Legal
Data processing agreement
Last updated: 9 September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between eplatforms ltd, a company registered in England and Wales under company number 3954521, whose registered office is the address recorded against that number at Companies House ("Processor", "we"), and the merchant installing the Order Exceptions app ("Controller", "you").
It is entered into automatically when you install the app, and governs our processing of personal data relating to your customers. It is designed to meet Article 28(3) of the UK GDPR and the EU GDPR.
Where this DPA conflicts with our general terms of service, this DPA prevails in respect of personal data.
1. Roles
You are the controller of personal data relating to your customers. We are the processor. We process that data only to provide the app to you.
For personal data about you and your staff — your store details, the alert recipients you configure, and your billing records — we act as controller, and our Privacy Policy applies instead.
2. Subject matter, duration, nature and purpose
Subject matter. Monitoring of refund and payment status on your store, whether it runs on Shopify, BigCommerce, WooCommerce or Shopware.
Duration. From installation until 48 hours after uninstallation, when Shopify sends the shop/redact webhook and we erase all data held for your store. Data within an active installation is additionally subject to the retention periods in clause 7.
Nature and purpose. To detect refunds where money has not reached the customer — a failed refund transaction, a refund stalled in a pending state, or a refund recorded with no payment transaction — and to notify you so you can resolve it.
3. Types of personal data
We process the following, obtained from the Shopify Admin API and Shopify webhooks under the read_orders scope:
- Shopify order, refund and transaction identifiers
- Order number
- Refund amount, order total and currency
- Payment gateway name, transaction status, gateway error code and message
- Timestamps relating to the order, refund and transaction
We do not process customer names, email addresses, postal addresses or telephone numbers. These fields are not read from the API response, not stored, not displayed, and never included in any notification.
We also do not request or store the free-text note attached to a refund, since it could contain anything your staff type into it.
4. Categories of data subjects
Your customers, to the extent that the data above can be linked back to them. Because we hold no direct identifiers, the data is pseudonymous in our systems and can be re-identified only by you, within your own Shopify admin.
5. Our obligations
We shall:
1. Process only on your documented instructions. Your instructions are this DPA, our terms, and the configuration choices you make in the app. If we believe an instruction infringes data protection law, we will tell you. 2. Not process for our own purposes. We do not sell personal data, use it for marketing, profiling, advertising or personalisation, or use it to train machine learning models. 3. Ensure confidentiality. Personnel authorised to process personal data are bound by written confidentiality obligations. 4. Implement appropriate security measures under Article 32, as described in clause 9. 5. Engage sub-processors only under clause 6. 6. Assist you in responding to data subject rights requests, taking account of the nature of processing. In practice we hold no identifying data, so we can rarely locate a specific individual; we will confirm this in writing where that is the answer. 7. Assist you with Articles 32 to 36 — security, breach notification, data protection impact assessments and prior consultation — taking account of the information available to us. 8. Delete data in accordance with clause 7. 9. Make available the information necessary to demonstrate compliance, and allow and contribute to audits under clause 10. 10. Notify you of a personal data breach without undue delay, and in any event within 48 hours of becoming aware, with the nature of the breach, the categories and approximate volume of records affected, the likely consequences, and the measures taken.
6. Sub-processors
You give general written authorisation for us to engage sub-processors. Our current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Application and database hosting | United Kingdom |
| eplatforms ltd's own mail server | Sending alert emails | United Kingdom |
We impose data protection obligations on each sub-processor no less protective than those in this DPA, and we remain fully liable to you for their performance.
We will give you at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate the app subscription without penalty.
Where you configure an outbound alert webhook, the destination is chosen and controlled by you. It is not our sub-processor, and you are responsible for its security and for any onward processing at that endpoint.
7. Retention and deletion
- Settled refund and transaction records, and closed exceptions, are deleted automatically after 180 days.
- Records carrying an unresolved exception are kept until resolved, because they represent money you may still owe a customer.
- Webhook replay-protection records are kept for 30 days.
- On uninstallation, your store is deactivated immediately and all data held for it is erased when Shopify sends the
shop/redactwebhook, 48 hours later. - You may request earlier deletion in writing at any time, and we will comply within 30 days.
Deleted records persist in encrypted, access-controlled backups until those backups age out, currently 7 days. Backups are never used to repopulate deleted data; if one is restored in a disaster-recovery event, deletions already applied are re-applied.
We retain no other copy after deletion except where required by law, in which case the data remains subject to this DPA.
8. International transfers
Personal data is hosted in the United Kingdom. Where we transfer personal data outside the UK or EEA, we do so under the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference, together with any supplementary measures required following a transfer impact assessment.
9. Security measures
| Measure | Implementation |
|---|---|
| Data minimisation | No customer names, emails, addresses or phone numbers are processed at all |
| Least privilege | Only the read_orders scope is requested |
| Encryption in transit | TLS for all connections, inbound and outbound |
| Encryption at rest | Provided by our database host |
| Authenticity of inbound data | Shopify webhooks verified by HMAC-SHA256; unsigned requests rejected |
| Authenticity of outbound data | Alert webhooks signed with HMAC-SHA256 |
| Tenant isolation | Every query is scoped to the authenticated store |
| Access control | Production access restricted to named personnel with multi-factor authentication |
| Resilience | Encrypted, access-controlled backups |
| Testing | Automated test suite covering data handling, including assertions that no customer identifier can enter a notification |
We may update these measures, provided the level of security is not reduced.
10. Audit
We will make available on request the information reasonably necessary to demonstrate compliance with this DPA, including our security documentation and the results of any third-party assessment.
You may audit no more than once in any 12-month period, on 30 days' written notice, at your own cost, during business hours, without unreasonable disruption and subject to confidentiality. Where an audit is triggered by a personal data breach affecting your data, this frequency limit does not apply.
11. Liability
Liability under this DPA is subject to the limitations and exclusions in our terms of service, save where those limitations are not permitted by law.
12. Contact
Data protection enquiries: [email protected]