Data Processing Agreement
GDPR Article 28 processing terms between the Merchant (Controller) and Shoptest (Processor). This DPA is incorporated into and forms part of the Shoptest Terms of Service.
1. Parties and Background
This Data Processing Agreement ("DPA") is entered into between the Merchant that has accepted the Shoptest Terms of Service ("Merchant", "Controller") and the operator of the Shoptest application, Hyper Effekt sp. z o.o., a company registered in Poland under KRS number 0001118008, REGON 529220060, NIP 7831908473, with its registered office at ul. 27 Grudnia 5/5A, 61-737 Poznań, Poland ("Shoptest", "Processor", "Company").
2. Definitions
- "Merchant Personal Data" means any Personal Data processed by Shoptest on behalf of the Merchant in connection with the Service, as described in the Data Access & Processing Disclosure.
- "Data Protection Laws" means the GDPR and any other applicable data protection or privacy law.
- "Sub-processor" means any third party engaged by Shoptest to process Merchant Personal Data.
- "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Merchant Personal Data.
- "Applicable Data Protection Law" means the GDPR, the UK GDPR, and US state privacy laws that apply to the processing, including the California Consumer Privacy Act as amended by the CPRA.
- "Business Purpose" means providing the Shoptest service described in the Terms and the Data Access & Processing Disclosure: storefront testing, monitoring, alerting, and related support.
3. Roles of the Parties
For Merchant Personal Data, the Merchant is the Controller and Shoptest is the Processor, within the meaning of Article 4 GDPR. Where Merchant Personal Data includes End Customer data that Shoptest incidentally processes, the Merchant remains Controller of that data and Shoptest processes it strictly as its Processor.
3A. US Privacy / Service Provider
Where US state privacy law applies (including the CPRA), Shoptest is a service provider (or contractor) to the Merchant, not a third party that "sells" or "shares" personal information.
Shoptest will:
- process Merchant Personal Data only for the Business Purpose above;
- not sell or share it, and not use it for cross-context behavioural advertising;
- not retain, use, or disclose it outside the direct Merchant–Shoptest relationship, except as required by law or to the sub-processors listed on shoptest.ai/legal/subprocessors;
- not combine it with personal information from other customers or from our own consumer products, except as needed to provide the Service (for example security, billing, or aggregate product improvement that does not identify the Merchant or any shopper);
- not use Merchant content, screenshots, or logs to train our own or a sub-processor's foundation models;
- tell the Merchant if we determine we can no longer meet these obligations.
The Merchant may take reasonable steps to confirm this, as set out in Section 14.
4. Subject Matter, Duration, Nature and Purpose
The subject matter, duration, nature, purpose, categories of data subjects, and categories of Merchant Personal Data processed under this DPA are as set out in Annex 1, which incorporates by reference the Data Access & Processing Disclosure rather than restating it.
Processing continues for as long as the App is installed and the Agreement is in effect, and thereafter only as needed to complete deletion obligations under Section 13.
5. Processing on Instructions
Shoptest will process Merchant Personal Data only on the Merchant's documented instructions, which consist of: (a) the Agreement and this DPA; (b) the Merchant's configuration and use of the Service; and (c) any further written instructions the Merchant issues, unless required to do otherwise by law.
If Shoptest believes an instruction infringes Applicable Data Protection Law, we will tell the Merchant and pause that instruction unless the law requires us to continue.
6. Confidentiality of Personnel
Shoptest ensures that personnel authorized to process Merchant Personal Data are subject to confidentiality obligations and have received appropriate guidance on handling personal data.
7. Security Measures
Shoptest implements technical and organizational measures appropriate to the risk. Merchant Personal Data is encrypted in transit (TLS) across all public and inter-service communication, and at rest using our cloud providers' default encryption. Access to production infrastructure is restricted to authorized personnel, and our infrastructure providers maintain SOC 2 Type II and ISO 27001 certifications.
A detailed technical and organizational measures annex is provided directly to Merchants as part of the signed Agreement, and is available on request at legal@shoptest.ai.
8. Sub-processors
The Merchant grants Shoptest general authorization to engage Sub-processors to support delivery of the Service, subject to the conditions below. Our current sub-processors are listed at shoptest.ai/legal/subprocessors.
- We will give notice of any new Sub-processor at least 30 days before it begins processing Merchant Personal Data.
- The Merchant may object in writing within 15 days of notice; the parties will work in good faith to address the objection, and if unresolved, the Merchant may terminate the affected part of the Service as its exclusive remedy.
- Shoptest remains responsible for each Sub-processor's compliance with obligations equivalent to those in this DPA.
- The current list, including AI and email providers, is at shoptest.ai/legal/subprocessors and is incorporated into this DPA.
9. Assistance with Data Subject Rights
Shoptest supports Merchant compliance with data-subject requests through Shopify's mandatory compliance webhooks described in the Disclosure (data request, customer redact, shop redact). Where a data subject contacts Shoptest directly regarding End Customer data, Shoptest will redirect them to the Merchant without undue delay.
10. Personal Data Breach Notification
Shoptest will notify the Merchant without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting Merchant Personal Data, and will provide the information we have at that time (nature, likely consequences, mitigation). We will update the Merchant as we learn more.
