Shopify app
Data Processing Agreement (DPA)
Data Processing Agreement (DPA) — EU AI Label (Shopify App)
Published at: https://euailabel.app/app-dpa
Last updated: 1 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between:
Controller (Merchant): The entity that installs and uses EU AI Label on its Shopify store (“Merchant”, “you”).
Processor: Damian Klimarczyk MDGA, ul. Olecka 16/4, 60-458 Poznań, Poland, VAT PL7812019335 (“we”, “us”, “Processor”).
This DPA applies when we process personal data on your behalf in connection with the EU AI Label Shopify app and supplements our Terms of Service / Merchant Agreement and App Privacy Policy.
By installing the app, business merchants accept this DPA as incorporated into the Terms. A signed copy is available on request at privacy@euailabel.com.
1. Subject matter and duration
1.1. We process personal data solely to provide the EU AI Label Shopify app and related services you configure (label rendering, audit logs, Compliance Hub hosting, support).
1.2. Processing continues for the duration of your installation/subscription and until deletion under Section 9.
2. Nature and purpose of processing
| Activity | Purpose |
|---|---|
| Storing product/image IDs and label configuration | Render AI transparency labels on your storefront |
| Recording admin user IDs and timestamps | Audit trail for internal compliance workflows |
| Hosting Compliance Hub page content you configure | Publish deployer transparency information you provide |
| Backups and logs | Security, reliability, support |
We do not process your end-customers’ personal data through the core Shopify app workflow.
3. Types of personal data and categories of data subjects
Data subjects: Merchant staff (Shopify admin users whose IDs appear in audit logs); optionally individuals whose data you include in Compliance Hub text (your responsibility).
Personal data (where applicable): Shopify staff user identifiers; merchant contact email; any personal data you voluntarily include in custom label text or Compliance Hub content; support correspondence.
Non-personal operational data (product IDs, image IDs, handles) is processed on your instructions as part of the Service.
4. Processor obligations (GDPR Art. 28)
We shall:
4.1. Process personal data only on documented instructions from you, as reflected in your use of the Service, the Terms, and this DPA, unless required by EU or member-state law (in which case we inform you unless prohibited).
4.2. Ensure persons authorised to process data are bound by confidentiality.
4.3. Implement appropriate technical and organisational measures (see App Privacy Policy §11).
4.4. Respect conditions for engaging sub-processors (Section 6).
4.5. Assist you, considering the nature of processing, with:
- responding to data subject requests (Art. 15–22);
- security of processing (Art. 32);
- breach notification (Art. 33–34);
- data protection impact assessments and prior consultation (Art. 35–36), where applicable.
4.6. At your choice, delete or return personal data after end of services, subject to legal retention (Section 9).
4.7. Make available information necessary to demonstrate compliance and allow audits, subject to reasonable notice, confidentiality, and frequency limits (no more than once per year unless required by a supervisory authority).
5. Controller obligations
You shall:
5.1. Ensure a valid legal basis exists for any personal data you cause us to process.
5.2. Provide necessary privacy notices to your staff and customers.
5.3. Not instruct us to process data unlawfully.
5.4. Configure the Service responsibly and review Compliance Hub content before publication.
6. Sub-processors
6.1. You provide general written authorisation for us to engage sub-processors listed in our App Privacy Policy §8 (Shopify app infrastructure: Shopify, Neon, Render).
6.2. We impose data-protection terms on sub-processors equivalent to this DPA.
6.3. We will notify you of new or materially changed sub-processors by both:
- updating the sub-processor list in the App Privacy Policy; and
- sending active notice to the merchant contact email on file (and, where technically feasible, an in-app notification) at least 14 days before the new sub-processor begins processing personal data on your behalf.
You may object on reasonable grounds relating to data protection within 14 days of the active notice. If we cannot accommodate the objection, you may terminate the affected Service without penalty for the remaining billing period.
6.4. Current sub-processors: Shopify Inc., Neon (database, EU/Frankfurt), Render (application hosting, EU/Frankfurt).
7. International transfers
Where personal data is transferred outside the EEA, we rely on adequacy decisions, EU Standard Contractual Clauses (2021/914), and/or the EU–US Data Privacy Framework, where applicable. Upon request, we provide SCC details for relevant sub-processors.
8. Personal data breaches
We will notify you without undue delay (and in any event within 72 hours of becoming aware) of a personal data breach affecting data we process on your behalf, providing the nature of the breach, categories and approximate number of records, likely consequences, and measures taken or proposed.
You remain responsible for notifying supervisory authorities and data subjects where required as controller.
9. Deletion and return
Upon app uninstall, an enforceable deletion request, or receipt of Shopify’s shop/redact compliance webhook (sent approximately 48 hours after uninstall):
- we delete or anonymise personal data within 30 days, except data we must retain by law (e.g. tax books and records kept for 5 years counting from the end of the calendar year in which the tax payment deadline expired, as required by the Polish Tax Ordinance Act — Ordynacja podatkowa).
This aligns with Shopify API Terms §6.2.3 and Shopify compliance webhook requirements.
You may export audit logs before uninstall.
10. Liability
Liability under this DPA is subject to the limitations and indemnification provisions in our Terms of Service §§11–12, except where mandatory GDPR or national law provides otherwise.
11. Precedence
If there is a conflict between this DPA and the Terms regarding personal data processing, this DPA prevails. Otherwise, the Terms govern.
12. Contact
Privacy / DPA enquiries: privacy@euailabel.com
Damian Klimarczyk MDGA, ul. Olecka 16/4, 60-458 Poznań, Poland
This DPA is provided for GDPR Art. 28 compliance. It does not constitute legal advice.