolve a reasonable objection, Emersoft may offer an alternative configuration where reasonably available. If no reasonable alternative is available, either party may terminate the affected Services without penalty, and Emersoft will refund any prepaid fees for the unused affected period.

7.6 Shopify, Ingram, Gardners, Pubnet and other services selected by the Controller may be independent platforms, recipients, processors or controllers under their own agreements. Their classification must be assessed by reference to the actual contract and processing. They are not automatically Emersoft Subprocessors merely because the Services integrate with them.

8. International Transfers

8.1 The Controller authorises Emersoft to make the transfers described in Schedule 4, subject to a valid transfer mechanism and the requirements of Applicable Data Protection Law.

8.2 Where a Restricted Transfer is not covered by an applicable adequacy decision or regulation, the parties will rely on an appropriate safeguard, which may include the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally recognised mechanism.

8.3 Emersoft will complete and periodically review a Transfer Risk Assessment, also referred to in current UK guidance as a data protection test, where required. Emersoft will implement reasonable supplementary measures identified as necessary, taking account of the data, destination, recipient, encryption, access controls and likelihood of government access.

8.4 Emersoft will require relevant Subprocessors to maintain an appropriate transfer mechanism for onward transfers. Mandatory transfer clauses prevail over inconsistent terms in this DPA.

8.5 If a valid transfer mechanism becomes unavailable, the parties will cooperate in good faith to implement a replacement. Emersoft may suspend the affected transfer where required by law.

9. Data Subject Requests

9.1 Taking into account the nature of processing, Emersoft will provide reasonable assistance through appropriate technical and organisational measures so the Controller can respond to requests for access, rectification, erasure, restriction, portability or objection.

9.2 If Emersoft receives a request directly from a Data Subject relating to Merchant Personal Data, Emersoft will, where lawful, redirect the requester to the Controller or notify the Controller. Emersoft will not independently respond except on the Controller’s documented instruction or where required by law.

9.3 Emersoft implements Shopify’s mandatory compliance webhooks for customers/data_request, customers/redact and shop/redact. Emersoft will process valid Shopify privacy requests in accordance with the workflow described in Schedule 1 and the Privacy Policy.

9.4 The Controller must provide information reasonably necessary to identify the relevant store, customer, order or request. Assistance beyond the ordinary functionality of the Services may be charged at reasonable rates if extensive, repetitive or caused by the Controller’s non-compliance, unless prohibited by law.

10. Personal Data Breaches

10.1 Emersoft will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Merchant Personal Data.

10.2 To the extent information is available, the notice will describe the nature of the breach, affected data and Data Subjects, likely consequences, containment and remediation measures, and a contact for follow-up. Information may be provided in phases where it is not available at the same time.

10.3 Emersoft will take reasonable steps to contain, investigate and remediate the breach, preserve relevant evidence, and provide assistance reasonably required for the Controller’s risk assessment, regulatory notification and communication to affected individuals.

10.4 Emersoft’s notice is not an admission of fault or liability. The Controller remains responsible for deciding whether notification to a regulator or Data Subject is required, except where law imposes a direct obligation on Emersoft.

11. Assistance, DPIAs and Regulatory Enquiries

Taking into account the nature of processing and information available, Emersoft will reasonably assist the Controller with security obligations, breach notifications, data protection impact assessments, prior consultation with regulators, and enquiries concerning Emersoft’s processing. The Controller remains responsible for its legal decisions and filings.

12. Compliance Information and Audits

12.1 Emersoft will make available information reasonably necessary to demonstrate compliance with Article 28-type processor obligations, including this DPA, the Subprocessor List, relevant security information and summaries of third-party assurance where available.

12.2 The Controller may conduct an audit no more than once in any 12-month period, unless a Personal Data Breach, regulator request or reasonable evidence of material non-compliance justifies an additional audit.

12.3 Audits must normally begin with written questionnaires and remote evidence. An onsite inspection requires at least 30 days’ notice, must occur during normal business hours, must not unreasonably disrupt operations, and must protect other customers, confidential information and security.

