Data Processing Agreement
For Tacotech Affiliate, our Shopify app. Entered into automatically when you install it.
Effective from:
Parties
This Data Processing Agreement forms part of the agreement between Tacotech AB, organisation number 559259-2132 (”Processor”, ”Tacotech”) and the merchant using the Tacotech Affiliate app (”Controller”, ”you”). It is entered into automatically when you install the app, and reflects Article 28 of Regulation (EU) 2016/679 (”GDPR”).
1. Roles
You are the controller of your customers’ personal data. Tacotech is a processor, acting only on your documented instructions. Installing and configuring the app constitutes those instructions.
2. Subject matter and duration
Tacotech processes data in order to attribute sales in your store to the publishers who referred them, to calculate commission, and to report both to you. Processing continues for as long as the app is installed, and ends when the app is uninstalled and the associated data is erased.
3. Nature and purpose of processing
Collection, storage, structuring and transmission of order and referral data, for the purpose of affiliate attribution, commission calculation, reporting and invoicing.
4. Categories of data subjects
Visitors to and customers of your online store.
5. Types of personal data
Tacotech is designed to minimise this category. Processed and retained:
- Order number and internal order identifier
- Order value, currency and tax treatment
- Discount codes applied to an order
- Checkout identifier
- Affiliate click and channel identifiers stored in a first-party cookie
- Order and refund timestamps and status
Not processed or retained: customer names, email addresses, telephone numbers, billing or shipping addresses, IP addresses, order notes, or line-item properties. Where Shopify transmits such fields, they are removed before storage by a technical control in the application.
6. Processor obligations
Tacotech shall:
- Process personal data only on your documented instructions, including as regards transfers to a third country, unless required otherwise by Union or Member State law.
- Ensure that persons authorised to process the data are bound by an appropriate obligation of confidentiality.
- Implement the technical and organisational measures set out in Section 8.
- Not engage another processor without the authorisation in Section 7.
- Assist you, so far as possible and taking into account the nature of the processing, in fulfilling your obligation to respond to data subject requests.
- Assist you in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available.
- At your choice, delete or return all personal data at the end of the provision of services, and delete existing copies, unless retention is required by Union or Member State law.
- Make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in Section 10.
Tacotech shall inform you immediately if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
7. Sub-processors
You give general authorisation for the engagement of the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Addrevenue AB | Operation of the affiliate network the programme runs on | Sweden (EU) |
| Hetzner Online GmbH | Hosting and database infrastructure | Finland (EU) |
Tacotech will inform you of any intended addition or replacement of a sub-processor with reasonable notice, and you may object on reasonable data protection grounds. Tacotech remains fully liable to you for the performance of any sub-processor’s obligations.
8. Technical and organisational measures
- Encryption in transit. All connections use TLS.
- Encryption at rest of credentials. Merchant access tokens are encrypted with AES-256-GCM. Encryption keys are held separately from the database.
- Data minimisation by design. Personal data fields are removed from incoming data before it is written to storage.
- Network isolation. The database is not reachable from the public internet.
- Access control. Access to internal systems requires named accounts. Actions affecting a merchant’s configuration are recorded in an audit log.
- Segregation. Data belonging to different merchants is separated by store, and every request is authenticated to a specific store.
9. Personal data breach
Tacotech shall notify you without undue delay after becoming aware of a personal data breach affecting your data, and shall provide the information you reasonably require to meet your own notification obligations.
10. Audit
On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority, Tacotech shall make available the information necessary to demonstrate compliance with this DPA, and shall cooperate with an audit conducted by you or an auditor you appoint. Audits shall be conducted during business hours, shall not unreasonably disrupt operations, and shall respect the confidentiality of other customers’ data.
11. International transfers
All processing takes place within the European Economic Area. Tacotech will not transfer personal data outside the EEA without first putting an appropriate transfer mechanism in place and informing you.
12. Deletion
On uninstall, Shopify notifies Tacotech and requests erasure of the store’s data. Tacotech deletes the store record and its associated data on receipt of that request, normally within 48 hours. Records required for invoicing and statutory accounting purposes are retained for the period required by law and are limited to order numbers, values and dates.
Contact
Tacotech ABCompany reg. no.: 559259-2132
Södra Bulltoftavägen 51, 212 22 Malmö
joel@tacotech.se