Data Processing Agreement (DPA)

Data Processing Agreement pursuant to Article 28 of the GDPR

LDT SOFT (“LDT”, “we”, “Processor”) and the Merchant (“Customer”, “Controller”) acknowledge that any installation, activation, authorization, and use of the LDT application on Shopify shall be deemed as the Customer having read, accepted, agreed, and signed this Data Processing Agreement.

1. Purpose and Scope of the DPA

This Agreement defines how LDT collects, processes, stores, secures, transmits, restores, deletes, and handles personal data during the delivery of LDT application services to Shopify businesses. The scope of this DPA includes customer-provided data submitted during app installation, store interaction, feature usage, and app operational data received during usage.

This DPA applies to store information, domain information, Shopify user data, customer list data, order information, order data, access data, and application usage data related to the operation of LDT products.

2. Roles of the Parties

Data Controller: The Customer determines the purpose, scope, and method of processing personal data within its Shopify environment.

Data Processor: LDT processes data in accordance with the Customer’s instructions and in the context of the services provided.

Where LDT uses subcontractors to support operations, LDT remains responsible to the Customer for data processing and privacy protection as required under this DPA.

3. Data Processed

The categories of data that may be processed by LDT include, but are not limited to:

  • Store information: Store ID, Store domain, Store plan, Store owner, app installation, and app configuration data.
  • Customer and order information: names, email addresses, shipping and billing addresses, phone numbers, postal codes, country, order numbers, order value, transaction history, order IDs, and related service details.
  • Operational data: install history, upgrade history, uninstall history, activity logs, access timestamps, browser information, operating system data, and application activity records.
  • Support and contact data: information submitted through chat, email, or support channels.

4. Purpose of Data Processing

LDT processes data only for the following purposes: (i) operation, provision, and optimization of the application; (ii) support for users and technical support requests; (iii) application usage analytics, including integration with internal analytics; (iv) compliance with legal obligations, contract enforcement, fraud prevention, and security; and (v) service improvement, process automation, and error diagnosis.

5. Subprocessors and Service Providers

LDT may transfer or grant access to data to subcontractors or service providers to perform services. The subprocessors and service providers currently used or that may be used include:

  • AWS – cloud infrastructure provider for hosting, servers, storage, backup, logging, and environment support.
  • Cloudflare – CDN and security service provider, handling traffic protection, caching, DDoS protection, and secure delivery.
  • Crisp – live chat and support platform handling customer communication, chat history, tickets, and related support records.

These subprocessors and service providers may use data only under LDT’s instruction and solely to the extent necessary to provide the contracted services. LDT commits to reviewing and ensuring that such providers maintain appropriate security and data protection controls.

6. Security and Data Controls

LDT commits to implementing reasonable technical, organizational, and administrative safeguards to protect personal data from loss, disclosure, unauthorized access, alteration, destruction, or other foreseeable risks. These safeguards include access controls, encryption during transport and/or at rest where configured, monitoring, logging, backup, and incident response procedures.

The Customer is responsible for managing access to its systems, protecting administrative accounts, and providing data only for legitimate service-related purposes.

7. International Data Transfers

Data may be stored, processed, and transferred across national borders as part of the services provided by AWS, Cloudflare, and Crisp. LDT and its subprocessors will apply appropriate safeguards to protect data when it is transferred to other jurisdictions or regions.

8. Retention and Deletion

Data will be retained for the period necessary to perform services and meet legal obligations. Upon app uninstallation, LDT automatically processes data deletion in compliance with Shopify’s mandatory GDPR webhooks (customers/redact, shop/redact) within the required timeframe.

9. Incident Reporting and Legal Compliance

In the event of a security incident, unauthorized access, data loss, or other breach related to Customer data, LDT will follow incident response procedures, assess the impact, and notify the Customer as required by applicable law and contractual obligations.

LDT will cooperate with Customer and relevant authorities to support regulatory reporting, investigation, and protection of commercial and user rights.

10. Acceptance and Signature

The Customer’s installation, activation, authorization, and ongoing use of the LDT application on the Shopify environment shall be deemed acceptance of, agreement to, and signature upon this Data Processing Agreement. Data will be processed in accordance with the purposes, scope, terms, and security commitments stated herein.

If the Customer does not agree with this DPA, the Customer shall not download, install, activate, or continue using the LDT application.

For more information regarding DPA, data retention, or policy support, contact: [email protected]