Upfront Invoice

Data Processing Agreement

Version 1.3 · Effective 18 August 2026

Version 1.3 replaces section 4. Our own remote administrative access from Thailand is now expressly identified as a restricted transfer under Chapter V of the GDPR, and the EU Standard Contractual Clauses and the UK International Data Transfer Addendum are incorporated by reference. Section 1 now describes how acceptance actually happens and adds Module One for the merchant’s own data; Annex A is completed as SCC Annex I with a full list of parties, and Annexes B and C are identified as SCC Annexes II and III. Section 3.9 now says plainly that our preference for documentary audits is a request rather than a limit, because Clause 8.9 prevails over it; section 3.10 gives data subjects the direct complaint contact Clause 11(a) requires; the backup window is corrected from 7 days to the 6 hours our database actually retains; and Table 4 of the UK Addendum now elects the Importer under Section 19.

1. Parties and roles

This DPA is between the Merchant (the Shopify store installing the App) and Woratas Nirasratom, sole proprietor (Samut Sakhon, Thailand) (“Provider”, “we”), operator of Upfront Invoice.

Acceptance. By installing the App and continuing to use it, the Merchant accepts this DPA, including the EU SCCs and the UK Addendum incorporated by reference in section 4. We do not currently present a separate acceptance screen inside the App, because Shopify’s install flow does not surface this document and adding a blocking step before first use would conflict with Shopify’s guidance that merchants can start using an app immediately after installing it. A Merchant who requires a signed instrument may request a countersigned copy under section 4.6, which we provide free of charge. This DPA prevails over any other terms between the parties with respect to the processing of personal data.

2. Scope of processing

We process personal data only on the Merchant’s documented instructions. Installing and configuring the App constitutes those instructions. We will tell the Merchant if we believe an instruction breaches applicable data-protection law.

Full details are in Annex A.

3. Our obligations as processor

  1. Instructions only — no processing for our own purposes. We never sell or rent personal data, use it for marketing, or use it to train AI models.
  2. Confidentiality — everyone with access is bound by confidentiality.
  3. Security — we maintain the technical and organisational measures in Annex B.
  4. Subprocessors — general authorisation is granted for the subprocessors listed in Annex C. We impose equivalent obligations on each and remain liable for their performance. We give the Merchant fourteen (14) days notice of any addition or replacement so they may object — the notice period elected under Clause 9(a) Option 2 of the EU SCCs (section 4.2).
  5. Data subject requests — we assist the Merchant in responding, and act on Shopify’s customers/data_request, customers/redact and shop/redact webhooks.
  6. Breach — we notify the Merchant without undue delay after becoming aware of a personal data breach, with the information they need for their own notification duties.
  7. Assistance — we reasonably assist with DPIAs and prior consultations.
  8. Data minimisation by design — customer personal data is never written to our database and never stored as a file; it exists only in memory for the duration of a single render. On termination or uninstall, at the Merchant’s choice we return or delete the Merchant’s shop record and all attached invoice records; absent a choice we delete them, within 48 hours, unless law requires retention. Because customer personal data is never stored, a return request can only concern the Merchant’s own records. Encrypted backups age out on their own schedule (currently a 6-hour point-in-time window at our database provider); we do not restore them to recover deleted data.
  9. Information & audit — we make available the information needed to demonstrate compliance and allow audits. We will usually satisfy an audit with documentation and written responses, and we ask Merchants to accept that where it answers the question, given the size of our operation. This is a request, not a limit: for transfers governed by the EU SCCs, Clause 8.9 — including the right to on-site inspection — prevails over this paragraph by operation of section 4.6.
  10. Complaints from data subjects — under Clause 11(a) of the EU SCCs a data subject may complain to us directly. Write to [email protected]; we deal with such complaints promptly and keep the Merchant informed. This is in addition to, not instead of, a data subject’s right to raise the matter with the Merchant.

4. International transfers

1. Transfers to the Provider. The Provider is Woratas Nirasratom, a sole proprietor established in Thailand. Thailand is not the subject of an adequacy decision under Article 45 of the GDPR or of adequacy regulations under the UK GDPR. The Merchant acknowledges that the Provider accesses Personal Data remotely from Thailand for support and system administration purposes, and that such access constitutes a transfer of Personal Data to a third country within the meaning of Chapter V of the GDPR notwithstanding that the Personal Data is hosted in Frankfurt, Germany and that invoice email is dispatched from Ireland.

