Data Processing Agreement (DPA)

Version: 2026-09-18

Last updated: September 18, 2026

This Data Processing Agreement ("DPA") applies between the Shopify merchant that installs or uses Contact AutoResponder ("Controller") and WebPanda Solutions ("Processor"). This DPA forms part of the agreement for use of the App and governs the processing of personal data on behalf of Controller in accordance with Article 28 GDPR and, where applicable, UK GDPR and Swiss data protection law.

Execution mechanism: By enabling and using the App and/or by accepting legal terms in the App interface, Controller agrees to this DPA.

1. Scope and Roles

1.1 Controller determines the purposes and means of processing personal data.

1.2 Processor processes personal data only on Controller's documented instructions as set out in this DPA, the App configuration selected by Controller, and documented support instructions, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which Processor is subject. In such a case, Processor shall inform Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

1.3 Processor shall immediately inform Controller if, in Processor's opinion, an instruction from Controller infringes the GDPR or other applicable data protection provisions.

1.4 This DPA applies only to processing where Processor acts as a processor or service provider on behalf of Controller.

2. Subject Matter, Duration, Nature, and Purpose

  • Subject matter: automated transactional reply emails triggered by storefront form submissions.
  • Duration: for as long as the App is installed and active, plus any limited retention period required by law or security operations.
  • Nature of processing: collection, transmission, and use of form submission data for autoresponder delivery, plus storage of merchant configuration data required to provide the service.
  • Purpose: provide and secure the App, prevent abuse, and support merchant operations.

For clarity, Processor stores merchant configuration data in its own app database. Storefront customer submission content is processed transiently for autoresponder delivery and is not stored in Processor's own app database for this flow.

Mailchimp Transactional (formerly Mandrill), acting as a subprocessor for email delivery, may retain delivery-related message data for a limited period, up to 90 days, according to provider settings and policies.

3. Types of Personal Data and Data Subjects

  • Data subjects: merchant staff users and storefront visitors/customers submitting forms.
  • Personal data categories: name, email address, phone number (if provided), message content, and related transactional metadata.

4. Controller Obligations

  • Controller is responsible for lawful basis, transparency notices, and compliance with applicable privacy and marketing laws.
  • Controller confirms that it has all rights and permissions needed for Processor to process personal data under this DPA.

5. Processor Obligations

  • Process personal data only on documented instructions from Controller.
  • Ensure personnel authorized to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Notify Controller without undue delay after becoming aware of a personal data breach affecting processing under this DPA.

6. Security and Confidentiality

We implement reasonable technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, and we limit access to authorized personnel only.

A summary of current technical and organizational measures is included in Annex B.

7. Subprocessors

7.1 Controller provides general written authorisation for Processor to engage the subprocessors listed in Annex C where necessary to provide the App, including Shopify platform services and Mailchimp Transactional (formerly Mandrill) for email delivery.

7.2 Processor will inform Controller of any intended addition or replacement of subprocessors (for example by updating Annex C of this DPA and its version), giving Controller the opportunity to object to such changes. If Controller reasonably objects on data protection grounds and no resolution is found, Controller may stop using the App by uninstalling it.

7.3 Processor will impose data protection obligations on each subprocessor that are materially equivalent to those set out in this DPA, by way of a contract or other legal act. Where a subprocessor fails to fulfil its data protection obligations, Processor remains fully liable to Controller for the performance of that subprocessor's obligations.

8. International Data Transfers

Where personal data is transferred outside the EEA/UK/Switzerland, Processor will use a valid transfer mechanism required by applicable law, such as adequacy decisions, Standard Contractual Clauses, or other permitted safeguards.

9. Data Subject Rights and Compliance Assistance

Taking into account the nature of processing, Processor will provide reasonable assistance to Controller for data subject rights requests and for compliance obligations relating to security assessments, breach notifications, and consultations with supervisory authorities where required.

10. Deletion or Return of Data

Upon termination of the service, Processor will, at the choice of Controller, delete or return all in-scope personal data to Controller and delete existing copies, unless storage of the personal data is required by Union or Member State law.

Unless a longer period is legally required, Processor targets deletion or irreversible anonymization of in-scope personal data in its systems within 90 days of app uninstallation or account closure.

11. Audit and Information Rights

Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable audits or assessments where required by applicable law.

To protect security and other customers, audit requests must be reasonable in scope, no more than once per year unless legally required or prompted by a security incident, and subject to confidentiality.

12. Order of Precedence

If there is a conflict between this DPA and other service terms, this DPA governs with respect to personal data processing obligations.

13. Liability and Governing Terms

Liability arising out of this DPA is subject to liability terms in the underlying service terms, except where mandatory data protection law requires otherwise.

14. Contact Points

  • Processor contact: support@webpanda-solutions.com
  • Controller contact: the email/contact details associated with the merchant Shopify account and billing profile.

Annex A - Details of Processing

  • Subject matter: transactional autoresponder email delivery.
  • Duration: for the App usage period plus limited retention for legal, security, and operational obligations.
  • Nature/purpose: process storefront form submissions to send automatic replies; store merchant configuration; maintain security and abuse prevention.
  • Data subjects: merchant staff users and storefront visitors/customers.
  • Personal data: name, email address, phone number (if provided), message content, and delivery metadata.
  • Special categories: Controller must not intentionally send special category data unless lawful and strictly necessary.

Annex B - Technical and Organizational Measures (TOMs)

  • Access controls: access to production systems is limited to authorized personnel based on role.
  • Credential security: secrets and API credentials are managed using secure environment configuration practices.
  • Transmission security: data is transmitted over encrypted channels (for example HTTPS/TLS and secure SMTP transport where applicable).
  • Change and release controls: code changes are reviewed and deployed through controlled workflows.
  • Incident response: Processor maintains incident handling procedures and will notify Controller without undue delay when legally required.
  • Data minimization: customer submission content is processed transiently for delivery and not stored long-term in Processor's app database for this flow.

Annex C - Subprocessors and Transfer Safeguards

  • Shopify Inc. and affiliates - platform integration, authentication, billing, and app embedding.
  • Mailchimp Transactional (formerly Mandrill) - transactional email delivery and delivery-related operational logs (up to 90 days in current setup).
  • Hosting and infrastructure providers - application hosting, runtime, and database operations.
  • Transfers: where data is processed outside the EEA/UK/Switzerland, Processor and subprocessors rely on lawful transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, or equivalent safeguards.

Contact

For DPA requests or signed copy exchanges, contact support@webpanda-solutions.com.