Data Processing Agreement

Article 1 (Parties)

This Data Processing Agreement (hereinafter "DPA") is entered into between the following parties.

Data Processor: Gojiberry (hereinafter "Processor") A Shopify application that provides survey and product quiz functionality.

Data Controller: Customer (hereinafter "Controller") A shop that has installed the Gojiberry application.

Hereinafter, the Processor and the Controller shall collectively be referred to as the "Parties."

Article 2 (Background)

The Controller operates a Shopify store and uses the Processor's application (Gojiberry) to conduct surveys and product quizzes for the Controller's customers. In the course of providing this service, the Processor processes personal data on behalf of the Controller.

This DPA sets forth the conditions under which the Processor shall process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (hereinafter "GDPR") and other applicable data protection laws.

Article 3 (Definitions)

  • "Personal Data" means any information relating to an identified or identifiable natural person as defined in Article 4(1) of the GDPR.
  • "Processing" means any operation performed on personal data as defined in Article 4(2) of the GDPR.
  • "Data Subject" means an identified or identifiable natural person to whom personal data relates (in the context of this agreement, the Controller's customers).
  • "Sub-processor" means a third party engaged by the Processor to process personal data on behalf of the Controller.
  • "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

Article 4 (Subject Matter and Scope of Processing)

4.1 Categories of Data Subjects End customers of the Controller's Shopify store who use surveys or product quizzes.

4.2 Categories of Personal Data The Processor may process the following categories of personal data:

  • Survey and product quiz responses
  • Email addresses
  • Names
  • Order and purchase information from Shopify
  • Preferences and product interests indicated through quiz responses

4.3 Nature and Purpose of Processing Personal data shall be processed solely for the following purposes:

  • Enabling the Controller to conduct surveys and product quizzes
  • Storing and displaying survey/quiz results to the Controller
  • Facilitating product recommendations based on quiz responses

4.4 Duration of Processing Processing shall continue for the duration of the service agreement between the Parties and for the retention period specified in Article 8.

Article 5 (Obligations of the Processor)

The Processor shall:

  1. Process personal data only on the basis of documented instructions from the Controller, unless required to do so by law
  2. Ensure that persons authorized to process personal data are bound by confidentiality obligations
  3. Implement appropriate technical and organizational security measures as set out in Annex B
  4. Comply with the conditions for engaging Sub-processors as set out in Article 6
  5. Assist the Controller in responding to requests from Data Subjects
  6. Assist the Controller in ensuring compliance with obligations relating to security, breach notification, and data protection impact assessments
  7. Delete or return all personal data upon termination of the service relationship as set out in Article 8
  8. Provide all information necessary to demonstrate compliance and permit audits as set out in Article 10

Article 6 (Sub-processors)

6.1 Authorized Sub-processors The Controller grants the Processor a general authorization to engage Sub-processors. A list of current Sub-processors is set out in Annex A.

6.2 Obligations The Processor shall:

  1. Maintain an up-to-date list of Sub-processors
  2. Notify the Controller of any intended changes to Sub-processors and provide the Controller with an opportunity to object
  3. Ensure that Sub-processors are bound by data protection obligations equivalent to or greater than those set out in this DPA
  4. Be fully liable for the acts and omissions of its Sub-processors

Article 7 (Data Subject Rights)

The Processor shall assist the Controller in fulfilling its obligations to respond to requests from Data Subjects, including:

  • Withdrawal of consent
  • Access to personal data
  • Rectification of inaccurate data
  • Erasure of personal data
  • Restriction of processing
  • Data portability
  • Objection to processing
  • Exercise of the right not to be subject to automated decision-making

The Processor shall provide a mechanism for processing deletion requests received through Shopify's GDPR Webhooks.

Article 8 (Data Retention and Deletion)

8.1 Retention Period Personal data shall be retained only for as long as necessary to fulfill the purposes of processing or as required by applicable law.

