Legal
Data Processing Agreement
Effective date: 4 August 2026 - Last updated: 4 August 2026
This agreement governs personal data that Aspedan Inc. processes on your behalf when you use Prime MOQ & Order Limits. It satisfies Article 28(3) of the GDPR and the equivalent provisions of the UK GDPR, and it is written to be read rather than to be survived.
Annex 1 sets out exactly what is processed and why. That is the part most procurement reviews go straight to, so it is on this page rather than in an attachment nobody can find. This page is laid out to print cleanly: use your browser's print or save-as-PDF command and the site chrome drops away.
1. Parties and how this is accepted
Processor: Aspedan Inc., 325 Front St West, Suite 300, Toronto, ON M5V 2Y1, Canada. Contact: support@primemoq.app.
Controller: the merchant operating the Shopify store on which the app is installed.
Acceptance. This agreement takes effect when you install the app, and no signature is required. It forms part of the Terms of Service and, on the subject of personal data, prevails over them. If your organisation requires a counter-signed copy on your own paper, write to us and we will sign it.
Duration. This agreement runs for as long as the app is installed and continues afterwards for as long as we hold personal data processed under it.
2. Definitions
"Personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Article 4 of the GDPR. "Applicable data protection law" means the GDPR, the UK GDPR, PIPEDA, the Act respecting the protection of personal information in the private sector (Quebec), the CCPA as amended by the CPRA, and any other privacy law applicable to the processing. "Standard Contractual Clauses" means the clauses annexed to Commission Implementing Decision (EU) 2021/914.
3. Roles
You are the controller of the personal data in your Shopify store. We are your processor for that data and we process it only on your documented instructions.
Your instructions are: the configuration you set in the app, your use of its features, the scopes you approved on install, and anything else you tell us in writing. We do not process your data for our own purposes, we do not sell or share it, and we do not use it to train models or to build any profile.
If we believe an instruction infringes applicable data protection law, we will tell you before acting on it, as Article 28(3) requires.
For the marketing website at primemoq.app we are a controller in our own right, not your processor. That processing is described in the privacy policy and is outside this agreement.
4. Scope, nature and purpose of the processing
The subject matter, duration, nature and purpose of the processing, and the categories of data subject and personal data, are set out in Annex 1. It is part of this agreement.
5. Our obligations as processor
Under Article 28(3) we:
- Process only on documented instructions, including for a transfer to a third country, unless required to do otherwise by law, in which case we tell you before processing unless that law forbids it.
- Bind everyone with access to confidentiality. Access is limited to the people who need it to operate or support the app, each under a confidentiality obligation.
- Implement the measures required by Article 32, described in Annex 2.
- Engage sub-processors only under section 6, and remain fully liable to you for their performance.
- Assist you with data subject requests, taking account of the nature of the processing, by appropriate technical and organisational measures. In practice Shopify's mandatory redaction webhooks give you a direct route, described in section 8.
- Assist you with Articles 32 to 36: security, breach notification to the supervisory authority and to data subjects, data protection impact assessments and prior consultation, taking into account the information available to us.
- Delete or return the data on termination, under section 10.
- Make available the information needed to demonstrate compliance and allow for audits, under section 11.
6. Sub-processors
You give us general authorisation to engage sub-processors. The current list is published at /subprocessors and forms part of this agreement.
Before adding or replacing a sub-processor we will update that page and notify you at least 14 days before the change takes effect. You may object on reasonable data protection grounds within those 14 days by writing to support@primemoq.app. If we cannot resolve your objection, you may terminate this agreement and uninstall the app without penalty, and we will delete your data under section 10.
Every sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their acts and omissions.
7. International transfers
We are established in Canada. Transfers of personal data from the EEA to a Canadian organisation subject to PIPEDA are covered by the European Commission's adequacy decision of 20 December 2001.
Where a sub-processor processes personal data outside the EEA or the UK in a country without an adequacy decision, the transfer is made under the Standard Contractual Clauses. Module Three (processor to processor) applies to transfers from us to a sub-processor, and Module Two (controller to processor) applies where you transfer to us as a processor and a safeguard is needed. For transfers out of the United Kingdom, the UK International Data Transfer Addendum (version B1.0) applies to those clauses.
