Version: 2026-09-18
Last updated: September 18, 2026
This Data Processing Agreement ("DPA") applies between the Shopify merchant that installs or uses Contact AutoResponder ("Controller") and WebPanda Solutions ("Processor"). This DPA forms part of the agreement for use of the App and governs the processing of personal data on behalf of Controller in accordance with Article 28 GDPR and, where applicable, UK GDPR and Swiss data protection law.
Execution mechanism: By enabling and using the App and/or by accepting legal terms in the App interface, Controller agrees to this DPA.
1.1 Controller determines the purposes and means of processing personal data.
1.2 Processor processes personal data only on Controller's documented instructions as set out in this DPA, the App configuration selected by Controller, and documented support instructions, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which Processor is subject. In such a case, Processor shall inform Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
1.3 Processor shall immediately inform Controller if, in Processor's opinion, an instruction from Controller infringes the GDPR or other applicable data protection provisions.
1.4 This DPA applies only to processing where Processor acts as a processor or service provider on behalf of Controller.
For clarity, Processor stores merchant configuration data in its own app database. Storefront customer submission content is processed transiently for autoresponder delivery and is not stored in Processor's own app database for this flow.
Mailchimp Transactional (formerly Mandrill), acting as a subprocessor for email delivery, may retain delivery-related message data for a limited period, up to 90 days, according to provider settings and policies.
We implement reasonable technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, and we limit access to authorized personnel only.
A summary of current technical and organizational measures is included in Annex B.
7.1 Controller provides general written authorisation for Processor to engage the subprocessors listed in Annex C where necessary to provide the App, including Shopify platform services and Mailchimp Transactional (formerly Mandrill) for email delivery.
7.2 Processor will inform Controller of any intended addition or replacement of subprocessors (for example by updating Annex C of this DPA and its version), giving Controller the opportunity to object to such changes. If Controller reasonably objects on data protection grounds and no resolution is found, Controller may stop using the App by uninstalling it.
7.3 Processor will impose data protection obligations on each subprocessor that are materially equivalent to those set out in this DPA, by way of a contract or other legal act. Where a subprocessor fails to fulfil its data protection obligations, Processor remains fully liable to Controller for the performance of that subprocessor's obligations.
Where personal data is transferred outside the EEA/UK/Switzerland, Processor will use a valid transfer mechanism required by applicable law, such as adequacy decisions, Standard Contractual Clauses, or other permitted safeguards.
Taking into account the nature of processing, Processor will provide reasonable assistance to Controller for data subject rights requests and for compliance obligations relating to security assessments, breach notifications, and consultations with supervisory authorities where required.
Upon termination of the service, Processor will, at the choice of Controller, delete or return all in-scope personal data to Controller and delete existing copies, unless storage of the personal data is required by Union or Member State law.
Unless a longer period is legally required, Processor targets deletion or irreversible anonymization of in-scope personal data in its systems within 90 days of app uninstallation or account closure.
Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable audits or assessments where required by applicable law.
To protect security and other customers, audit requests must be reasonable in scope, no more than once per year unless legally required or prompted by a security incident, and subject to confidentiality.
If there is a conflict between this DPA and other service terms, this DPA governs with respect to personal data processing obligations.
Liability arising out of this DPA is subject to liability terms in the underlying service terms, except where mandatory data protection law requires otherwise.
For DPA requests or signed copy exchanges, contact support@webpanda-solutions.com.