Skip to content
  • Demo
  • Pricing
  • FAQ
  • Contact
Start your trial
Demo Pricing FAQ Contact
Start your trial

Legal

Data Processing Agreement

Effective date: 17 July 2026 · Last updated: 16 September 2026

On this page

  1. Parties & scope
  2. Definitions
  3. Roles of the parties
  4. Processing on instructions
  5. Confidentiality
  6. Security (Art. 32)
  7. Sub-processors
  8. International transfers
  9. Assistance & data subject rights
  10. Personal data breaches
  11. Return & deletion
  12. Audits
  13. Liability & term
  14. Annex A — Processing details
  15. Annex B — Sub-processors
  16. Annex C — Security measures
  17. Contact

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Xirvy and the merchant (“you”, the “Customer”) using the Xirvy Shopify application (the “App”). It governs the processing of personal data that we carry out on your behalf as your processor, in accordance with Article 28 of the UK GDPR.

1. Parties and scope

  • Processor: Xirvy.
  • Controller: the Customer (the Shopify merchant) that installs and uses the App.

This DPA applies where, and to the extent that, we process Customer Personal Data on your behalf in connection with the App. It takes effect when you install or use the App and continues for as long as we process Customer Personal Data for you. Where there is a conflict between this DPA and the Terms of Service in respect of data protection, this DPA prevails.

2. Definitions

  • UK GDPR, controller, processor, data subject, personal data, processing, and personal data breach have the meanings given in the UK GDPR and the Data Protection Act 2018 (“Data Protection Laws”).
  • Customer Personal Data means personal data contained within the data we process on your behalf through the App, as described in Annex A.
  • Sub-processor means any processor engaged by us to process Customer Personal Data.

3. Roles of the parties

In relation to Customer Personal Data, you are the controller and we are the processor. Where Shopify acts as a processor for you and we act as a sub-processor within the Shopify ecosystem, this DPA describes our obligations accordingly. You are responsible for ensuring you have a lawful basis for the processing and for the accuracy, quality, and legality of the Customer Personal Data and the instructions you give us.

We process our own limited data (for example, merchant account and billing-relationship records, and website analytics) as an independent controller; that processing is described in our Privacy Policy and is outside the scope of this DPA.

4. Processing on documented instructions

We will process Customer Personal Data only:

  • on your documented instructions, including as set out in this DPA, the Terms of Service, and your configuration and use of the App; and
  • as required by applicable law, in which case we will (unless legally prohibited) inform you of that legal requirement before processing.

We will inform you if, in our opinion, an instruction infringes Data Protection Laws. We will not sell Customer Personal Data or use it for advertising, retargeting, or our own independent marketing purposes. We do not carry out processing of Customer Personal Data that would require a storefront customer’s marketing consent.

5. Confidentiality

We ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations (whether contractual or statutory) and are made aware of the confidential nature of the data. Access is limited to personnel who need it to provide the App.

6. Security measures (Article 32)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. A summary of these measures is set out in Annex C. We may update our security measures from time to time provided that the level of protection is not materially reduced.

7. Sub-processors

You provide general authorisation for us to engage sub-processors to process Customer Personal Data, subject to this section. Our current sub-processors are described in Annex B. We will:

  • impose data protection obligations on each sub-processor that are no less protective than those in this DPA, by written contract;
  • remain liable to you for the performance of each sub-processor’s obligations; and
  • give you reasonable notice of any intended addition or replacement of a sub-processor (for example by updating Annex B or notifying you), giving you the opportunity to object on reasonable data protection grounds.

If you reasonably object to a new sub-processor and we cannot provide a commercially reasonable alternative, you may terminate use of the affected part of the App.

8. International transfers

We will not transfer Customer Personal Data outside the United Kingdom unless appropriate safeguards are in place, such as an adequacy decision, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures required. Certain sub-processors (for example, infrastructure or platform providers) may process data outside the UK on this basis.

9. Assistance and data subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligations to respond to requests from data subjects exercising their rights under Data Protection Laws. If we receive such a request directly relating to Customer Personal Data, we will (unless legally prohibited) promptly notify you and not respond ourselves except on your instructions or as required by law.

