Data Processing Agreement (DPA)
Last updated: June 20, 2026
This Data Processing Agreement ("DPA") supplements the Profit Agent Terms of Service (https://profit-agent.app/terms) and Privacy Policy (https://profit-agent.app/privacy). It applies when you, as a Shopify merchant ("Controller", "you"), install or use Profit Agent and we, Profit Agent ("Processor", "we"), process personal data on your behalf.
By installing or continuing to use Profit Agent, you accept this DPA for processing your end customers' personal data through the app. If you do not accept this DPA, do not install the app.
DPA / GDPR contact: contact@profit-agent.app
1. Parties and roles
- Controller: you, the merchant owner of the Shopify store, for end customers' personal data processed via Profit Agent.
- Processor: Eric Dos Santos (EI), publisher of the Profit Agent application (trade name), registered office: 1 rue de stockholm, 75008 Paris,France, SIRET: 797 630 878 00040, contact: contact@profit-agent.app.
- Purpose: govern processing entrusted by the Controller to the Processor under Regulation (EU) 2016/679 (GDPR) and applicable national law.
2. Subject matter, nature, and duration
Subject matter: provision of Profit Agent (catalog analytics, recommendations, draft actions, outcome measurement, optional abandoned cart recovery, campaign links, AI features you trigger).
Nature of processing: collection, recording, organisation, storage, consultation, use, erasure — solely for contractual purposes.
Duration: for as long as the app is installed and OAuth-authorized on your store, then until complete erasure per section 11.
3. Data and data subjects
Categories of data subjects:
- You and your staff (merchant account, support, billing).
- Your end customers (only for enabled features, e.g. cart recovery).
Types of personal data (depending on features used):
- Merchant contact data: shop domain, owner email (via Shopify), locale preferences, account metadata.
- End customer data: email, phone, display name, checkout locale — only for abandoned carts when you use recovery; Shopify order IDs in aggregated line snapshots without customer names.
- Technical data: internal identifiers, logs without customer PII content.
Details are in the Privacy Policy. We do not process special categories (GDPR Art. 9) or criminal conviction data (Art. 10).
4. Documented instructions
We process personal data only on your documented instructions, except where required by mandatory law.
Your instructions include:
- Installing and maintaining the app with granted OAuth scopes.
- Enabling and using in-app features (e.g. launching cart recovery, approving drafts).
- Shopify compliance webhooks (`customers/data_request`, `customers/redact`, `shop/redact`) we execute to assist your responses.
You warrant that you have a valid legal basis (consent, contract, legitimate interests, etc.) for processing you entrust to us, especially before contacting customers via cart recovery.
5. Processor obligations
We will:
- Process data only to perform this DPA and your instructions.
- Ensure confidentiality of persons authorized to process data.
- Implement security measures described in the Privacy Policy and our incident response policy.
- Not engage another processor without informing you (section 6).
- Assist you, considering the nature of processing, with data subject rights requests.
- Assist with DPIAs and prior consultations where required by law, to the extent of information available to us.
- Delete or return data at contract end, except where law requires retention (section 11).
- Make information available to demonstrate GDPR compliance and allow reasonable audits (section 12).
- Inform you without undue delay if we believe an instruction infringes GDPR or applicable law.
6. Subprocessors
You authorize engagement of subprocessors necessary for the service, provided they are bound by obligations equivalent to this DPA.
The current list is in our GDPR Subprocessors documentation (available on request at contact@profit-agent.app) and includes notably:
- Shopify Inc. — platform hosting, API, webhooks, app billing.
- Hosting / database provider — application runtime and encrypted storage.
- AI provider (e.g. OpenAI or compatible) — only when you explicitly trigger an AI feature.
- Email infrastructure — only if configured for cart recovery you initiate.
We will inform you of material subprocessor changes via the Privacy Policy, this DPA, or in-app / email notice where required. You may object on legitimate data protection grounds; if objection is well-founded, we will offer a reasonable remedy (e.g. disable affected feature) or terminate the affected service.
7. Transfers outside the EEA
Transfers outside the European Economic Area may occur (e.g. Shopify, cloud or AI providers in the US). Where required, we rely on appropriate safeguards: EU Standard Contractual Clauses (Decision 2021/914) or equivalent recognized mechanisms, supplemented by additional measures where necessary.
You acknowledge Shopify also processes data globally under its own compliance mechanisms.
8. Security of processing (Art. 32)
Appropriate technical and organisational measures, including:
- HTTPS encryption in transit; OAuth tokens encrypted at rest (AES-256-GCM).
- Multi-tenant isolation by shop identifier.
- Limited retention and automated purge (90-day orders, 12-month closed carts).
- Mandatory GDPR webhooks and HMAC verification.
- Structured logging without customer PII in application logs.
- Security incident response policy (72-hour notification where GDPR requires).
Technical details are referenced from our Privacy Policy and incident response policy.
9. Personal data breaches
If a personal data breach affecting your customer data occurs, we will notify you without undue delay after becoming aware, with available information to help you meet your obligations (nature of breach, approximate categories and numbers of persons and records, likely consequences, measures taken or proposed).
We will cooperate with you regarding notification to supervisory authorities or data subjects where you are responsible as Controller.
10. Assistance — data subject rights
We assist you, by appropriate technical and organisational measures, with requests to exercise rights (access, rectification, erasure, restriction, objection, portability) regarding data we process for your account.
Primary mechanisms:
- Shopify webhooks `customers/data_request` and `customers/redact` (JSON export to shop owner or erasure processing).
- Direct requests to contact@profit-agent.app with identification of the affected shop.
You remain responsible for responding to data subjects within legal timeframes (generally one month, GDPR Art. 12).
11. End of processing and deletion
On uninstall (`app/uninstalled`): OAuth tokens are revoked.
On `shop/redact` (typically ~48 hours after uninstall): deletion of your shop record and associated data (cascade on linked tables), except where legal retention is required (e.g. limited billing evidence).
Before `shop/redact`, we may provide a reasonable export of merchant metadata we directly control upon written request, subject to identity verification.
12. Audits and compliance
We provide documented information necessary to demonstrate GDPR compliance (public policies, technical documentation, reasonable questionnaire responses).
On-site audits are required only where mandated by law or after a major confirmed incident; they will be scheduled in advance, within reasonable limits, and subject to confidentiality. Shopify Protected customer data requirements and reviews supplement this framework for App Store apps.
13. Liability
Each party remains liable for breaches of its own GDPR obligations. Where the Processor causes damage through processing inconsistent with this DPA, liability is limited per the Terms of Service, unless mandatory law provides otherwise.
The Processor is not liable for processing you perform as Controller outside instructions or outside app functionality.
14. Governing law and precedence
This DPA is governed by French law. If the DPA, Privacy Policy, and Terms conflict regarding data protection obligations, this DPA prevails.
If any clause is invalid, the remainder remains effective. This DPA may be updated; the current version is published at https://profit-agent.app/dpa. Continued use after update constitutes acceptance unless you uninstall within any stated notice period.
15. Contact
DPA / GDPR / processing questions:
For support, privacy requests, GDPR requests, legal inquiries, or data deletion requests, contact contact@profit-agent.app.
Privacy Policy: https://profit-agent.app/privacy
Terms of Service: https://profit-agent.app/terms