1. Roles and processing chain #
The data processed comes from Shopify stores. Depending on your situation, you act as controller (you run your own store) or as processor for the merchants whose stores you manage (you are an agency).
Vaultify acts solely as a processor — or as a sub-processor where you are yourself a processor. We never determine the purposes or the essential means of processing store data.
Processing relating to your account (identity, billing, support) follows a separate regime: we are the controller for it, and it is described in the privacy policy.
2. Subject matter, nature and purpose #
| Subject matter | Backup, retention, return and restoration of the data of a Shopify store. |
|---|---|
| Nature of operations | Collection through the Shopify API, recording, storage, making available, writing back to a store, deletion. |
| Purpose | Enabling recovery after an incident, migration between stores, and keeping a versioned history, at the customer's request. |
| Duration | The term of the subscription, plus the purge periods in clause 7. |
3. Categories of data and data subjects #
Data subjects: customers of the stores backed up, prospects who provided an address, and where applicable staff of the merchant appearing in the content.
Categories of data: identity and contact details, shipping and billing addresses, order and cart history, marketing consent status, gift cards, and any personal data the customer has placed in content, files or metadata.
The service has no access to payment data: the Shopify API does not expose card numbers, so they appear in no backup. No special category data within the meaning of GDPR article 9 is processed intentionally; if the customer introduces such data into their store content, it is for them to establish the legal basis.
4. Instructions and obligations of the processor #
Vaultify undertakes to:
- Process the data only on the customer's documented instructions. Normal use of the service constitutes those instructions: the resource types selected, the schedule, the retention policy, the destination disk and the restores triggered. Vaultify informs the customer if an instruction appears to infringe the GDPR.
- Ensure confidentiality: access limited to authorised personnel bound by a confidentiality undertaking.
- Implement the security measures set out in the annex and on the Security page.
- Assist the customer, so far as possible and taking into account the nature of the processing, in responding to data subject requests and in meeting the obligations of GDPR articles 32 to 36.
- Notify any personal data breach to the customer within 48 hours of becoming aware of it, with the information needed for their own notification to the supervisory authority.
- Make available the information needed to demonstrate compliance and allow an annual audit, on thirty days' notice, at the customer's expense, without access to other customers' data.
5. Sub-processors #
The customer gives general authorisation to the sub-processors listed in the privacy policy. Any change is notified at least thirty days in advance; the customer may object on legitimate grounds, which may result in termination without penalty.
Vaultify contractually imposes on its sub-processors obligations equivalent to those of this agreement.
6. Location and transfers #
Data is hosted and backed up in the European Union, with IONOS.
A flow to Shopify is inherent to the service: data is read through its API, to which the merchant already entrusted it. The European contracting entity is Shopify International Ltd. (Ireland); intra-group transfers, in particular to Shopify Inc. in Canada, rely on the European Commission's adequacy decision for Canada, on Shopify's Binding Corporate Rules and on the standard contractual clauses of decision (EU) 2021/914. No other transfer outside the EU or EEA is carried out without a valid mechanism under GDPR articles 44 et seq., nor without prior notice to the customer.
7. Return and deletion #
- During the subscription, the customer may at any time export their backups as ZIP archives containing NDJSON files and media.
- At the end of the contract, or when the customer deletes a store or an account, Vaultify effectively deletes the backup files, media and associated metadata; deletion propagates down to the stored files.
- For an app installed from the App Store, deletion is triggered by the redaction request sent by Shopify, forty-eight hours after uninstall.
- Technical backups of the platform itself (database dumps) expire after [TO COMPLETE: number of rolling days].
- In case of non-payment, data is kept read-only for [TO COMPLETE: agreed period], after warning, then purged. [TO IMPLEMENT: this purge is not automated today — do not commit to it until it is in place.]
8. Liability and audit #
Each party answers for its own breaches. The liability caps agreed in clause 9 of the terms of service apply between the parties under this agreement.
Those caps govern the relationship between the parties only. They have no effect on administrative fines imposed by a supervisory authority under GDPR article 83, nor on the right to compensation that article 82 gives data subjects directly: a contract can neither exclude nor limit them.
Annex — Technical and organisational measures #
| Area | Measure |
|---|---|
| Encryption in transit | TLS for all exchanges, with the platform and with the Shopify API. |
| Encryption at rest | Provided by the underlying storage; Shopify access tokens encrypted at application level in the database. [TO CONFIRM: volume and/or object storage encryption to be enabled and documented with the host.] |
| Isolation | Per-customer isolation enforced at the database query and authorization layers, covered by automated tests; storage separated per store. |
| Access control | Distinct roles, optional two-factor authentication, time-limited signed download links (15 minutes). |
| Traceability | Audit log of sensitive actions: who, what, when. |
| Continuity | Backup of the platform database and monitoring of processing. [TO COMPLETE: platform backup frequency and how often restores are tested.] |
| Incident management | Documented response and notification procedure — see the Security page. |