GDPR Article 28 Compliance
Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") governs the processing of personal data by Woonic on behalf of Shopify merchants under the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
1. Scope and Roles of the Parties
For the purposes of the GDPR (Regulation (EU) 2016/679) and applicable data protection legislation:
- Merchant as Data Controller: The merchant operates as the Data Controller with respect to customer personal data contained within their Shopify store account.
- Woonic as Data Processor: Woonic acts as a Data Processor, processing store and customer data solely on documented instructions from the Merchant to execute backup, restoration, diffing, and staging operations.
2. Processor Obligations (GDPR Art. 28(3))
Woonic warrants and undertakes that it shall:
- Process personal data strictly in accordance with documented instructions from the Merchant and platform webhook triggers from Shopify Inc.
- Ensure all engineering personnel authorized to process personal data have committed themselves to strict confidentiality agreements.
- Implement technical and organizational security measures pursuant to GDPR Article 32, including AES-256 cloud encryption and TLS 1.3 transit encryption.
- Assist the Controller in fulfilling Data Subject Rights requests, including processing mandatory Shopify GDPR webhooks (
customers/data_requestandcustomers/redact). - Permanently delete or return all personal data upon termination of the Service within 30 business days pursuant to our data retention schedule.
3. Authorized Sub-Processors
The Controller authorizes Woonic to engage the third-party infrastructure providers listed in our Security Whitepaper (including Amazon Web Services S3 for encrypted storage) subject to equivalent data protection standards.
4. Contact & Inquiries
For DPA signature requests, GDPR compliance questions, or Data Protection Officer inquiries, email info.woonic@gmail.com.