Svenska English, current language
Contact

Book a call

Leave your details and we will get back to you. We listen to where you are before proposing anything.

Your details are used only to get in touch. See our privacy policy.

Data Processing Agreement

For Tacotech Affiliate, our Shopify app. Entered into automatically when you install it.

Effective from:

Parties

This Data Processing Agreement forms part of the agreement between Tacotech AB, organisation number 559259-2132 (”Processor”, ”Tacotech”) and the merchant using the Tacotech Affiliate app (”Controller”, ”you”). It is entered into automatically when you install the app, and reflects Article 28 of Regulation (EU) 2016/679 (”GDPR”).

1. Roles

You are the controller of your customers’ personal data. Tacotech is a processor, acting only on your documented instructions. Installing and configuring the app constitutes those instructions.

2. Subject matter and duration

Tacotech processes data in order to attribute sales in your store to the publishers who referred them, to calculate commission, and to report both to you. Processing continues for as long as the app is installed, and ends when the app is uninstalled and the associated data is erased.

3. Nature and purpose of processing

Collection, storage, structuring and transmission of order and referral data, for the purpose of affiliate attribution, commission calculation, reporting and invoicing.

4. Categories of data subjects

Visitors to and customers of your online store.

5. Types of personal data

Tacotech is designed to minimise this category. Processed and retained:

  • Order number and internal order identifier
  • Order value, currency and tax treatment
  • Discount codes applied to an order
  • Checkout identifier
  • Affiliate click and channel identifiers stored in a first-party cookie
  • Order and refund timestamps and status

Not processed or retained: customer names, email addresses, telephone numbers, billing or shipping addresses, IP addresses, order notes, or line-item properties. Where Shopify transmits such fields, they are removed before storage by a technical control in the application.

6. Processor obligations

Tacotech shall:

  • Process personal data only on your documented instructions, including as regards transfers to a third country, unless required otherwise by Union or Member State law.
  • Ensure that persons authorised to process the data are bound by an appropriate obligation of confidentiality.
  • Implement the technical and organisational measures set out in Section 8.
  • Not engage another processor without the authorisation in Section 7.
  • Assist you, so far as possible and taking into account the nature of the processing, in fulfilling your obligation to respond to data subject requests.
  • Assist you in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available.
  • At your choice, delete or return all personal data at the end of the provision of services, and delete existing copies, unless retention is required by Union or Member State law.
  • Make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in Section 10.

Tacotech shall inform you immediately if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

7. Sub-processors

You give general authorisation for the engagement of the following sub-processors:

Sub-processorPurposeLocation
Addrevenue ABOperation of the affiliate network the programme runs onSweden (EU)
Hetzner Online GmbHHosting and database infrastructureFinland (EU)

Tacotech will inform you of any intended addition or replacement of a sub-processor with reasonable notice, and you may object on reasonable data protection grounds. Tacotech remains fully liable to you for the performance of any sub-processor’s obligations.

8. Technical and organisational measures

  • Encryption in transit. All connections use TLS.
  • Encryption at rest of credentials. Merchant access tokens are encrypted with AES-256-GCM. Encryption keys are held separately from the database.
  • Data minimisation by design. Personal data fields are removed from incoming data before it is written to storage.
  • Network isolation. The database is not reachable from the public internet.
  • Access control. Access to internal systems requires named accounts. Actions affecting a merchant’s configuration are recorded in an audit log.
  • Segregation. Data belonging to different merchants is separated by store, and every request is authenticated to a specific store.

9. Personal data breach

Tacotech shall notify you without undue delay after becoming aware of a personal data breach affecting your data, and shall provide the information you reasonably require to meet your own notification obligations.

10. Audit

On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority, Tacotech shall make available the information necessary to demonstrate compliance with this DPA, and shall cooperate with an audit conducted by you or an auditor you appoint. Audits shall be conducted during business hours, shall not unreasonably disrupt operations, and shall respect the confidentiality of other customers’ data.

11. International transfers

All processing takes place within the European Economic Area. Tacotech will not transfer personal data outside the EEA without first putting an appropriate transfer mechanism in place and informing you.

12. Deletion

On uninstall, Shopify notifies Tacotech and requests erasure of the store’s data. Tacotech deletes the store record and its associated data on receipt of that request, normally within 48 hours. Records required for invoicing and statutory accounting purposes are retained for the period required by law and are limited to order numbers, values and dates.

Contact

Tacotech AB
Company reg. no.: 559259-2132
Södra Bulltoftavägen 51, 212 22 Malmö
joel@tacotech.se