1. Scope and Application
This Addendum applies whenever we process personal data on your behalf in the course of providing the Apps and that processing is subject to the EU GDPR: because you are established in the European Economic Area, or because you offer goods or services to, or monitor the behaviour of, data subjects in the EEA. It forms part of, and is incorporated into, our Terms of Service. Where this Addendum conflicts with the Terms of Service, this Addendum prevails in respect of the processing of personal data.
Processing subject to the UK GDPR is governed by our separate UK Data Processing Addendum. If your store is subject to both regimes, each Addendum applies to the processing within its own scope.
The processor under this Addendum is TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED (TIGREN COMPANY LIMITED), trading as Easify, business registration number 0105887692, of No. 2, Alley 113, Giap Bat Street, Tuong Mai Ward, Hanoi, Vietnam. The controller is the merchant that installed the Apps. Contact for all matters under this Addendum: support@tigren.com.
No signature is required for this Addendum to apply. If your compliance process needs a countersigned copy, email support@tigren.com and we will send our standard DPA for review and signature.
2. Definitions
- “Apps” means the Easify applications installed on your Shopify store, together with the related support we provide, as described in our Terms of Service.
- “EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation), together with the laws of EU Member States that supplement it.
- “Data Protection Legislation” means the EU GDPR, applicable Member State data protection and ePrivacy laws, and any other law of the European Union or a Member State that applies to the processing carried out under this Addendum.
- “Controller,” “Processor,” “Data Subject,” “Processing,” “Supervisory Authority” carry the meanings given to them in Article 4 of the EU GDPR.
- “EEA” means the European Economic Area: the Member States of the European Union together with Iceland, Liechtenstein, and Norway.
- “Personal Data” means data that constitutes personal data under the EU GDPR and that we process on your behalf in connection with the Apps.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- “Restricted Transfer” means a transfer of Personal Data to a country outside the EEA that is not the subject of an adequacy decision of the European Commission under Article 45 of the EU GDPR.
- “SCCs” means the standard contractual clauses for the transfer of personal data to third countries approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- “Sub-processor” means a third party engaged by us to process Personal Data on your behalf.
3. Roles of the Parties
For the purposes of the EU GDPR, you are the Controller and we are the Processor of the Personal Data we handle on your behalf.
You determine the purposes and means of the processing through your configuration and use of the Apps. We process Personal Data only on your documented instructions, which this Addendum, the Terms of Service, and your use of the Apps constitute. We do not determine the purpose of the processing, and we do not process the Personal Data for any purpose of our own.
If we are required by Union or Member State law to process Personal Data other than on your instructions, we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
4. Our Processing Obligations
In accordance with Article 28(3) of the EU GDPR, when processing Personal Data on your behalf we will:
- Process it only as a Processor, for the purpose of providing the Apps, in accordance with your documented instructions, including with regard to transfers of Personal Data to a third country.
- Not retain, use, or disclose it for any purpose other than providing the Apps, except where Union or Member State law requires.
- Not combine it with data from other sources, except as the Data Protection Legislation authorises.
- Ensure that personnel authorised to process it have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement and maintain the technical and organisational measures required by Article 32, as set out in Annex II.
- Respect the conditions in sections 9 and 10 for engaging Sub-processors and for international transfers.
- Assist you, by appropriate technical and organisational measures and insofar as possible, in fulfilling your obligation to respond to requests from Data Subjects under Chapter III of the EU GDPR.
- Assist you in meeting your obligations under Articles 32 to 36, including security, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of the processing and the information available to us.
- Delete or return all Personal Data at the end of the provision of the Apps, as described in section 8.
- Make available to you all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in section 12.
- Inform you immediately if, in our opinion, an instruction infringes the EU GDPR or other Union or Member State data protection provisions.
- Notify you promptly of any inquiry we receive from a Supervisory Authority relating to the Personal Data we process for you.
