Skip to content

Data Processing Addendum

This Data Processing Addendum (“Addendum”) governs the processing of personal data that TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED, trading as Easify (“TIGREN COMPANY LIMITED,” “Easify,” “we,” “us,” or “our”) carries out on behalf of a merchant (“Customer,” “you”) in connection with the Easify apps installed on your Shopify store. It forms part of our Terms of Service and reflects the requirements of Article 28 of the UK and EU GDPR.

Last updated: September 10, 2026

1. Scope and Application

This Addendum applies whenever we process personal data on your behalf in the course of providing the Apps. It forms part of, and is incorporated into, our Terms of Service. Where this Addendum conflicts with the Terms of Service, this Addendum prevails in respect of the processing of personal data.

The processor under this Addendum is TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED (TIGREN COMPANY LIMITED), trading as Easify, business registration number 0105887692, of No. 2, Alley 113, Giap Bat Street, Tuong Mai Ward, Hanoi, Vietnam. The controller is the merchant that installed the Apps. Contact for all matters under this Addendum: support@tigren.com.

No signature is required for this Addendum to apply. If your compliance process needs a countersigned copy, email support@tigren.com and we will send our standard DPA for review and signature.


2. Definitions

  • “Apps” means the Easify applications installed on your Shopify store, together with the related support we provide, as described in our Terms of Service.
  • “Controller,” “Processor,” “Business,” “Service Provider,” “Data Subject,” “Processing” carry the meanings given to them in the applicable Data Protection Legislation.
  • “Data Protection Legislation” means the EU GDPR, the UK GDPR and its implementing legislation, the California Consumer Privacy Act as amended, applicable data breach notification laws, and any other law applicable to the processing carried out under this Addendum.
  • “Personal Data” means data that constitutes personal data under the Data Protection Legislation and that we process on your behalf in connection with the Apps.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
  • “Restricted Transfer” means a transfer of Personal Data to a country outside the UK or EEA that is not covered by an adequacy decision.
  • “SCCs” means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 and, for UK transfers, the UK International Data Transfer Addendum issued by the ICO.
  • “Sub-processor” means a third party engaged by us to process Personal Data on your behalf.

3. Roles of the Parties

For the purposes of the UK and EU GDPR, you are the Controller and we are the Processor of the Personal Data we handle on your behalf. For the purposes of the CCPA, you are the Business and we are the Service Provider.

You determine the purposes and means of the processing through your configuration and use of the Apps. We process Personal Data only on your documented instructions, which these terms, the Terms of Service, and your use of the Apps constitute. We do not determine the purpose of the processing, and we do not process the Personal Data for any purpose of our own.


4. Our Processing Obligations

When processing Personal Data on your behalf, we will:

  • Process it only as a Processor, for the purpose of providing the Apps, in accordance with your documented instructions.
  • Not retain, use, or disclose it for any purpose other than providing the Apps, except where the Data Protection Legislation expressly permits.
  • Not sell Personal Data and not share it for cross-context behavioural advertising.
  • Not combine it with data from other sources, except as the Data Protection Legislation authorizes.
  • Ensure that personnel with access to it are bound by confidentiality obligations and are trained appropriately.
  • Implement and maintain the technical and organizational measures set out in Appendix 2.
  • Notify you if we consider that an instruction from you conflicts with the Data Protection Legislation.
  • Notify you promptly of any inquiry we receive from a supervisory authority relating to the Personal Data we process for you.
  • Notify you of any binding request from a public authority for Personal Data we process for you, unless the law prohibits that notification, and challenge any request that appears unlawful.
  • Provide reasonable assistance with data protection impact assessments and related consultations, to the extent the Data Protection Legislation requires it of us.
  • Comply with the Data Protection Legislation applicable to us as a Processor.

5. Your Obligations

  • You will ensure you have the rights, authority, and lawful basis, including any consent required, to provide Personal Data to us for processing under this Addendum.
  • You will comply with your own obligations as a Controller, including providing the notices and honouring the rights your shoppers are entitled to.
  • You will not act in a way that causes us to breach the Data Protection Legislation.
  • You will tell us promptly about any request or inquiry you receive that is relevant to our obligations under this Addendum.
  • You are responsible for the settings you configure in the Apps, including which optional fields you collect from shoppers.

6. Data Subject Requests

You are responsible for responding to requests from your shoppers to exercise their rights. Where a shopper contacts us directly, we will direct them to you and will not respond on your behalf, except to confirm that we act as your processor.

We will provide reasonable assistance, as far as is necessary and technically feasible, to help you respond, including access, correction, deletion, and export of the Personal Data we hold for your store. Requests submitted through Shopify’s mandatory privacy webhooks are handled as described in section 8.


7. Personal Data Breach

We will notify you without undue delay after becoming aware of a confirmed Personal Data Breach affecting Personal Data we process for you, and will provide the information reasonably available to us: the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed.

You remain responsible for any notification owed to a supervisory authority or to affected data subjects. We will cooperate with you in good faith to investigate and remediate the breach.


8. Retention and Deletion

We retain Personal Data only for as long as needed to provide the Apps or as the law requires. On termination of the Terms of Service, or on uninstall of an app, we stop processing the Personal Data for that store and delete or anonymize it.

If you ask us before the deletion is carried out, we will first return or export the Personal Data we hold for your store in a commonly used format.