Where the Clauses are incorporated: the optional docking clause applies; the supervisory authority is that of the member state in which you are established; the governing law of the Clauses is Irish law for EEA transfers and the law of England and Wales for UK transfers; Annex I and Annex II of the Clauses are populated by Annex 1 and Annex 2 of this agreement, and Annex III by the list at /subprocessors.
8. Data subject rights
You are responsible for responding to your customers. We assist you in two concrete ways rather than in the abstract:
- Shopify's mandatory webhooks. When Shopify sends us a
customers/data_request, we search the records we hold for that customer and email the result to your store's contact address, so you can meet your own 30 day deadline. When Shopify sends us acustomers/redact, we erase the customer personal data we hold that matches it. - Direct request. Write to support@primemoq.app and we will act on a documented instruction from you within 10 business days.
If a data subject contacts us directly about data we process for you, we will not respond on the substance. We will tell them to contact you and forward the request to you without undue delay.
Current limitation, stated plainly. Our customers/redact handler today erases the customer email address from the order records we hold. It does not yet erase the Shopify customer identifiers held for rule targeting, segment synchronisation and blocked-attempt statistics. Until it does, a redaction instruction covering those requires a manual step on our side, which we will carry out on request within the same 10 business days. {{VERIFY: the date this handler is extended to cover RuleCustomer, CustomerSegmentSync and the two tracking collections, after which this paragraph should be deleted}}
9. Personal data breach
We notify you of a personal data breach affecting your data without undue delay, and in any event within 48 hours of becoming aware of it. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of that at once, we provide it in phases as it becomes available.
Notifying the supervisory authority under Article 33 and the data subjects under Article 34 is your decision as controller. We will give you the information you reasonably need to make it and to make it on time.
10. Deletion and return
On termination of this agreement, at your choice, we delete or return the personal data we process for you and delete existing copies, unless a law we are subject to requires us to keep it.
What actually happens on uninstall today. The uninstall webhook drains your queued jobs, marks the shop as uninstalled and deletes every stored session and access token for it, so a revoked Shopify token can never be reused. It does not yet delete your rule configuration, your shop record or the order records that reference it. Shopify sends a shop/redact request 48 hours after uninstall, and our handler for it is not yet implemented.
{{VERIFY: the deletion window this section commits to, once the shop/redact handler is implemented. The intended commitment is deletion within 30 days of uninstall, but this agreement must not state a period the code cannot honour. Do not ship this page to merchants with this placeholder unresolved}}
Until then, you can require deletion at any time by writing to support@primemoq.app, and we will confirm it in writing.
11. Audits
On reasonable written notice of at least 30 days, and no more than once in any twelve month period, you may audit our compliance with this agreement, or appoint an independent auditor who is not a competitor of ours to do so. The restriction on frequency does not apply where you are required to audit by a supervisory authority, or following a personal data breach affecting your data.
An audit must be carried out during business hours, must not unreasonably disrupt our operations, and is subject to confidentiality. We will first offer the information we hold, including our security documentation and answers to a reasonable security questionnaire, and an on-site audit applies only where that is genuinely insufficient. Each party bears its own costs.
12. Liability
Each party's liability under this agreement is subject to the limitations and exclusions in section 12 of the Terms of Service, and the cap there is an aggregate cap across the Terms and this agreement rather than a separate one for each. Nothing in this section limits liability that cannot lawfully be limited, including a data subject's rights under Article 82 of the GDPR.
13. Governing law
This agreement is governed by the laws of the Province of Ontario and the federal laws of Canada applicable in it, and the courts of Toronto, Ontario have exclusive jurisdiction, except that where the Standard Contractual Clauses are incorporated under section 7, their own governing law and forum provisions apply to them.
Annex 1: details of processing
Subject matter and duration
Providing Prime MOQ & Order Limits: evaluating and enforcing the order limit rules a merchant configures, and reporting on them. Duration: for as long as the app is installed, plus the deletion window in section 10.
