Legal
Data Processing Agreement
Effective date: 4 August 2026 - Last updated: 5 August 2026
This agreement governs personal data that Aspedan Inc. processes on your behalf when you use Prime MOQ & Order Limits. It satisfies Article 28(3) of the GDPR and the equivalent provisions of the UK GDPR, and it is written to be read rather than to be survived.
Annex 1 sets out exactly what is processed and why. That is the part most procurement reviews go straight to, so it is on this page rather than in an attachment nobody can find. This page is laid out to print cleanly: use your browser's print or save-as-PDF command and the site chrome drops away.
1. Parties and how this is accepted
Processor: Aspedan Inc., 325 Front St West, Suite 300, Toronto, ON M5V 2Y1, Canada. Contact: support@primemoq.app.
Controller: the merchant operating the Shopify store on which the app is installed.
Acceptance. This agreement takes effect when you install the app, and no signature is required. It forms part of the Terms of Service and, on the subject of personal data, prevails over them. If your organisation requires a counter-signed copy on your own paper, write to us and we will sign it.
Duration. This agreement runs for as long as the app is installed and continues afterwards for as long as we hold personal data processed under it.
2. Definitions
"Personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Article 4 of the GDPR. "Applicable data protection law" means the GDPR, the UK GDPR, PIPEDA, the Act respecting the protection of personal information in the private sector (Quebec), the CCPA as amended by the CPRA, and any other privacy law applicable to the processing. "Standard Contractual Clauses" means the clauses annexed to Commission Implementing Decision (EU) 2021/914.
3. Roles
You are the controller of the personal data in your Shopify store. We are your processor for that data and we process it only on your documented instructions.
Your instructions are: the configuration you set in the app, your use of its features, the scopes you approved on install, and anything else you tell us in writing. We do not process your data for our own purposes, we do not sell or share it, and we do not use it to train models or to build any profile.
If we believe an instruction infringes applicable data protection law, we will tell you before acting on it, as Article 28(3) requires.
For the marketing website at primemoq.app we are a controller in our own right, not your processor. That processing is described in the privacy policy and is outside this agreement.
4. Scope, nature and purpose of the processing
The subject matter, duration, nature and purpose of the processing, and the categories of data subject and personal data, are set out in Annex 1. It is part of this agreement.
5. Our obligations as processor
Under Article 28(3) we:
- Process only on documented instructions, including for a transfer to a third country, unless required to do otherwise by law, in which case we tell you before processing unless that law forbids it.
- Bind everyone with access to confidentiality. Access is limited to the people who need it to operate or support the app, each under a confidentiality obligation.
- Implement the measures required by Article 32, described in Annex 2.
- Engage sub-processors only under section 6, and remain fully liable to you for their performance.
- Assist you with data subject requests, taking account of the nature of the processing, by appropriate technical and organisational measures. In practice Shopify's mandatory redaction webhooks give you a direct route, described in section 8.
- Assist you with Articles 32 to 36: security, breach notification to the supervisory authority and to data subjects, data protection impact assessments and prior consultation, taking into account the information available to us.
- Delete or return the data on termination, under section 10.
- Make available the information needed to demonstrate compliance and allow for audits, under section 11.
6. Sub-processors
You give us general authorisation to engage sub-processors. The current list is published at /subprocessors and forms part of this agreement.
Before adding or replacing a sub-processor we will update that page and notify you at least 14 days before the change takes effect. You may object on reasonable data protection grounds within those 14 days by writing to support@primemoq.app. If we cannot resolve your objection, you may terminate this agreement and uninstall the app without penalty, and we will delete your data under section 10.
Every sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their acts and omissions.
7. International transfers
We are established in Canada. Transfers of personal data from the EEA to a Canadian organisation subject to PIPEDA are covered by the European Commission's adequacy decision of 20 December 2001.
