Data Processing Addendum
Our processor obligations when we handle personal information on behalf of a business customer or a merchant.
Who needs to read thisBusiness customers and merchants. If you are an individual using one of our apps, the document that covers you is the Privacy Policy, not this one.
Section 1When this addendum applies
This Data Processing Addendum applies automatically, and forms part of the Terms of Service, whenever Native Code LLC processes personal data on your behalf. That happens when:
- we build or operate software that holds personal data about your customers or your staff;
- you install one of our applications on your Shopify store;
- you subscribe to software we host, and put personal data into it.
You do not have to ask us to sign something for these terms to bind us. They are in force from the moment we start processing. If your own procurement process needs a signed copy on your paper, see Section 18.
Section 2What the words mean
- Personal data
- Any information relating to an identified or identifiable person. Same meaning as in the GDPR, and read to include "personal information" as United States state laws define it.
- Controller
- Whoever decides why and how personal data is processed. In this addendum, that is you.
- Processor
- Whoever processes it on the controller’s behalf. That is us.
- Subprocessor
- Anyone we bring in who processes the data as part of delivering our service to you.
- Data protection law
- The GDPR, the UK GDPR, United States state privacy laws, and any other law about personal data that applies to either of us.
Section 3Who is the controller and who is the processor
You are the controller of the personal data you put into our software or ask us to handle. We are your processor for it. You are responsible for having a lawful basis to collect it and to give it to us, and for the notices you give the people it is about.
Separately, we are the controller of our own business records about you: your account, your billing details, and the messages you send us. Those are covered by our Privacy Policy, not by this addendum. The two do not overlap, and we do not mix the data.
Section 4We only act on your instructions
We process your personal data only:
- to provide the service you are paying for, as described in our agreement;
- on your further documented instructions, including instructions given through the software itself;
- where a law we are subject to requires it, in which case we will tell you first unless that law forbids it.
Specifically, we will not:
- sell your personal data, or share it for cross context behavioral advertising;
- use it for our own purposes, including product analytics or marketing;
- use it to train machine learning models, ours or anybody else’s;
- combine it with personal data from another customer or from another source.
If we believe an instruction from you breaches data protection law, we will tell you and may pause that processing until it is resolved.
Section 5What we process, and for how long
The specifics depend on the software, so this is the frame rather than the detail. Your order or project scope fills in the rest.
| Item | Typically |
|---|---|
| Subject matter | Providing, hosting and supporting the software described in our agreement |
| Duration | For as long as the agreement lasts, plus the deletion window in Section 14 |
| Nature and purpose | Storage, retrieval, display, transmission, backup, and any processing the software’s own features perform |
| Types of personal data | Contact details, account credentials, and whatever else you choose to put into the software |
| Categories of data subject | Your customers, your staff, and anyone else whose data you enter |
| Special category data | Not expected. Tell us in advance if your use involves it, because it changes what we have to put in place |
Section 6The people who touch it
Access is limited to the people who need it to deliver the service. Everyone with access is bound by a duty of confidentiality that survives the end of their engagement with us, and access is removed the day it is no longer needed.
Section 7Security measures
We keep appropriate technical and organizational measures in place, taking account of the state of the art, the cost, and the risk to the people the data is about. In practice: encryption in transit and at rest, least privilege access with multi factor authentication, isolation between customers enforced at the database, secrets kept out of source code, automated checks that block a bad deploy, and tested backups.
The Security page describes all of this in full and is incorporated into this addendum by reference. We may improve these measures at any time, and we will not reduce the overall level of protection during your agreement.
Section 8Subprocessors
You give us general authorisation to use subprocessors. The current list, with what each one does and where it runs, is at Subprocessors.
- Every subprocessor is under a written contract imposing obligations no weaker than these.
- We stay fully liable to you for what our subprocessors do.
- Before adding one that will process your personal data, we give at least 30 days' notice by email.
- You may object on reasonable data protection grounds within that window. If we cannot resolve the objection, you may terminate the affected service without penalty and receive a refund of the unused prepaid period.
Section 9Helping you answer a data subject
If somebody exercises a right against you, the tools in the software are the fastest route: you can find, export, correct and delete records yourself, without waiting for us.
