Data Processing Agreement
This agreement is part of the Terms of Service of the app. It applies from the moment you install the app and governs the personal data we process for you under Article 28(3) of the GDPR. The English text is the binding one. A German translation is provided for convenience.
We change this agreement only after telling you at least 30 days before. If you do not agree, you can end it by uninstalling the app before the change applies. If your business needs a signed copy, write to support@larchline.co and we send one.
How we tell you. Where this agreement says we tell you something, you get the same notice in two places. The app shows it on every page until you mark it read. It stops showing 30 days after the change takes effect, or 60 days after we post it when it names no date. We also send it by email to the address Shopify holds for your store, when Shopify gives us one. The sender is noreply@larchline.co, and you can reply to support@larchline.co. The Privacy Policy says how we handle that address.
1. Parties
- Controller: the merchant who installs the app, identified by its store's
myshopify.comaddress and the company details in its settings ("you"). - Processor: Scena Labs LLC, a limited liability company in Washington State, 522 W Riverside Ave, Ste N, Spokane, WA 99201, United States, support@larchline.co ("we", "us"). Contact for data protection: the owner of Scena Labs LLC, at support@larchline.co.
You accept this agreement when you install the app and accept the Terms of Service.
2. Subject matter and duration
We make invoices, delivery notes and credit notes from your Shopify orders. We keep the register of issued documents and the activity log, and act on Shopify's privacy notices for your store. This agreement lasts as long as the app is installed, and after that until we have deleted the data as section 9 says.
3. Nature and purpose
When you or your staff make a document, we read the order from Shopify and put what the document needs into a PDF. The PDF is sent to your browser and not kept. We store the register so that no number is used twice, and the activity log so you can see what was issued. We process the data for no other purpose.
The transfer is continuous: data reaches us each time a document is made. You are responsible for having a lawful basis for this processing and for telling your customers about it. You may give us further instructions in writing, by email, at any time.
4. Data subjects and data
| People | Data | Kept |
|---|---|---|
| Your customers, and contact people at business customers | Name or company, billing and shipping address, VAT ID on business orders, items and amounts. | Read when a document is made, not stored |
| Your customers | Shopify's order identifier and order number, linked to a document's number, date and amounts | In the register, until deletion |
| Your customers | Shopify's order identifiers named in a customer data request, with its date | At most 60 days, with 55 days to download |
| Your customers | Shopify's order and refund identifiers, in log lines and in the address of a page requested | In technical logs, 30 days |
| Your customers | Shopify's customer number in a privacy notice Shopify sends us | Read when the notice arrives, not stored |
| Your staff | Shopify user number of the person who made a document, with the time | In the activity log, until deletion |
| Your staff and customers named in an email to us | Whatever the email contains. | In the support mailbox, until you ask us to delete it, at most 24 months |
No special categories of data (Article 9 GDPR) are processed. The app does not read your customers' email addresses or phone numbers.
5. Our obligations
- Instructions. We process the data only on your documented instructions. These terms, your settings and your clicks in the app are those instructions, and they include the transfers in section 8. If a law of the European Union or a member state requires other processing, we tell you before, unless that law forbids it. If we think an instruction breaks data protection law, or we cannot follow it, we tell you at once.
- Confidentiality. Only the two people who run the app can reach the data, and only as far as their work on the app needs it. Both are committed to keep it confidential. The AI tool they build and run the app with works under the written rule in section 6 and never reads the data.
- Security. We keep the measures in section 6 in place. We check them at least once a year and after any incident, and improve them when a risk calls for it.
- Sub-processors. We use only the sub-processors in section 7, under the rules there.
- Your customers' rights. We help you answer requests from your customers. Shopify's privacy notices reach us directly and we act on them as the Privacy Policy describes. For any other request, write to us and we help without undue delay.
- Your other duties. We help you with security, breach notices, impact assessments and consultations with an authority, as far as our part of the processing allows.
- Breaches. We tell you without undue delay, and at the latest within 48 hours after we become aware of a personal data breach that affects your data. We tell you what we know: what happened, which data, and roughly how many people and records. We also tell you the likely effects, what we have done and plan to do, and who to contact for more. We add facts as we learn them. You decide whether to notify an authority or your customers.
- Information and audits. We give you the information you need to show that we meet this agreement. If that is not enough, you may audit us, yourself or through an auditor bound to confidentiality. Ask in writing at least 30 days before. Audits take place at reasonable intervals, or sooner if there are signs that we do not meet this agreement. Each side bears its own costs.
6. Security measures
- Customer names and addresses are never stored. Documents are made in memory and sent to the browser, not written to disk, a database or a cache.
- Only names and addresses are read. The app has no permission to read Shopify's customer records, your customers' email addresses or their phone numbers.
- Data travels encrypted: the app is served over https only and reaches its database through Google's encrypted connector. The database and its backups are encrypted at rest.
- The database is backed up daily and backups are kept for 7 days, so it can be restored.