12.4 The Controller bears reasonable audit costs. Emersoft will bear its own reasonable costs where an audit identifies a material breach of this DPA by Emersoft. Auditors must be independent, suitably qualified and bound by confidentiality.

13. Government and Legal Requests

If Emersoft receives a legally binding request for Merchant Personal Data, it will, where legally permitted, notify the Controller before disclosure, review the request for validity, seek to limit disclosure to what is legally required, and challenge disproportionate requests where there are reasonable grounds to do so.

14. Return and Deletion

14.1 On termination of the affected Services, Emersoft will, at the Controller’s choice, return or delete Merchant Personal Data and delete existing copies, unless applicable law requires continued storage. Where the Controller requests return, Emersoft will provide the data in a reasonably available format appropriate to the nature of the Services before deletion. The Controller should request or export information it requires before uninstalling the App where practicable; this does not limit the Controller’s rights under Applicable Data Protection Law.

14.2 The current Shopify uninstallation and redaction process is described in Schedule 1. Operational shop data is removed at uninstall. Remaining shop records, billing history, imported-product mappings and related records are removed when the shop/redact process completes, normally approximately 48 hours after uninstall, subject to Shopify delivery and technical processing.

14.3 Data in encrypted backups may remain beyond active-system deletion until the normal backup cycle expires. It will be put beyond ordinary use, remain protected and be deleted automatically when the relevant backup expires. Current offsite backup retention is up to three weeks.

14.4 During an active subscription, Emersoft currently does not operate a complete automated age-based purge for all historical order records. Valid deletion requests are handled through Shopify compliance workflows or manually. Schedule 1 identifies this operational limitation, and the implementation review recommends adoption of a documented fixed retention schedule.

15. US State Privacy Terms

Where Emersoft processes personal information as a service provider or contractor under applicable US state privacy law, Emersoft will:

  • process the information only for the specific business purposes described in the Services Agreement and this DPA;

  • not sell or share the information for cross-context behavioural advertising;

  • not retain, use or disclose the information outside the direct business relationship except as permitted by law;

  • not combine it with personal information received from another person or collected from Emersoft’s own consumer interaction except as legally permitted;

  • apply the same level of privacy protection required by applicable law;

  • notify the Controller if Emersoft determines it can no longer meet its obligations; and

  • allow the Controller to take reasonable and appropriate steps to verify, stop and remediate unauthorised use.

16. Liability

Each party’s liability arising from this DPA is subject to the limitations and exclusions in the Services Agreement, except to the extent prohibited by Applicable Data Protection Law or mandatory transfer clauses. Nothing limits liability that cannot lawfully be limited.

17. Term and General Terms

17.1 This DPA remains in effect for as long as Emersoft processes Merchant Personal Data for the Controller.

17.2 Amendments must be in writing or made through a lawful update process under the Services Agreement. Emersoft may update the Schedules to reflect service, legal, security or Subprocessor changes, provided that the overall protection of Merchant Personal Data is not materially reduced.

17.3 The governing law, jurisdiction, notices, assignment, severability and interpretation provisions of the Services Agreement apply to this DPA. If there is no governing-law provision, England and Wales applies for a Controller established in the UK, and Nevada applies for other Controllers, subject to mandatory law and transfer clauses.

Signature or Electronic Acceptance

This DPA may be accepted electronically with the Services Agreement. If a signed copy is requested, the parties may complete the details below. Electronic signatures and counterparts are permitted.

Field

Details

Controller legal name

[Merchant legal name]

Controller registered address

[Merchant registered address]

Controller signatory, title and date

[Name / title / date]

Processor

The Emersoft Contracting Entity identified in the Services Agreement

Processor contact

[email protected]

Processor signatory, title and date

[Authorised Emersoft representative / title / date]

Schedule 1

Data Processing Details

Element

Description

Subject matter

Provision of the Emersoft Books Shopify application, including catalogue import, product and inventory synchronisation, Pubnet EDI functions, fulfilment order processing, tracking synchronisation, security and support.

Duration

For the Services term and the deletion period described below.

