Data Processing Addendum (UK GDPR Article 28) — UK Carrier Sync
Version 1.0. Parties: the merchant (“Controller”) and World Gig Insider Ltd (“Processor”).
- Subject matter and duration. Processing of order and customer data to create shipments in the Controller’s carrier account, for as long as the app is installed plus the retention period in clause 7.
- Nature and purpose. Receiving order webhooks from Shopify; transmitting recipient details, item details and customs data to the Controller’s carrier account; retrieving labels and tracking; displaying errors.
- Data and data subjects. Customers of the Controller: name, delivery address, e-mail, phone, order contents and values. No special-category data.
- Processor obligations. The Processor shall: (a) process only on the Controller’s documented instructions (the app settings and these terms); (b) ensure persons authorised to process are bound by confidentiality; (c) implement appropriate technical and organisational measures (Annex 1); (d) not engage another processor without general written authorisation (Annex 2 lists current sub-processors; 30 days’ notice of changes with right to object); (e) assist the Controller with data-subject requests and Articles 32–36; (f) delete or return all personal data at the end of the service (clause 7); (g) make available information necessary to demonstrate compliance and allow audits on reasonable notice, no more than once a year unless required by a supervisory authority; (h) notify the Controller without undue delay, and in any event within 48 hours, of a personal data breach.
- Controller obligations. The Controller warrants it has a lawful basis and has given customers the information required by Article 13, including that data is shared with the carrier (an independent controller under the carrier’s terms).
- International transfers. Data is hosted in the UK/EEA (Fly.io, London region). Any transfer outside the UK will be under the UK IDTA/Addendum or an adequacy regulation.
- Retention and deletion. Order data deleted 30 days
after receipt; all Controller data deleted within 30 days of uninstall;
Shopify
shop/redactandcustomers/redactrequests honoured automatically. - Liability. As in the App Terms.
Annex 1 — Security measures: TLS 1.2+ in transit; encryption at rest (database and backups); separate production and test environments; least-privilege access with MFA for staff; access logging to protected data; incident response procedure; data minimisation (only fields needed for the shipment); secrets in a managed vault. Annex 2 — Sub-processors: Fly.io (London, UK); none yet (alerts logged); Shopify (platform). The carrier (Royal Mail/Evri) is an independent controller, not a sub-processor.