Data Processing Addendum

Last updated September 6, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Subscription Concierge LLC, a Utah limited liability company ("Provider," "Subscription Concierge," "we") and the merchant that installs or uses the Subscription Concierge application ("Merchant," "you") (the "Agreement"). Where there is no separate signed Agreement, installing or using the app constitutes your acceptance of this DPA. It governs our processing of Personal Data that we handle on your behalf when you use the app. It works alongside our Privacy Policy; where the two conflict on the treatment of Merchant or customer Personal Data, this DPA controls.

1. Definitions

"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and comparable US state privacy laws.

"Controller," "Processor," "Data Subject," "Personal Data," and "processing" have the meanings given in the GDPR. "Business," "Service Provider," and "sale" have the meanings given in the CCPA. "Merchant Personal Data" means Personal Data contained in Shopify data that we process on your behalf under the Agreement, described in Annex I. "Sub-processor" means any third party engaged by us to process Merchant Personal Data.

2. Roles of the parties

For Merchant Personal Data, you are the Controller (or a Processor acting for another Controller) and Business, and we are your Processor and Service Provider. We process Merchant Personal Data only to provide and support the app, and only on your documented instructions, including as set out in this DPA and the app's configuration options. If we are legally required to process Merchant Personal Data for another purpose, we will tell you first unless the law prohibits it.

We act as an independent Controller for a limited set of data we need to run the business — Merchant account and staff contact details, authentication records, billing records, security and audit logs, and aggregate, non-identifying usage statistics. Our handling of that data is described in the Privacy Policy and is not governed by this DPA's Processor terms.

3. Scope, nature, and purpose of processing

The subject matter, duration, nature and purpose of the processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I. Processing continues for the duration of the Agreement and until deletion in accordance with Section 9.

Subscription Concierge is designed to minimize the Personal Data it processes. We do not copy a subscriber's name, email address, telephone number, or postal address into our database. Each customer record we hold is keyed to Shopify's opaque customer identifier; the underlying contact details remain in Shopify as the source of truth. We access Shopify's Customer and Order resources only through Protected Customer Data-gated APIs and only for the identifiers and subscription, order, and product data needed to operate the features you enable.

4. Merchant instructions and compliance

5. Confidentiality

We restrict access to Merchant Personal Data to personnel who need it to provide or support the app, who are bound by written confidentiality obligations and trained on their data-protection responsibilities. Access by our personnel to records that identify an individual customer or subscription is logged.

6. Security measures

We implement and maintain the technical and organizational measures set out in Annex II, designed to protect Merchant Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. We may update those measures over time provided the overall level of protection is not reduced.

7. Sub-processors

8. Assistance to the Merchant

9. Personal data breach notification

We will notify you without undue delay, and no later than 72 hours, after confirming a Personal Data breach affecting Merchant Personal Data. The notice will describe the nature of the breach, the data and, where known, the Data Subjects affected, the likely consequences, and the measures taken or proposed. We will cooperate with you and take reasonable steps to mitigate and remediate the breach.

10. Return and deletion

On termination of the Agreement, or on your earlier written request, we will delete Merchant Personal Data within 30 days, except where retention is required by law. When you uninstall the app or an erasure request comes through Shopify, the subscription, queue, dunning, gift, skip, and access-log records for the affected shop or customer are deleted. Independently of any request, canceled-subscription history and staff access-log entries are automatically purged after 365 days. Backups containing Merchant Personal Data are overwritten on their normal rotation cycle and are not restored except for disaster recovery.

11. International transfers

Merchant Personal Data is processed and stored in the United States. Where Merchant Personal Data originates in the European Economic Area, the United Kingdom, or Switzerland, the transfer to us and our Sub-processors is made under the European Commission's Standard Contractual Clauses (Module Two or Module Three as applicable), the UK International Data Transfer Addendum, and the Swiss addendum, which are incorporated into this DPA by reference and completed with the information in the Annexes. By installing the app you instruct us to carry out that transfer. We rely on the data-processing agreements and transfer mechanisms of the Sub-processors in Annex III for onward transfers.