Nature of processing

Collection through Shopify APIs and webhooks; access; validation; organisation; storage; retrieval; transmission to selected fulfilment providers; synchronisation; support; security logging; export; deletion and redaction.

Purpose

To operate the App, transmit orders for fulfilment, return fulfilment and tracking status to Shopify, maintain merchant configurations, provide support, protect the Service and comply with valid instructions and law.

Frequency

Continuous or event-driven during active use, including order, fulfilment, inventory, product and privacy webhook events.

Data Subjects

Merchant customers and order recipients; merchant owners, employees and authorised users; supplier and support contacts where their personal data is included in merchant instructions.

Personal data

Name; shipping address; email address; telephone number when provided; Shopify store, customer, order and fulfilment identifiers; order line items; delivery instructions; fulfilment and tracking information; merchant account and configuration information; limited technical, IP, browser and log data.

Special categories

Not intentionally required or supported. Controllers must not submit special-category or highly sensitive data unless expressly agreed and lawfully authorised.

Payment data

Emersoft does not collect full payment-card data. Customer payments remain handled by Shopify and relevant payment providers.

Children’s data

Not intentionally targeted or required. Ordinary recipient information may relate to a minor without Emersoft knowing age; the Controller remains responsible for lawful collection and disclosure.

Geographic processing

Production compute in Ashburn, Virginia; managed database in New York City, New York; AWS us-east-1 provides Docker/container storage and GPG-encrypted offsite backups; Grafana Cloud processes technical logs in US East (Ohio) with 30-day retention; edge and security providers may process technical data in other locations as described in the Subprocessor List.

Shopify permissions and protected customer data

Shopify scope

Purpose

write_products

Create and update Shopify products when importing titles.

write_inventory

Manage inventory quantities at the app fulfilment location.

write_fulfillments

Create fulfilments and synchronise tracking information.

read_assigned_fulfillment_orders

Read fulfilment orders assigned to the App.

write_assigned_fulfillment_orders

Accept, reject or place holds on assigned fulfilment orders.

read_locations / write_locations

Create and manage the dedicated app fulfilment location.

read_orders / write_orders

Read order and fulfilment data required for Consumer Direct Fulfilment and update order or fulfilment state.

write_third_party_fulfillment_orders

Handle third-party fulfilment workflows.

read_publications / write_publications

Publish imported products to sales channels.

read_product_listings

Access product-listing information used in catalogue and import flows.

The App does not request read_customers or write_customers. Protected customer fields are obtained through order and fulfilment resources under read_orders. Confirmed Level 2 fields are customer name, shipping address, email address and telephone number when provided. These fields are used for fulfilment and are not used for marketing, advertising or profiling.

Operational and privacy webhooks

Webhook

Processing action

products/delete

Remove or update local product mappings.

app/uninstalled

Mark store uninstalled, stop jobs and remove operational shop data.

app_subscriptions/update

Synchronise billing and subscription state.

bulk_operations/finish

Continue or complete bulk import processing.

fulfillment_orders/hold_released / placed_on_hold

Manage fulfilment order status.

inventory_levels/connect / disconnect / update

Maintain inventory mappings and state.

customers/data_request

Record and support a customer data access request.

customers/redact

Delete app-stored data linked to listed Shopify order identifiers.

shop/redact

Complete final erasure of remaining shop data, normally about 48 hours after uninstall.

Retention and deletion

Category

Current retention or deletion rule

Operational shop data

Removed on app/uninstalled, including sessions, shop configuration, fulfilment services and fulfilment orders, Pubnet/FTP operational records, selected product mappings, background jobs and caches.

Remaining shop and billing records

Retained briefly after uninstall for billing history and reinstall/reconcile handling; removed on shop/redact, normally approximately 48 hours later.

Customer/order data subject to redaction

Deleted following a valid customers/redact request.

Active-service historical order data

No complete automated age-based purge is currently implemented. Data is retained as operationally necessary and deleted manually or through Shopify compliance workflows. A fixed retention schedule should be adopted.