- The app's own Shopify key and the database password are kept in Google Secret Manager, never in code. Each store's Shopify access token is kept in the app's database, which is encrypted at rest.
- Test and production are separate: separate app records, databases, secrets and servers. Test data comes from a test store only.
- The app's server accounts can reach only the database and the secrets they need. No bulk export works without a signed-in app session.
- The database can be reached only through Google's sign-in.
- Two-factor sign-in is on for the Google Cloud, Shopify Partner and Microsoft 365 accounts.
- A written rule binds the AI tool the operators build and run the app with. It never reads the personal data this agreement covers, from any source: email, logs, the database or screenshots. It acts only through the operators' own Google sign-in and works with counts and test data.
- Logs hold identifiers, numbers and counts, such as a keyed tag that stands for the store, Shopify's order and refund identifiers, document numbers and counts. The app's logger refuses a name, an address, a customer number and a staff user number. Lines that Node or React Router write by themselves are kept as they are written, outside that rule. The activity log records who made which document and when, and Google Cloud records administrative actions on the project.
- A written incident procedure covers personal data breaches, including the 48-hour notice to you.
7. Sub-processors
You give us general written authorisation to use sub-processors. We use these today:
| Sub-processor | What it does | Where |
|---|---|---|
| Google LLC (Google Cloud) | Hosting, database, backups and technical logs | Belgium (europe-west1); backups in the European Union |
| Microsoft Corporation (Microsoft 365) | Support email. Your customers' data reaches it only if you or a customer put it in an email to us | May include the United States |
Shopify is not a sub-processor. Shopify holds your store's data under your own agreement with Shopify. When you make a document, the app receives from Shopify, over an encrypted connection, the order data that document needs.
The company that sends the notice emails in the introduction is not a sub-processor under this agreement either. Those emails carry the address Shopify holds for your store and the notice text. They carry none of your customers' personal data. The Privacy Policy names that company and says where it keeps the emails.
We tell you at least 30 days before we add or replace a sub-processor, in the way the introduction describes. You may object in that time. If we cannot resolve your objection, you may end this agreement by uninstalling the app. Each sub-processor is bound by a written contract with the same data protection obligations as this agreement. We remain fully liable to you for their work. On request we send you a copy of those terms, with confidential parts removed.
8. Transfers outside the European Union
We are a company in the United States. The data is stored in Belgium. You make it available to a United States company, and the people who run the app can reach it from the United States. So the rules on transfers apply.
For any transfer of personal data from the European Economic Area to us, the European Commission's standard contractual clauses apply and are part of this agreement. These are the clauses of Implementing Decision (EU) 2021/914, Module Two (controller to processor). You are the data exporter and we are the data importer. The choices in the clauses are:
- Clause 7 (docking clause): not used.
- Clause 9(a): option 2, general written authorisation, with the 30 days' notice in section 7.
- Clause 11(a): the optional wording is not used.
- Clause 13: the supervisory authority of the EU member state where you are established.
- Clause 17: option 2, the law of the EU member state where you are established. Where that law does not allow third-party beneficiary rights, the law of Ireland.
- Clause 18: the courts of the EU member state where you are established.
- Annex I is sections 1 to 4 of this agreement, Annex II is section 6 and Annex III is section 7.
Clause 14 of those clauses asks both sides to look at the law of the United States for these transfers and to write down what they found. We have written down our assessment. Write to support@larchline.co and we send it to you.
If the European Commission adopts standard contractual clauses for importers that are themselves subject to the GDPR, those clauses replace these, and we tell you.
For transfers from Switzerland, the same clauses apply. The Swiss Federal Data Protection and Information Commissioner is the authority. The Swiss Federal Act on Data Protection is read in place of the GDPR where it applies. For transfers from the United Kingdom, the International Data Transfer Addendum issued by the UK Information Commissioner applies. If the clauses conflict with this agreement or the terms, the clauses win.
9. End of processing
When you uninstall the app, the access token is deleted at once and everything else when Shopify sends us the removal notice, 48 hours after you uninstall. One record stays: that the notice was handled, with your store's web address, the kind of notice and its date, so the same notice is not processed twice. We delete that record at the earliest 23 days after it arrives, and in any case within 30 days of its arrival. The record of the removal notice is deleted within 30 days after you uninstall. You can ask us to delete the rest sooner. Deleted data leaves our encrypted backups within 8 days. When the deletion is done, we confirm it to you by email if you ask.
We keep no copy of your documents, so the only thing to return is the register. If you want it, write to us before you uninstall and we send it to you. On the Pro plan you can also download the invoices, credit notes and cancellation invoices from the register in the app as a CSV file at any time. Support emails that contain your customers' data are deleted when you ask, and otherwise within 24 months.
10. Liability and precedence
The limitation of liability in the Terms of Service applies to this agreement, to the extent the law allows. It does not limit liability under the standard contractual clauses in section 8. This agreement is governed by the law chosen in Clause 17 of those clauses, and disputes about it go to the courts chosen in Clause 18. On data protection, this agreement takes precedence over the rest of the terms.