2. EEA transfers — EU Standard Contractual Clauses. The standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCCs”) are hereby incorporated into this DPA by reference and are deemed executed by the Merchant and the Provider, and apply to all transfers of Personal Data subject to Chapter V of the GDPR from the Merchant (as data exporter) to the Provider (as data importer). Module Two (Controller to Processor) applies to the Merchant’s customer personal data, where the Merchant acts as a controller. Module Three (Processor to Processor) applies to that data where the Merchant acts as a processor on behalf of its own controller. Module One (Controller to Controller) applies to the Merchant’s own data described in section 1 — staff session and invoice-template business details — which both parties process as controllers. For the purposes of the EU SCCs: the optional Clause 7 (docking clause) does not apply; in Clause 9(a), Option 2 (general written authorisation) applies, with a notice period of fourteen (14) days; in Clause 11(a), the optional independent dispute resolution provision does not apply; in Clause 17, the governing law is the law of the EU Member State in which the Merchant is established, and where that law does not allow third-party beneficiary rights, the law of Ireland; in Clause 18(b), the forum is the courts of the EU Member State in which the Merchant is established.

Annexes I, II and III to the EU SCCs are set out in Annexes A, B and C to this DPA respectively. For Annex I.A (list of parties), the exporter is the Merchant, identified by the Shopify shop domain and shop owner contact recorded at installation, and the importer is the Provider as named in section 1. For Annex I.C, the competent supervisory authority is the supervisory authority of the EU Member State in which the Merchant is established or, where the Merchant is not established in the EEA, the supervisory authority of the Member State in which the Merchant’s Article 27 representative is designated.

3. UK and Swiss transfers. To the extent that a transfer is subject to the UK GDPR, the EU SCCs as incorporated above apply as varied by the International Data Transfer Addendum issued by the Information Commissioner, and the following applies: “Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.” The information required by Part 1 of the Addendum is that set out in Annexes A to C to this DPA. For the purposes of Table 4 of the Addendum (“Ending this Addendum when the Approved Addendum changes”), the Importer is the Party that may end the Addendum as set out in Section 19. This does not affect automatic updating: under Section 18 this Addendum “is automatically amended as set out in the revised Approved Addendum from the start date specified” whatever Table 4 says. Section 19 is available only where a revised Approved Addendum would cause a substantial, disproportionate and demonstrable increase in the Importer’s direct costs or risk that it has first taken reasonable steps to reduce. Where a transfer is subject to Swiss data protection law, references in the EU SCCs to the GDPR are read as references to the Swiss Federal Act on Data Protection, references to Member State courts and authorities are read as references to the Swiss courts and the Federal Data Protection and Information Commissioner, and the term “data subject” includes legal entities to the extent Swiss law so provides.

4. Onward transfers to sub-processors. The Provider engages the sub-processors listed in Annex C, including Fly.io, Neon and Resend in the United States. Each is engaged under that provider’s published data processing agreement, linked in Annex C, which imposes data protection obligations providing in substance the same level of protection as this DPA and which incorporates the EU SCCs. Each transfer accordingly relies on an adequacy decision or on the EU SCCs under the applicable Module, in accordance with Clause 8.8 and Clause 9 of the EU SCCs. No sub-processor is located in Thailand.

5. Transfer assessment. The Provider has prepared and documented a transfer assessment for the transfer to Thailand under Clause 14(b) of the EU SCCs, which also serves as a transfer risk assessment under the UK Addendum, and makes it available to the Merchant and to any competent supervisory authority on request and without charge in accordance with Clause 14(d). The Provider will, on request and without charge, provide the Merchant with the information reasonably necessary for the Merchant to conduct or adopt its own assessment, will notify the Merchant in accordance with Clause 14(e) and Clause 15 of the EU SCCs, and will review the assessment at least annually.

6. Precedence and acceptance. In the event of any conflict between the EU SCCs (as varied by the UK Addendum where applicable) and any other term of this DPA — including the governing law and jurisdiction stated in section 5 — the Provider’s Terms of Service, or any other agreement between the parties, the EU SCCs prevail in accordance with Clause 5 of the EU SCCs. The Merchant accepts this DPA, including the EU SCCs and the UK Addendum incorporated by reference, in the manner described in section 1. The Provider will, on request and free of charge, execute a countersigned copy of this DPA and the EU SCCs naming the Merchant and stating the Provider’s full postal address — write to [email protected] with the store’s myshopify.com domain.

