Data Processing Agreement
Last updated 27 July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions between Uniligo (“Processor”) and the customer (“Controller”). It applies where Uniligo processes personal data on the Controller’s behalf in the course of providing the service, and it takes effect automatically when the Controller accepts those terms.
It reflects Article 28 of the UK GDPR and of Regulation (EU) 2016/679. Where the Controller requires a signed counterpart or their own paper, write to privacy@uniligo.com.
1. Roles
The Controller determines the purposes and means of processing personal data relating to their own customers. Uniligo processes that data only on documented instructions from the Controller. Using the service — connecting a channel, running a sync, opening a report — constitutes such an instruction.
Uniligo is an independent controller for the Controller’s own account data (names, email addresses, authentication records), which is governed by the Privacy Policy rather than by this DPA.
2. Subject matter and duration
- Subject matter: providing a consolidated order and fulfilment dashboard.
- Duration: for as long as the Controller’s workspace is open, plus the retention periods in section 9.
- Nature and purpose: importing, storing, aggregating and displaying order and fulfilment records; producing derived operational metrics.
3. Categories of data subject and personal data
Data subjects: the Controller’s customers, and the Controller’s own staff who hold accounts.
| Category | Processed? | Note |
|---|---|---|
| Order identifiers, references, channel | Yes | How an order is identified |
| Line items: SKU, quantity, price | Yes | |
| Order value, timestamps, fulfilment state, warehouse, carrier | Yes | |
| Customer name | No | Never requested from the provider |
| Customer email address | No | Removed on ingest |
| Telephone and fax numbers | No | Removed on ingest |
| Postal addresses | No | Removed on ingest |
| Payment card or bank details | No | Never received |
| Special category data (Article 9) | No | Not requested; must not be submitted |
Uniligo holds no customer personal data, and this is enforced in code rather than by policy. The Processor does not request the customer record from Shopify at all, and email addresses, telephone and fax numbers and postal address fields are stripped from every provider response before it reaches the database — including the raw payload retained for diagnostics.
The data is therefore not held, not backed up, and not available to be disclosed. The
Processor holds neither the read_customers permission nor approval to read
Shopify’s protected customer fields.
4. Processor obligations
Uniligo shall:
- Process personal data only on the Controller’s documented instructions, including as to international transfers, unless required otherwise by law — in which case we will inform the Controller first unless that law forbids it.
- Ensure that people authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures in section 5.
- Respect the conditions in section 6 for engaging sub-processors.
- Assist the Controller, so far as reasonably possible, in responding to data subject requests (section 7).
- Assist the Controller with data protection impact assessments and with prior consultation of a supervisory authority, taking into account the nature of the processing and the information available to us.
- Delete or return personal data at the Controller’s choice on termination (section 9).
- Make available the information necessary to demonstrate compliance, and allow for audits (section 10).
- Inform the Controller promptly if, in our opinion, an instruction infringes data protection law.
5. Security measures
Uniligo maintains appropriate technical and organisational measures, having regard to the state of the art and the risks presented. Specifically:
- Data minimisation at ingest. No customer record is requested from the provider, and direct contact details are removed before storage, as described in section 3.
- Tenant isolation. Each workspace’s records are separated by PostgreSQL row-level security, enforced by the database rather than by application code. The application connects under a role that cannot bypass those policies, and a query arriving without a workspace context returns no rows.
- Encryption in transit. TLS throughout.
- Encryption of credentials at rest. Provider access tokens and API keys are encrypted with AES-256-GCM.
- Authentication. Passwords are stored only as scrypt hashes; authentication endpoints are rate limited.
- Least privilege. Access scopes requested from connected platforms are read-only.
- Logging. Operational events are logged without personal data.
6. Sub-processors
The Controller gives general authorisation for the sub-processors below.
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway Corporation | Application hosting and database | United States |
| Resend | Transactional email only — no order data | United States |
| Google LLC (Gemini) | Optional AI features, only where the Controller supplies their own API key | United States |
The AI sub-processor receives aggregate operational facts only — sales channel, fulfilment stage and state, arrival timestamp, unit count and number of distinct SKU lines, plus daily totals. No customer names, order references or product-level detail are transmitted. Where the Controller does not enable the feature, no data is transmitted at all.
We will give at least 30 days’ notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees.
7. Data subject requests
Uniligo implements the Shopify compliance webhooks, so a request routed through the Controller’s store is actioned automatically:
- Access request. We record the request and provide the Controller with the data held for that customer within 30 days, for the Controller to disclose.
- Customer erasure. Little is held to erase — no name, email, telephone number or address — but the retained provider payload for the affected orders is deleted. The order records are preserved with nothing identifying a person in them, because deleting them would restate the Controller’s own revenue and fulfilment history.
- Shop erasure. All imported orders, line items, fulfilment events, channels, sync history and stored credentials for that store are deleted.
Where a data subject contacts Uniligo directly, we will refer them to the Controller and will not respond substantively without the Controller’s instruction.
8. Personal data breach
Uniligo will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where full information is not immediately available we will provide it in phases without undue further delay.
9. Return and deletion
- The Controller may export their data at any time while the workspace is open.
- On termination, personal data is deleted within 30 days unless the Controller asks in writing for it to be returned first.
- Routine backups are retained for up to 30 days and are then overwritten on a rolling basis.
- Uninstalling a Shopify store triggers deletion as described in the Privacy Policy.
10. Audit
Uniligo will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits conducted by the Controller or an auditor they mandate. Audits shall be on at least 30 days’ written notice, no more than once in any 12-month period unless a breach has occurred or a supervisory authority requires it, during business hours, and subject to confidentiality.
11. International transfers
Where personal data is transferred out of the UK or EEA, the transfer is made under the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, module two: controller to processor) and, for UK transfers, the ICO’s International Data Transfer Addendum. Those clauses are incorporated into this DPA by reference. Where they conflict with this DPA, the clauses prevail.
12. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms & Conditions. In the event of conflict between this DPA and those terms, this DPA prevails in respect of the processing of personal data.
13. Contact
Data protection enquiries: privacy@uniligo.com.