12. Audit

On reasonable written request, no more than once per year (unless required by a supervisory authority or following a Personal Data breach), we will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits. Audits will be conducted during business hours, with reasonable advance notice, subject to confidentiality obligations, and in a manner that does not disrupt our operations or compromise other customers' data. We may satisfy an audit request by providing third-party reports or questionnaires where available.

13. California and US state privacy terms

We act as a Service Provider (and, under other US state laws, a "processor" or "contractor"). We will not: (a) sell or share Merchant Personal Data; (b) retain, use, or disclose it for any purpose other than performing the services in the Agreement, or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship; or (d) combine it with Personal Data received from another source, except as the CCPA permits for a Service Provider. We certify that we understand and will comply with these restrictions. You may take reasonable steps to stop and remediate unauthorized use of Merchant Personal Data.

14. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. If there is no separate Agreement with a liability cap, each party's aggregate liability arising out of this DPA is limited to the greater of the fees paid or payable for the app in the 12 months before the event giving rise to the claim, or USD 100. In the event of a conflict, this DPA prevails over the rest of the Agreement and the Privacy Policy on the subject of Processor obligations for Merchant Personal Data; the Standard Contractual Clauses prevail over this DPA.

15. Governing law

This DPA is governed by the law stated in the Agreement, or, if none is stated, the laws of the State of Utah, United States, without regard to its conflict-of-laws rules, except that the Standard Contractual Clauses are governed by the law they specify.

Annex I — Details of processing

ItemDetail
RolesMerchant: Controller / Business. Provider: Processor / Service Provider.
Subject matterProvision of the Subscription Concierge app for managing recurring-order subscription programs on the Merchant's Shopify store.
DurationThe term of the Agreement, plus the deletion period in Section 10.
Nature and purposeStoring, organizing, retrieving, using, and erasing data to operate subscription management, the customer self-service portal, queue and anchor management, dunning and payment-recovery notifications, checkout and post-purchase upsells, retention offers, product recommendations, and merchant analytics.
Categories of Data SubjectsThe Merchant's customers who hold or held a subscription; the Merchant's staff who use the merchant dashboard.
Categories of Personal Data — customersShopify customer identifier; subscription, contract, and queue state; billing cycle dates and status; associated product and variant identifiers; order identifiers and line items for fulfilled orders; cancellation reasons voluntarily provided. Name, email, phone, and address are not stored by the app unless the Merchant later enables a feature that requires them and access is granted.
Categories of Personal Data — staffWork email address, assigned role (Admin / Viewer), authentication session records, and access-log entries (who viewed which record, and when).
Special category dataNone requested or intentionally processed.
FrequencyContinuous for the duration of the Agreement.
Competent supervisory authorityDetermined by the Merchant's establishment or the SCCs; where the Merchant is EEA-established, its lead supervisory authority.

Annex II — Technical and organizational measures

Annex III — Sub-processors

Sub-processorPurposeLocation
Amazon Web Services, Inc.Cloud hosting and compute (managed Kubernetes), managed PostgreSQL database, message queue and event routing, object storage, managed model inference for product recommendations, and secrets management.United States
Cloudflare, Inc.DNS, TLS termination, content delivery, edge security, aggregate traffic analytics, and inbound email routing for the support address.Global (edge); configuration in the United States
Transactional email provider (Amazon SES)Delivery of transactional email such as failed-payment notices. Engaged only where the Merchant enables a feature that sends email to identified recipients; not used while such features are disabled.United States

Shopify Inc. is the platform on which the app runs and the source of the data processed; it is the Merchant's own processor under the Merchant's agreements with Shopify and is not a Sub-processor of Provider.

Contact

Questions about this DPA, Sub-processor notifications, or data-protection matters: [email protected].

Legal notices to Provider: Subscription Concierge LLC, 11045 Lamasa Cir., Sandy, UT 84092, attention Data Protection, with a copy by email to the address above.