- Notify you of any binding request from a public authority for Personal Data we process for you, unless the law prohibits that notification, and challenge any request that appears unlawful.
5. Your Obligations
- You will ensure you have the rights, authority, and lawful basis under Article 6, including any consent required, to provide Personal Data to us for processing under this Addendum.
- You will comply with your own obligations as a Controller, including providing the information required by Articles 13 and 14 and honouring the rights your shoppers are entitled to under Chapter III.
- You will not act in a way that causes us to breach the Data Protection Legislation.
- You will tell us promptly about any request or inquiry you receive from a Data Subject or a Supervisory Authority that is relevant to our obligations under this Addendum.
- You are responsible for the settings you configure in the Apps, including which optional fields you collect from shoppers, and for ensuring those settings comply with the EU GDPR.
6. Data Subject Requests
You are responsible for responding to requests from your shoppers to exercise their rights. Where a shopper contacts us directly, we will direct them to you and will not respond on your behalf, except to confirm that we act as your processor.
We will provide reasonable assistance, as far as is necessary and technically feasible, to help you respond, including access, correction, deletion, and export of the Personal Data we hold for your store. Requests submitted through Shopify’s mandatory privacy webhooks are handled as described in section 8.
7. Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data we process for you, so that you can meet your obligations under Articles 33 and 34 of the EU GDPR. Our notification will include the information reasonably available to us: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where the information cannot be provided at the same time, it may be provided in phases without undue further delay.
You remain responsible for any notification owed to a Supervisory Authority or to affected Data Subjects. We will cooperate with you in good faith to investigate, remediate, and document the breach.
8. Retention and Deletion
We retain Personal Data only for as long as needed to provide the Apps or as the law requires. On termination of the Terms of Service, or on uninstall of an app, we stop processing the Personal Data for that store and delete or anonymize it.
If you ask us before the deletion is carried out, we will first return or export the Personal Data we hold for your store in a commonly used format.
We follow Shopify’s mandatory data-redaction process for installed apps:
- Shop redaction: Shopify sends the request 48 hours after you uninstall an app; we erase that store’s Personal Data within 30 days of receiving it.
- Customer redaction: when a shopper asks for erasure, we delete or anonymize the Personal Data we hold in connection with that shopper within 30 days of receiving Shopify’s request.
- Customer data request: we provide the order-related Personal Data we hold in connection with that shopper to you within 30 days of receiving Shopify’s request.
Where we are legally required to retain specific data, we keep only what the law requires and delete the rest. Aggregated or anonymized data that cannot be associated with an individual or with your store is not Personal Data and may be retained.
9. Sub-processors
Under Article 28(2) of the EU GDPR, you give us general written authorisation to engage Sub-processors. Under Article 28(4), each Sub-processor is engaged under a written contract that imposes data protection obligations no less protective than those in this Addendum, and we remain fully liable to you for the performance of that Sub-processor’s obligations.
Our current Sub-processors, which also constitute Annex III of the SCCs, are:
- Akamai Technologies, Inc. (United States): cloud infrastructure and hosting, in the regions listed in section 10.
- RunCloud Sdn. Bhd. (Malaysia): server management control panel; holds server configuration and administrative access, not a copy of Personal Data at rest.
- Crisp IM SAS (France): in-app live chat and support conversations; data stored in the European Union (Netherlands and Germany).
We will notify you by email to your store contact address at least 14 days before adding or replacing a Sub-processor, giving you the opportunity to object. You may object on reasonable data protection grounds within that period by writing to support@tigren.com. If we cannot provide the affected functionality without the Sub-processor, either party may terminate the affected app, and you will not be charged for the period after termination.
