Version 1.3 replaces section 4. Our own remote administrative access from Thailand is now expressly identified as a restricted transfer under Chapter V of the GDPR, and the EU Standard Contractual Clauses and the UK International Data Transfer Addendum are incorporated by reference. Section 1 now describes how acceptance actually happens and adds Module One for the merchant’s own data; Annex A is completed as SCC Annex I with a full list of parties, and Annexes B and C are identified as SCC Annexes II and III. Section 3.9 now says plainly that our preference for documentary audits is a request rather than a limit, because Clause 8.9 prevails over it; section 3.10 gives data subjects the direct complaint contact Clause 11(a) requires; the backup window is corrected from 7 days to the 6 hours our database actually retains; and Table 4 of the UK Addendum now elects the Importer under Section 19.
This DPA is between the Merchant (the Shopify store installing the App) and Woratas Nirasratom, sole proprietor (Samut Sakhon, Thailand) (“Provider”, “we”), operator of Upfront Invoice.
Acceptance. By installing the App and continuing to use it, the Merchant accepts this DPA, including the EU SCCs and the UK Addendum incorporated by reference in section 4. We do not currently present a separate acceptance screen inside the App, because Shopify’s install flow does not surface this document and adding a blocking step before first use would conflict with Shopify’s guidance that merchants can start using an app immediately after installing it. A Merchant who requires a signed instrument may request a countersigned copy under section 4.6, which we provide free of charge. This DPA prevails over any other terms between the parties with respect to the processing of personal data.
We process personal data only on the Merchant’s documented instructions. Installing and configuring the App constitutes those instructions. We will tell the Merchant if we believe an instruction breaches applicable data-protection law.
Full details are in Annex A.
customers/data_request, customers/redact and shop/redact webhooks.1. Transfers to the Provider. The Provider is Woratas Nirasratom, a sole proprietor established in Thailand. Thailand is not the subject of an adequacy decision under Article 45 of the GDPR or of adequacy regulations under the UK GDPR. The Merchant acknowledges that the Provider accesses Personal Data remotely from Thailand for support and system administration purposes, and that such access constitutes a transfer of Personal Data to a third country within the meaning of Chapter V of the GDPR notwithstanding that the Personal Data is hosted in Frankfurt, Germany and that invoice email is dispatched from Ireland.
2. EEA transfers — EU Standard Contractual Clauses. The standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCCs”) are hereby incorporated into this DPA by reference and are deemed executed by the Merchant and the Provider, and apply to all transfers of Personal Data subject to Chapter V of the GDPR from the Merchant (as data exporter) to the Provider (as data importer). Module Two (Controller to Processor) applies to the Merchant’s customer personal data, where the Merchant acts as a controller. Module Three (Processor to Processor) applies to that data where the Merchant acts as a processor on behalf of its own controller. Module One (Controller to Controller) applies to the Merchant’s own data described in section 1 — staff session and invoice-template business details — which both parties process as controllers. For the purposes of the EU SCCs: the optional Clause 7 (docking clause) does not apply; in Clause 9(a), Option 2 (general written authorisation) applies, with a notice period of fourteen (14) days; in Clause 11(a), the optional independent dispute resolution provision does not apply; in Clause 17, the governing law is the law of the EU Member State in which the Merchant is established, and where that law does not allow third-party beneficiary rights, the law of Ireland; in Clause 18(b), the forum is the courts of the EU Member State in which the Merchant is established.
Annexes I, II and III to the EU SCCs are set out in Annexes A, B and C to this DPA respectively. For Annex I.A (list of parties), the exporter is the Merchant, identified by the Shopify shop domain and shop owner contact recorded at installation, and the importer is the Provider as named in section 1. For Annex I.C, the competent supervisory authority is the supervisory authority of the EU Member State in which the Merchant is established or, where the Merchant is not established in the EEA, the supervisory authority of the Member State in which the Merchant’s Article 27 representative is designated.
3. UK and Swiss transfers. To the extent that a transfer is subject to the UK GDPR, the EU SCCs as incorporated above apply as varied by the International Data Transfer Addendum issued by the Information Commissioner, and the following applies: “Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.” The information required by Part 1 of the Addendum is that set out in Annexes A to C to this DPA. For the purposes of Table 4 of the Addendum (“Ending this Addendum when the Approved Addendum changes”), the Importer is the Party that may end the Addendum as set out in Section 19. This does not affect automatic updating: under Section 18 this Addendum “is automatically amended as set out in the revised Approved Addendum from the start date specified” whatever Table 4 says. Section 19 is available only where a revised Approved Addendum would cause a substantial, disproportionate and demonstrable increase in the Importer’s direct costs or risk that it has first taken reasonable steps to reduce. Where a transfer is subject to Swiss data protection law, references in the EU SCCs to the GDPR are read as references to the Swiss Federal Act on Data Protection, references to Member State courts and authorities are read as references to the Swiss courts and the Federal Data Protection and Information Commissioner, and the term “data subject” includes legal entities to the extent Swiss law so provides.
4. Onward transfers to sub-processors. The Provider engages the sub-processors listed in Annex C, including Fly.io, Neon and Resend in the United States. Each is engaged under that provider’s published data processing agreement, linked in Annex C, which imposes data protection obligations providing in substance the same level of protection as this DPA and which incorporates the EU SCCs. Each transfer accordingly relies on an adequacy decision or on the EU SCCs under the applicable Module, in accordance with Clause 8.8 and Clause 9 of the EU SCCs. No sub-processor is located in Thailand.