Where a sub-processor processes personal data outside the EEA or the UK in a country without an adequacy decision, the transfer is made under the Standard Contractual Clauses. Module Three (processor to processor) applies to transfers from us to a sub-processor, and Module Two (controller to processor) applies where you transfer to us as a processor and a safeguard is needed. For transfers out of the United Kingdom, the UK International Data Transfer Addendum (version B1.0) applies to those clauses.
Where the Clauses are incorporated: the optional docking clause applies; the supervisory authority is that of the member state in which you are established; the governing law of the Clauses is Irish law for EEA transfers and the law of England and Wales for UK transfers; Annex I and Annex II of the Clauses are populated by Annex 1 and Annex 2 of this agreement, and Annex III by the list at /subprocessors.
8. Data subject rights
You are responsible for responding to your customers. We assist you in two concrete ways rather than in the abstract:
- Shopify's mandatory webhooks. When Shopify sends us a
customers/data_request, we search the records we hold for that customer and email the result to your store's contact address, so you can meet your own 30 day deadline. When Shopify sends us acustomers/redact, we erase the customer personal data we hold that matches it. - Direct request. Write to support@primemoq.app and we will act on a documented instruction from you within 10 business days.
If a data subject contacts us directly about data we process for you, we will not respond on the substance. We will tell them to contact you and forward the request to you without undue delay.
Current limitation, stated plainly. A customers/redact instruction automatically erases the customer email address from the order records we hold. The customer identifiers we keep for rule targeting, segment membership and rule statistics are erased by us as a manual step, which we carry out within the same 10 business days. We are extending the automatic route to cover them, and this paragraph goes when it does.
9. Personal data breach
We notify you of a personal data breach affecting your data without undue delay, and in any event within 48 hours of becoming aware of it. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of that at once, we provide it in phases as it becomes available.
Notifying the supervisory authority under Article 33 and the data subjects under Article 34 is your decision as controller. We will give you the information you reasonably need to make it and to make it on time.
10. Deletion and return
On termination of this agreement, at your choice, we delete or return the personal data we process for you and delete existing copies, unless a law we are subject to requires us to keep it.
What happens on uninstall. Uninstalling stops all processing and deletes every stored session and access token for your store, so we lose access to it at that moment and a revoked Shopify token can never be reused.
Your configuration and records are not deleted at that moment. They are kept so that reinstalling restores your setup rather than starting you from an empty account. We do not use them for anything else, and no one outside the people who operate the app can reach them.
You can require deletion at any time, including immediately after uninstalling, by writing to support@primemoq.app. We complete it within 30 days of the request and confirm it in writing. We say deletion on request rather than deletion on a timer because that is the commitment we can honour today, and a period we could not honour would be a breach of this agreement rather than a reassurance.
11. Audits
On reasonable written notice of at least 30 days, and no more than once in any twelve month period, you may audit our compliance with this agreement, or appoint an independent auditor who is not a competitor of ours to do so. The restriction on frequency does not apply where you are required to audit by a supervisory authority, or following a personal data breach affecting your data.
An audit must be carried out during business hours, must not unreasonably disrupt our operations, and is subject to confidentiality. We will first offer the information we hold, including our security documentation and answers to a reasonable security questionnaire, and an on-site audit applies only where that is genuinely insufficient. Each party bears its own costs.
12. Liability
Each party's liability under this agreement is subject to the limitations and exclusions in section 12 of the Terms of Service, and the cap there is an aggregate cap across the Terms and this agreement rather than a separate one for each. Nothing in this section limits liability that cannot lawfully be limited, including a data subject's rights under Article 82 of the GDPR.
13. Governing law
This agreement is governed by the laws of the Province of Ontario and the federal laws of Canada applicable in it, and the courts of Toronto, Ontario have exclusive jurisdiction, except that where the Standard Contractual Clauses are incorporated under section 7, their own governing law and forum provisions apply to them.
Annex 1: details of processing
Subject matter and duration
Providing Prime MOQ & Order Limits: evaluating and enforcing the order limit rules a merchant configures, and reporting on them. Duration: for as long as the app is installed, plus the period described in section 10.
