# 

# 

# 

# 

# 

# **Order Editing**

ORDER EDITING, LTD. **EIN 61-2125323**

# DATA PROCESSING

# AGREEMENT

**DATA PROCESSING AGREEMENT**

**PARTIES & EXECUTION**  
**A         PARTIES**  
**A.1 Processor or Company**

| Party name | Order Editing, Ltd. EIN 61-2125323 ("Processor" or "Company") |
| :---- | :---- |
| **Address** | 1111b South Governors Avenue Dover, DE 19904 US |
| **Contact** | Hamish McKay \- hamish@orderediting.com |

**A.2 Controller or Client**

| Party name |   |
| :---- | :---- |
| **Address** |  |
| **Contact** |  |

**B         EXECUTION**   
By signing below, the parties agree to the Particulars and the General Conditions set out in this Agreement.

**EXECUTED by ORDER EDITING, LTD.**                   
   
 

---

                                                                  **Date:**  
                                                                  **Name: Hamish McKay**  
                                                                  **Title: Co-founder**

**EXECUTED by** 

 

---

                                                                  **Date:**  
                                                                  **Name:**   
                                                                  **Title:** 

**INTRODUCTION:**  
This DPA shall apply to the extent that the Company Processes any Personal Data on behalf of the Client. The Company shall Process Personal Data solely for the purpose of providing order editing services as authorised by Shopify and requested by the Client's customers, and as further specified in Schedule 1 to this DPA.

**IMPORTANT CLARIFICATIONS:**
- The Company does NOT track users, resell data, or use Personal Data for any commercial purposes beyond providing the order editing service
- Customer contact information is transitory and only accessible during active order editing sessions
- No copies of customer information are retained outside of the specific order editing functionality
- The Client acknowledges that the Order Editing app is accessible to all users within the Client's Shopify organization, and the Client is responsible for managing internal access controls and user permissions
- The Client assumes all risks associated with providing access to Order Editing app to their employees, contractors, or third parties

1. **DEFINITIONS:**

1. In this DPA, the following terms shall have the following meanings: 

2. **"Business Day"** means any day which is not a Saturday, Sunday or public holiday in the United States.  
3. **"Data Protection Law"** means any applicable laws relating to the protection of personal data, including without limitation: (i) the EU General Data Protection Regulation 2016/679 ("GDPR"); (ii) the GDPR as it forms part of the law of England and Wales by virtue of the European Union (Withdrawal) Act 2018 ("UK GDPR"); (iii) the Data Protection Act 2018; (iv) the California Consumer Privacy Act ("CCPA"); (v) any other applicable data protection laws and mandatory regulations, all as may be amended or superseded from time to time.  
4. "**Restricted Transfer**" shall mean any transfer of Personal Data that would not be permitted, under the Data Protection Laws, without the Standard Contractual Clauses in accordance with this DPA;

5. "**Standard Contractual Clauses**" or "**SCC**" shall mean: (i) the the European Commission’s Implementing Decision (EU) 2021/914 of 4 June 2021 standard contractual clauses for the transfer of personal data to third countries pursuant to GDPR (the “**EU SCCs**”); and/or (ii) the UK’s International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner’s Office under S119A(1) of the Data Protection Act 2018 (“**UK IDTA**”).

6. **"Sub-processor"** means any processor engaged by the Company to process Personal Data on behalf of the Client.  
7. The terms **"Controller," "Data Subject," "Personal Data," "Personal Data Breach," "Processing," "Processor"** and **"Supervisory Authority"** shall have the meaning given under Data Protection Law.

2. **DATA PROTECTION:**

1. The parties agree that the Client is the Controller and the Company is the Processor of any Personal Data processed under this DPA.Each party shall comply with its obligations under Data Protection Law. 

2.  The Client warrants and represents that it has the authority, rights and consents necessary to enable the Company to Process the Personal Data in accordance with the Data Protection Law for the purposes of this DPA.

