This DPA forms part of the Terms of Service and applies where Fixiby processes personal data on behalf of the Merchant in connection with UpsellPilot AI, in accordance with Article 28 GDPR / UK GDPR and analogous “service provider” obligations under the CCPA/CPRA.
Processor provides the App described in the Terms. Processing lasts for the period the App is installed on the Merchant’s shop and any wind-down retention stated in the Privacy Policy, unless longer retention is required by law.
Processing is limited to hosting and operating upsell/cross-sell configuration, delivering offer surfaces, coordinating Shopify discounts, computing privacy-first analytics, authenticating Admin API access, and fulfilling Shopify mandatory privacy webhooks—strictly to provide the App per Merchant instructions (configuration and Shopify platform events).
| Data subjects | Personal data (typical) |
|---|---|
| Merchant staff / store operators | Shop domain, session tokens, settings, support emails |
| Shoppers (end customers) | Generally limited to event metrics and technical signals; core App design avoids storing shopper contact or payment PII. Order identifiers may be processed for attribution/deduplication when order webhooks are enabled. |
Processor shall:
Controller is responsible for the lawfulness of processing instructions, storefront notices/consent, and Shopify theme/cookie compliance toward shoppers.
Controller generally authorizes Processor to use infrastructure subprocessors in these categories:
Processor will notify Controller of material subprocessor changes via email or App notice where practicable. Continued use after notice constitutes acceptance, subject to mandatory objection rights under GDPR.
Where personal data is transferred outside the EEA/UK, Processor shall ensure an appropriate transfer mechanism (adequacy, SCCs, UK IDTA/Addendum) is in place with relevant providers.
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, and provide information reasonably available to help Controller meet its notification duties.
Processor is a “service provider” / “contractor” to Merchant. Processor will not sell or share personal information, retain/use/disclose it outside the business purpose of providing the App (or as otherwise permitted by the CCPA/CPRA), or combine it with other personal information except as allowed for that business purpose. Processor certifies that it understands these restrictions.
If there is a conflict between this DPA and the Terms regarding data-protection obligations, this DPA prevails. The Privacy Policy describes Fixiby’s independent controller activities (e.g., support email handling).
Fixiby Software Technologies · info@fixiby.com