8.2 Deletion upon Termination Upon termination of the service agreement, the Processor shall delete all personal data within 30 days, except where:

  1. The Controller requests the return of data
  2. Retention is required by applicable law

8.3 Deletion Requests With respect to deletion requests from Data Subjects received during the service period, the Processor shall delete the relevant personal data within a reasonable period not exceeding 30 days from receipt of a valid request.

Article 9 (Data Breach Notification)

In the event of a Data Breach affecting personal data processed under this DPA:

  1. The Processor shall notify the Controller without undue delay and in any event within 48 hours of becoming aware of the breach
  2. The notification shall include:
    • A description of the nature of the breach
    • The categories and approximate number of Data Subjects affected
    • The likely consequences of the breach
    • The measures taken or proposed to be taken to address the breach
  3. The Processor shall cooperate with the Controller in investigating and mitigating the breach

Article 10 (Audit Rights)

The Processor shall:

  1. Provide the Controller with all information necessary to demonstrate compliance with this DPA
  2. Permit and cooperate with audits, including inspections, conducted by the Controller or an auditor mandated by the Controller
  3. Establish reasonable prior notice requirements for audits and protect confidential information

Article 11 (International Data Transfers)

Personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including:

  • Japan
    where the primary infrastructure is hosted
  • United States
    where certain Sub-processors are located

Such transfers shall be carried out in compliance with Chapter V of the GDPR, relying on:

  1. Adequacy decisions (Japan has received an adequacy decision from the European Commission)
  2. EU-US Data Privacy Framework certification (for Sub-processors in the United States)
  3. Standard Contractual Clauses (SCCs) (where applicable)

Details of the transfer mechanism for each Sub-processor are set out in Annex A.

Article 12 (General Provisions)

12.1 Governing Law This DPA shall be governed by the law applicable to the principal service agreement between the Parties.

12.2 Amendments Any amendments to this DPA must be made in writing and signed by both Parties.

12.3 Conflicts In the event of any conflict between this DPA and the principal service agreement, this DPA shall prevail with respect to matters relating to data protection.

12.4 Severability If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

Annex A: Sub-processors

The following Sub-processors are authorized to process personal data on behalf of the Controller:

Sub-processor
Purpose
Location
Transfer Mechanism
Google Cloud Platform (GCP)
Cloud infrastructure and data hosting
Japan (Tokyo)
Adequacy decision
Brevo
Email delivery service
EU (France/Germany)
N/A (within EU)
Zapier
Workflow automation
United States
EU-US DPF + SCCs

Note: The following analytics tools are used on Gojiberry's website/application for the purpose of service improvement. These tools process limited data (typically anonymized or pseudonymized data) and are not used to directly process customer personal data:

  • Google Analytics 4 (United States, EU-US DPF)
  • Microsoft Clarity (United States, EU-US DPF)
  • Meta Pixel (United States/EU, SCCs)
  • LinkedIn Insight Tag (United States, EU-US DPF)

Annex B: Technical and Organizational Security Measures

The Processor implements the following security measures to protect personal data:

  1. Data Encryption
    • Data at rest: Encrypted using industry-standard encryption
    • Data in transit: Protected using TLS/SSL encryption
  2. Access Controls
    • Role-based access controls to restrict data access to authorized personnel
    • Strong authentication requirements for all system access
    • Regular access reviews and prompt revocation of permissions upon role changes
  3. Audit Logging
    • System audit logging enabled on cloud infrastructure
    • Logging of administrative operations and data access events
    • Log retention in accordance with security best practices
  4. Infrastructure Security
    • Hosted on Google Cloud Platform with enterprise-grade security
    • High-availability configuration for database systems
    • Regular automated backups using Cloud SQL backup functionality
    • Network security controls and monitoring
  5. Organizational Measures
    • Confidentiality obligations for all personnel
    • Data protection awareness and training
    • Incident response procedures
    • Regular review and updating of security measures

Effective Date
August 20, 2026