3. Without prejudice to clause 2.a., in respect of any Processing of Personal Data on behalf of the Client pursuant to the Agreement, the Company will: 

4. only Process the Personal Data on the documented instructions from the Client, unless required to do so by applicable law to which the Company is subject; in such case, the Company shall inform the Client of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. The Company shall immediately inform the Client in writing if, in its reasonable opinion, an instruction actually infringes Data Protection Law. The parties agree that the description of Processing at Schedule 1 of this DPA is an accurate description of the Processing undertaken in relation to the Services. The duration of this DPA corresponds to the duration of the Agreement. However, the termination of the Agreement will not relieve the parties of their respective obligations regarding confidentiality and protection of Personal Data as long as such Personal Data is processed, including stored, after such termination; 

5. taking into account the state of technical development and the nature of Processing, implement appropriate operational, managerial, physical, technical and organisational measures (TOMs) as set forth in Schedule 2 to protect the Personal Data against accidental or unlawful destruction, loss, alteration and unauthorised disclosure or access appropriate to the risk concerning confidentiality, integrity, availability and resilience of systems as required by Data Protection Law. The Company’s TOMs shall at all times ensure a strict logical separation between the Personal Data processed under the Agreement and this DPA, and the Company’s own data. The Company undertakes to maintain an appropriate process in order to regularly review and, if necessary, improve the effectiveness of the TOMs in order to ensure the adequate security of Personal Data on an ongoing basis. Changes to security measures are to be notified to the Client in text form (including e-mail); 

6. send the Client written notice within 24 hours of discovering any loss of or unauthorised access to Personal Data maintained by the Company or an approved Sub-processor ("Security Breach"). The notice must include a description of (i) the nature of the Security Breach; (ii) the likely consequences; and (iii) the measures taken or proposed to be taken to address the Security Breach. Where it is not possible for the Company to provide this information, this information may be provided in phases without undue further delay. The Company shall reasonably assist the Client in investigating, containing and remedying Security Breaches in relation to Personal Data; 

7. keep accurate written records of all processing activities of Personal Data. Upon written request, the Company provides these records to the Client (insofar as relating to the Personal Data that the Company processes on behalf of the Client in connection with the Agreement); 

8. upon reasonable notice, make available to the Client information necessary to demonstrate compliance with the obligations laid down in this DPA. The Client acknowledges that the Order Editing product is hosted by the Company’s hosting Sub-processors who maintain independently validated security programs. Further, at the Client’s written request, the Company will provide written responses (on a confidential basis) to all reasonable requests for information made by the Client necessary to confirm the Company’s compliance with this DPA, provided that the Client does not exercise this right more than once per calendar year unless the Client has reasonable grounds to suspect non-compliance with the DPA;

9. promptly inform the Client if the Company receives any request or complaint from a Supervisory Authority relating to the Personal Data.

3. **AUDITS:**

1. The Company permits only Shopify (not the Client directly) to inspect and audit the Company's processing operations and compliance with this DPA upon reasonable notice. The Company provides Shopify with reasonably necessary information on a confidential basis relating to the processing of Personal Data. No other party has audit rights under this DPA.

2. In the event of any finding resulting from Shopify audits, the Company will use commercially reasonable efforts to address legitimate security or compliance concerns. Any corrective actions shall be limited to technical and organizational measures within the Company's reasonable control and shall not exceed a total cost equal to three (3) months of fees paid by the Client to the Company under the Main Agreement in the 12 months preceding the audit finding. The Company reserves the right to implement alternative measures that achieve equivalent data protection outcomes.

3. The Company shall audit on a recurring basis its compliance and its Subcontractors’ compliance with this DPA, the Agreement and Data Protection Laws in regards to the processing of Personal Data. The previous paragraph applies mutatis mutandis to findings in such self-audits.  

4. If audits are carried out by a supervisory authority which relates to this DPA, the Company provides and ensures that its Sub-processors provide support in such audits. 

5. In relation to the Sub-processors, the Client may also exercise the audit rights under this section by instructing the Company to use its audit rights vis-a-vis the Sub-processor to the extent permitted by the Company’s contractual arrangement with its Sub-processors. The Client has the right to obtain from the Company a copy of the audit report. 

4.  **RIGHTS OF DATA SUBJECTS:**

1. The Company shall provide adequate assistance to the Client to carry out data protection impact assessments and to consult with supervisory or other competent authorities in relation with Personal Data, taking into account the nature of the Processing and the information available to the Company.  