If a request reaches us instead of you, we will not respond to it substantively. We will tell the person to contact you, and pass the request to you without undue delay. Where you need help we cannot provide through the software, we will assist, at no charge for a reasonable volume of requests.
Section 10Telling you about a breach
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 48 hours of becoming aware. We give ourselves a tighter deadline than the 72 hours the law gives you, because you cannot meet your own deadline if we use all of yours first.
The notice will include what we know at the time: what happened, which categories and roughly how many records are involved, the likely consequences, and what we are doing about it. If we do not have the full picture yet we will send what we have and follow up, rather than waiting.
We will help you meet your own notification duties, and we will not make a public statement identifying you without your agreement unless the law requires it.
Section 11Impact assessments and prior consultation
If you have to carry out a data protection impact assessment, or consult a supervisory authority beforehand, we will give you the information about our processing that you reasonably need. Ask through the contact form.
Section 12Audits and evidence
We will make available the information needed to show we are meeting these obligations, and will contribute to audits carried out by you or an auditor you appoint.
In the first instance we will answer a security questionnaire and provide documentation. Where that is genuinely not enough, you may audit us on 30 days' written notice, no more than once a year unless a regulator requires otherwise or we have had a breach. An audit must happen in business hours, must not unreasonably disrupt us, and is at your cost. The auditor must not be a competitor of ours and must sign a confidentiality agreement.
Section 13International transfers
We are in the United States and we process there. Where you transfer personal data covered by United Kingdom or European law to us, the transfer relies on the European Commission’s Standard Contractual Clauses, module two, controller to processor, which are incorporated into this addendum by reference and completed as follows: you are the data exporter and Native Code LLC is the data importer; the option for general subprocessor authorisation applies with the 30 day notice in Section 8; the governing law and forum clauses are completed with Ireland unless your establishment requires another member state; and the annexes are populated by Sections 5, 7 and 8 of this addendum together with the Subprocessors page.
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies. For transfers from Switzerland, references are read as referring to the Swiss Federal Act on Data Protection and to the Federal Data Protection and Information Commissioner.
We have carried out a transfer risk assessment and apply encryption in transit and at rest as a supplementary measure. If we receive a government request for your data, we will challenge it where there are grounds to, disclose only the minimum required, and tell you unless we are legally prohibited from doing so.
Section 14What happens when we stop working together
When the agreement ends, you choose whether we return your personal data or delete it.
- Your data stays available for you to export for 30 days after the agreement ends.
- After that we delete it from live systems, unless you have told us to return it first.
- Backups containing it roll over and are cleared within 35 days of deletion.
- We keep only what a law requires us to keep, and it stays subject to these obligations for as long as we hold it.
We will confirm the deletion in writing if you ask.
Section 15Merchants on Shopify
Shopify applies its own requirements to any app that touches protected customer data, and we meet them. In practice that means:
- we request the minimum data scopes the app needs, and we explain why each one is needed;
- we implement Shopify’s mandatory compliance webhooks, so a customer data request, a customer redaction or a shop redaction sent by Shopify is actioned automatically;
- we respond to a merchant’s or a customer’s data request within 30 days;
- we encrypt protected customer data in transit and at rest, and we do not retain it longer than the app’s function requires;
- uninstalling the app triggers deletion of the store’s data on the schedule in Section 14.
Shopify itself is a subprocessor for these purposes and appears on the Subprocessors list.
Section 16California and other United States laws
For the California Consumer Privacy Act as amended, Native Code LLC is a service provider, and equivalent terms apply where other state laws use "processor". We certify that we:
- do not sell or share personal information, and receive none of it as consideration;
- do not retain, use or disclose it for any purpose other than performing the service, and never for a commercial purpose of our own;
- do not combine it with personal information from another source, except as the law permits;
- will notify you if we determine we can no longer meet these obligations;
- grant you the right to take reasonable steps to stop and remediate unauthorised use.
Section 17Liability and precedence
Liability under this addendum is subject to the limits in the Terms of Service, except where data protection law does not permit that.
Where this addendum conflicts with the Terms of Service, this addendum wins for matters of data protection. Where it conflicts with the Standard Contractual Clauses, the Clauses win.
Section 18How to put this in place
These terms already bind us, so for most customers there is nothing to do. If your procurement or compliance process needs a countersigned copy, or needs this on your own template, ask through the contact form and we will handle it. We will not make you chase us for it.