Data Processing Agreement
This Agreement governs the processing of personal data by Fast COD Form (“Processor”) on behalf of the merchant who installs it (“Controller”). It takes effect when the merchant installs the App and remains in force for as long as the App is installed. It forms part of, and is subject to, the Shopify Partner Program Agreement.
| Processor | Moussa Seddik, Aïn Témouchent, Algeria — ademyaniceines@gmail.com |
|---|---|
| Controller | The merchant operating the Shopify store on which the App is installed |
1. Subject matter and duration
The Processor processes personal data solely to provide the cash-on-delivery order form and to create the resulting orders in the Controller’s Shopify store. Processing lasts for the duration of the installation, plus the retention periods set out in clause 5.
2. Categories of data and data subjects
| Data subjects | Shoppers who submit the order form on the Controller’s storefront |
|---|---|
| Categories | Full name; phone number; email address (optional); delivery address, wilaya and commune; order lines and amounts; IP address and browser user agent; tracking consent state |
| Special categories | None. The App never processes special-category data. |
3. Obligations of the Processor
- Process personal data only on documented instructions from the Controller, which installing and configuring the App constitutes.
- Never use the data for its own purposes, including marketing, analytics or profiling.
- Never sell, rent or otherwise disclose the data, except to Shopify and to the Controller.
- Ensure that anyone authorised to process the data is bound by confidentiality.
- Implement the technical and organisational measures set out in clause 6.
- Assist the Controller in responding to data-subject requests, including via Shopify’s
mandatory
customers/data_requestandcustomers/redactwebhooks. - Assist the Controller with security, breach notification and data protection impact assessments, taking into account the nature of the processing.
- Delete or return all personal data at the end of the service, as set out in clause 5.
- Make available the information necessary to demonstrate compliance and allow for audits (see clause 8).
4. Sub-processors
The Controller gives general authorisation for the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify Inc. | Platform; destination of created orders | Canada / global |
| Contabo GmbH | Server hosting | Germany |
| Cloudflare, Inc. | DNS and traffic protection | Global |
The Processor will give merchants prior notice of any new or replacement sub-processor that handles personal data, and the Controller may object.
5. Retention and deletion
| Data | Retention | Action |
|---|---|---|
| Submissions with no order created | 90 days | Permanent deletion |
| Submissions with an order created | 24 months | Anonymisation: name, phone, email and address erased |
| IP address and user agent | 30 days | Erasure |
| Access and action logs | 12 months | Deletion |
These rules are enforced by an automated nightly job. On shop/redact the
Processor deletes all personal data belonging to that shop.
6. Technical and organisational measures
- Encryption in transit: HTTPS/TLS 1.2 or above on all public endpoints; SSH key-only access for administration, password authentication disabled.
- Encrypted backups: daily backups encrypted with AES-256 and an RSA-4096 key whose private half is held off-server.
- Access control: least privilege, one account per person, an access register, and revocation on termination of any engagement.
- Logging: creations and reads of shopper data are recorded, with a 12-month retention.
- Monitoring: hourly automated integrity checks of server configuration, accounts, scheduled tasks, open ports and critical file checksums; brute-force protection on administrative access.
- Data minimisation: the App requests only the API scopes it uses and collects only the fields the Controller has enabled.
- Incident response: a written policy is in force, with severity levels and defined response times.
- Encryption at rest: every personal field (name, phone, email, address, IP address, user agent) is encrypted with AES-256-GCM before being written to disk and decrypted only in memory. The key is held in the server environment and included in the encrypted backups.
7. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach, and in any case within 72 hours, providing the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Shopify will be notified in parallel.
8. Audit
On reasonable written request, and no more than once per year unless required by a supervisory authority, the Processor will provide documentation of the measures in clause 6 and answer a security questionnaire. On-site audits may be arranged where legally required.
9. International transfers
Data is stored in Germany. The Processor is established in Algeria. Where personal data of individuals in the European Economic Area is transferred outside it, the parties rely on the European Commission’s Standard Contractual Clauses, which are incorporated into this Agreement by reference, with the Controller as data exporter and the Processor as data importer (Module Two: controller to processor).
10. Governing terms
Where this Agreement conflicts with the Shopify Partner Program Agreement or Shopify’s Protected Customer Data requirements, those take precedence.