Data Processing Addendum
This addendum sets out the Article 28 GDPR terms on which Express RV International LLC processes personal data on behalf of merchants. It takes effect automatically when you install Profytly — no signature is needed. If your organisation requires a countersigned copy, write to profytly@gmail.com and we will provide one.
1. Parties and roles
You, the merchant, are the controller. Express RV International LLC is the processor, acting only on your documented instructions. Your instructions are: the configuration you set inside the app, the platforms you connect, and this addendum together with the Terms of Service.
For our own merchant account data — your contact details, billing records, security logs — we act as controller, and our Privacy Policy governs.
2. Subject matter, duration, nature and purpose
Subject matter: provision of profit analytics for a Shopify store.
Duration: for as long as the app is installed, plus the deletion window in section 8.
Nature and purpose: reading order, product and inventory data and any connected advertising data, computing profit metrics from it, and displaying and exporting those metrics to you.
3. Categories of data and data subjects
Data subjects: you and any staff you authorise. Your customers are not data subjects of this processing: the app does not read customer personal data.
Categories of personal data: merchant contact details and shop identifiers; authentication and security logs; billing records. Order data is processed in a form that excludes customer identifiers — amounts, taxes, fees, line items and destination country only.
Special categories: none are processed. You must not use the app in a way that submits special-category data to it.
4. Our obligations
We will:
- Process personal data only on your documented instructions, including on transfers, unless required otherwise by law — in which case we tell you first, unless the law forbids it.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement the technical and organisational measures described in section 6.
- Respect the conditions in section 5 for engaging sub-processors.
- Assist you, by appropriate measures, in responding to data subject requests.
- Assist you with security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to us.
- Delete or return personal data at the end of the service, as set out in section 8.
- Make available the information needed to demonstrate compliance and allow for audits under section 9.
- Tell you immediately if we consider an instruction infringes data protection law.
5. Sub-processors
You give general authorisation for us to engage the sub-processors listed on our sub-processors page. We give at least 30 days' notice before adding or replacing one, and you may object on reasonable data protection grounds — in which case you may terminate without penalty, with a pro-rata refund. Each sub-processor is bound by written terms at least as protective as this addendum, and we remain fully liable to you for their performance.
6. Security measures (Article 32)
- TLS encryption for all data in transit; access tokens and secrets encrypted at rest with AES-256.
- Database not publicly reachable; access limited to the personnel who operate the service, on a need-to-know basis.
- HMAC verification of every incoming webhook and signed-token authentication for embedded requests, so requests cannot be forged.
- Back-office access protected by rate limiting with exponential lockout, and recorded in an append-only audit log.
- Encrypted backups taken nightly, stored off-site, rotated on a 14-day window, and restorable.
- Least-privilege scopes: the app requests read-only access and no customer personal data.
- Ongoing review of dependencies and prompt application of security updates.
7. International transfers
Merchant data is stored in the European Union (Fly.io, Frankfurt region) and we do not relocate it to the United States. However, we are established in the United States, so our personnel access EU-hosted data from outside the EEA, and that access is itself a restricted transfer.
Both that access and any processing by a sub-processor outside the EEA are covered by the European Commission's Standard Contractual Clauses (Decision 2021/914), controller-to- processor Module Two, which are incorporated into this addendum by reference and which prevail over it in the event of conflict. For UK data, the UK International Data Transfer Addendum to those clauses applies; for Swiss data, the clauses apply with the amendments the Swiss FDPIC requires.
Supplementary measures: data at rest stays in the EU; access is over encrypted channels, limited to named personnel and logged; tokens and secrets are encrypted at rest. We have never received a government or law enforcement request for merchant data. If we receive one we will challenge it where there are reasonable grounds, disclose only the minimum legally required, and notify you unless legally prohibited from doing so.
8. Deletion and return
On uninstall we delete all personal data processed on your behalf within 48 hours of receiving Shopify's shop/redact webhook. Encrypted backups age out within the 14-day rolling retention window. You can export your data at any time before that from the app's CSV export, and may request an export up to the point of deletion. We retain only what statutory retention obligations require, as set out in the Privacy Policy.
9. Audits
On reasonable written notice, no more than once a year unless a supervisory authority or a security incident requires otherwise, we will answer a reasonable security questionnaire and provide documentation on our measures. Where an on-site audit is legally required, it must be at your cost, during business hours, under confidentiality, and arranged so as not to disrupt the service or the data of other merchants.
10. Breach notification
We notify you without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting your data, with the nature of the breach, the categories and approximate volume of data involved, the likely consequences and the measures taken.
11. Liability and precedence
Liability under this addendum is subject to the limitations in the Terms of Service. Where this addendum conflicts with those Terms on the processing of personal data, this addendum prevails.
12. Contact
Data protection contact: profytly@gmail.com
Express RV International LLC, 2201 Menaul Blvd NE, Ste A, Albuquerque, NM 87107, United States
New Mexico Business ID 7272839