Shopify app
Data Processing Agreement (DPA)
Data Processing Agreement (DPA) — EU AI Label
Last updated: 28 July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between:
Controller (Merchant): The entity that installs and uses EU AI Label on its Shopify store or WordPress/WooCommerce site (“Merchant”, “you”).
Processor: Damian Klimarczyk MDGA, ul. Olecka 16/4, 60-458 Poznań, Poland, VAT PL7812019335 (“we”, “us”, “Processor”).
This DPA applies when we process personal data on your behalf in connection with the EU AI Label Service and supplements our Terms of Service and Privacy Policy.
1. Subject matter and duration
1.1. We process personal data solely to provide the EU AI Label app and related services you configure (label rendering, audit logs, Compliance Hub hosting, support).
1.2. Processing continues for the duration of your subscription/installation and until deletion under Section 9.
2. Nature and purpose of processing
| Activity | Purpose |
|---|---|
| Storing product/image IDs and label configuration | Render AI transparency labels on your storefront |
| Recording admin user IDs and timestamps | Audit trail for internal compliance workflows |
| Hosting Compliance Hub page content you configure | Publish deployer transparency information you provide |
| Backups and logs | Security, reliability, support |
We do not process your end-customers’ personal data through the core Shopify app workflow.
3. Types of personal data and categories of data subjects
Data subjects: Merchant staff (Shopify admin users whose IDs appear in audit logs); optionally individuals whose data you include in Compliance Hub text (your responsibility).
Personal data (where applicable): Shopify staff user identifiers; any personal data you voluntarily include in custom label text or Compliance Hub content; support correspondence.
Non-personal operational data (product IDs, image IDs, handles) is processed on your instructions as part of the Service.
4. Processor obligations (GDPR Art. 28)
We shall:
4.1. Process personal data only on documented instructions from you, as reflected in your use of the Service, these Terms, and this DPA, unless required by EU or member-state law (in which case we inform you unless prohibited).
4.2. Ensure persons authorised to process data are bound by confidentiality.
4.3. Implement appropriate technical and organisational measures (see Privacy Policy §11).
4.4. Respect conditions for engaging sub-processors (Section 6).
4.5. Assist you, considering the nature of processing, with:
- responding to data subject requests (Art. 15–22);
- security of processing (Art. 32);
- breach notification (Art. 33–34);
- data protection impact assessments and prior consultation (Art. 35–36), where applicable.
4.6. At your choice, delete or return personal data after end of services, subject to legal retention (Section 9).
4.7. Make available information necessary to demonstrate compliance and allow audits, subject to reasonable notice, confidentiality, and frequency limits (no more than once per year unless required by a supervisory authority).
5. Controller obligations
You shall:
5.1. Ensure a valid legal basis exists for any personal data you cause us to process.
5.2. Provide necessary privacy notices to your staff and customers.
5.3. Not instruct us to process data unlawfully.
5.4. Configure the Service responsibly and review Compliance Hub content before publication.
6. Sub-processors
6.1. You provide general written authorisation for us to engage sub-processors listed in our Privacy Policy §7.
6.2. We impose data-protection terms on sub-processors equivalent to this DPA.
6.3. We will notify you of new or materially changed sub-processors by both:
- updating the sub-processor list in our Privacy Policy §7; and
- sending active notice to the merchant contact email on file (and, where technically feasible, an in-app notification in the EU AI Label admin) at least 14 days before the new sub-processor begins processing personal data on your behalf.
Passive monitoring of the Privacy Policy alone is not required; the email and/or in-app notice is the operative notification for objection purposes. You may object on reasonable grounds relating to data protection within 14 days of the active notice. If we cannot accommodate the objection, you may terminate the affected Service without penalty for the remaining billing period.
6.4. Current key sub-processors: Shopify Inc., Supabase, Cloudflare, and others as listed in the Privacy Policy.
7. International transfers
Where personal data is transferred outside the EEA, we rely on:
- adequacy decisions;
- EU Standard Contractual Clauses (2021/914); and/or
- the EU–US Data Privacy Framework, where applicable.
Upon request, we provide SCC details for relevant sub-processors.
8. Personal data breaches
We will notify you without undue delay (and in any event within 72 hours of becoming aware) of a personal data breach affecting data we process on your behalf, providing:
- nature of the breach;
- categories and approximate number of records;
- likely consequences;
- measures taken or proposed.
You remain responsible for notifying supervisory authorities and data subjects where required as controller.
9. Deletion and return
Upon app uninstall or receipt of Shopify’s shop/redact webhook:
- we delete or anonymise personal data within 30 days, except data we must retain by law (e.g. tax books and records kept for 5 years counting from the end of the calendar year in which the tax payment deadline expired, as required by the Polish Tax Ordinance Act — Ordynacja podatkowa).
You may export audit logs before uninstall. We are not obliged to retain data after deletion except as required by law.
10. Liability
Liability under this DPA is subject to the limitations and indemnification provisions in our Terms of Service §§11–12, except where mandatory GDPR or national law provides otherwise.
11. Precedence
If there is a conflict between this DPA and the Terms regarding personal data processing, this DPA prevails. Otherwise, the Terms govern.
12. Contact
Privacy / DPA enquiries: privacy@euailabel.app
Damian Klimarczyk MDGA, ul. Olecka 16/4, 60-458 Poznań, Poland
By installing EU AI Label, business customers accept this DPA as incorporated into the Terms. A signed copy is available on request.