Data Processing Addendum
Last updated: 10 October 2026
This addendum is part of the TransparencyPassport Terms of Service. It applies when we process personal data for you through the app.
- Controller: you, the merchant who installed the app.
- Processor: Otium; contact [email protected].
Words such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in the EU General Data Protection Regulation (GDPR).
1. What we process
| Item | Details |
|---|---|
| Subject matter | Running the TransparencyPassport app for your Shopify store |
| Duration | While the app is installed, plus the erasure steps in section 9 |
| Nature and purpose | Storing, displaying and publishing Digital Product Passports (web page and machine-readable file); storing and serving compliance documents; issuing and checking access links; reading products from Shopify; counting anonymous passport views; rate-limiting public routes; optional AI drafting and translation from product text; email notifications; Shopify Flow triggers; nightly backups and restores; support |
| Data subjects | Your staff and contacts whose details you enter (for example a notification email, a manufacturer contact in a passport, a name in an access-link label); people named in passport text or documents you upload; visitors to your passport pages (IP address only, briefly) |
| Personal data | Contact details you enter (name, email, address); any personal data you write into passport fields or that appears in documents you upload; visitors' IP addresses, held for about one minute in memory for rate limits |
| Special categories | None. Do not enter them |
The app does not have access to your customers, orders or payments (it only has the read_products permission). Passport view events are anonymous: they hold no IP address, user agent, cookie or customer ID. Access links record how often they were used, not who used them.
2. Your instructions
We process personal data only on your documented instructions. These terms, your use of the app's features and its settings are your instructions. If the law requires us to process data in another way, we will tell you first unless the law forbids it. We will tell you if we think an instruction breaks data protection law.
3. Confidentiality
Everyone we allow to process the data is bound by confidentiality.
4. Security
We keep the technical and organisational measures described in our security overview. We may improve them, but we will not lower the overall level of protection.
5. Subprocessors
You allow us to use the subprocessors listed in our Privacy Policy: Shopify, Google (Firebase / Cloud Firestore; Gemini API if AI is switched on), Supabase (PostgreSQL for Shopify sign-in sessions), DigitalOcean (hosting and document storage), DigitalOcean Spaces (backup bucket, Amsterdam) (backups), Cloudflare (if the CDN is on), Resend (if email delivery is on) and Sentry (if error tracking is on).
We will give you at least 30 days' notice of a new subprocessor, by updating that list and telling you in the app or by email. You may object on reasonable data protection grounds. If we cannot address the objection, you may end the agreement by uninstalling the app.
We put data protection terms in place with each subprocessor that are at least as protective as this addendum. We remain responsible for them.
6. International transfers
Some subprocessors process data outside the EU, UK or Switzerland, for example in the USA. For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) or the EU–US Data Privacy Framework where the recipient is certified. Where the Standard Contractual Clauses are needed between you and us, Module 2 (controller to processor) is incorporated by reference.
7. Helping you
Taking into account what we process, we will help you:
- answer data subject requests. Most can be handled in the app: edit or delete passports and unpublished documents, revoke access links, export CSV, change settings. Documents in a published version are locked in the app; if one must be removed, ask us and we will help. If a data subject contacts us directly about your data, we will pass the request to you;
- meet your duties on security, breach notification, impact assessments and consultation with authorities, as far as they relate to the app.
8. Personal data breaches
We will tell you without undue delay, and in any case within 72 hours, after we become aware of a personal data breach affecting your data. We will tell you what we know, what we are doing, and update you as we learn more.
9. End of processing
- You can export your passports and analytics as CSV, and download your documents, at any time.
- When you uninstall, the app deletes its Shopify session and takes your passports offline at once.
- When Shopify sends the
shop/redactrequest (48 hours after you uninstall), the app erases all your shop's data: database records, document files and backup bundles. - Copies of document files in the backup bucket, emails held by the email provider, logs, error reports and rate-limit counters expire on the schedule in our Privacy Policy.
We keep data longer only if the law requires it.
10. Audits
We will give you the information you reasonably need to show that we meet this addendum. If that is not enough, you may audit us once a year, with 30 days' written notice, at your own cost, during business hours, under confidentiality, and without access to other merchants' data. We may meet an audit request with a recent independent report, if we have one.
11. Order of precedence
If this addendum and the Terms of Service conflict about personal data, this addendum wins.
Contact
Privacy questions: [email protected]