2. The Company shall inform the Client without delay, as permitted under applicable law, (i) where a supervisory authority contacts the Company directly in relation with the processing of the Client’s Personal Data, and/or (ii) where the Client’s Personal Data is or is threatened to be affected by seizure, bankruptcy proceedings or a similar event. In that case, the Company shall inform any third party involved in such measures (including authorities) that the Client has control over the Personal Data. 

3. The Company shall disclose Personal Data to public authorities (including courts, administrative and law enforcement authorities) only with the prior written consent of the Client or where it is legally compelled to do so. If the Company is requested to make such disclosure, it shall inform the Client without undue delay, unless it is prohibited from doing so. The Company shall seek all remedies available against any such request, unless otherwise directed by the Client , and shall keep the Client informed of the progress thereof. 

5.  **SUB-PROCESSORS:**

1. The Client hereby authorises The Company to engage the following Sub-processors:

   **Core Infrastructure Sub-processors (Always Active):**
   
   *Sub-processors that may handle Customer Personal Data:*
   (a) Amazon Web Services (AWS) - hosting, data storage, queuing, and transactional email (SES)
   (b) Upstash - transient data processing only  
   (c) Radar (for address auto-completion)  
   (d) OpenAI (for localizations)  
   (e) Google Cloud (invoice generation)  
   (f) Vercel (Web hosting, developer logging, caching)  
   (g) Shopify (for invoice storage and data processing)
   (l) Cloudinary (for image processing and optimization)
   (m) Turnstile/Cloudflare (for bot protection and security)
   (n) Gleap (customer support messaging, help center, and feedback)
   (aj) Google (Gemini) (AI-assisted generation of merchant configuration text; no Customer Personal Data is included in prompts)
   (ak) Zendesk (customer support ticketing, where support workflows are enabled)
   (al) Intercom (merchant support messaging)
   (an) Tinybird (analytics event storage and processing; events may include order identifiers and address components such as city and postal code)

   *Sub-processors that only handle anonymized/non-PII data:*
   (h) Sentry (for anonymized error monitoring and application logging)
   (i) PostHog (for anonymized user analytics and behavior tracking)
   (j) ClickHouse (for anonymized analytics data storage and processing)
   (k) Vercel Analytics (for anonymized performance monitoring)
   (am) Axiom (system logging and observability; log output is scrubbed of email addresses and credentials before ingestion)

   **Optional Integration Sub-processors (Client-Controlled):**
   The following sub-processors are only engaged when the Client explicitly enables specific integrations within their Order Editing account. Data is only shared with these services when the Client has actively connected and configured the relevant integration:

   **Analytics & Marketing Integrations:**
   (o) Klaviyo (email marketing and customer analytics)
   (p) Attentive (SMS marketing and customer engagement)
   (q) Nosto (product recommendations and personalization)
   (ao) Postscript (SMS marketing and customer engagement)
   (ap) UpPromote (affiliate marketing attribution)
   (aq) Yotpo (loyalty and rewards)

   **Subscription Management Integrations:**
   (ar) Recharge (subscription management and address synchronisation)
   (as) Skio (subscription management and address synchronisation)

   **Fraud Detection & Security Integrations:**
   (r) Forter (fraud detection and prevention)
   (s) Signifyd (fraud detection and chargeback protection)
   (t) Kount (fraud detection and risk assessment)
   (u) NoFraud (fraud detection and prevention)
   (at) SEON (fraud detection and risk assessment)

   **Fulfillment & Shipping Integrations:**
   (v) ShipStation (shipping management and fulfillment)
   (w) ShipBob (fulfillment and logistics)
   (x) ShipHero (warehouse management and fulfillment)
   (y) Printful (print-on-demand fulfillment)
   (z) Shippit (shipping and delivery management)
   (aa) Starshippit (shipping automation and tracking)
   (ab) Fulfillrite (fulfillment services)
   (au) Mintsoft (warehouse management and fulfillment)
   (av) Swap Commerce (returns and cross-border shipping)
   (aw) Swish (wishlist and returns workflows)

