Data Processing Addendum
Last updated: July 27, 2026
Parties, scope, and instructions
This DPA forms part of the Merchant Terms between the Shopify merchant as Controller and DIGIT DECK AGENCY S.A.S. as Processor. Digitdeck processes Customer Data only under the Terms, enabled-module configuration, support requests, documented merchant instructions, or applicable law.
Confidentiality, security, and subprocessors
Authorized personnel are bound by confidentiality and least privilege. Digitdeck maintains risk-appropriate safeguards described in the Security Policy. The Controller grants general authorization for the published subprocessors, which receive equivalent data-protection duties; Digitdeck remains responsible as required by law.
Rights, incidents, and deletion
Digitdeck reasonably assists with data-subject requests, impact assessments, and compliance. Confirmed Customer Data breaches are notified without undue delay with available impact and remediation information. At termination or valid instruction, data is returned or deleted unless law requires retention; Shopify redaction events control where applicable.
Transfers and audit
Applicable lawful transfer safeguards are used. Where required for EEA transfers, the unmodified European Commission SCCs, Module 2, apply. Digitdeck provides reasonable compliance evidence and permits a scoped annual audit under confidentiality when that evidence is insufficient.
Processing details
Processing covers the subscription term and limited deletion/legal periods; includes collection, storage, lookup, analysis, transmission, display, and deletion; concerns merchant staff, shoppers, customers, reviewers, subscribers, and referral participants; and is limited to the data categories described in the Privacy Policy. Sensitive data is not intended or authorized.