Data Processing Agreement
Last updated: 2026-08-15
1. Definitions
Terms used but not defined below have the meanings given in the UK GDPR / EU GDPR (Regulation 2016/679) as applicable to the Merchant. Where the Merchant is subject to the CCPA/CPRA, references to “Controller” also include “Business,” and “Processor” also includes “Service Provider” as those terms are defined under California law.
2. Roles and scope
The Merchant is the Controller of any personal data of its end customers that may be processed by the Service. Trident BI is the Processor of such personal data and acts only on documented instructions from the Controller.
By design, the Service does not require and does not persistend-customer personal data. It operates on public product catalogues and the Merchant's own product/order aggregates. Any customer PII incidentally received (for example, in a Shopify webhook payload not requested by the Service) is discarded without persistence.
3. Subject matter, duration, nature and purpose
- Subject matter: processing operations necessary to provide the Service.
- Duration: the term of the Merchant's active installation, plus up to 30 days for backup roll-off after uninstall.
- Nature and purpose:automated collection of public product-catalogue data, statistical modelling, delivery of alerts and digests to the Merchant, and (upon explicit Merchant instruction) writing price changes to the Merchant's Shopify store.
- Categories of data subjects: the merchant admin user; incidentally, end customers of the Merchant only if PII is submitted, which the Service is designed to avoid.
- Categories of personal data: merchant admin email; Shopify shop domain and access token; incidental order metadata (product ID, quantity, order timestamp) if
read_ordersis granted (contains no customer PII by design).
4. Processor obligations
Trident BI will:
- Process personal data only on the documented instructions of the Controller, including with regard to transfers of personal data to a third country, unless required to do so by law (in which case Trident BI will notify the Controller before processing unless prohibited from doing so).
- Ensure that persons authorised to process personal data are bound by confidentiality obligations.
- Implement the technical and organisational security measures described in Section 9 below.
- Assist the Controller with obligations under Articles 32–36 UK/EU GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to Trident BI.
- At the Controller's election, delete or return all personal data at the end of the provision of Services, and delete existing copies unless retention is required by law.
- Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits.
5. Sub-processors
The Controller grants Trident BI general authorisation to engage sub-processors, provided that Trident BI:
- Maintains a current list of sub-processors in the Privacy Policy, section 6
- Imposes on each sub-processor data-protection obligations no less onerous than those set out in this DPA
- Remains liable to the Controller for the performance of each sub-processor's obligations
Sub-processor notification:Trident BI will notify the Controller of any intended addition or replacement of a sub-processor by updating the Privacy Policy and (for material changes) surfacing an in-app notice, giving the Controller at least thirty (30) days to object. If the Controller reasonably objects on demonstrable data-protection grounds, the Controller's sole remedy is to terminate the Service without penalty for the remainder of any pre-paid term.
6. International transfers
Where personal data is transferred out of the UK or EEA in the course of providing the Service, the parties incorporate, by reference:
- The EU Commission's Standard Contractual Clauses of 4 June 2021 (Module Two: controller-to-processor) for transfers subject to EU GDPR; and
- The UK International Data Transfer Addendum to the EU Standard Contractual Clauses, version B1.0, for transfers subject to UK GDPR.
The parties agree the SCCs are entered into as follows: the Controller is the “data exporter”; Trident BI is the “data importer”; the governing-law and forum options in the SCCs are set to England & Wales; the docking clause is not selected; and the description of transfer, categories of data, and security measures are as set out in this DPA and the Privacy Policy.
7. Data subject rights and assistance
Trident BI will, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights. Requests received by Trident BI relating to a data subject of the Controller will be forwarded to the Controller without undue delay; Trident BI will not respond to such a request without the Controller's instruction.
8. Personal-data breach notification
Trident BI will notify the Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware of a personal-data breach affecting personal data processed on behalf of the Controller. The notification will describe, to the extent then known: the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences, and the measures taken or proposed to address the breach.
9. Security measures (Article 32 UK/EU GDPR)
Trident BI implements the following technical and organisational measures:
- TLS 1.2+ for all data in transit; database TLS enforced with certificate validation
- Encryption at rest for all persistent stores (managed by Neon on AWS
us-east-1) - Session-token-based authentication for all merchant API endpoints; HMAC-signed webhook payloads
- Principle-of-least-privilege for internal access; access to production is limited to a small number of authorised personnel
- Audit logging of merchant-initiated settings changes and privileged operations
- Automated backups managed by the database sub-processor with 7–30 day retention
- Secure software-development lifecycle; dependency-vulnerability scanning; static type checking
- Sub-processors of record are SOC 2 Type II or equivalent (Neon, Vercel, Anthropic, Resend)
Measures may be updated over time. Updates will only enhance the level of security.
10. Deletion or return of personal data
Following termination of the Service (i.e. uninstall of the Shopify app or expiry of the Controller's account), Trident BI will delete all personal data processed on behalf of the Controller from operational storage within forty-eight (48) hours in fulfilment of Shopify's shop/redact webhook. Encrypted backups managed by the database sub-processor will roll off within a further thirty (30) days. Where the Controller requests a return of personal data before deletion, Trident BI will provide it in a commonly-used, structured, machine-readable format.
11. Audits
Trident BI will make available to the Controller, on reasonable prior written request, all information reasonably necessary to demonstrate compliance with this DPA. Given the SMB context of the Service, in the first instance Trident BI will satisfy audit requests by providing existing certifications, penetration-test summaries, and completed security questionnaires. Where an on-site or independent audit is required to satisfy a specific regulatory obligation of the Controller, the parties will agree the scope and cost reasonably in advance; the Controller will bear reasonable third-party audit costs.
12. Liability
The liability provisions of the Terms of Service (section 8 — Limitation of liability) apply to all claims under this DPA. Nothing in this DPA is intended to exclude or limit either party's liability where such exclusion or limitation is prohibited by applicable data-protection law.
13. Order of precedence
If there is a conflict between this DPA, the Terms of Service, and the Privacy Policy in relation to the processing of personal data, this DPA prevails. In relation to all other matters, the Terms of Service prevail.
14. Term and termination
This DPA takes effect on the date the Merchant installs the Service or accepts the current Terms of Service, whichever is later, and continues for so long as Trident BI processes personal data on behalf of the Merchant. Sections that by their nature should survive termination (including 8, 9, 10, 12, and 13) will do so.
15. Governing law
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction over any dispute, subject to any mandatory data-protection rights of a data subject to complain to a supervisory authority.
16. Countersignature
Acceptance by the Merchant of the Terms of Service (recorded in the Service's audit log with version and timestamp) constitutes acceptance of this DPA. A separately countersigned copy is available on request for enterprise procurement. Requests: dean@tridentbi.com.
17. Contact
Trident BI Limited · dean@tridentbi.com

