DATA PROCESSING AGREEMENT (DPA) — Public Shopify App

Version: 1.1

Effective date: the date the Merchant installs the App or starts using it (whichever occurs first).

This DPA forms part of the Provider's Terms of Service (the “Main Agreement”).

Provider / Data Processor

Juan Angel Garcia Rodenas, self-employed, NIF 44380284J, with business address in Arganda del Rey, Madrid, Spain (the “Provider” or “Processor”).

Privacy / GDPR contact: contacto@nextronics-es.com

Merchant / Data Controller

The natural or legal person that owns/operates the Shopify store that installs or uses the Nextronics Inventory Manager application (the “App”) (the “Merchant” or “Controller”).

For the purposes of this DPA, the Merchant is identified by its Shopify store domain (for example, xxxx.myshopify.com) and/or by the store identifier (shop_id) recorded in the Provider's systems.


1. Definitions

1.1. “Personal Data”, “Processing”, “Personal Data Breach”, “Data Subject”, “Controller” and “Processor” shall have the meaning set out in Regulation (EU) 2016/679 (the “GDPR”).

1.2. “Merchant Data” means the data (including Personal Data) that the Merchant uploads, exports, imports or processes using the App (including CSV/XLSX files).

1.3. “Subprocessor” means any third party engaged by the Provider to process Personal Data on behalf of the Merchant.

2. Purpose and scope

2.1. This DPA governs the Processing of Personal Data by the Provider as Processor on behalf of the Merchant as Controller, in connection with the provision of the App and related services.

2.2. Details of the Processing are described in Annex 1.

3. Merchant instructions

3.1. The Provider shall process Personal Data only on documented instructions from the Merchant, including instructions implied by the Merchant's use of the App and its configurations.

3.2. The Merchant is responsible for: (i) having a valid legal basis for the Processing, (ii) providing appropriate information to data subjects where required, and (iii) not including unnecessary data or special categories of data (Art. 9 GDPR), unless strictly necessary and lawful.

3.3. If the Provider considers that an instruction infringes the GDPR or other applicable law, it shall inform the Merchant without undue delay.

4. Confidentiality

4.1. The Provider shall ensure that persons authorized to process Personal Data are subject to a duty of confidentiality.

4.2. Access shall be limited to personnel strictly necessary on a “need-to-know” basis.

5. Security measures

5.1. The Provider shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR.

5.2. Minimum measures are described in Annex 2.

5.3. In particular, import/export files are stored temporarily in a database (PostgreSQL) in compressed format (ZIP) and, when enabled, encrypted at the application level (at-rest encryption) before being persisted.

5.4. The Provider may update such measures to improve security, provided that it does not materially reduce the level of protection.

6. Subprocessors

6.1. The Merchant authorizes the Provider to use Subprocessors to provide the service (e.g., VPS/hosting provider), in accordance with this DPA.

6.2. The Provider shall maintain a list of Subprocessors in Annex 3 (including location).

6.3. The Provider shall impose data protection obligations on Subprocessors equivalent to those in this DPA.

6.4. The Provider shall notify material changes to Subprocessors by email to the Merchant's contact address and/or via notice in the App, with reasonable advance notice where possible. The Merchant may object on reasonable grounds related to data protection.

7. Processing location and international transfers

7.1. Files and data are hosted on a VPS operated by OVHcloud in France (European Union / EEA).

7.2. In the current configuration, the Provider does not perform international transfers of Personal Data outside the EEA for the primary storage of files.

7.3. If in the future the Provider uses Subprocessors or locations outside the EEA, it shall ensure a valid legal basis (e.g., SCCs) and update the relevant Annexes.

8. Assistance to the Merchant

8.1. Taking into account the nature of the Processing, the Provider shall assist the Merchant in responding to data subject rights requests and in meeting obligations relating to security and impact assessments where applicable.

8.2. If the Provider receives a request from a data subject directly relating to Personal Data processed for the Merchant, it shall forward it to the Merchant without responding, unless legally required.

8.3. Where technically feasible, the Provider shall facilitate deletion of data associated with the store (e.g., deletion of uploaded files within the retention period).