Managed database point-in-time recovery

Up to seven days.

Encrypted offsite backups

Created twice daily and retained for up to three weeks.

Application logs in Grafana Cloud

Stored in Grafana Cloud in the US East (Ohio) region and retained for 30 days.

Schedule 2

Technical and Organisational Measures

Important
This Schedule records technical and organisational measures currently confirmed by Emersoft. Recommendations and outstanding implementation tasks are maintained separately in the Delivery Index and Website and Shopify App Store Disclosure Review; they are not representations that unimplemented measures are already in place.

Governance and access

  • Full Kubernetes cluster access is restricted to designated authorised DevOps personnel.

  • Atlassian Bitbucket CI/CD is used for deployment automation and has limited access required only to roll out new application versions.

  • Cloud-provider administrative access is restricted to authorised senior technical or management personnel with a business need.

  • Direct database access is limited to the production application cluster and designated authorised operational personnel when required.

  • Access must be removed when no longer required and reviewed periodically.

Encryption and transmission

  • The managed database is encrypted at rest using LUKS.

  • Database connections use TLS/SSL.

  • Integration credentials are transmitted using SSL/TLS and stored encrypted at rest.

  • Offsite database backups are GPG-encrypted before transfer.

Network and application protection

  • All public application access is routed through Cloudflare.

  • Cloudflare Web Application Firewall protections are enabled.

  • HTTP access is not supported; HTTPS is required.

  • Database access is restricted through IP allowlisting.

Environment segregation

  • Production and non-production environments operate in separate physical clusters and data centres.

  • Production data is not copied into non-production environments.

  • Testing uses generated test orders in dedicated Shopify test stores.

Logging and monitoring

  • Application logs are streamed to Grafana Cloud in the US East (Ohio) region, monitored regularly and retained for 30 days.

  • Uptime monitoring covers the App API and frontend.

  • Grafana alerts are configured for deployment failures and are sent to a restricted Emersoft Discord channel. Emersoft has confirmed that these Discord alerts are purely technical and do not contain personal information.

  • Emersoft should continue to ensure that application logs do not unnecessarily contain customer names, addresses, credentials or other Merchant Personal Data.

Backups and resilience

  • Database backups are created twice daily.

  • GPG-encrypted backups are stored offsite in AWS us-east-1 for up to three weeks.

  • Managed database point-in-time recovery is available for the preceding seven days.

Shopify data minimisation

  • The App requests only the Shopify scopes required for catalogue, inventory, order and fulfilment functions.

  • The App does not request customer-resource scopes such as read_customers or write_customers.

  • Protected customer fields are limited to name, shipping address, email and telephone number when provided.

  • Payment-card data is not collected by Emersoft.

Privacy and deletion controls

  • Mandatory Shopify privacy webhooks are implemented.

  • Operational data is removed at uninstall and remaining shop data is removed through shop/redact.

  • Customer records can be deleted in response to customers/redact.

  • Manual deletion is available where automated age-based deletion is not yet implemented.

Incident response

  • Emersoft will identify and contain the cause of a suspected compromise, investigate the root cause, implement remediation and notify affected Controllers without undue delay.

Supplier management

  • Subprocessors must be assessed for appropriate security and contractual safeguards.

  • Written data-processing terms and lawful transfer mechanisms must be maintained where required.

  • Subprocessor changes must follow the notification and objection process in this DPA.

Schedule 3

Authorised Subprocessors and Third-Party Recipients

Provider

Purpose

Location

Data

Role

Hetzner Online GmbH

Application hosting and compute

Ashburn, Virginia, United States

Merchant, order, fulfilment and technical data processed by the application

Subprocessor

DigitalOcean, LLC

Managed database hosting

New York City, New York, United States

Merchant configuration, order, fulfilment and application records

Subprocessor

Amazon Web Services, Inc.

Docker/container storage and encrypted offsite backup storage

us-east-1, United States

Docker/container storage and GPG-encrypted database backups

Subprocessor

Cloudflare, Inc.