   **E-commerce & Product Integrations:**
   (ac) Rebuy (product recommendations and upsells)
   (ad) Simple Bundles (product bundling)
   (ae) Shopify Bundles (native Shopify product bundling)
   (af) Shopify Combined Listings (inventory management)

   **Address & Tax Validation:**
   (ag) Avalara (tax calculation and compliance)
   (ah) Google Maps (address validation and geocoding)
   (ax) Experian (address validation and auto-completion)
   (ay) Postcode.eu (European address validation)
   (az) USPS (United States address validation)
   (ba) Maps.co (address geocoding)

   **Payment & Financial Services:**
   (ai) Shop Pay (Shopify's payment solution)

2. The Company shall be generally authorised by the Client to engage the Sub processors listed here subject to the Company notifying the Client of any intended changes concerning the addition or replacement of a Sub-processor by updating the webpage and providing the Client with a mechanism to subscribe to email notifications of such changes at least fifteen (15) days in advance of the change being made. The Client may object in writing to any such changes within ten (10) Business Days of receiving the email notification on reasonable grounds relating to data protection. If the Client does not raise an objection in accordance with this clause 5.II., the Client is deemed to have accepted the change and the Company may appoint the Sub-processor. 

6.  **LIABILITY AND INDEMNITY:**

1. Each party’s liability and indemnity obligations arising out of or related to this DPA, whether in contract, tort or otherwise, shall be limited to the total amount of fees paid by the Client to the Company under the Main Agreement in the 12 months preceding the event giving rise to the liability.

2. The Company shall not be liable for any claim brought by a Data Subject arising from any action or omission by the Company, to the extent that such action or omission resulted from instructions received from the Client.

3. The Client shall defend, indemnify and hold harmless the Company against claims, actions, proceedings, losses, damages, expenses and costs (including without limitation court costs and reasonable legal fees) arising out of or in connection with: (a) the Client's breach of this DPA or applicable Law; (b) unauthorized access by the Client's employees, contractors, or third parties; (c) the Client's failure to properly manage user access within their Shopify organization; or (d) any misuse of the Order Editing service by persons authorized by the Client.

4. **Data Access and Security Acknowledgments:** The Client acknowledges and assumes all risks related to:
   - Order Editing's reliance on Shopify's authentication and security systems
   - The accessibility of the Order Editing app to all users within the Client's Shopify organization
   - The Client's responsibility to manage internal access controls and user permissions
   - Potential exposure of customer data and analytical data (including sales metrics) to Client's employees and authorized users
   - Any security breaches in Shopify or other apps that may compromise customer authentication
   - Customer sharing of order information or authentication credentials with third parties

5. **Limited Liability for Organizational Access:** The Company is not liable for any consequences arising from the Client's organizational structure, employee access, internal security policies, or decisions regarding who has access to the Shopify store and Order Editing app. The Client is solely responsible for managing and monitoring access by their personnel.

6. **No Liability for Third-Party Platforms:** The Company is not liable for security breaches, data losses, or service interruptions caused by Shopify, other Shopify apps, or any third-party platforms or services outside the Company's direct control.

7.  **GENERAL:**

1. This DPA shall terminate upon the expiry or termination of the Agreement or, if earlier, the Company ceases to Process Personal Data on behalf of the Client.

2. Except as set out in this DPA, the Agreement shall continue in full force and effect.  

3. The parties to this DPA hereby submit to the choice of jurisdiction of Delaware, United States of America with respect to any disputes arising under this DPA, including disputes regarding its existence, validity or termination or the consequences of its nullity. 

4. This DPA is governed by the laws stipulated for this purpose in the Agreement. 

**SCHEDULE 1**

**Data Processing Instruction** 

**Purpose(s) of data Processing** 

The purpose of the data Processing is strictly limited to:
1. Providing self-service order editing functionality to the Client's customers
2. Facilitating order modifications and updates as requested by customers
3. Technical operation and security of the order editing service
4. Product improvement using anonymized, non-personal analytics data

The Company does NOT use Personal Data for:
- User tracking or behavioral profiling for commercial purposes
- Data resale or monetization
- Marketing to customers outside the scope of order editing functionality
- Any purpose beyond the specific order editing service contracted by the Client

**Period Personal Data will be retained and frequency (if that is not possible, the criteria used to determine that period)** 

**Important:** The Company does not retain Personal Data independently. Customer Personal Data is only accessed transiently through Shopify's API during order editing sessions. The only data retained by the Company consists of anonymized analytics and system logs as specified in the Data Storage and Security section.

