Data Processing Addendum
1. Parties and roles
This DPA is between the Shopify merchant using the App (the “Merchant”) and Genius Nutrition SRL (the “Provider”). For personal data processed through the App on the Merchant's documented instructions, the Merchant acts as controller or processor and the Provider acts as processor or subprocessor.
2. Processing details
- Subject matter and purpose: Shopify authentication, SGR product configuration, technical deposit handling, monthly reporting, support, security, and billing projection.
- Duration: while the App is installed, followed by the deletion and retention periods in the Privacy Policy.
- Data subjects: merchant owners, staff, collaborators, and buyers represented in Shopify order metadata.
- Data types: account contact and role data, shop and session identifiers, catalog data, order, edit, return, refund, and cancellation identifiers and quantities, configuration, subscription status, and operational logs. No special-category data is intended.
3. Documented instructions
The Provider processes personal data only to deliver the App under the Terms, this DPA, the merchant's in-product configuration, and lawful written instructions. The Provider will notify the Merchant if an instruction appears to violate applicable data protection law, unless prohibited from doing so.
4. Confidentiality and security
Authorized personnel are subject to confidentiality obligations. Measures include HTTPS, authenticated encryption of Shopify tokens at rest, HMAC validation for webhooks, least-privilege API scopes, access controls, environment-separated secrets, bounded operational retention, dependency review, and database backups provided by the hosting environment when configured.
5. Subprocessors
The Merchant authorizes the use of Shopify for platform and API services and Railway Corporation for application and database hosting. The Provider remains responsible for imposing appropriate data protection obligations on subprocessors. Material additions or replacements will be published through this page or another reasonable notice channel, allowing the Merchant to object on legitimate data protection grounds.
6. International transfers
The current production environment is hosted in the United States. Where Chapter V GDPR applies, the parties rely on an applicable adequacy mechanism or the European Commission's Standard Contractual Clauses, as incorporated by the relevant subprocessor agreement, together with supplementary measures where required.
7. Assistance
Taking into account the nature of processing, the Provider will reasonably assist the Merchant with data-subject requests, security obligations, breach notifications, impact assessments, and supervisory-authority consultations. Shopify's mandatory privacy webhooks are used for access and deletion workflows.
8. Personal data breaches
The Provider will notify the Merchant without undue delay after becoming aware of a personal data breach affecting Merchant data and will provide available information needed for the Merchant's legal assessment and notifications.
9. Return, deletion, and audit information
On termination, personal data is deleted under the Privacy Policy and Shopify's mandatory shop deletion process unless law requires retention. On reasonable request, the Provider will make available information necessary to demonstrate compliance and will support proportionate audits, subject to confidentiality, security, and cost safeguards.
10. Contact and precedence
Privacy and DPA requests: gdpr@obsedia.ai. If this DPA conflicts with the Terms on personal-data processing, this DPA prevails.