DNS, proxy, CDN, TLS termination and Web Application Firewall

Global network; processing locations depend on service configuration and applicable Cloudflare terms

IP address, request and security metadata; transient application traffic

Subprocessor

Grafana Cloud / applicable provider entity under Emersoft's subscription

Application logging, monitoring and alerting

US East (Ohio), United States

Application logs and technical events; 30-day retention; avoid unnecessary order/customer data

Subprocessor, subject to applicable provider DPA and transfer safeguards where required

Merchant-selected platforms and fulfilment recipients

Provider

Role clarification

Shopify

Merchant ecommerce platform and source of API/webhook data. Shopify’s role is governed by its agreement with the merchant and is not automatically that of an Emersoft Subprocessor.

Ingram Content Group / Ingram fulfilment services

Receives delivery and order information when selected or enabled for fulfilment. Role depends on the merchant’s supplier and fulfilment agreement.

Gardners

Receives delivery and order information for UK home delivery when selected or enabled. Role depends on the merchant’s agreement.

Pubnet

Supports EDI purchase-order workflows. Its legal and data-protection role is governed by the merchant’s Pubnet and supplier agreements and may vary by implementation.

Google, Meta and TikTok

Listed as App integrations. They are not treated as order-data Subprocessors unless they process Merchant Personal Data on Emersoft’s behalf. Separate website or sales-channel processing is governed by the relevant configuration and provider terms.

Schedule 4

International Data Transfer Provisions

1. Transfer framework

The application’s confirmed production compute, database and backup infrastructure is located in the United States. Accordingly, Merchant Personal Data originating in the UK or EEA may be subject to a Restricted Transfer.

Where an adequacy mechanism applies to the relevant recipient and transfer, the parties may rely on that mechanism. This may include the UK Extension to the EU-US Data Privacy Framework for an eligible participating US recipient handling UK data, or the EU-US Data Privacy Framework for an eligible participating US recipient handling EEA data. If no applicable adequacy mechanism covers the transfer, the safeguards below apply as relevant:

  • UK Controller to a US Processor: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as selected and completed for the transfer;

  • EEA Controller to a US Processor: the European Commission Standard Contractual Clauses dated 4 June 2021, generally Module Two for controller-to-processor transfers;

  • Processor to a US Subprocessor: the relevant processor-to-processor clauses, generally Module Three of the EU Standard Contractual Clauses, together with the UK Addendum where UK data is involved; and

  • another lawful safeguard approved or recognised under Applicable Data Protection Law.

2. Transfer details

Item

Details

Exporter

Controller, or Emersoft where Emersoft initiates an onward transfer.

Importer

The US Emersoft entity or an authorised US Subprocessor, depending on the transfer.

Data Subjects

Merchant customers and recipients; merchant users and support contacts where included.

Data

Names, shipping addresses, email addresses, telephone numbers when provided, order and fulfilment identifiers, order lines, tracking information, merchant configuration and limited technical data.

Purpose

Application hosting, database storage, container storage, fulfilment processing, security, monitoring and encrypted backup.

Frequency

Continuous or event-driven during active service.

Retention

As described in Schedule 1 and the relevant Subprocessor agreement.

Competent authority

The authority determined under the applicable SCCs, UK Addendum, IDTA and governing data-protection law.

3. Supplementary measures

  • TLS/SSL for data in transit and HTTPS-only public access;

  • LUKS encryption at rest for the managed database;

  • GPG encryption for offsite backups;

  • IP allowlisting and restricted administrative access;

  • data minimisation through limited Shopify permissions and protected fields;

  • Cloudflare WAF and application monitoring;

  • contractual confidentiality, purpose limitation and onward-transfer restrictions; and

  • review of government-access risk and additional measures through the applicable data protection test / transfer-risk assessment.

4. Mandatory clauses

If the parties execute or incorporate mandatory transfer clauses, those clauses are incorporated into this DPA by reference and will be completed using the information in this Schedule, the DPA Particulars and Schedule 1. The parties must not amend mandatory clauses except as permitted by the relevant instrument. Where required, the parties will execute the official form separately.