Personal data is processed on a transient, as-needed basis when customers access the order editing functionality.

**Categories of data subjects** 

The Personal Data processed concern the following categories of Data Subjects:

1. Customers of the Client's Shopify store  
2. Potential customers of the Client's Shopify store  
3. Employees or representatives of the Client who use the Company’s services

**Categories of personal data** 

The Personal Data processed include the following types of data:

1. Order details (including but not limited to order number, date, items, quantities)  
2. Customer contact information (name, email address, phone number)  
3. Shipping address  
4. Billing information (excluding full payment card details)  
5. IP address  
6. Performance and usage data (anonymized page views, response times, error rates)
7. Behavioral analytics data (anonymized user interactions, feature usage patterns)
8. Error logs and debugging information (with PII redacted/anonymized)
9. Security event data (anonymized failed authentication attempts, suspicious activity patterns)
10. Image and media files uploaded by users
11. Any other Personal Data that the Client's customers choose to provide when using The Company's services

**Processing Operations**

The Company performs the following Processing operations on the Personal Data:

1. Reading order data from Shopify  
2. Presenting order data to customers with an authenticated order status url that is made available to the customer by Shopify over email and customer accounts  
3. Processing customer-requested order modifications  
4. Updating order data on Shopify  
5. Generating and storing logs for troubleshooting and security purposes  
6. Performing address verification using Radar  
7. Using OpenAI for localization of content  
8. Storing transient data on AWS and Upstash
9. Error monitoring and debugging (with PII anonymization)
10. User behavior analytics and product optimization (using anonymized data)
11. Performance monitoring and optimization (using anonymized metrics)
12. Security threat detection and prevention (using anonymized patterns)
13. Image processing and optimization
14. Data synchronization with Client-enabled third-party integrations
15. Fraud detection and prevention (when fraud detection integrations are enabled by Client)
16. Marketing automation and customer engagement (when marketing integrations are enabled by Client)
17. Fulfillment coordination and shipping management (when fulfillment integrations are enabled by Client)

**Special categories of data (if applicable)** 

**The Company** does not store special category Personal Data. Clients should not provide information that is considered special categories of Personal Data to the Company, including information about racial or ethnic origin, political opinions, religious beliefs, trade union membership, health data, genetic data, biometric data for the purpose of uniquely identifying a natural person, or sexual life or orientation. 

**Location of data processing** 

**Customer Data**: The Company does not store customer Personal Data independently. Customer data is only accessed via Shopify's API. Customer invoices are generated and saved to AWS S3 and Shopify servers on a transient basis.

**System and Analytics Data**: Anonymized analytics data is stored in ClickHouse databases. Anonymized error logs are stored by Sentry. Anonymized performance data is collected by Vercel Analytics. Non-PII system data is processed on AWS Americas and Upstash in the USA. Processed images are stored by Cloudinary. When Client-enabled integrations are active, relevant data may be processed in the geographic regions where those third-party services operate.

**Data Storage and Security** 

**Customer Data Access and Retention:**
The Company does NOT retain, mirror, or copy customer Personal Data. All customer data is accessed exclusively through Shopify's API on a real-time, transient basis. The Company only reads/writes from Shopify without saving a duplicate copy, hard copy, or clones of the original order. If an order is deleted on Shopify, the Company has no way of retrieving the full order details as no customer data is stored independently.

