1. Scope and Application
This Addendum applies whenever we process personal data on your behalf in the course of providing the Apps and that processing is subject to the UK GDPR: because you are established in the United Kingdom, or because you offer goods or services to, or monitor the behaviour of, data subjects in the United Kingdom. It forms part of, and is incorporated into, our Terms of Service. Where this Addendum conflicts with the Terms of Service, this Addendum prevails in respect of the processing of personal data.
Processing subject to the EU GDPR is governed by our separate EU Data Processing Addendum. If your store is subject to both regimes, each Addendum applies to the processing within its own scope.
The processor under this Addendum is TIGREN TECHNOLOGY SOLUTION COMPANY LIMITED (TIGREN COMPANY LIMITED), trading as Easify, business registration number 0105887692, of No. 2, Alley 113, Giap Bat Street, Tuong Mai Ward, Hanoi, Vietnam. The controller is the merchant that installed the Apps. Contact for all matters under this Addendum: support@tigren.com.
No signature is required for this Addendum to apply. If your compliance process needs a countersigned copy, email support@tigren.com and we will send our standard DPA for review and signature.
2. Definitions
- “Apps” means the Easify applications installed on your Shopify store, together with the related support we provide, as described in our Terms of Service.
- “UK GDPR” means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended.
- “Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and any other law of the United Kingdom that applies to the processing carried out under this Addendum.
- “Controller,” “Processor,” “Data Subject,” “Processing” carry the meanings given to them in Article 4 of the UK GDPR.
- “ICO” means the Information Commissioner’s Office, the supervisory authority for the United Kingdom.
- “Personal Data” means data that constitutes personal data under the UK GDPR and that we process on your behalf in connection with the Apps.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- “Restricted Transfer” means a transfer of Personal Data to a country outside the United Kingdom that is not covered by adequacy regulations made under section 17A of the Data Protection Act 2018.
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the ICO under section 119A of the Data Protection Act 2018 and in force from 21 March 2022, applied to the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914.
- “Sub-processor” means a third party engaged by us to process Personal Data on your behalf.
3. Roles of the Parties
For the purposes of the UK GDPR, you are the Controller and we are the Processor of the Personal Data we handle on your behalf.
You determine the purposes and means of the processing through your configuration and use of the Apps. We process Personal Data only on your documented instructions, which this Addendum, the Terms of Service, and your use of the Apps constitute. We do not determine the purpose of the processing, and we do not process the Personal Data for any purpose of our own.
If we are required by domestic law to process Personal Data other than on your instructions, we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
4. Our Processing Obligations
In accordance with Article 28(3) of the UK GDPR, when processing Personal Data on your behalf we will:
- Process it only as a Processor, for the purpose of providing the Apps, in accordance with your documented instructions, including with regard to transfers of Personal Data outside the United Kingdom.
- Not retain, use, or disclose it for any purpose other than providing the Apps, except where domestic law requires.
- Not combine it with data from other sources, except as the Data Protection Legislation authorises.
- Ensure that personnel authorised to process it have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement and maintain the technical and organisational measures required by Article 32, as set out in Appendix 2.
- Respect the conditions in sections 9 and 10 for engaging Sub-processors and for international transfers.
- Assist you, by appropriate technical and organisational measures and insofar as possible, in fulfilling your obligation to respond to requests from Data Subjects under Chapter III of the UK GDPR.
- Assist you in meeting your obligations under Articles 32 to 36, including security, breach notification, data protection impact assessments, and prior consultation with the ICO, taking into account the nature of the processing and the information available to us.
- Delete or return all Personal Data at the end of the provision of the Apps, as described in section 8.
- Make available to you all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in section 12.
- Inform you immediately if, in our opinion, an instruction infringes the UK GDPR or other domestic data protection provisions.
- Notify you promptly of any inquiry we receive from the ICO relating to the Personal Data we process for you.
- Notify you of any binding request from a public authority for Personal Data we process for you, unless the law prohibits that notification, and challenge any request that appears unlawful.
5. Your Obligations
- You will ensure you have the rights, authority, and lawful basis under Article 6, including any consent required, to provide Personal Data to us for processing under this Addendum.
- You will comply with your own obligations as a Controller, including providing the information required by Articles 13 and 14 and honouring the rights your shoppers are entitled to under Chapter III.
- You will not act in a way that causes us to breach the Data Protection Legislation.
- You will tell us promptly about any request or inquiry you receive from a Data Subject or the ICO that is relevant to our obligations under this Addendum.
- You are responsible for the settings you configure in the Apps, including which optional fields you collect from shoppers, and for ensuring those settings comply with the UK GDPR.
6. Data Subject Requests
You are responsible for responding to requests from your shoppers to exercise their rights. Where a shopper contacts us directly, we will direct them to you and will not respond on your behalf, except to confirm that we act as your processor.