We will also provide reasonable assistance with your data protection impact assessments and prior consultations with the ICO, to the extent required by Articles 35 and 36 UK GDPR and relevant to our processing.

10. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to us to help you meet your obligations to notify the ICO and affected data subjects where required. This notification is not an acknowledgement of fault or liability.

11. Return and deletion of data

Customer Personal Data is retained while the App remains installed (including where you cancel a subscription but keep the App installed). On your written request, or when you uninstall the App, we will delete or return Customer Personal Data as you elect. After uninstall, Shopify sends a shop data deletion request (shop/redact) approximately 48 hours later; we then delete Customer Personal Data from our systems, unless applicable law requires continued storage. Certain data may persist in routine backups for a limited period and will be deleted in the ordinary course; while it remains, we continue to protect it under this DPA.

12. Audits

We will make available to you information reasonably necessary to demonstrate compliance with Article 28 UK GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To minimise disruption, we may satisfy audit requests by providing relevant documentation, certifications, or a summary of controls, and audits will be on reasonable prior notice, during business hours, no more than once per year (except where required following a breach or by a supervisory authority), and subject to confidentiality.

13. Liability and term

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA remains in force for as long as we process Customer Personal Data on your behalf; provisions that by their nature should survive termination will do so.

Annex A — Details of processing

  • Subject matter: provision of the Xirvy App (volume discounts, upsells, and related offers) to the Customer.
  • Duration: for the term of the Customer’s installation/use of the App. After uninstall, Shopify sends a shop data deletion request (shop/redact) approximately 48 hours later, at which point we delete Customer Personal Data from our systems unless applicable law requires continued storage.
  • Nature and purpose: hosting, storing, and processing configuration and order-related data to apply discounts, display offers/widgets, and produce performance analytics for the Customer.
  • Types of personal data: primarily store and configuration data, limited merchant staff identifiers (such as name, email, and Shopify user identifier from the Shopify session, and optionally on in-app roadmap or feedback posts), and order-related identifiers and aggregates. The App is designed to minimise personal data and does not require customer names, email addresses, phone numbers, or payment card details for core operation. Limited personal data (such as order identifiers) may be processed to apply discounts and attribute performance. We do not use Customer Personal Data for advertising, retargeting, or sale, and we do not set advertising or analytics cookies on the merchant’s storefront.
  • Categories of data subjects: the Customer’s end customers and, where relevant, the Customer’s staff/store users.

Annex B — Sub-processors

We use the following categories of sub-processor to provide the App:

  • Shopify Inc. and affiliates — platform, hosting, authentication, and billing within the Shopify ecosystem.
  • Cloud hosting and infrastructure provider(s) — application hosting and data storage.
  • Crisp — live chat support within the App. Receives the shop domain and the contents of any chat a merchant starts.

An up-to-date list of named sub-processors is available on request — see Contact. We will update this Annex when adding or replacing sub-processors and provide notice as described in section 7.

Annex C — Technical and organisational security measures

We maintain measures appropriate to the risk, including:

  • Encryption in transit (HTTPS/TLS) for data transmitted between systems.
  • Encryption at rest of production database storage and backups via our hosting providers, and application-level encryption of Shopify access tokens (AES-256-GCM).
  • Access control on a least-privilege basis, with authentication for administrative access.
  • Data minimisation in the App’s design, avoiding collection of customer names, email addresses, phone numbers, or payment details for core operation.
  • Reliance on reputable infrastructure providers that maintain recognised security controls and physical data-centre security.
  • Logging and monitoring appropriate to the service to help detect and respond to issues.
  • Change management and secure development practices proportionate to the size of the service.
  • Incident response procedures to identify, manage, and notify personal data breaches.

Contact

Questions about this DPA or to request our current sub-processor list: contact@xirvy.com.

Volume discounts and upsells for Shopify. Increase AOV with offers that apply automatically at checkout.

Product

  • Features
  • Pricing
  • Demo

Resources

  • FAQ
  • Support

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use
  • Data Processing Agreement
© 2026 Xirvy. All rights reserved.