Bioshelf

Data processing agreement

Updated on

This data processing agreement ("DPA") is part of the terms of service between Joanis Innovative Ventures B.V., 1015 XW Amsterdam, Netherlands, Chamber of Commerce number 93438540 ("Bioshelf", "we"), and the merchant who installs the Bioshelf app ("you"). It applies automatically from the installation, for as long as we process personal data for you. It sets out the terms required by article 28 of the General Data Protection Regulation (GDPR). If it conflicts with the terms of service on data protection, this DPA applies.

1. Roles

For the personal data described in section 3, you are the controller and we are your processor. For the data about you as our customer (your store's account, subscription and the weekly email), we are the controller, as our privacy policy explains; this DPA doesn't cover that data. Words such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have their GDPR meaning.

2. Subject matter, duration, nature and purpose

3. Data subjects and personal data

Data subjectsPersonal data
Visitors to your Bioshelf pageA pseudonymous visitor code, made from the shortened IP address (IPv4 /24, IPv6 /48), the user agent and the page with a key that changes every day; the link and product clicked; the host name of the referring site; the UTM values in the page's address; the time of the click. The IP address and user agent themselves are never stored.
Visitors to your Bioshelf page, when you add a pixelTheir choice about the cookie banner, kept only in their own browser (localStorage). We don't receive it.
Visitors to your Bioshelf pageTechnical data in our hosting and network providers' logs: IP address, browser details and the address requested.
Your customers whose order came through a link on your pageThe Shopify order ID, total, currency and time, the link on your page, and whether it was a test order.
Your customers, while an order is being checkedThe order ID, total, currency and time, for at most 3 days; the order's visit history (landing pages and referral codes), read from Shopify and not kept.

We store no names, email addresses, phone numbers, postal addresses, customer IDs or IP addresses of your visitors or customers, and no special categories of personal data. Shopify's notice of a new order contains more details about the customer: we read only the fields listed above and discard the rest in the same request, without storing, queueing or logging it.

Retention: click records and attributed orders are deleted automatically after 13 months; the daily key behind visitor codes is deleted at the end of its day (UTC); order checks end within 3 days.

4. Our obligations

5. Security

We take appropriate technical and organisational measures to protect the data (article 32 of the GDPR), including:

We may improve these measures over time, as long as the level of protection doesn't go down.

6. Sub-processors

You give us a general authorisation to use sub-processors. We use these today:

Sub-processorWhat it doesLocation and transfer safeguard
Render Services, Inc.Hosts the app and its databaseFrankfurt region, Germany. A US company: the European Commission's standard contractual clauses
Cloudflare, Inc.Domain name service, and the network that delivers your page and keeps copies of it for speed; sees visitors' IP addresses while doing soA US company: the EU-US Data Privacy Framework, under which Cloudflare states it is certified, with the standard contractual clauses as a fallback
BrevoSends the weekly email; it handles only your email address and aggregated figures, no visitor or customer dataEU

Shopify isn't our sub-processor: it is your platform, the source of the store data, and it handles your subscription under its own terms.

We impose data protection obligations on each sub-processor by contract that are at least as protective as this DPA, and we remain responsible to you for them. We'll tell you about a new or replacement sub-processor by email or in the app, and on this page, at least 30 days before it starts processing your data. If you object, you can end the service by uninstalling Bioshelf before the change applies.

7. International transfers

We host the app in the EU (Render's Frankfurt region). Where a sub-processor processes personal data outside the European Economic Area, the transfer is covered by the European Commission's standard contractual clauses, or by the EU-US Data Privacy Framework where the sub-processor is certified under it, as shown in section 6.

8. Helping you

9. Personal data breaches

If we become aware of a personal data breach affecting your data, we tell you without undue delay, and at the latest within 48 hours, at the store owner's email address that Shopify holds for your store. We give you the information you need to meet your own obligations (article 33(3) of the GDPR) as it becomes available, and we take steps to contain the breach.

10. Deletion at the end

When you uninstall Bioshelf, your page goes offline at once. 48 hours later, Shopify asks us to delete your store's data, and we delete everything we hold for your store, including the data in section 3. If that request doesn't arrive, we delete the data ourselves within about an hour after those 48 hours. Deleted data stays in our database backups until they expire, within 7 days. If you want a copy of your statistics before they are deleted, ask us at hello@bioshelf.co before you uninstall.

11. Audits

We give you the information needed to show that we meet this DPA. Once a year, on request, we answer your reasonable written questions or questionnaire and give you the relevant documentation. On-site audits take place only where the law or a supervisory authority requires them, with reasonable notice, under confidentiality, and at your cost.

12. Your obligations

You are responsible for having a legal basis for the processing, for telling your visitors and customers about it in your privacy policy, and for any consent you must obtain, including for the pixels you add. Your instructions to us must comply with the law.

13. Liability, term and law

The limits of liability in the terms of service apply to this DPA, as far as the GDPR allows. This DPA lasts as long as we process personal data for you. It is governed by the laws of the Netherlands, and disputes go to the competent court in Amsterdam, Netherlands.

14. Contact

Questions about this DPA go to hello@bioshelf.co.