5. Term, liability, governing law

This DPA applies for as long as the App is installed.

Governing law: the laws of the Kingdom of Thailand, with the courts of Thailand having jurisdiction — this does not deprive the Merchant or any data subject of the protection of mandatory provisions of the law that applies to them, including the GDPR and UK GDPR. This clause does not apply to transfers governed by the EU SCCs: for those, Clause 17 and Clause 18(b) as stated in section 4.2 govern, and they prevail over this section by operation of section 4.6 and Clause 5 of the EU SCCs.

Our aggregate liability under this DPA is limited to the fees paid by the Merchant for the App in the twelve months preceding the claim, except where such a limitation is not permitted by applicable law.


Annex A — Details of processing

This Annex is Annex I to the EU SCCs and supplies the information required by Part 1 of the UK Addendum (Tables 1–3).

A.1 — List of parties (SCC Annex I.A · Addendum Table 1)

Data exporterData importer
NameThe Merchant — the Shopify store installing the App, identified by its myshopify.com domainWoratas Nirasratom, sole proprietor
AddressThe store address held in the Merchant’s Shopify accountSamut Sakhon, Thailand. The full postal address is stated in the countersigned copy issued on request under section 4.6; it is withheld here because this is a public page and the Provider is a natural person.
Contact personThe Shopify shop owner contact recorded at installation[email protected] — also the Clause 11(a) contact for data subjects
Activities relevant to the transferOperating a Shopify store and instructing the App to issue invoices for its ordersGenerating PDF invoices from order data and emailing them to buyers; supporting that service
RoleController (Module Two) · Processor (Module Three) · Controller (Module One, for its own data)Processor (Modules Two and Three) · Controller (Module One)
Signature and dateSigned by virtue of reference to, and incorporation of, these Clauses in this DPA, accepted as described in section 1, on the date the App is installedAs above

A.2 — Description of the transfer (SCC Annex I.B · Addendum Table 2)

ItemDetail
Frequency of transferCustomer data: on a continuous basis, once per paid order, automatically. Administrative access by the Provider: occasional and reactive — incident response and system administration only, not routine or bulk
RetentionSee section 3.8. Customer personal data is not retained at all; invoice records are retained while the Merchant’s account is active and deleted within 48 hours of uninstall
Transfers to sub-processorsSubject matter, nature and duration as set out in Annex C; each engaged under that provider’s own DPA
Competent supervisory authority (Annex I.C)As determined in section 4.2

A.3 — Processing details

ItemDetail
Subject matterGenerating and delivering invoices
DurationWhile the App is installed (+ up to 48h for deletion of stored records)
Nature & purposeAutomated retrieval of order data, rendering to PDF in memory, emailing to the buyer
Categories of data subjectsThe Merchant’s customers (buyers); Merchant staff users
Categories of personal dataName; billing and shipping address; email; order contents, amounts, tax lines, currency, dates
Stored by the ProviderInvoice number, sequence, Shopify order ID, issue date, template version, shop domain, the Merchant’s own template settings, and an access log of which order was rendered and when
Never stored by the ProviderCustomer name, address, email; the generated PDF
Explicitly excludedCustomer phone number (not requested); payment card data; special-category data

Annex B — Technical and organisational measures (Art. 32)

This Annex is Annex II to the EU SCCs. The Commission’s explanatory note requires these to be described in specific, not generic, terms.

Encryption in transit (TLS) and at rest, including encrypted backups · least-privilege access with strong passwords and 2FA · access logging for every read of protected customer data · separation of test and production data · data-loss-prevention controls (no public database exposure, no bulk personal-data export endpoint) · documented incident response · data minimisation (phone field never requested; customer data never persisted).

Annex C — Subprocessors

This Annex is Annex III to the EU SCCs. Each entry links the provider’s own data processing agreement, which is the agreement under which that sub-processor is engaged.

SubprocessorPurposeCustomer dataLocationTheir terms
Shopify Inc. (Canada)App platform; source of order dataController-side platformGlobalshopify.com/legal/dpa
Fly.io, Inc. (USA)Application hosting; PDF renderingIn memory only, during a renderFrankfurt, Germanyfly.io/legal/dpa
Neon, LLC (USA — a Databricks company)Invoice record and settings storageNoneFrankfurt, Germany (AWS eu-central-1)neon.com DPA · subprocessors
Resend, Inc. (USA)Invoice email deliveryRecipient address and attached PDF, in transitIreland (AWS eu-west-1)resend.com/legal/dpa