C Capyo
nl

Data Processing Agreement

Last updated: 2026-09-05

These are the processor terms required by Article 28(3) GDPR. They form part of the Terms of Service and take effect when you install the app — you do not need to sign or return anything. If your organisation requires a countersigned copy, email gimbernat13@gmail.com and we will provide one.

1. The parties

Controller: you, the merchant that installed the app.
Processor: EU Guarantee Label, operated by an individual developer.

Operator legal name and address: see the Privacy Policy.

Shopify is a separate processor for you, under Shopify's own data processing addendum, which governs the Shopify-to-merchant relationship and is unaffected by this document. All personal data we process reaches us through Shopify.

2. Subject matter, duration, nature and purpose

3. Types of personal data

Most of what the app stores is store configuration rather than personal data. Where it is personal data, it is business-contact and account data about you and your staff:

Excluded by design: no customer personal data, no orders, no carts or checkouts, no payment data, no theme code. The app requests no Shopify scope that would give it access to any of these.

4. Categories of data subjects

The merchant and the merchant's staff and collaborators who use the app. Not the merchant's customers, and not storefront visitors: the storefront components set no cookies, load no external scripts and make no third-party requests.

5. Your instructions

We process personal data only on your documented instructions. Installing the app, configuring it and using its features are those instructions; the Privacy Policy describes their scope. Further or different instructions can be sent to gimbernat13@gmail.com; if one would require disproportionate effort or a change to the service, we will say so rather than silently not do it.

If EU or member-state law obliges us to process beyond your instructions, we will tell you before doing so, unless that law forbids telling you. If we believe an instruction infringes the GDPR, we will inform you.

6. Confidentiality

Access is limited to the operator, who is bound by a duty of confidentiality that survives the end of this agreement. There are no other staff. Should that change, anyone given access will be bound by an equivalent written obligation before receiving it.

7. Security measures (Art. 32)

We hold no ISO 27001 or SOC 2 certification and do not claim application-level encryption at rest beyond what the hosting providers apply to their own storage.

8. Sub-processors

You give general authorisation for the sub-processors below.

Sub-processorCompany countryPurposeWhere the servers are
Shopify International Ltd Ireland Platform, source of all data, and billing Per Shopify's own DPA
Hostinger International Ltd Cyprus Application hosting (virtual server) Boston, Massachusetts, United States
netcup GmbH Germany Database hosting (PostgreSQL) Manassas, Virginia, United States
GitHub, Inc. United States Hosting of this public website only; no app data reaches it GitHub Pages infrastructure

Changes. Before a new sub-processor starts processing, a listed one is replaced, or a hosting location moves, we update this table with a new date at the top of the page and announce the change on the changelog page. You may object on reasonable data-protection grounds by writing to gimbernat13@gmail.com; if we cannot accommodate the objection, you may uninstall the app and stop paying, with a pro-rata refund of any prepaid period through Shopify.

Each sub-processor is bound by data-protection obligations at least equivalent to these terms. We remain fully liable to you for their performance.

9. International transfers (GDPR Chapter V)

Merchant data processed through the app is stored on servers located in the United States: the application server in Boston, Massachusetts and the PostgreSQL database in Manassas, Virginia. The companies operating them are European (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing takes place outside the EEA.

Those transfers rely on the Standard Contractual Clauses included in the providers' data processing terms, together with the providers' technical and organisational security commitments and the measures in section 7.

The app stores no end-customer personal data, so no consumer data is transferred. The transferred data is the store configuration, scan findings, generated reports, usage events and access tokens described in section 3.

Hosting locations may change, including a move to an EU region. Any such change is announced on the changelog page before it takes effect, under the notice rule in section 8. Shopify's own transfers are governed by its DPA and transfer mechanisms.

10. Assistance to you

11. Deletion at the end of the agreement

Sessions are deleted immediately on the app/uninstalled webhook. All remaining data about your shop — store record, scan runs and findings, generated reports, usage events — is deleted when Shopify sends the shop/redact webhook, dispatched 48 hours after uninstall, or earlier if you ask us in writing. Server logs age out within 30 days. Nothing is retained afterwards except where EU or member-state law requires it; there is no backup copy kept for our own purposes.

Guarantee durations are metafields on your own Shopify store and are unaffected by uninstalling: they stay with your products, under your control.

12. Audit

On written request we provide the information needed to demonstrate compliance with Article 28 — the current sub-processor list, the security measures in section 7, the data model, and answers to a reasonable security questionnaire — once per twelve months, or more often after a breach affecting your data or where a supervisory authority requires it. Because the service is small and single-tenant per shop, we do not host on-site audits; where a controller's law requires an inspection, we will agree a proportionate remote alternative in good faith.

13. Order of precedence

Where this document conflicts with the Terms of Service on a matter of personal-data processing, this document wins. The GDPR wins over both.

14. Contact

gimbernat13@gmail.com. See also the Privacy Policy and the Terms of Service.