Data Processing Addendum
This Data Processing Addendum (DPA) applies when ShopiDeck processes Klaviyo profile data for a merchant using ShopiDeck: Klaviyo Bot Cleaner. It supplements the Terms of Use and the Privacy Policy.
1. Object and roles
The merchant is the controller and ShopiDeck is the processor for personal data processed through the merchant's authorized Klaviyo account and documented instructions. This DPA describes the processing needed to provide the service, including profile auditing, scoring, results, merchant-confirmed suppression, audit history, and privacy-request assistance.
2. Duration
This DPA begins when the merchant accepts the Terms or uses the service and continues while ShopiDeck processes personal data for the merchant. It ends when that processing ends, subject to retention required by law, security, dispute, or the documented deletion flows.
3. Instructions
ShopiDeck processes personal data only on the merchant's documented instructions, the Terms, the Privacy Policy, and the configuration and actions the merchant takes in the app. The merchant must ensure that its instructions are lawful and that it has authority to connect Klaviyo and provide the data.
4. Categories of data
- Klaviyo Account ID, scopes, and encrypted OAuth access and refresh tokens.
- Profile ID, email, name, phone, city, country, IP when available, creation and update dates, email domain, and marketing subscription status.
- Normalized detection patterns, risk score, risk level, reasons, suppression results, audit history, and suppression history.
- Shopify store identifiers, session and account information, plan and usage information, support requests, and limited technical records needed for the service.
5. Categories of data subjects
- Customers and contacts represented by Klaviyo profiles.
- The merchant's owners, administrators, and authorized users.
- People whose information appears in support, privacy, security, or operational records.
6. Confidentiality
ShopiDeck will restrict access to personal data to people and providers who need it to provide, secure, support, or comply with the service and who are subject to confidentiality obligations or an appropriate legal duty.
7. Security
ShopiDeck applies the technical and organizational measures described in the Privacy Policy, including encrypted Klaviyo tokens, HTTPS, server-side secrets, authenticated routes, webhook verification, backend validation, ownership checks, merchant confirmation before suppression, backend limits, and encrypted privacy requests. No measure guarantees absolute security.
8. Subprocessors
The merchant authorizes the subprocessors listed on the public subprocessor page: Shopify, Klaviyo, Supabase, Vercel, and Resend. ShopiDeck will use them only for the purposes described there and will keep the list current when the service changes.
9. International transfers
Processing may occur in the United States and other countries where the listed providers operate. Supabase uses the US East region and Vercel processes in the United States. ShopiDeck uses provider contracts and safeguards when applicable. The merchant may request additional information about transfer safeguards at team@shopideck.com.
10. Assistance with rights
ShopiDeck assists the merchant with documented privacy requests received through Shopify and with the implemented customer data-request and redaction webhooks. The merchant remains responsible for responding to its customers and deciding whether a request is valid and how it should be fulfilled.
11. Incidents
ShopiDeck investigates suspected security incidents and notifies the merchant when required by law or appropriate to the relevant incident. The merchant must promptly report compromised credentials or suspected unauthorized access to team@shopideck.com and must not send secrets by email.
12. Audits and information
ShopiDeck will make the information in the Privacy Policy, this DPA, and the public subprocessor list available to help the merchant assess the processing. Any additional audit or information request must be proportionate to the service, protect confidential information, and be sent to team@shopideck.com.
13. Deletion or return
When the merchant disconnects Klaviyo, the OAuth tokens and connection are removed while retained history may remain. On uninstall, account deletion, and shop/redact, ShopiDeck follows the implemented deletion flows. Local records are removed according to the retention periods and flows in the Privacy Policy. Shopify and Klaviyo may retain data independently.
14. Merchant obligations
- Maintain a lawful basis and appropriate notices for customer data.
- Give lawful and documented instructions.
- Have authority over the Shopify and Klaviyo accounts.
- Review and confirm suppressions.
- Respond to data-subject requests and complaints as controller.
- Do not send sensitive data, credentials, API keys, or passwords through the service or support channels inappropriately.
15. Technical and organizational measures
The service's measures include access control through Shopify authentication, protected routes, encrypted OAuth tokens, HTTPS, server-side secret handling, webhook verification, backend validation, ownership verification for critical actions, backend usage limits, suppression confirmation, and encrypted privacy-request exports. These measures may be updated as the service evolves without reducing the obligations of the parties under applicable law.
16. Contact
For this DPA, contact team@shopideck.com or write to Cra. 79A # 6-04, Bogotá D.C., Colombia.