5. Transfer assessment. The Provider has prepared and documented a transfer assessment for the transfer to Thailand under Clause 14(b) of the EU SCCs, which also serves as a transfer risk assessment under the UK Addendum, and makes it available to the Merchant and to any competent supervisory authority on request and without charge in accordance with Clause 14(d). The Provider will, on request and without charge, provide the Merchant with the information reasonably necessary for the Merchant to conduct or adopt its own assessment, will notify the Merchant in accordance with Clause 14(e) and Clause 15 of the EU SCCs, and will review the assessment at least annually.
6. Precedence and acceptance. In the event of any conflict between the EU SCCs (as varied by the UK Addendum where applicable) and any other term of this DPA — including the governing law and jurisdiction stated in section 5 — the Provider’s Terms of Service, or any other agreement between the parties, the EU SCCs prevail in accordance with Clause 5 of the EU SCCs. The Merchant accepts this DPA, including the EU SCCs and the UK Addendum incorporated by reference, in the manner described in section 1. The Provider will, on request and free of charge, execute a countersigned copy of this DPA and the EU SCCs naming the Merchant and stating the Provider’s full postal address — write to [email protected] with the store’s myshopify.com domain.
This DPA applies for as long as the App is installed.
Governing law: the laws of the Kingdom of Thailand, with the courts of Thailand having jurisdiction — this does not deprive the Merchant or any data subject of the protection of mandatory provisions of the law that applies to them, including the GDPR and UK GDPR. This clause does not apply to transfers governed by the EU SCCs: for those, Clause 17 and Clause 18(b) as stated in section 4.2 govern, and they prevail over this section by operation of section 4.6 and Clause 5 of the EU SCCs.
Our aggregate liability under this DPA is limited to the fees paid by the Merchant for the App in the twelve months preceding the claim, except where such a limitation is not permitted by applicable law.
This Annex is Annex I to the EU SCCs and supplies the information required by Part 1 of the UK Addendum (Tables 1–3).
| Data exporter | Data importer | |
|---|---|---|
| Name | The Merchant — the Shopify store installing the App, identified by its myshopify.com domain | Woratas Nirasratom, sole proprietor |
| Address | The store address held in the Merchant’s Shopify account | Samut Sakhon, Thailand. The full postal address is stated in the countersigned copy issued on request under section 4.6; it is withheld here because this is a public page and the Provider is a natural person. |
| Contact person | The Shopify shop owner contact recorded at installation | [email protected] — also the Clause 11(a) contact for data subjects |
| Activities relevant to the transfer | Operating a Shopify store and instructing the App to issue invoices for its orders | Generating PDF invoices from order data and emailing them to buyers; supporting that service |
| Role | Controller (Module Two) · Processor (Module Three) · Controller (Module One, for its own data) | Processor (Modules Two and Three) · Controller (Module One) |
| Signature and date | Signed by virtue of reference to, and incorporation of, these Clauses in this DPA, accepted as described in section 1, on the date the App is installed | As above |
| Item | Detail |
|---|---|
| Frequency of transfer | Customer data: on a continuous basis, once per paid order, automatically. Administrative access by the Provider: occasional and reactive — incident response and system administration only, not routine or bulk |
| Retention | See section 3.8. Customer personal data is not retained at all; invoice records are retained while the Merchant’s account is active and deleted within 48 hours of uninstall |
| Transfers to sub-processors | Subject matter, nature and duration as set out in Annex C; each engaged under that provider’s own DPA |
| Competent supervisory authority (Annex I.C) | As determined in section 4.2 |
| Item | Detail |
|---|---|
| Subject matter | Generating and delivering invoices |
| Duration | While the App is installed (+ up to 48h for deletion of stored records) |
| Nature & purpose | Automated retrieval of order data, rendering to PDF in memory, emailing to the buyer |
| Categories of data subjects | The Merchant’s customers (buyers); Merchant staff users |
| Categories of personal data | Name; billing and shipping address; email; order contents, amounts, tax lines, currency, dates |
| Stored by the Provider | Invoice number, sequence, Shopify order ID, issue date, template version, shop domain, the Merchant’s own template settings, and an access log of which order was rendered and when |
| Never stored by the Provider | Customer name, address, email; the generated PDF |
| Explicitly excluded | Customer phone number (not requested); payment card data; special-category data |
This Annex is Annex II to the EU SCCs. The Commission’s explanatory note requires these to be described in specific, not generic, terms.
Encryption in transit (TLS) and at rest, including encrypted backups · least-privilege access with strong passwords and 2FA · access logging for every read of protected customer data · separation of test and production data · data-loss-prevention controls (no public database exposure, no bulk personal-data export endpoint) · documented incident response · data minimisation (phone field never requested; customer data never persisted).
This Annex is Annex III to the EU SCCs. Each entry links the provider’s own data processing agreement, which is the agreement under which that sub-processor is engaged.
| Subprocessor | Purpose | Customer data | Location | Their terms |
|---|---|---|---|---|
| Shopify Inc. (Canada) | App platform; source of order data | Controller-side platform | Global | shopify.com/legal/dpa |
| Fly.io, Inc. (USA) | Application hosting; PDF rendering | In memory only, during a render | Frankfurt, Germany | fly.io/legal/dpa |
| Neon, LLC (USA — a Databricks company) | Invoice record and settings storage | None | Frankfurt, Germany (AWS eu-central-1) | neon.com DPA · subprocessors |
| Resend, Inc. (USA) | Invoice email delivery | Recipient address and attached PDF, in transit | Ireland (AWS eu-west-1) | resend.com/legal/dpa |