Skip to main content

Data Processing Addendum

Version 1 — effective [PENDING — set when published, after t031 entity decision and t012 lawyer review]

About this document

This Data Processing Addendum ("DPA") forms part of the Shop-OS Terms of Service. It applies when you use Shop-OS to process personal data about your staff — for example, Discord IDs, usernames, roles, and sales or commission records tied to them. For that data, you are the controller and Shop-OS is the processor. This DPA does not cover your own account data (your Discord ID, email, name) — that's covered by the Privacy Policy, where Shop-OS is the controller.

Who's who

- You ("Customer", "Controller"): the Shop-OS account owner. You decide what staff data to enter, who your staff are, and how their commission is calculated.

- Shop-OS ("Processor", "we", "us"): [PENDING — entity name, set at t031] operates the Shop-OS platform and processes your staff's data only to provide the service to you.

Subject matter and duration

Shop-OS processes staff data for as long as your account is active, plus the retention periods set out in the Privacy Policy (account/business data: account lifetime + 6 years for legal/tax reasons; audit logs: 2 years; backups: 90 days).

Nature and purpose of processing

Recording sales and stock movements against staff members, calculating and reporting commission, generating performance and activity reports, and sending role-relevant notifications (e.g., low-stock alerts) via Discord.

Categories of data subjects and personal data

- Data subjects: your staff — the Discord users you assign roles to within your Shop-OS business.

- Personal data: Discord user ID, Discord username, assigned role, commission rate (if overridden per-role), and the sales/stock records logged against them via `/recordsale` and related bot commands.

Our obligations as processor

We will:

1. Process staff data only on your documented instructions — i.e., through the Shop-OS platform's normal functionality, and not for our own separate purposes.

2. Keep it confidential — anyone on our side with access to staff data (currently: the founder and co-founder) is bound by confidentiality.

3. Implement appropriate technical and organisational security measures, including: row-level security enforcing tenant isolation between businesses, encrypted backups, audit logging of administrative actions, rate limiting, and role-based access control in our own admin panel (including read-only enforcement during customer-support impersonation sessions).

4. Not engage a new sub-processor without telling you first. Current sub-processors are listed below; we'll update this list and give you a chance to object before adding a new one that would materially change how your staff's data is handled.

5. Help you respond to your staff's data subject requests (access, deletion, correction) to the extent we're able to, given the data we hold.

6. Help you meet your own security, breach-notification, and (if applicable) impact-assessment obligations, to the extent they concern data we process for you.

7. Notify you without undue delay if we become aware of a personal data breach affecting your staff's data.

8. Delete or anonymise staff data when your account is deleted, per the retention schedule in the Privacy Policy (in practice: personal identifiers are anonymised at the point of deletion; financial/trading records are retained for the 6-year UK statutory minimum).

9. Make available the information reasonably necessary to demonstrate compliance with this DPA on request.

Sub-processors

| Sub-processor | What they do | Where |

|---|---|---|

| Discord | Authentication, bot platform | US |

| Resend | Transactional email delivery | US, EU infrastructure |

| Sentry | Error tracking | [PENDING — confirm EU region configuration] |

| Cloudflare | DNS / network | US, EU points of presence |

| Backblaze B2 | Encrypted backups | EU-Central |

| VoltHosting | VPS hosting | UK/EU |

| Stripe | Billing (processes your own payment details, not your staff's data) | US, Ireland |

International transfers

Where a sub-processor is based outside the UK, transfers are made under an appropriate safeguard (UK International Data Transfer Agreement, or the UK extension to the EU-US Data Privacy Framework where the recipient is certified). `[PENDING — confirm the specific mechanism per sub-processor at t012]`

Your obligations as controller

You're responsible for having a lawful basis to process your staff's data, for telling them how their data is used (a short notice, not a full privacy policy, is generally enough for this), and for using Shop-OS's staff-management features in a way that's proportionate to running your business.

Audit

You can request written confirmation of our compliance with this DPA once per year. Given our current scale, we don't offer on-site audits — if your organisation specifically requires one, contact us to discuss.

General

This DPA is governed by the same law as the Terms of Service (England & Wales) and doesn't expand our liability beyond what the Terms of Service already caps.

Contact

privacy@shop-os.app