We will provide reasonable assistance, as far as is necessary and technically feasible, to help you respond, including access, correction, deletion, and export of the Personal Data we hold for your store. Requests submitted through Shopify’s mandatory privacy webhooks are handled as described in section 8.
7. Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data we process for you, so that you can meet your obligations under Articles 33 and 34 of the UK GDPR, including notification to the ICO within 72 hours where required. Our notification will include the information reasonably available to us: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where the information cannot be provided at the same time, it may be provided in phases without undue further delay.
You remain responsible for any notification owed to the ICO or to affected Data Subjects. We will cooperate with you in good faith to investigate, remediate, and document the breach.
8. Retention and Deletion
We retain Personal Data only for as long as needed to provide the Apps or as the law requires. On termination of the Terms of Service, or on uninstall of an app, we stop processing the Personal Data for that store and delete or anonymize it.
If you ask us before the deletion is carried out, we will first return or export the Personal Data we hold for your store in a commonly used format.
We follow Shopify’s mandatory data-redaction process for installed apps:
- Shop redaction: Shopify sends the request 48 hours after you uninstall an app; we erase that store’s Personal Data within 30 days of receiving it.
- Customer redaction: when a shopper asks for erasure, we delete or anonymize the Personal Data we hold in connection with that shopper within 30 days of receiving Shopify’s request.
- Customer data request: we provide the order-related Personal Data we hold in connection with that shopper to you within 30 days of receiving Shopify’s request.
Where we are legally required to retain specific data, we keep only what the law requires and delete the rest. Aggregated or anonymized data that cannot be associated with an individual or with your store is not Personal Data and may be retained.
9. Sub-processors
Under Article 28(2) of the UK GDPR, you give us general written authorisation to engage Sub-processors. Under Article 28(4), each Sub-processor is engaged under a written contract that imposes data protection obligations no less protective than those in this Addendum, and we remain fully liable to you for the performance of that Sub-processor’s obligations.
Our current Sub-processors are:
- Akamai Technologies, Inc. (United States): cloud infrastructure and hosting, in the regions listed in section 10.
- RunCloud Sdn. Bhd. (Malaysia): server management control panel; holds server configuration and administrative access, not a copy of Personal Data at rest.
- Crisp IM SAS (France): in-app live chat and support conversations; data stored in the European Union (Netherlands and Germany).
We will notify you by email to your store contact address at least 14 days before adding or replacing a Sub-processor, giving you the opportunity to object. You may object on reasonable data protection grounds within that period by writing to support@tigren.com. If we cannot provide the affected functionality without the Sub-processor, either party may terminate the affected app, and you will not be charged for the period after termination.
10. Processing Location and International Transfers
Personal Data is processed on Akamai cloud infrastructure, in the region assigned to each app:
- Easify Custom Product Options: London, United Kingdom
- Easify Box Bundle Builder: Dallas, Texas, United States
- Easify Product Attachments: Dallas, Texas, United States
- Easify Inventory Sync: Dallas, Texas, United States
Crisp stores support conversations in the European Union. RunCloud processes server configuration and administrative access in Malaysia and other locations outside the United Kingdom. Our own personnel access Personal Data from Vietnam for the purpose of providing the Apps and support. We update this section when we release a new app or change a processing location.
Transfers to the EEA and to other countries covered by UK adequacy regulations are not Restricted Transfers for as long as those regulations remain in force.
Transfers to the United States, Malaysia, Vietnam, and any other country without UK adequacy regulations are Restricted Transfers. For these we rely on the UK Addendum as incorporated in section 11, together with the supplementary measures in Appendix 2. Akamai Technologies, Inc. is certified under the EU-U.S. Data Privacy Framework and its UK Extension; for transfers to Akamai in the United States we rely on that certification in addition to the UK Addendum. Where any other recipient in the United States is certified under the UK Extension, we may additionally rely on that certification. The parties will cooperate in good faith to resolve any compliance issue arising from a Restricted Transfer.
11. International Data Transfer Addendum
For every Restricted Transfer, the UK Addendum is incorporated into this Addendum by reference and forms part of it, applying the EU standard contractual clauses as amended by the UK Addendum. The parties agree the following selections:
- Table 1 (Parties): you are the exporter and we are the importer, with the details set out in Appendix 1.
- Table 2 (Selected SCCs): Module Two (transfer controller to processor); Clause 7 (docking clause) applies; Clause 9(a) Option 2, general authorisation, with the notice period of 14 days set out in section 9; the optional language in Clause 11 does not apply.
- Table 3 (Appendix information): Annex 1A and 1B are populated by Appendix 1, Annex II by Appendix 2, and Annex III by section 9 of this Addendum.
