Data Processing Agreement

Last updated 27 July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions between Uniligo (“Processor”) and the customer (“Controller”). It applies where Uniligo processes personal data on the Controller’s behalf in the course of providing the service, and it takes effect automatically when the Controller accepts those terms.

It reflects Article 28 of the UK GDPR and of Regulation (EU) 2016/679. Where the Controller requires a signed counterpart or their own paper, write to privacy@uniligo.com.

1. Roles

The Controller determines the purposes and means of processing personal data relating to their own customers. Uniligo processes that data only on documented instructions from the Controller. Using the service — connecting a channel, running a sync, opening a report — constitutes such an instruction.

Uniligo is an independent controller for the Controller’s own account data (names, email addresses, authentication records), which is governed by the Privacy Policy rather than by this DPA.

2. Subject matter and duration

3. Categories of data subject and personal data

Data subjects: the Controller’s customers, and the Controller’s own staff who hold accounts.

CategoryProcessed?Note
Order identifiers, references, channelYesHow an order is identified
Line items: SKU, quantity, priceYes
Order value, timestamps, fulfilment state, warehouse, carrierYes
Customer nameNoNever requested from the provider
Customer email addressNoRemoved on ingest
Telephone and fax numbersNoRemoved on ingest
Postal addressesNoRemoved on ingest
Payment card or bank detailsNoNever received
Special category data (Article 9)NoNot requested; must not be submitted

Uniligo holds no customer personal data, and this is enforced in code rather than by policy. The Processor does not request the customer record from Shopify at all, and email addresses, telephone and fax numbers and postal address fields are stripped from every provider response before it reaches the database — including the raw payload retained for diagnostics.

The data is therefore not held, not backed up, and not available to be disclosed. The Processor holds neither the read_customers permission nor approval to read Shopify’s protected customer fields.

4. Processor obligations

Uniligo shall:

5. Security measures

Uniligo maintains appropriate technical and organisational measures, having regard to the state of the art and the risks presented. Specifically:

6. Sub-processors

The Controller gives general authorisation for the sub-processors below.

Sub-processorPurposeLocation
Railway CorporationApplication hosting and databaseUnited States
ResendTransactional email only — no order dataUnited States
Google LLC (Gemini)Optional AI features, only where the Controller supplies their own API keyUnited States

The AI sub-processor receives aggregate operational facts only — sales channel, fulfilment stage and state, arrival timestamp, unit count and number of distinct SKU lines, plus daily totals. No customer names, order references or product-level detail are transmitted. Where the Controller does not enable the feature, no data is transmitted at all.

We will give at least 30 days’ notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees.

7. Data subject requests

Uniligo implements the Shopify compliance webhooks, so a request routed through the Controller’s store is actioned automatically:

Where a data subject contacts Uniligo directly, we will refer them to the Controller and will not respond substantively without the Controller’s instruction.

8. Personal data breach

Uniligo will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where full information is not immediately available we will provide it in phases without undue further delay.

9. Return and deletion

10. Audit

Uniligo will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28, and will contribute to audits conducted by the Controller or an auditor they mandate. Audits shall be on at least 30 days’ written notice, no more than once in any 12-month period unless a breach has occurred or a supervisory authority requires it, during business hours, and subject to confidentiality.

11. International transfers

Where personal data is transferred out of the UK or EEA, the transfer is made under the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, module two: controller to processor) and, for UK transfers, the ICO’s International Data Transfer Addendum. Those clauses are incorporated into this DPA by reference. Where they conflict with this DPA, the clauses prevail.

12. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms & Conditions. In the event of conflict between this DPA and those terms, this DPA prevails in respect of the processing of personal data.

13. Contact

Data protection enquiries: privacy@uniligo.com.