11. Data Protection Impact Assessment Support
Shoptest will provide reasonably requested information to support the Merchant in carrying out a data protection impact assessment or prior consultation with a supervisory authority, to the extent the request relates to Shoptest's processing under this DPA.
12. International Data Transfers
Merchant Personal Data is primarily hosted and processed in the United States (Render, Virginia — US East; Google Cloud Platform, us-east4), with browser-recording infrastructure hosted on Google Cloud Platform in europe-west2 (London, UK). Because the Company is established in the EEA, this means Merchant Personal Data originating in the EEA is transferred to the United States as part of ordinary processing under this DPA.
- Google Cloud Platform: covered — Google's Cloud Data Processing Addendum, accepted by the Company as a Google Cloud customer, incorporates the EU Standard Contractual Clauses automatically.
- Render: known gap, disclosed transparently. Render does not offer Standard Contractual Clauses. We disclose this directly rather than asserting a mechanism that isn't in place, and we are monitoring this — including the possibility of consolidating storage onto Google Cloud, which already provides SCC coverage.
- OpenRouter: covered — our Enterprise-tier agreement with OpenRouter includes a signed Data Processing Agreement with Standard Contractual Clauses. AI models (Anthropic, OpenAI, Google Gemini) are accessed exclusively through OpenRouter and are covered as OpenRouter's own sub-processors under that agreement.
- Sentry (error monitoring, United States) and Stripe (payment processing, EU-registered account) are addressed in our sub-processor list.
13. Deletion and Return of Data
While a Merchant's subscription is active, test-run history is retained according to the retention period of the Merchant's plan. If a Merchant cancels its subscription but does not uninstall the App, most Merchant data is retained, except that screenshots captured during test runs automatically expire after 60 days regardless of subscription status.
On uninstallation of the App, Shopify's shop/redact process triggers permanent erasure of all Merchant data within approximately 48 hours, regardless of subscription status at the time of uninstall.
At the Merchant's written request we will export available Merchant data (or return it in a reasonable machine-readable form) and/or delete it, including when the Merchant asks us to delete without uninstalling. We will also instruct sub-processors to delete that data, except where law requires retention (for example invoices).
14. Audit Rights
On reasonable written notice, and no more than once per year (or more often if a regulator requires it or after a Security Incident), the Merchant may:
- request a written description of our security measures;
- request our then-current security questionnaire answers or equivalent (and a SOC 2 report or pen-test summary if we have one);
- ask follow-up questions reasonably needed to confirm compliance with this DPA.
On-site inspection of production systems is not offered as a default. If a regulator or a Security Incident makes a deeper review necessary, the parties will agree a scoped review under confidentiality, in a way that does not put other customers' data at risk.
15. Liability
Each party's liability under this DPA is subject to the limitation of liability set out in the Terms of Service.
16. Term and General
This DPA takes effect on the date the Merchant accepts the Terms of Service and remains in effect for as long as Shoptest processes Merchant Personal Data. In case of conflict between this DPA and the Terms of Service on a data-protection matter, this DPA controls.
This DPA is governed by the laws of Poland, and disputes are subject to the exclusive jurisdiction of the competent court for the Company's registered seat in Poznań, Poland, consistent with the Terms of Service.
Annex 1 — Details of Processing
- Categories of data subjects: Merchant staff/owner; the Merchant's End Customers (incidentally).
- Categories of personal data: as described in the Data Access & Processing Disclosure.
- Special categories of data: none — the Service is not designed to process special categories of personal data.
- Nature and purpose of processing: automated storefront testing and monitoring.
- Duration: for the term of the Agreement, plus the deletion window described in Section 13.
Categories of personal data typically processed:
- Merchant staff / store owner: name, work email, phone, account and billing contacts
- Shop business data: shop name, domain, address, plan, access token
- Orders (last 60 days at install, then ongoing): totals, status, line items, channel, and browser IP where Shopify sends it — not customer profiles, and not card numbers
- Catalog, discounts, themes (read), store content, Markets, aggregate analytics
- Shopper-journey signals from our storefront pixel: hashed session id and page-type path (not raw URLs or customer profiles)
- Test artifacts: screenshots, logs, and recordings of the public storefront
- Incidental end-customer data if it appears on a public page or in a webhook we do not store as a customer record
Special categories: none. The Service is not designed to process them.
Annex 2 — Technical and Organizational Measures
A summary of our security posture:
- Hosting: Render (Virginia) and GCP (Virginia + London)
- Encryption: TLS in transit; provider-managed encryption at rest
- Access: production access limited to authorized personnel; admin tools are role-gated
- Monitoring: application error monitoring (Sentry); platform logs/metrics from the host
- Backups: provider-managed backups on the hosting platform
- Vendors: subprocessors listed at shoptest.ai/legal/subprocessors, including AI vendors used only for generation and diagnosis
A longer TOM sheet (access control, DR, vulnerability management) is available at legal@shoptest.ai.
Annex 3 — Sub-processors
See our current sub-processor list at shoptest.ai/legal/subprocessors.