Data Processing Agreement

Last updated: 2026-08-05

1. Parties, Scope, and Incorporation

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Do The Proof (“we,” “us,” the “Processor”) and the merchant that installs the Do The Proof Shopify app (“you,” the “Controller”). It is incorporated into those Terms by reference and takes effect when you install the app. Where this DPA and the Terms conflict on the processing of personal data, this DPA prevails.

This DPA governs our processing of your customers’ personal data on your behalf. It does not govern your own account data (your store details, your email address, your billing plan), for which we are an independent controller as described in our Privacy Policy.

“GDPR” means Regulation (EU) 2016/679; “UK GDPR” means the GDPR as retained in United Kingdom law; “Data Protection Law” means either or both as applicable to the processing, together with any other privacy law that applies to it.

2. Details of the Processing

Subject matter and nature:
Assembling chargeback dispute evidence from your connected Shopify and Stripe accounts; generating draft rebuttal text; transmitting evidence you approve to your payment processor; and the storage, retrieval, and deletion those activities require.
Purpose:
The establishment, exercise, and defence of your legal claims arising from disputed transactions, being the service described in the Terms.
Duration:
The period the app is installed, plus the retention windows in the Privacy Policy (30-day post-uninstall grace for the account; at most 90 days after closure for each dispute record; immediate on a shop/redact instruction).
Categories of data subjects:
Your customers who are party to a disputed transaction, including their appearance in prior order history.
Categories of personal data:
Name; email address; billing and shipping addresses; order contents, amounts, and dates; fulfilment and tracking data; checkout IP address; refund records. No special categories of data are processed, and none may be submitted to the service.

3. Instructions

We process your customers’ personal data only on your documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law that applies to us, in which case we will inform you of that legal requirement before processing unless that law prohibits it. Your documented instructions are: the Terms, this DPA, your configuration and use of the app (including each submission you initiate), and the compliance webhooks Shopify sends on your behalf (customers/data_request, customers/redact, shop/redact).

We will inform you immediately if, in our opinion, an instruction infringes the GDPR, the UK GDPR, or other applicable data protection provisions.

4. Confidentiality

We ensure that every person we authorise to process your customers’ personal data is bound by a contractual or statutory duty of confidentiality. Operator access to production data is limited to the service operator.

5. Security

We implement the technical and organisational measures described in the Security Measures section of the Privacy Policy, including AES-256-GCM encryption of stored access credentials with the key held separately from the database, TLS 1.2 or higher in transit, provider-level encryption of storage and backups, redaction of personal data patterns before error telemetry, store-scoped access control, and separation of production and staging environments. Those measures take into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as required by Article 32. That section is the current statement of measures and is maintained as the system changes.

6. Sub-processors

You give general written authorisation for the sub-processors listed in the Sub-processors section of the Privacy Policy, which states each service and the data categories it receives.

  • Changes: We will notify you by email to your account address at least 14 days before adding or replacing a sub-processor that processes your customers’ personal data, and update the published list.
  • Objection: If you object on reasonable data-protection grounds within that 14-day window and we cannot offer an alternative, you may terminate by uninstalling the app before the change takes effect; the deletion and return rights in Section 9 then apply. Continued use after the change takes effect constitutes acceptance of that sub-processor.
  • Flow-down: We impose data-protection obligations on each sub-processor materially equivalent to those in this DPA, and we remain fully liable to you for each sub-processor’s performance.

7. Assistance

  • Data subject rights: Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in responding to data subject requests under Chapter III, including the Shopify webhook flows: access requests are logged on receipt, with the export compiled manually and delivered as described in the Privacy Policy, and erasure requests are executed as described in the Erasure section of the Privacy Policy, including the Article 17(3)(e) deferral while a claim is live.
  • Security, breach, and impact assessments: We assist you in ensuring compliance with Articles 32 to 36, taking into account the nature of the processing and the information available to us.
  • Personal data breach: We will notify you without undue delay after becoming aware of a personal data breach affecting your customers’ personal data, by email to your account address, with the information Article 33(3) requires to the extent it is available to us, supplemented as it becomes available.

8. International Transfers

We are located in the United States, and the sub-processors listed are primarily US services. Where Data Protection Law requires a transfer mechanism for personal data you make available to us from the European Economic Area, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference, with you as data exporter and us as data importer; Annex I is completed by Section 2 (details of processing) and the parties’ details in Sections 1 and 11; Annex II is completed by Section 5 (security); Annex III is the sub-processor list referenced in Section 6. For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) is incorporated by reference on the same basis, with its tables completed by the same sections. If the SCCs or the Addendum conflict with this DPA, they prevail.

9. Deletion and Return at End of Services

At the end of the services you elect deletion or return:

  • Return: Before or at uninstallation, you may request a copy of the customer personal data we hold for you by emailing hello@dotheproof.com; we compile and deliver it within 30 days.
  • Deletion (the default): Absent a return request, data is deleted on the schedule in the Privacy Policy: the 30-day post-uninstall grace period, then permanent deletion, or immediately upon a shop/redact instruction, which overrides the grace period and deletes all records including open disputes.
  • Copies: We delete existing copies unless storage is required by law that applies to us; backup copies age out on our database provider’s seven-day rolling backup cycle (backups are taken daily and retained for seven days). Evidence already submitted to Stripe or a card issuer at your instruction is in those parties’ systems and outside our control.

10. Information and Audit

We make available to you the information necessary to demonstrate compliance with the obligations of Article 28, including this DPA and the Privacy Policy’s named sub-processors, retention schedule, and security measures, and we answer reasonable written audit questionnaires within 30 days. We allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on at least 30 days’ written notice, at most once per 12-month period absent a supervisory authority requirement or a personal data breach, during business hours, without access to other merchants’ data, and at your cost.

11. Term, Precedence, and Contact

This DPA applies for as long as we process your customers’ personal data and survives termination of the Terms until that processing ends under Section 9. We may update this DPA under the same 14-day email-notice mechanism as the Terms; changes required by Data Protection Law or by a sub-processor change under Section 6 follow the notice mechanics of those provisions.

Data protection contact: hello@dotheproof.com