We follow Shopify’s mandatory data-redaction process for installed apps:

  • Shop redaction: Shopify sends the request 48 hours after you uninstall an app; we erase that store’s Personal Data within 30 days of receiving it.
  • Customer redaction: when a shopper asks for erasure, we delete or anonymize the Personal Data we hold in connection with that shopper within 30 days of receiving Shopify’s request.
  • Customer data request: we provide the order-related Personal Data we hold in connection with that shopper to you within 30 days of receiving Shopify’s request.

Where we are legally required to retain specific data, we keep only what the law requires and delete the rest. Aggregated or anonymized data that cannot be associated with an individual or with your store is not Personal Data and may be retained.


9. Sub-processors

You give us general authorization to engage Sub-processors. Each Sub-processor is engaged under a written contract that imposes data protection obligations no less protective than those in this Addendum, and we remain responsible for their performance.

Our current Sub-processors are:

  • Akamai: cloud infrastructure and hosting.
  • RunCloud: server management for our hosting environment.
  • Crisp: in-app live chat and support conversations.

We will notify you by email to your store contact address at least 14 days before adding or replacing a Sub-processor. You may object on reasonable data protection grounds within that period by writing to support@tigren.com. If we cannot provide the affected functionality without the Sub-processor, either party may terminate the affected app, and you will not be charged for the period after termination.


10. Processing Location and International Transfers

Personal Data is processed on Akamai cloud infrastructure, in the region assigned to each app:

  • Easify Custom Product Options: London, United Kingdom
  • Easify Box Bundle Builder: Dallas, Texas, United States
  • Easify Product Attachments: Dallas, Texas, United States
  • Easify Inventory Sync: Dallas, Texas, United States

Our other Sub-processors may process Personal Data outside the United Kingdom and the EEA, including in the United States.

Where a transfer is a Restricted Transfer, we rely on the SCCs or another mechanism recognized under the Data Protection Legislation, together with the technical measures in Appendix 2. The parties will cooperate in good faith to resolve any compliance issue arising from a Restricted Transfer.


11. Standard Contractual Clauses

For Restricted Transfers subject to the EU GDPR, the SCCs are incorporated into this Addendum by reference, with Module Two (controller to processor) applying: you are the data exporter, we are the data importer, the optional docking clause applies, the audit option in Clause 8.9 is exercised as described in section 12, and the governing law is the law of Ireland. Annexes I and II of the SCCs are populated by Appendix 1 and Appendix 2 of this Addendum, and Annex III, the list of Sub-processors, is populated by section 9.

For Restricted Transfers subject to the UK GDPR, the UK International Data Transfer Addendum is incorporated by reference on the same terms, with the laws of England and Wales governing it.


12. Audits and Information

On reasonable written request, and no more than once in any twelve-month period unless a supervisory authority requires otherwise, we will provide the information reasonably necessary to demonstrate our compliance with this Addendum, including summaries of our security measures and any attestations or certifications we hold.

Where an audit is required by the Data Protection Legislation and cannot be satisfied by that information, the parties will agree its scope, timing, and duration in advance, and you will bear the reasonable costs involved.


13. Order of Precedence, Changes, and Governing Law

This Addendum prevails over the Terms of Service in respect of the processing of Personal Data. If any provision of this Addendum is found invalid or unenforceable, it is severed and the remaining provisions stay in full force.

We may amend this Addendum on 30 days’ written notice, including by posting the revised version on this page. Continued use of the Apps after the notice period constitutes acceptance. If you do not accept an amendment, you may terminate the affected app during the notice period.

Except for the SCCs and the UK Addendum, which are governed by the laws stated in section 11, this Addendum is governed by the laws of Vietnam, and the competent courts of Hanoi, Vietnam have exclusive jurisdiction over any dispute arising out of it.

The liability provisions of the Terms of Service apply to claims under this Addendum, except where the Data Protection Legislation provides otherwise.


14. Appendix 1: Details of the Processing

  • Subject matter: provision of the Easify apps installed on your Shopify store, namely Easify Custom Product Options, Easify Box Bundle Builder, Easify Inventory Sync, and Easify Product Attachments, together with related support.
  • Duration: from installation until the Terms of Service end or the app is uninstalled, followed by the deletion process in section 8.
  • Nature and purpose: hosting, storage, retrieval, and display of the data needed to run the features you enable; responding to your support requests.
  • Categories of Personal Data: store and account data (Shopify domain, contact email, plan); app configuration; and order-linked customizations, options, bundles, and attachments, together with the product, variant, and order identifiers needed to render them. The Apps do not process shopper contact details and never process payment data.
  • Special categories: none. The Apps are not intended for the processing of special category data, and you must not configure them to collect it.
  • Categories of Data Subjects: your staff who use the Apps, and, indirectly, the shoppers whose orders the app-generated data relates to.
  • Frequency: continuous, for as long as the Apps are installed.

15. Appendix 2: Security Measures

  • Physical access control: our infrastructure providers operate data centres with security personnel, alarm systems, access control, and video surveillance.
  • System access control: access to systems processing Personal Data requires individual accounts with multi-factor authentication; changes go through a review process and are logged.
  • Data access control: access is granted on a least-privilege basis to authorized personnel only, and is reviewed periodically.
  • Transmission control: Personal Data is encrypted in transit over public networks and encrypted at rest on our infrastructure.
  • Availability control: regular backups, restoration testing, and documented recovery procedures protect against accidental loss or destruction.
  • Segregation: data is logically separated per store through application-level controls.
  • Personnel: staff with access are bound by confidentiality obligations and receive data protection guidance.

We may update these measures from time to time, provided no change materially reduces the overall level of security of the Apps.