Nature and purpose
Collection, storage, structuring, retrieval, use and erasure of store data for the sole purpose of determining whether a cart satisfies the merchant's rules, of showing the merchant's own message when it does not, and of reporting on how often that happened.
Categories of data subject
- The merchant, and the staff who administer their Shopify store.
- Customers of the merchant's store, including signed-in shoppers.
Categories of personal data
| Category | Data | Why it is processed |
|---|---|---|
| Merchant contact details | Store owner name, email address and phone number as reported by Shopify; the address set for the weekly digest; shop name, myshopify domain and public domain | Operating the account, sending service email, and routing a customer data request back to the merchant |
| Store configuration | Country, timezone, currency, Shopify plan, primary locale, money format, granted scopes, and the Shopify access token | Making the app behave correctly for the store and authenticating to Shopify on its behalf |
| Customer identifiers for rule targeting | Shopify customer ID, first name and last name, where a merchant scopes a rule to named customers; Shopify customer ID against segment IDs, so the checkout function can evaluate segment membership | Applying a rule to the customers the merchant chose |
| Order records | Shopify order ID and name, order totals, line items, and the customer email address on the order | Repurchase limits, and the blocked-order and valid-order counts a merchant sees |
| Storefront event records | Shopify customer ID of a signed-in shopper whose add-to-cart was blocked or who clicked the contact button, with the rule, product and quantity involved | The rule statistics on the merchant's dashboard |
No special categories of data under Article 9 are processed. No payment card data, postal address or telephone number of a customer is processed. No data of criminal convictions or offences is processed.
Frequency
Continuous while the app is installed: on each webhook Shopify sends, on each rule the merchant saves, on each cart evaluated at checkout, and on the scheduled jobs that synchronise segment membership and roll up statistics.
Retention
{{VERIFY: the retention period for each category above. See section 10. No period can be stated here until the shop/redact handler exists and a scheduled deletion is in place}}
Sub-processors
As published at /subprocessors, which is Annex III for the purposes of the Standard Contractual Clauses.
Annex 2: technical and organisational measures
These are the measures in place today. Where a measure that a merchant might reasonably expect is not yet in place, or we cannot confirm it from our own records, this annex says so rather than listing it as a control.
In place
- Encryption in transit. TLS on the app admin, the backend API, the website and every call between them and Shopify.
- Access token handling. Tokens are stored server side only, never exposed to a browser, and every stored session for a shop is deleted when the app is uninstalled.
- Request authentication. Admin requests carry a Shopify App Bridge session token, verified on every call. Storefront requests are accepted only through Shopify's app proxy and only after their signature is verified, so the customer identifier on them cannot be supplied by a client.
- Webhook verification. Every Shopify webhook is HMAC verified before it is acted on.
- Tenant isolation. Every record is keyed to a shop and every query is scoped to it. One store's rules and data are never visible to another.
- Least privilege in the browser. Client code holds only publishable credentials. Privileged database access exists only on the server.
- Row level security. Enabled on the website tables holding waitlist and support data, with no policy granting anonymous access.
- Cross site request forgery protection on server functions.
- Rate limiting on storefront endpoints, scoped per shop.
- Restricted administrative access. Two named accounts.
- Reproducible deployment. The backend is built and released from a versioned container image, so what runs in production is traceable to a commit.
Not yet confirmed or not yet in place
- {{VERIFY: encryption at rest on the PostgreSQL, MongoDB and Redis instances. Most managed database services enable it by default, but this is a self-managed host and it has not been confirmed}}
- {{VERIFY: whether multi-factor authentication is enforced on the hosting, container registry and database administration accounts}}
- {{VERIFY: the backup schedule, the backup retention period, whether backups are encrypted, and when a restore was last tested}}
- {{VERIFY: whether audit logging of administrative access exists, and how long those logs are kept}}
- Automated deletion. Not in place. There is no scheduled job that deletes or ages out data, and the
shop/redacthandler is a stub. See section 10. - Third party certification. We hold no ISO 27001 or SOC 2 report and we do not claim one.
Questions
A person reads every message, on any plan. If something on this page is unclear, or you want to exercise a right described in it, write to us and say so plainly.