Data Processing Agreement

GDPR Article 28 processing terms between the Merchant (Controller) and Shoptest (Processor). This DPA is incorporated into and forms part of the Shoptest Terms of Service.

1. Parties and Background

This Data Processing Agreement ("DPA") is entered into between the Merchant that has accepted the Shoptest Terms of Service ("Merchant", "Controller") and the operator of the Shoptest application, Hyper Effekt sp. z o.o., a company registered in Poland under KRS number 0001118008, REGON 529220060, NIP 7831908473, with its registered office at ul. 27 Grudnia 5/5A, 61-737 Poznań, Poland ("Shoptest", "Processor", "Company").

2. Definitions

• "Merchant Personal Data" means any Personal Data processed by Shoptest on behalf of the Merchant in connection with the Service, as described in the Data Access & Processing Disclosure.

• "Data Protection Laws" means the GDPR and any other applicable data protection or privacy law.

• "Sub-processor" means any third party engaged by Shoptest to process Merchant Personal Data.

• "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Merchant Personal Data.

3. Roles of the Parties

For Merchant Personal Data, the Merchant is the Controller and Shoptest is the Processor, within the meaning of Article 4 GDPR. Where Merchant Personal Data includes End Customer data that Shoptest incidentally processes, the Merchant remains Controller of that data and Shoptest processes it strictly as its Processor.

4. Subject Matter, Duration, Nature and Purpose

The subject matter, duration, nature, purpose, categories of data subjects, and categories of Merchant Personal Data processed under this DPA are as set out in Annex 1, which incorporates by reference the Data Access & Processing Disclosure rather than restating it.

Processing continues for as long as the App is installed and the Agreement is in effect, and thereafter only as needed to complete deletion obligations under Section 12.

5. Processing on Instructions

Shoptest will process Merchant Personal Data only on the Merchant's documented instructions, which consist of: (a) the Agreement and this DPA; (b) the Merchant's configuration and use of the Service; and (c) any further written instructions the Merchant issues, unless required to do otherwise by law.

6. Confidentiality of Personnel

Shoptest ensures that personnel authorized to process Merchant Personal Data are subject to confidentiality obligations and have received appropriate guidance on handling personal data.

7. Security Measures

Shoptest implements technical and organizational measures appropriate to the risk. Merchant Personal Data is encrypted in transit (TLS) across all public and inter-service communication, and at rest using our cloud providers' default encryption. Access to production infrastructure is restricted to authorized personnel, and our infrastructure providers maintain SOC 2 Type II and ISO 27001 certifications.

A detailed technical and organizational measures annex is provided directly to Merchants as part of the signed Agreement, and is available on request at legal@shoptest.ai.

8. Sub-processors

The Merchant grants Shoptest general authorization to engage Sub-processors to support delivery of the Service, subject to the conditions below. Our current sub-processors are listed at shoptest.ai/legal/subprocessors.

• We will give notice of any new Sub-processor at least 15 days before it begins processing Merchant Personal Data.

• The Merchant may object in writing within 10 days of notice; the parties will work in good faith to address the objection, and if unresolved, the Merchant may terminate the affected part of the Service as its exclusive remedy.

• Shoptest remains responsible for each Sub-processor's compliance with obligations equivalent to those in this DPA.

9. Assistance with Data Subject Rights

Shoptest supports Merchant compliance with data-subject requests through Shopify's mandatory compliance webhooks described in the Disclosure (data request, customer redact, shop redact). Where a data subject contacts Shoptest directly regarding End Customer data, Shoptest will redirect them to the Merchant without undue delay.

10. Personal Data Breach Notification

Shoptest will notify the Merchant without undue delay, and in any event within 72 hours of becoming aware, after confirming a Security Incident affecting Merchant Personal Data, and will provide available information regarding its nature, likely consequences, and mitigation steps taken.

11. Data Protection Impact Assessment Support

Shoptest will provide reasonably requested information to support the Merchant in carrying out a data protection impact assessment or prior consultation with a supervisory authority, to the extent the request relates to Shoptest's processing under this DPA.

12. International Data Transfers

Merchant Personal Data is primarily hosted and processed in the United States (Render, Virginia — US East; Google Cloud Platform, us-east4), with browser-recording infrastructure hosted on Google Cloud Platform in europe-west2 (London, UK). Because the Company is established in the EEA, this means Merchant Personal Data originating in the EEA is transferred to the United States as part of ordinary processing under this DPA.

• Google Cloud Platform: covered — Google's Cloud Data Processing Addendum, accepted by the Company as a Google Cloud customer, incorporates the EU Standard Contractual Clauses automatically.

• Render: known gap, disclosed transparently. Render does not offer Standard Contractual Clauses. We disclose this directly rather than asserting a mechanism that isn't in place, and we are monitoring this — including the possibility of consolidating storage onto Google Cloud, which already provides SCC coverage.

• Sentry (error monitoring, United States) and Stripe (payment processing, EU-registered account) are addressed in our sub-processor list.

13. Deletion and Return of Data

While a Merchant's subscription is active, test-run history is retained according to the retention period of the Merchant's plan. If a Merchant cancels its subscription but does not uninstall the App, most Merchant data is retained, except that screenshots captured during test runs automatically expire after 60 days regardless of subscription status.

On uninstallation of the App, Shopify's shop/redact process triggers permanent erasure of all Merchant data within approximately 48 hours, regardless of subscription status at the time of uninstall.

14. Audit Rights

On reasonable prior written notice, and no more than once per year (or more often if required by a supervisory authority or following a Security Incident), the Merchant may request information reasonably necessary to demonstrate Shoptest's compliance with this DPA.

15. Liability

Each party's liability under this DPA is subject to the limitation of liability set out in the Terms of Service.

16. Term and General

This DPA takes effect on the date the Merchant accepts the Terms of Service and remains in effect for as long as Shoptest processes Merchant Personal Data. In case of conflict between this DPA and the Terms of Service on a data-protection matter, this DPA controls.

This DPA is governed by the laws of Poland, and disputes are subject to the exclusive jurisdiction of the competent court for the Company's registered seat in Poznań, Poland, consistent with the Terms of Service.

Annex 1 — Details of Processing

• Categories of data subjects: Merchant staff/owner; the Merchant's End Customers (incidentally).

• Categories of personal data: as described in the Data Access & Processing Disclosure.

• Special categories of data: none — the Service is not designed to process special categories of personal data.

• Nature and purpose of processing: automated storefront testing and monitoring.

• Duration: for the term of the Agreement, plus the deletion window described in Section 13.

Annex 2 — Technical and Organizational Measures

A summary of our security posture:

• Hosting — Render (Virginia, US) and Google Cloud Platform (Virginia, US and London, UK).

• Encryption — TLS in transit; provider-managed encryption at rest.

• Infrastructure certifications — Render holds SOC 2 Type II and ISO 27001 certifications.

• Access control — production infrastructure access is restricted to authorized personnel; internal admin tools require explicitly provisioned roles.

• Monitoring — application error monitoring in place; platform-level logging and metrics via our hosting provider.

A full, detailed technical and organizational measures annex — covering access control specifics, backup and disaster recovery, and vulnerability management practices — is provided directly to Merchants as part of the signed Agreement, and is available on request at legal@shoptest.ai.

Annex 3 — Sub-processors

See our current sub-processor list at shoptest.ai/legal/subprocessors.

Test everything that matters

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Test everything that matters

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Test everything that matters

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.

Test everything that matters

Ensure your path to purchase works flawlessly.

Set up in 15 minutes, and let Shoptest do the rest.