Data Processing Agreement
Version 1.0 — 28 August 2026
1. Scope and Roles of the Parties
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Copify Terms of Service between Digitally Crafted, a business established in Australia ("Copify", "we", "us") and the merchant that installs or uses Copify ("Merchant", "you"). It is accepted automatically when you install Copify; no signature is required. Where the Merchant is subject to the GDPR, the UK GDPR, the Australian Privacy Act 1988 (Cth) or comparable law, the parties agree the following allocation of roles:
- The Merchant is the Controller of personal data contained in its Shopify stores and instructs Copify to process it.
- Copify is the Processor, acting only on the Merchant's documented instructions.
- Shopify Inc. is an independent Controller of the store data it holds; this DPA does not govern Shopify's own processing.
- Where Copify processes data about the Merchant's own account and staff for billing, support and service administration, Copify acts as an independent Controller under its Privacy Policy, not as Processor.
2. Definitions
Terms including "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" carry the meanings given to them in the GDPR. "Applicable Data Protection Law" means all privacy and data protection laws applicable to a party's processing under this DPA, including the EU GDPR, the UK GDPR, the Swiss FADP, the Australian Privacy Act 1988 (Cth) and its Australian Privacy Principles ("APPs"), and applicable United States state privacy laws. "Protected Customer Data" has the meaning given by Shopify's Protected Customer Data requirements for Shopify apps.
3. Subject Matter, Duration, Nature and Purpose
Copify synchronises data between Shopify stores the Merchant controls. The nature of the processing is the reading of records from a designated source store and the creation or update of corresponding records in one or more destination stores, together with the logging, versioning, conflict handling and backup functions necessary to operate that service reliably. The purpose is limited to providing the Copify service to the Merchant. Processing continues for as long as Copify is installed on the Merchant's store, and thereafter only for the limited retention periods described in Annex I.
4. Processing Instructions
Copify processes personal data only on the Merchant's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Copify is subject — in which case Copify will inform the Merchant of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. The Merchant's instructions are given through:
- The Terms of Service and this DPA.
- The sync configuration, field rules, pipelines, schedules and approval gates the Merchant sets in the Copify interface.
- The Shopify API scopes the Merchant grants at install, and any subsequent scope changes.
- Any further written instruction the Merchant gives, which Copify may charge for where it falls outside the standard service.
5. Confidentiality of Processing
Copify ensures that every person authorised to process personal data under this DPA is bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those personnel who require it in order to deliver, support or secure the service. Access to production systems is restricted to authenticated operator accounts and is role-gated.
6. Security of Processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of data subjects, Copify implements appropriate technical and organisational measures to ensure a level of security appropriate to that risk. Those measures are set out in Annex II and may be updated over time, provided the overall level of protection is not reduced.
7. Shopify Protected Customer Data
Copify requests Shopify API scopes that place it within Shopify's Protected Customer Data tier, including customer, order and gift card access. In relation to that data, Copify commits to:
- Request only the scopes required to deliver the sync functionality the Merchant has enabled.
- Process customer and order records in transit only — such records are read from the source store and written to the destination store, and are not retained in Copify's database after the sync operation completes.
- Apply encryption in transit to all data, and encryption at rest to stored Shopify access credentials.
- Implement and honour Shopify's mandatory compliance webhooks (customers/data_request, customers/redact and shop/redact).
- Not use Protected Customer Data to train machine learning or artificial intelligence models. Copify integrates no large language model or AI provider, and no store data is transmitted to any model provider.
- Not sell, rent or share Protected Customer Data, and not use it for advertising or for any purpose other than providing the service to the Merchant.
8. Sub-processors
The Merchant grants Copify general written authorisation to engage sub-processors. Those engaged as at the effective date of this DPA are listed in Annex III. Copify imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Merchant for their performance. Copify will give the Merchant at least thirty (30) days' notice before adding or replacing a sub-processor. The Merchant may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Merchant may terminate the affected service without penalty.
9. International Transfers
Copify is established in Australia and operates on globally distributed edge infrastructure, so personal data may be processed outside the Merchant's own jurisdiction, including outside the European Economic Area, the United Kingdom and Australia. Where such a transfer is restricted by Applicable Data Protection Law, it is made under an appropriate safeguard:
- For transfers from the EEA, the European Commission Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and completed with the information in Annex I, Annex II and Annex III.
- For transfers from the United Kingdom, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies.
- For transfers from Switzerland, the Standard Contractual Clauses apply, with references to the GDPR read as references to the Swiss FADP and the competent authority read as the Swiss FDPIC.
- For disclosures of personal information from Australia, Copify takes such steps as are reasonable in the circumstances, as required by APP 8, to ensure that overseas recipients handle the information consistently with the Australian Privacy Principles.
