This data processing agreement ("DPA") is part of the terms of service between Joanis Innovative Ventures B.V., 1015 XW Amsterdam, Netherlands, Chamber of Commerce number 93438540 ("Bioshelf", "we"), and the merchant who installs the Bioshelf app ("you"). It applies automatically from the installation, for as long as we process personal data for you. It sets out the terms required by article 28 of the General Data Protection Regulation (GDPR). If it conflicts with the terms of service on data protection, this DPA applies.
1. Roles
For the personal data described in section 3, you are the controller and we are your processor. For the data about you as our customer (your store's account, subscription and the weekly email), we are the controller, as our privacy policy explains; this DPA doesn't cover that data. Words such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have their GDPR meaning.
2. Subject matter, duration, nature and purpose
- Subject matter: the processing of personal data about your page visitors and your customers, needed to provide Bioshelf to you.
- Duration: from the installation until the data is deleted after you uninstall (section 10).
- Nature: receiving data from your Bioshelf page and from Shopify, turning visitor data into a pseudonymous code, storing, aggregating and showing it to you in the app and the weekly email, and deleting it.
- Purpose: to count clicks on your page, show which orders came through a link on your page, show you these statistics, and remember a visitor's choice about your pixels.
3. Data subjects and personal data
| Data subjects | Personal data |
|---|---|
| Visitors to your Bioshelf page | A pseudonymous visitor code, made from the shortened IP address (IPv4 /24, IPv6 /48), the user agent and the page with a key that changes every day; the link and product clicked; the host name of the referring site; the UTM values in the page's address; the time of the click. The IP address and user agent themselves are never stored. |
| Visitors to your Bioshelf page, when you add a pixel | Their choice about the cookie banner, kept only in their own browser (localStorage). We don't receive it. |
| Visitors to your Bioshelf page | Technical data in our hosting and network providers' logs: IP address, browser details and the address requested. |
| Your customers whose order came through a link on your page | The Shopify order ID, total, currency and time, the link on your page, and whether it was a test order. |
| Your customers, while an order is being checked | The order ID, total, currency and time, for at most 3 days; the order's visit history (landing pages and referral codes), read from Shopify and not kept. |
We store no names, email addresses, phone numbers, postal addresses, customer IDs or IP addresses of your visitors or customers, and no special categories of personal data. Shopify's notice of a new order contains more details about the customer: we read only the fields listed above and discard the rest in the same request, without storing, queueing or logging it.
Retention: click records and attributed orders are deleted automatically after 13 months; the daily key behind visitor codes is deleted at the end of its day (UTC); order checks end within 3 days.
4. Our obligations
- Instructions. We process the data only on your documented instructions: these terms, this DPA and the settings you choose in the app, unless EU or Member State law requires otherwise; in that case we tell you first, unless that law forbids it. If we think an instruction breaks the GDPR, we tell you.
- Confidentiality. Only people who need the data to run Bioshelf can access it, and they are bound by confidentiality.
- No other use. We don't use the data for our own purposes, sell it, or share it with anyone other than the sub-processors in section 6, unless the law requires it.
5. Security
We take appropriate technical and organisational measures to protect the data (article 32 of the GDPR), including:
- HTTPS for every connection to the app;
- a database encrypted at rest with AES-256 by our hosting provider, backups included, and Shopify access tokens encrypted a second time by the app;
- data minimisation: IP addresses and user agents are never stored, only a daily code whose key is deleted every day; orders are kept without customer details;
- every message from Shopify checked with its signature; the admin reachable only with Shopify's session tokens, and every request limited to your own store's data;
- our internal operations page behind a password, with sign-in attempts limited;
- logs that name the store's domain, never your customers, with session tokens removed;
- a strict content security policy on your page, which only allows the pixels you added;
- automatic deletion at the end of the retention periods.
We may improve these measures over time, as long as the level of protection doesn't go down.
6. Sub-processors
You give us a general authorisation to use sub-processors. We use these today:
| Sub-processor | What it does | Location and transfer safeguard |
|---|---|---|
| Render Services, Inc. | Hosts the app and its database | Frankfurt region, Germany. A US company: the European Commission's standard contractual clauses |
| Cloudflare, Inc. | Domain name service, and the network that delivers your page and keeps copies of it for speed; sees visitors' IP addresses while doing so | A US company: the EU-US Data Privacy Framework, under which Cloudflare states it is certified, with the standard contractual clauses as a fallback |
| Brevo | Sends the weekly email; it handles only your email address and aggregated figures, no visitor or customer data | EU |
Shopify isn't our sub-processor: it is your platform, the source of the store data, and it handles your subscription under its own terms.
We impose data protection obligations on each sub-processor by contract that are at least as protective as this DPA, and we remain responsible to you for them. We'll tell you about a new or replacement sub-processor by email or in the app, and on this page, at least 30 days before it starts processing your data. If you object, you can end the service by uninstalling Bioshelf before the change applies.
7. International transfers
We host the app in the EU (Render's Frankfurt region). Where a sub-processor processes personal data outside the European Economic Area, the transfer is covered by the European Commission's standard contractual clauses, or by the EU-US Data Privacy Framework where the sub-processor is certified under it, as shown in section 6.
8. Helping you
- Data subject requests. When your customer asks you to delete their data or for a copy of it, Shopify forwards the request to us. For a deletion, we delete what we hold for the orders listed. For a copy, we send you what we hold for those orders within 30 days. If a data subject writes to us directly, we pass the request on to you without undue delay. Visitor codes can't be linked back to a person once their day is over, so we usually can't find a single visitor's clicks.
- Other obligations. Taking into account the nature of the processing and the information we have, we help you with security, data protection impact assessments and prior consultations with a supervisory authority (articles 32 to 36 of the GDPR).
9. Personal data breaches
If we become aware of a personal data breach affecting your data, we tell you without undue delay, and at the latest within 48 hours, at the store owner's email address that Shopify holds for your store. We give you the information you need to meet your own obligations (article 33(3) of the GDPR) as it becomes available, and we take steps to contain the breach.
10. Deletion at the end
When you uninstall Bioshelf, your page goes offline at once. 48 hours later, Shopify asks us to delete your store's data, and we delete everything we hold for your store, including the data in section 3. If that request doesn't arrive, we delete the data ourselves within about an hour after those 48 hours. Deleted data stays in our database backups until they expire, within 7 days. If you want a copy of your statistics before they are deleted, ask us at hello@bioshelf.co before you uninstall.
11. Audits
We give you the information needed to show that we meet this DPA. Once a year, on request, we answer your reasonable written questions or questionnaire and give you the relevant documentation. On-site audits take place only where the law or a supervisory authority requires them, with reasonable notice, under confidentiality, and at your cost.
12. Your obligations
You are responsible for having a legal basis for the processing, for telling your visitors and customers about it in your privacy policy, and for any consent you must obtain, including for the pixels you add. Your instructions to us must comply with the law.
13. Liability, term and law
The limits of liability in the terms of service apply to this DPA, as far as the GDPR allows. This DPA lasts as long as we process personal data for you. It is governed by the laws of the Netherlands, and disputes go to the competent court in Amsterdam, Netherlands.
14. Contact
Questions about this DPA go to hello@bioshelf.co.