This DPA applies whenever we process personal data on your behalf during a delivery engagement (you are the controller, we are the processor). It satisfies UK GDPR Article 28 and EU GDPR Article 28 requirements. A signed PDF copy is available on request.
Controller: the client engaging shopifywebdeveloper.co.uk under a Statement of Work.
Processor: shopifywebdeveloper.co.uk (UK-registered business, London).
This DPA forms part of and supplements the Statement of Work. In the event of conflict between this DPA and the SOW, this DPA prevails for matters of personal data processing.
Subject matter: the personal data you instruct us to process in the course of delivering the services in your SOW (e.g. customer records during a Shopify migration, employee accounts during a B2B build).
Categories of data: typically — names, email addresses, postal addresses, order history, account credentials, payment metadata (not card numbers — those stay with Shopify Payments / Stripe and never touch our systems).
Categories of data subjects: typically — your customers, your employees, your trade buyers.
Duration: for the duration of the SOW, plus any tail period agreed in writing for handover and post-launch support.
We process personal data only on your documented instructions, including:
If we believe an instruction infringes UK or EU GDPR, we will notify you before acting on it.
Anyone we authorise to process your personal data is under a written confidentiality obligation (employment contract for staff, NDA for contractors). Access is limited to those who need it to perform the SOW.
We implement appropriate technical and organisational measures, including:
You authorise our use of the following sub-processors. Each operates under a written processing agreement compliant with UK GDPR Article 28:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Hosting (where applicable) | EU / US (with SCCs) |
| Cloudflare | DNS, edge caching | Global (with SCCs) |
| GitHub | Source code repository | US (with SCCs) |
| Linear / Notion | Project management, internal docs | US (with SCCs) |
| Slack | Client communication channels | US (with SCCs) |
| Loom | Sprint update video walkthroughs | US (with SCCs) |
We will give you 30 days' notice before adding or replacing a sub-processor. If you object, we'll work with you to find an alternative; if no alternative is workable, either party may terminate the affected portion of the SOW without penalty.
If a data subject contacts us directly with a request relating to data we process on your behalf, we will:
If we become aware of a personal data breach affecting your data, we will:
You remain responsible for any notification to the ICO and to affected data subjects.
Where personal data is transferred outside the UK / EEA in the course of the services, the transfer is governed by:
We will provide copies of the relevant transfer mechanism on request.
Once per 12 months, you may audit our compliance with this DPA on 30 days' written notice. The audit may take the form of:
We will assist with regulatory audits at no charge.
On termination of the SOW, you choose whether we:
We will provide written confirmation of deletion on request.
Our liability under this DPA is subject to the limits set out in the Master Services Agreement or Statement of Work, except where Article 82 of UK GDPR imposes direct liability on us as processor.
Most engagements: this DPA is incorporated by reference in the SOW you sign — no separate signature required. If your procurement process needs a separately signed DPA, email dpo@shopifywebdeveloper.co.uk and we'll countersign within 2 working days.