Data Processing Addendum

Last updated: August 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Sublyra ("Sublyra", "the App", "the Processor") and the merchant that installs the App ("Merchant", "the Controller"). It governs the processing of personal data by Sublyra on the Merchant's behalf and reflects the obligations of the EU/UK General Data Protection Regulation ("GDPR") for controller-to-processor relationships. Our Privacy Policy describes the same practices in plainer terms; if the two conflict on data protection, this DPA prevails.

1. Roles and scope

  • The Merchant is the data controller: the Merchant determines why and how store customer data is processed, and is responsible for having a lawful basis (including consent where required) for subscriptions and any marketing sent through the App or connected integrations.
  • Sublyra is the data processor: we process personal data only to provide the App's features, only on the Merchant's documented instructions (which include the Merchant's configuration of the App), and never for our own purposes such as advertising.
  • For Sublyra's own operational data about the Merchant (account contact, plan, billing), Sublyra acts as an independent controller.

Subject matter and duration: subscription management, dunning, retention, and analytics for the Merchant's Shopify store, for as long as the App is installed.

Categories of data subjects: the Merchant's store customers who hold or held a subscription created through the App.

Categories of personal data: customer name, email, and Shopify customer ID; subscription contract details (products, prices, billing intervals, status); order references and billing-attempt outcomes; cancellation-survey responses. We do not process payment card numbers — payment methods are tokenized and held by Shopify — and we do not intentionally process special-category data.

2. Processor obligations

Sublyra will:

  • Process personal data only on the Merchant's instructions and as needed to operate the App, unless law requires otherwise.
  • Ensure persons with access to personal data are bound by confidentiality.
  • Implement the security measures in Section 5.
  • Assist the Merchant with data-subject requests, primarily by honoring Shopify's mandatory compliance webhooks (Section 4), and notify the Merchant of any request received directly.
  • Notify the Merchant without undue delay after becoming aware of a personal-data breach affecting the Merchant's data, with the information reasonably needed for the Merchant to meet its own obligations.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA, and respond to reasonable written audit inquiries. On-site audits, where required, are at the Merchant's cost and on reasonable notice.

3. Subprocessors

The Merchant authorizes the following subprocessors. Some are engaged only when the Merchant connects the corresponding integration:

  • Shopify — commerce platform. Shopify processes customer and order data under its own terms with the Merchant; Sublyra reads and writes this data via Shopify's APIs and webhooks.
  • Hetzner — application and database hosting (VPS). All App data at rest is stored here.
  • Resend — transactional email delivery (dunning reminders, win-back messages, customer notifications).
  • Twilio — SMS delivery, only when the Merchant configures it with the Merchant's own credentials.
  • Klaviyo — marketing event sync, only when the Merchant connects it with the Merchant's own API key.
  • Mailchimp — marketing audience sync, only when the Merchant connects it with the Merchant's own API key.

When the Merchant connects Twilio, Klaviyo, or Mailchimp, data flows to that provider under the Merchant's own account and agreement with the provider. We will update this page when the list of core subprocessors changes; continued use of the App after notice constitutes consent to the updated list. The Merchant may object to a new core subprocessor on reasonable data-protection grounds by contacting us, and may uninstall the App if the objection cannot be resolved.

4. Retention and deletion

  • Personal data is retained while the App is installed and for no longer than needed to provide the service.
  • Uninstall: Shopify's shop/redact compliance request triggers deletion of the shop's data within 30 days. Order-derived financial aggregates may be retained in anonymized form where required for accounting.
  • Customer erasure (GDPR right to be forgotten): when Shopify forwards an erasure request via customers/redact, the customer's personal data is anonymized and any live subscription contracts are cancelled. Order totals are financial records and are kept in anonymized form.
  • Data-subject access: requests received via customers/data_request are exported and delivered to the Merchant's contact email, so the Merchant can fulfil its GDPR obligations.
  • On termination of the service, deletion follows the uninstall path above; no personal data is kept in identifiable form beyond that point.

5. Security measures

  • All traffic to and from the App is encrypted in transit over HTTPS/TLS.
  • Shopify webhook payloads are verified by HMAC signature before processing, so spoofed compliance or billing webhooks are rejected.
  • Third-party credentials the Merchant stores in the App (e.g. Twilio, Klaviyo, Mailchimp API keys) are encrypted at rest with AES-256-GCM and masked in the user interface.
  • Access to customer data is restricted to what each feature needs and is logged in an audit trail.
  • The application and database run on dedicated VPS infrastructure; administrative access is limited to authorized personnel.

6. International transfers

Data is processed where our infrastructure and subprocessors operate. Where personal data subject to the GDPR is transferred to a country without an adequacy decision, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses, or the subprocessor's own certified transfer mechanism) — contact us for details of the mechanism applicable to a given subprocessor.

7. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service, except where data-protection law provides otherwise. In case of conflict between this DPA and the Terms on the processing of personal data, this DPA prevails.

Contact

Data-protection questions, audit requests, or breach inquiries: support@sublyra.com