Nature and purpose
Collection, storage, structuring, retrieval, use and erasure of store data for the sole purpose of determining whether a cart satisfies the merchant's rules, of showing the merchant's own message when it does not, and of reporting on how often that happened.
Categories of data subject
- The merchant, and the staff who administer their Shopify store.
- Customers of the merchant's store, including signed-in shoppers.
Categories of personal data
| Category | Data | Why it is processed |
|---|---|---|
| Merchant contact details | Store owner name, email address and phone number as reported by Shopify; the address set for the weekly digest; shop name, myshopify domain and public domain | Operating the account, sending service email, and routing a customer data request back to the merchant |
| Store configuration | Country, timezone, currency, Shopify plan, primary locale, money format, granted scopes, and the Shopify access token | Making the app behave correctly for the store and authenticating to Shopify on its behalf |
| Customer identifiers for rule targeting | First name and last name, where a merchant scopes a rule to named customers; a Shopify customer identifier against the segments a shopper belongs to, so the app can evaluate a rule that targets a segment | Applying a rule to the customers the merchant chose |
| Order records | Shopify order ID and name, order totals, line items, and the customer email address on the order | Repurchase limits, and the blocked-order and valid-order counts a merchant sees |
| Storefront event records | Shopify customer ID of a signed-in shopper whose add-to-cart was blocked or who clicked the contact button, with the rule, product and quantity involved | The rule statistics on the merchant's dashboard |
No special categories of data under Article 9 are processed. No payment card data, postal address or telephone number of a customer is processed. No data of criminal convictions or offences is processed.
Frequency
Continuous while the app is installed: on each webhook Shopify sends, on each rule the merchant saves, on each cart evaluated at checkout, and on the scheduled jobs that synchronise segment membership and roll up statistics.
Retention
Every category above is retained while the app is installed and deleted under section 10, which sets one rule for all of them rather than a different period per row.
Sub-processors
As published at /subprocessors, which is Annex III for the purposes of the Standard Contractual Clauses.
Annex 2: technical and organisational measures
These are the measures in place today, described at the level a merchant needs to assess them. Where a measure a merchant might reasonably expect is not in place, this annex says so rather than listing it as a control.
In place
- Encryption in transit. TLS on the app admin, the backend API, the website and every call between them and Shopify.
- Encryption at rest. Provided by the hosting and database services the app runs on.
- Access token handling. Tokens are stored server side only, never exposed to a browser, and every stored session for a shop is deleted when the app is uninstalled.
- Request authentication. Admin requests carry a Shopify App Bridge session token, verified on every call. Storefront requests are accepted only through Shopify's app proxy and only after their signature is verified, so the customer identifier on them cannot be supplied by a client.
- Webhook verification. Every Shopify webhook is HMAC verified before it is acted on.
- Tenant isolation. Every record is keyed to a shop and every query is scoped to it. One store's rules and data are never visible to another.
- Least privilege in the browser. Client code holds only publishable credentials. Privileged database access exists only on the server.
- Row level security on the website database, with no policy granting anonymous read or write access.
- Cross site request forgery protection on server functions.
- Rate limiting on storefront endpoints, scoped per shop.
- Restricted administrative access. Limited to named accounts, granted on a least privilege basis, each under a confidentiality obligation.
- Audit logging. Administrative access to our infrastructure and the actions taken there are logged.
- Backups. Database backups are taken and held by us, and restoring from one is part of how we recover.
- Reproducible deployment. Production runs a versioned, traceable build, so what is live can always be tied back to the source it came from.
Not in place
- Automated deletion on a schedule. Deletion happens on request, under section 10, rather than on a timer. We would rather name the route we honour than publish a schedule we do not run.
- Third party certification. We hold no ISO 27001 or SOC 2 report and we do not claim one.
Questions
A person reads every message, on any plan. If something on this page is unclear, or you want to exercise a right described in it, write to us and say so plainly.