**Analytics and System Data Retention:**
All analytics, performance monitoring, and error logging data is anonymized and stripped of personally identifiable information (PII) before storage. Different types of non-customer data have specific retention periods:

- **Application logs**: Anonymized logs retained for 1 hour unless required for security/troubleshooting (maximum 30 days)
- **Error logs (Sentry)**: Anonymized error logs retained for 90 days for debugging purposes
- **Analytics data (PostHog/ClickHouse)**: Anonymized analytics data retained for 2 years for product optimization
- **Performance data (Vercel)**: Anonymized performance metrics retained for 1 year for performance monitoring
- **Processed images (Cloudinary)**: Retained until Client account termination
- **Integration data**: Retained according to each third-party service's retention policy only when integrations are enabled by Client
- **Fraud-prevention records**: De-identified normalized shipping-address tokens flagged as high-risk (following a payment dispute or risk assessment) are retained for up to 180 days for fraud prevention on the basis of legitimate interest (GDPR Art. 6(1)(f), Recital 47). These records carry no raw address, name, contact details, or customer/Client identifiers, and are excluded from per-customer erasure requests (GDPR Art. 17(3)) because erasing a flagged token on request would allow the fraud signal to be removed by the actor it protects against.

The Company implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

1. Encryption of Personal Data in transit and at rest using industry-standard encryption protocols and algorithms (e.g., TLS 1.2 or higher for data in transit, AES-256 for data at rest).  
2. Implementation of strong access controls, including multi-factor authentication for all staff accessing systems that process Personal Data.  
3. Regular security assessments and penetration testing of systems and applications.  
4. Implementation of least privilege access principles for all systems and data.  
5. Regular backup and disaster recovery testing to ensure the resilience of systems and data.  
6. Implementation of logging and monitoring systems to detect and alert on potential security incidents.  
7. Regular security awareness training for all staff.  
8. Physical security measures for all facilities where Personal Data is processed or stored.  
9. Secure development practices, including code reviews and vulnerability scanning.  
10. Patch management processes to ensure timely application of security updates.  
11. Network segmentation and firewalls to protect against unauthorised access.  
12. Incident response and management procedures to address potential security breaches promptly.

The Company shall review and update these security measures regularly to ensure they remain appropriate and effective.

**Deletion or Return of Personal Data**

The Company shall promptly and in any event within 30 days of the termination or expiry of the Main Agreement, delete and procure the deletion of all copies of the Client's Personal Data.

Subject to the immediately below clause, the Client may in its absolute discretion by written notice to the Company within 30 days of the termination or expiry of the Main Agreement require the Company to (a) return a complete copy of all Client Personal Data to the Client by secure file transfer in such format as is reasonably notified by the Client to the Company; and (b) delete and procure the deletion of all other copies of Client Personal Data Processed by the Company. The Company shall comply with any such written request within 30 days of receiving such written notice.

The Company may retain Client Personal Data to the extent required by applicable law and only to the extent and for such period as required by applicable law and always provided that the Company shall ensure the confidentiality of all such Client Personal Data and shall ensure that such Client Personal Data is only Processed as necessary for the purpose(s) specified in the applicable law requiring its storage and for no other purpose.

The Company shall provide written certification to the Client that it has fully complied with this Clause within 30 days of the date of deletion of all Client Personal Data.

**ADDITIONAL DEFINITIONS AND INTERPRETATIONS**

"**AWS**" means Amazon Web Services, a subsidiary of Amazon providing on-demand cloud computing platforms and APIs, which The Company uses for data storage and processing.

"**OpenAI**" means the artificial intelligence research laboratory consisting of the for-profit corporation OpenAI LP and its parent company, the non-profit OpenAI Inc., which The Company uses for localization services.

"**Radar**" means the online service used by Order Editing for address auto-completions.

"**Shopify**" means Shopify Inc. and its affiliated companies, through which the Client operates its e-commerce business.

"**Shopify** **App Store**" means the digital distribution platform for Shopify applications, where The Company's services are made available to Clients.

"**Upstash**" means the database service provider used by The Company for data storage and processing.

"**Sentry**" means the error monitoring and application performance monitoring service used by The Company for debugging and system reliability.

"**PostHog**" means the product analytics platform used by The Company for user behavior analysis and product optimization.

"**ClickHouse**" means the database management system used by The Company for analytics data storage and processing.

"**Cloudinary**" means the image and video management service used by The Company for media processing and optimization.

"**Turnstile/Cloudflare**" means Cloudflare's bot protection service used by The Company for security and spam prevention.

"**Client-Enabled Integrations**" means third-party services that the Client can optionally connect to their Order Editing account. Data is only processed by these services when the Client has explicitly enabled the integration and provided the necessary authentication credentials.