- Where the Clauses require an election: the optional docking clause applies; for Clause 9, Option 2 (general written authorisation) applies with the notice period stated in section 8; for Clause 11, the optional independent dispute resolution body is not selected; for Clause 17, the governing law is that of Ireland; and for Clause 18(b), the forum is the courts of Ireland.
10. Assistance with Data Subject Requests
Taking into account the nature of the processing, Copify assists the Merchant by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Merchant's obligation to respond to requests to exercise data subject rights. In practice this operates as follows:
- Copify implements Shopify's customers/data_request webhook and will provide the Merchant with any personal data Copify holds relating to the identified data subject.
- Copify implements Shopify's customers/redact webhook, which erases the identified customer record from Copify's systems and removes or redacts the associated identifiers from related logs and order records.
- Copify implements Shopify's shop/redact webhook, which erases the store's data from Copify's database and object storage.
- Because customer and order records are processed in transit rather than stored, the authoritative copy of a data subject's personal data ordinarily remains in the Merchant's Shopify stores, where the Merchant can action requests directly.
- If a data subject contacts Copify directly, Copify will not respond substantively but will, without undue delay, refer them to the Merchant and notify the Merchant of the request.
11. Personal Data Breach Notification
Copify notifies the Merchant without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting personal data processed under this DPA. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information. Where that detail is not all available at once, Copify will provide it in phases without undue further delay. Copify will assist the Merchant in meeting the Merchant's own notification obligations to supervisory authorities and to affected data subjects.
12. Data Protection Impact Assessments
Copify provides the Merchant with reasonable assistance in carrying out data protection impact assessments and, where required, in prior consultation with a supervisory authority, in each case taking into account the nature of the processing and the information available to Copify.
13. Deletion and Return of Personal Data
On termination of the Terms of Service, on uninstallation of the app, or at the Merchant's written request, Copify will delete the personal data it processes on the Merchant's behalf, except to the extent that Applicable Data Protection Law requires it to be retained. Specifically:
- Uninstalling the app immediately revokes and blanks the stored Shopify access credentials and halts all data flows for that store.
- Shopify's shop/redact webhook, sent after uninstall, triggers erasure of the store's records and stored backup objects from Copify's database and object storage.
- The Merchant may request deletion at any time before that by contacting hello@digitallycrafted.au, and may export its data through the app prior to termination.
- Backups, logs and version history are deleted on the schedules stated in Annex I; any residual copies held in system backups are overwritten in the ordinary course and remain subject to this DPA until they are.
14. Audits and Compliance Information
Copify makes available to the Merchant all information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and equivalent obligations, and allows for and contributes to audits, including inspections, conducted by the Merchant or an auditor it mandates. Audits are limited to once in any twelve month period unless required by a supervisory authority or following a personal data breach, must be requested with at least thirty (30) days' written notice, must be conducted during business hours without unreasonably disrupting Copify's operations, and are subject to confidentiality. Copify may satisfy an audit request by providing its current security documentation and its responses to a reasonable security questionnaire.
15. Australian Privacy Act Obligations
Where the Australian Privacy Act 1988 (Cth) applies, both parties will handle personal information in accordance with the Australian Privacy Principles. Copify will not do any act, or engage in any practice, that would breach an APP if done or engaged in by the Merchant. Where an eligible data breach under the Notifiable Data Breaches scheme is suspected, Copify will notify the Merchant promptly and assist with the assessment and with any notification to the Office of the Australian Information Commissioner and to affected individuals.
16. United States State Privacy Laws
Where the California Consumer Privacy Act as amended by the CPRA, or a comparable United States state privacy law, applies to the Merchant, Copify acts as a service provider or processor as those terms are defined in that law. Copify does not sell or share personal information; does not retain, use or disclose it for any purpose other than performing the services specified in the Terms of Service; does not combine it with personal information received from other sources except as permitted; and will not act outside the direct business relationship between the Merchant and the data subject. Copify certifies that it understands and will comply with these restrictions.
17. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, and any reference there to the liability of a party means the aggregate liability of that party under the Terms of Service and this DPA together. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law, including a data subject's right to compensation.
18. Precedence, Changes and Governing Law
In the event of a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service, in each case only to the extent of the conflict and only in respect of the subject matter of data protection. Copify may update this DPA where necessary to reflect changes in law, in its sub-processors or in the service, provided the change does not materially reduce the protection afforded to personal data; material changes will be notified in advance. This DPA is governed by the laws of New South Wales, Australia, and the parties submit to the non-exclusive jurisdiction of the courts of that State, without prejudice to section 9 in respect of the Standard Contractual Clauses.