10. Processing Location and International Transfers
Personal Data is processed on Akamai cloud infrastructure, in the region assigned to each app:
- Easify Custom Product Options: London, United Kingdom
- Easify Box Bundle Builder: Dallas, Texas, United States
- Easify Product Attachments: Dallas, Texas, United States
- Easify Inventory Sync: Dallas, Texas, United States
Crisp stores support conversations within the EEA, so no Restricted Transfer arises. RunCloud processes server configuration and administrative access in Malaysia and other locations outside the EEA. Our own personnel access Personal Data from Vietnam for the purpose of providing the Apps and support. We update this section when we release a new app or change a processing location.
Transfers to the United Kingdom are covered by the European Commission’s adequacy decision for the United Kingdom under Article 45 and are not Restricted Transfers for as long as that decision remains in force.
Transfers to the United States, Malaysia, Vietnam, and any other country without an adequacy decision are Restricted Transfers. For these we rely on the SCCs as incorporated in section 11, together with the supplementary measures in Annex II. Akamai Technologies, Inc. is certified under the EU-U.S. Data Privacy Framework; for transfers to Akamai in the United States we rely on that certification in addition to the SCCs. Where any other recipient in the United States is certified under the EU-U.S. Data Privacy Framework, we may additionally rely on that certification. The parties will cooperate in good faith to resolve any compliance issue arising from a Restricted Transfer.
11. Standard Contractual Clauses
For every Restricted Transfer, the SCCs are incorporated into this Addendum by reference and form part of it. The parties agree the following selections:
- Module: Module Two (transfer controller to processor). You are the data exporter and we are the data importer.
- Clause 7: the optional docking clause applies.
- Clause 9(a): Option 2, general written authorisation, with the notice period of 14 days set out in section 9.
- Clause 11(a): the optional language on independent dispute resolution bodies does not apply.
- Clause 13: the competent Supervisory Authority is identified in Annex I, Part C.
- Clause 17: Option 1; the SCCs are governed by the law of Ireland.
- Clause 18(b): disputes arising from the SCCs are resolved by the courts of Ireland.
- Annexes: Annex I of the SCCs is populated by section 14, Annex II by section 15, and Annex III by section 9 of this Addendum.
Under Clause 14, we confirm that we have assessed the laws and practices of the destination countries and have no reason to believe they prevent us from fulfilling our obligations under the SCCs. We will notify you promptly if that changes, and will cooperate with you to identify additional measures or, where none are available, to suspend the affected transfer.
If the European Commission adopts new standard contractual clauses, or if the SCCs are otherwise superseded, the parties will cooperate in good faith to put the successor mechanism in place. Nothing in this Addendum varies or contradicts the SCCs; in the event of conflict, the SCCs prevail.
12. Audits and Information
In accordance with Article 28(3)(h), on reasonable written request, and no more than once in any twelve-month period unless a Supervisory Authority requires otherwise, we will make available the information necessary to demonstrate our compliance with this Addendum, including summaries of our security measures and any attestations or certifications we hold.
Where an audit or inspection is required by the EU GDPR and cannot be satisfied by that information, we will allow for and contribute to it, conducted by you or an independent auditor mandated by you. The parties will agree its scope, timing, and duration in advance, and you will bear the reasonable costs involved. This section also constitutes the exercise of the audit option in Clause 8.9 of the SCCs.
13. Order of Precedence, Changes, and Governing Law
This Addendum prevails over the Terms of Service in respect of the processing of Personal Data. The SCCs prevail over this Addendum. If any provision of this Addendum is found invalid or unenforceable, it is severed and the remaining provisions stay in full force.
We may amend this Addendum on 30 days’ written notice, including by posting the revised version on this page. Continued use of the Apps after the notice period constitutes acceptance. If you do not accept an amendment, you may terminate the affected app during the notice period.
Except for the SCCs, which are governed by the law of Ireland as stated in section 11, this Addendum is governed by the laws of Vietnam, and the competent courts of Hanoi, Vietnam have exclusive jurisdiction over any dispute arising out of it. Nothing in this section deprives a Data Subject of the rights conferred by Articles 79 and 82 of the EU GDPR.