- Table 4 (Ending the Addendum): neither party may end the UK Addendum when the ICO issues a revised approved addendum; the parties will instead cooperate to adopt the revised version.
- Governing law and jurisdiction: the UK Addendum, and the standard contractual clauses as amended by it, are governed by the laws of England and Wales, and disputes are resolved by the courts of England and Wales.
- Supervisory authority: the ICO.
We confirm that we have assessed the laws and practices of the destination countries and have no reason to believe they prevent us from fulfilling our obligations under the UK Addendum. We will notify you promptly if that changes, and will cooperate with you to identify additional measures or, where none are available, to suspend the affected transfer.
Nothing in this Addendum varies or contradicts the UK Addendum; in the event of conflict, the UK Addendum prevails.
12. Audits and Information
In accordance with Article 28(3)(h), on reasonable written request, and no more than once in any twelve-month period unless the ICO requires otherwise, we will make available the information necessary to demonstrate our compliance with this Addendum, including summaries of our security measures and any attestations or certifications we hold.
Where an audit or inspection is required by the UK GDPR and cannot be satisfied by that information, we will allow for and contribute to it, conducted by you or an independent auditor mandated by you. The parties will agree its scope, timing, and duration in advance, and you will bear the reasonable costs involved. This section also constitutes the exercise of the audit option in Clause 8.9 of the standard contractual clauses as amended by the UK Addendum.
13. Order of Precedence, Changes, and Governing Law
This Addendum prevails over the Terms of Service in respect of the processing of Personal Data. The UK Addendum prevails over this Addendum. If any provision of this Addendum is found invalid or unenforceable, it is severed and the remaining provisions stay in full force.
We may amend this Addendum on 30 days’ written notice, including by posting the revised version on this page. Continued use of the Apps after the notice period constitutes acceptance. If you do not accept an amendment, you may terminate the affected app during the notice period.
Except for the UK Addendum, which is governed by the laws of England and Wales as stated in section 11, this Addendum is governed by the laws of Vietnam, and the competent courts of Hanoi, Vietnam have exclusive jurisdiction over any dispute arising out of it. Nothing in this section deprives a Data Subject of the rights conferred by Articles 79 and 82 of the UK GDPR.
The liability provisions of the Terms of Service apply to claims under this Addendum, except where the UK GDPR or the UK Addendum provide otherwise.
14. Appendix 1: Details of the Processing
- Subject matter: provision of the Easify apps installed on your Shopify store, currently Easify Custom Product Options, Easify Box Bundle Builder, Easify Inventory Sync, and Easify Product Attachments, and any further Easify app you install, together with related support.
- Duration: from installation until the Terms of Service end or the app is uninstalled, followed by the deletion process in section 8.
- Nature and purpose: hosting, storage, retrieval, and display of the data needed to run the features you enable; responding to your support requests.
- Categories of Personal Data: store and account data (Shopify domain, contact email, plan); app configuration; and order-linked customizations, options, bundles, and attachments, together with the product, variant, and order identifiers needed to render them. The Apps do not process shopper contact details and never process payment data.
- Special categories: none. The Apps are not intended for the processing of special category data under Article 9, and you must not configure them to collect it.
- Categories of Data Subjects: your staff who use the Apps, and, indirectly, the shoppers whose orders the app-generated data relates to.
- Frequency: continuous, for as long as the Apps are installed.
15. Appendix 2: Security Measures
- Physical access control: our infrastructure providers operate data centres with security personnel, alarm systems, access control, and video surveillance.
- System access control: access to systems processing Personal Data requires individual accounts with multi-factor authentication; changes go through a review process and are logged.
- Data access control: access is granted on a least-privilege basis to authorized personnel only, and is reviewed periodically.
- Transmission control: Personal Data is encrypted in transit over public networks and encrypted at rest on our infrastructure.
- Availability control: regular backups, restoration testing, and documented recovery procedures protect against accidental loss or destruction.
- Segregation: data is logically separated per store through application-level controls.
- Personnel: staff with access are bound by confidentiality obligations and receive data protection guidance.
- Logging and monitoring: access to production systems and administrative actions are logged; systems are monitored for errors, abuse, and security events, and alerts are reviewed by our engineering team.
- Secure development and patching: code changes go through review before deployment; operating systems, runtimes, and dependencies are kept up to date with security patches through our server management tooling.
- Incident management: a documented procedure covers detection, containment, assessment, notification under section 7, and post-incident review of security incidents.
- Regular evaluation: we test, assess, and evaluate the effectiveness of these measures on a regular basis and after any significant change to our infrastructure, in line with Article 32(1)(d).
These measures address the confidentiality, integrity, availability, and resilience of our processing systems and our ability to restore access to Personal Data in a timely manner, as required by Article 32(1)(a) to (d). We may update them from time to time, provided no change materially reduces the overall level of security of the Apps.