9. Personal data breach notification

9.1. The Provider shall notify the Merchant without undue delay after becoming aware of a Personal Data Breach.

9.2. The notification shall include, where possible: the nature of the breach, approximate categories and volume, likely consequences, and measures taken or proposed.

10. Return and deletion of data

10.1. Upon termination of the services or at the Merchant's request, the Provider shall delete or return Personal Data, unless retention is required by law.

10.2. File retention (import/export): files uploaded by the Merchant are retained for a maximum of 7 days, with automatic deletion upon expiry of that period, unless the Merchant requests earlier deletion.

10.2 bis. Controlled download: import/export files are not exposed through direct access to the server file system. Downloads are provided through authenticated endpoints (e.g., session token) and/or signed links with expiration.

10.3. Uninstall: if the Merchant uninstalls the App, the Provider shall delete or anonymize data associated with the store (including files within retention) within a maximum of 30 days, unless legally required.

10.4. Backups: if backups exist, data will be deleted following the Provider's backup retention cycle and within a reasonable period, with no active access except for incident restoration.

11. Audits and information

11.1. The Provider shall make available to the Merchant information reasonably necessary to demonstrate compliance with this DPA.

11.2. The Merchant may request reasonable audits subject to: (i) at least 15 days' prior notice, (ii) a maximum frequency of once per year, (iii) confidentiality, and (iv) not compromising security or the rights of other customers.

11.3. Alternatively, the Provider may provide equivalent evidence (security questionnaires, policies, control evidence) where sufficient.

12. Liability

12.1. Liability shall be governed by the Main Agreement, to the extent permitted by applicable law.

12.2. Each party shall be responsible for its own GDPR breaches.

13. Governing law and jurisdiction

13.1. This DPA shall be governed by the laws of Spain, without prejudice to mandatory rules applicable to data protection.

13.2. The parties submit to the courts of Madrid (Spain), unless mandatory law provides otherwise.

14. Acceptance (click-wrap)

14.1. The Merchant accepts this DPA by installing or using the App, in accordance with the Main Agreement.

14.2. If the user installing/using the App does so on behalf of an entity, they represent that they have authority to accept this DPA on behalf of such entity.

14.3. The Provider may record acceptance evidence (date/time, Shopify store, DPA version) for compliance purposes.


ANNEX 1 — Processing details

A. Subject matter: provision of the App for importing/exporting data in Shopify (including inventory).

B. Duration: while the Merchant uses the App and during the defined retention periods.

C. Nature: file upload, temporary storage (in a database in ZIP format; at-rest encryption when enabled), reading/validation, transformation, import/export execution, result generation, error handling and technical traceability.

D. Purpose: enable the Merchant to import/export data and automate operational processes related to their Shopify store.

E. Categories of data subjects: Merchant customers, prospective customers, Merchant contacts/employees (if they appear in files).

F. Categories of personal data (possible): first name, last name, email, phone, shipping/billing addresses, customer/order identifiers and any other personal data included by the Merchant in files.

G. Special categories (Art. 9 GDPR): the App is not designed to process special categories; the Merchant should not include them.

H. Retention:

I. Location: VPS operated by OVHcloud in France (EU/EEA).

ANNEX 2 — Security measures (minimum)

The Provider applies, at minimum:

  1. HTTPS/TLS in transit.
  2. Role-based access control and least privilege.
  3. Logical separation by store (tenant isolation).
  4. Secret protection (tokens/keys) through a system credentials store and separation of non-sensitive configuration (avoiding secrets in plaintext in configuration files).
  5. Logs of critical actions and administrative access.
  6. VPS hardening (firewall, patching, closing ports).
  7. Backups with restricted access and retention policy.
  8. Incident response and notification procedure.
  9. Automatic deletion of files after 7 days.
  10. Storage of import/export files compressed (ZIP) and, when enabled, encrypted at rest before being persisted in the database.
  11. File downloads via authentication and/or expiring signed links.

ANNEX 3 — Subprocessors

  1. VPS/Hosting: OVHcloud — Location: France (EU/EEA) — Service: hosting/VPS.

ANNEX 4 — International transfers

Not currently applicable, as primary storage is performed in France (EU/EEA) with OVHcloud.


Last updated: 2026-02-23