The liability provisions of the Terms of Service apply to claims under this Addendum, except where the EU GDPR or the SCCs provide otherwise.
14. Annex I: Details of the Processing
A. List of parties
- Data exporter (Controller): the merchant that installed the Apps, identified by the Shopify store name, domain, and contact email in your Shopify account. Role: controller.
- Data importer (Processor): TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED, trading as Easify, No. 2, Alley 113, Giap Bat Street, Tuong Mai Ward, Hanoi, Vietnam. Contact: support@tigren.com. Role: processor.
B. Description of the transfer
- Subject matter: provision of the Easify apps installed on your Shopify store, currently Easify Custom Product Options, Easify Box Bundle Builder, Easify Inventory Sync, and Easify Product Attachments, and any further Easify app you install, together with related support.
- Duration: from installation until the Terms of Service end or the app is uninstalled, followed by the deletion process in section 8.
- Nature and purpose: hosting, storage, retrieval, and display of the data needed to run the features you enable; responding to your support requests.
- Categories of Personal Data: store and account data (Shopify domain, contact email, plan); app configuration; and order-linked customisations, options, bundles, and attachments, together with the product, variant, and order identifiers needed to render them. The Apps do not process shopper contact details and never process payment data.
- Special categories: none. The Apps are not intended for the processing of special category data under Article 9, and you must not configure them to collect it.
- Categories of Data Subjects: your staff who use the Apps, and, indirectly, the shoppers whose orders the app-generated data relates to.
- Frequency: continuous, for as long as the Apps are installed.
- Retention: as set out in section 8.
- Transfers to Sub-processors: the Sub-processors in section 9, for the subject matter, nature, and duration described above.
C. Competent Supervisory Authority
Where you are established in an EU Member State, the Supervisory Authority of that Member State. Where you are not established in the EEA but have appointed a representative under Article 27, the Supervisory Authority of the Member State in which the representative is established. Otherwise, the Supervisory Authority of the Member State in which the Data Subjects whose Personal Data is transferred are located.
15. Annex II: Technical and Organisational Measures
The measures below are implemented by the data importer to ensure the security of the Personal Data in accordance with Article 32 and Clause 8.6 of the SCCs, and serve as supplementary measures for Restricted Transfers.
- Physical access control: our infrastructure providers operate data centres with security personnel, alarm systems, access control, and video surveillance.
- System access control: access to systems processing Personal Data requires individual accounts with multi-factor authentication; changes go through a review process and are logged.
- Data access control: access is granted on a least-privilege basis to authorised personnel only, and is reviewed periodically.
- Transmission control: Personal Data is encrypted in transit over public networks and encrypted at rest on our infrastructure.
- Availability control: regular backups, restoration testing, and documented recovery procedures protect against accidental loss or destruction.
- Segregation: data is logically separated per store through application-level controls.
- Data minimisation: the Apps collect only the fields needed for the features you enable and do not process shopper contact details or payment data.
- Personnel: staff with access are bound by confidentiality obligations and receive data protection guidance.
- Sub-processor oversight: Sub-processors are bound by written contracts under section 9 and are reviewed before engagement.
- Logging and monitoring: access to production systems and administrative actions are logged; systems are monitored for errors, abuse, and security events, and alerts are reviewed by our engineering team.
- Secure development and patching: code changes go through review before deployment; operating systems, runtimes, and dependencies are kept up to date with security patches through our server management tooling.
- Incident management: a documented procedure covers detection, containment, assessment, notification under section 7, and post-incident review of security incidents.
- Regular evaluation: we test, assess, and evaluate the effectiveness of these measures on a regular basis and after any significant change to our infrastructure, in line with Article 32(1)(d).
These measures address the confidentiality, integrity, availability, and resilience of our processing systems and our ability to restore access to Personal Data in a timely manner, as required by Article 32(1)(a) to (d). We may update them from time to time, provided no change materially reduces the overall level of security of the Apps.