Annex I — Description of the Processing
For the purposes of the Standard Contractual Clauses, the Merchant is the data exporter and controller and Digitally Crafted is the data importer and processor. The competent supervisory authority is determined by the Merchant's place of establishment or by its appointed EU representative.
- Categories of data subjects: the Merchant's retail customers; the Merchant's staff and authorised users of the Copify app; the Merchant's account and billing contact; and, where applicable, partner agency contacts.
- Categories of personal data processed in transit and not retained: customer name, email address, phone number, postal and shipping addresses, company name, customer notes and tags, email marketing consent status, order and draft order details, gift card holder identifiers, and the locale and network identifiers present in the corresponding Shopify records.
- Categories of personal data stored by Copify: Merchant account identifiers (name, email address, role, store domain), billing and subscription status, Shopify access credentials, partner contact details, and operational records such as sync logs, conflict records and version history, which may contain entity identifiers.
- Special categories of personal data: none. Copify does not request, require or intentionally process special category data, and the Merchant must not instruct it to do so.
- Nature and purpose of processing: reading records from a designated source store and creating or updating corresponding records in destination stores, together with logging, versioning, conflict resolution and backup, solely to provide the Copify service.
- Frequency of processing: continuous for the duration of the installation — real time, scheduled or on demand, according to the Merchant's configuration.
- Retention: customer and order records are not retained; sync logs are retained for 14 days for routine events and 90 days for material events; entity version history for 30 days; product and content backups for 30 days by default, configurable by plan; diagnostic telemetry for 14 days and lifecycle events for 180 days; account records for the life of the account and thereafter only as required by law.
- Transfers to sub-processors: as set out in Annex III, for the duration of the service and for the purposes stated there.
Annex II — Technical and Organisational Measures
Copify implements the following measures, which may evolve over time provided the overall level of protection is not reduced:
- Encryption in transit: TLS for all connections between the Merchant, Copify and the Shopify API.
- Encryption at rest: all stored data, including database contents and object storage, is encrypted at rest with AES-256-GCM by the underlying infrastructure. Shopify access and refresh credentials carry an additional layer of AES-256-GCM application level encryption with a key held only by Copify, so that a database disclosure yields ciphertext rather than usable store credentials. Third party migration connector credentials are encrypted on the same basis.
- Data minimisation by design: customer and order records are streamed from source to destination and are not written to Copify's database; scheduled backups cover products, collections, content and metadata only, and exclude customer and order records.
- Access control: authenticated, role-gated operator access to administrative surfaces; API keys stored only as irreversible hashes; per-store scoping of all queries.
- Source store integrity: the designated source store is treated as read-only, so the service cannot modify or delete records within it.
- Logging and auditability: sync logs, audit trails and conflict records with defined retention, supporting reconstruction of what was changed, when, and by whom.
- Resilience and recovery: managed, replicated database and object storage; scheduled backups with configurable retention and restore capability.
- Change control and monitoring: staged release of updates, error level telemetry, operational alerting, and a public status page.
- Authenticity of inbound requests: HMAC verification of Shopify webhooks, including the mandatory compliance webhooks.
- Personnel: confidentiality obligations, least privilege access, and revocation of access on role change or departure.
Annex III — Approved Sub-processors
As at the effective date of this DPA, Copify engages the sub-processors listed below. Copify engages no artificial intelligence or large language model provider, and no Merchant or customer data is transmitted to one.
- Cloudflare, Inc. — application hosting, database, object storage and content delivery. Processes all categories of data described in Annex I. Globally distributed edge infrastructure.
- Clerk, Inc. — authentication for Copify operator and administrative accounts only. Processes Copify staff identity data; does not process Merchant customer data. United States.
- Klaviyo, Inc. — lifecycle and onboarding email sent to the Merchant's account contact. Processes that contact's name, email address and store domain; does not process the Merchant's own customer records. United States.
- Crisp IM SARL — support chat. Processes the Merchant contact's email address and store identifiers. European Union.
- PostHog, Inc. — product analytics. Processes store domain and pseudonymous usage events; does not process customer records. United States.
- Honeycomb.io, Inc. — error and performance diagnostics. Processes technical trace data. United States.
- Slack Technologies, an affiliate of Salesforce, Inc. — delivery of sync notifications, engaged only where the Merchant connects a Slack workspace. Processes the notification content the Merchant configures. United States.
- Shopify Inc. — the underlying platform. Shopify acts as an independent controller rather than as a Copify sub-processor, and is listed here for completeness.
Contact and Requests
For data protection enquiries, sub-processor objections, audit requests or a countersigned copy of this agreement, contact our privacy team at hello@digitallycrafted.au