📄 Data Processing Agreement
PriceCalc Pro – Shopify app · Template · Last updated: 26 August 2026
Agreement on the processing of personal data on behalf of a controller
pursuant to Art. 28 of Regulation (EU) 2016/679 (GDPR)
Customer (Controller)
Company, address, represented by · myshopify domain
Provider (Processor)
JRMedia
Janine Fabienne Eicker
Unnersberger Allee 10
42659 Solingen, Germany
support@jrmedia.software
§ 1 Subject matter and duration
(1) The subject matter of this agreement is the processing of personal data carried out by the Provider for the Customer in the course of providing the Shopify app PriceCalc Pro. Details of the nature, purpose, data categories and categories of data subjects are set out in Annex 1.
(2) This agreement takes effect upon signature and remains in force for as long as the app is installed in the Customer's shop. It ends upon uninstallation without the need for separate termination. The right to terminate for cause remains unaffected.
(3) This agreement supplements the usage agreement for the app. In the event of conflict on matters of data protection law, this agreement prevails.
§ 2 Scope and instructions
(1) The Provider processes personal data exclusively within the scope of the agreements made and on documented instructions from the Customer, unless required to process by Union or Member State law. In that case, the Provider informs the Customer of the legal requirement before processing, unless the law prohibits this on important grounds of public interest.
(2) Use of the app by the Customer constitutes an instruction within the meaning of paragraph 1. Further instructions are given in text form to support@jrmedia.software.
(3) The Provider informs the Customer without delay if, in its opinion, an instruction infringes data protection law. It is entitled to suspend the instruction concerned until the Customer confirms or amends it.
(4) The Provider does not process the data for its own purposes. This does not affect the processing described in the Privacy Policy that the Provider carries out as an independent controller (in particular contract performance, billing and abuse prevention); such processing is not the subject of this agreement.
§ 3 Obligations of the Customer
(1) As controller, the Customer is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects.
(2) The Customer informs the Provider without delay if it detects errors or irregularities in the results of the processing.
(3) The Customer ensures that the product, price and supplier fields it maintains contain no personal data that is not necessary for using the app. Special categories of personal data under Art. 9 GDPR must not be processed through the app.
§ 4 Confidentiality
(1) The Provider processes the data confidentially and ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(2) This obligation continues after termination of this agreement.
§ 5 Technical and organisational measures
(1) The Provider implements the technical and organisational measures described in Annex 2 pursuant to Art. 32 GDPR and maintains them for the duration of this agreement.
(2) The measures are subject to technical progress. The Provider may adapt them provided the agreed level of protection is not reduced.
§ 6 Sub-processors
(1) The Customer grants the Provider general authorisation to engage further processors. The sub-processors engaged at the time this agreement is concluded are listed in Annex 3 and are hereby approved.
(2) The Provider notifies the Customer in text form of any intended change concerning the addition or replacement of sub-processors. The Customer may object to such a change within 30 days of receipt of the notification on important data protection grounds. If the Customer objects and the processing cannot reasonably be continued without the sub-processor concerned, either party may terminate this agreement and the usage agreement with effect from the end of the current billing period.
(3) The Provider imposes on its sub-processors a level of protection equivalent to that of this agreement and is liable for their conduct as for its own.
§ 7 Rights of data subjects
(1) The Provider assists the Customer by appropriate technical and organisational measures in responding to requests from data subjects under Chapter III GDPR.
(2) If a data subject contacts the Provider directly, the Provider forwards the request to the Customer without delay and informs the data subject accordingly. The Provider does not respond on the merits itself.
(3) The Provider further assists the Customer with data protection impact assessments and prior consultations of the supervisory authority under Art. 35 and 36 GDPR, insofar as the necessary information is available to it.
§ 8 Personal data breaches
(1) The Provider notifies the Customer of any personal data breach without undue delay and in any event within 48 hours of becoming aware of it, in text form.
(2) The notification includes, where available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
(3) The Provider assists the Customer with its notification obligations under Art. 33 and 34 GDPR.
§ 9 Deletion and return
(1) The calculation and pricing data generated by the Customer remains as metafields in the Customer's Shopify store and stays available there unchanged after this agreement ends. No return by the Provider is required in this respect.
(2) After termination, the Provider deletes the data stored for the shop. Deletion occurs
automatically upon receipt of the Shopify webhook shop/redact, which Shopify
triggers 48 hours after the app is uninstalled. Only a technical record
without personal content remains (shop identifier and myshopify domain) so that a later
reinstallation can be matched correctly.
(3) At the sub-processor named in Annex 3, deletion follows the periods applicable there, at the latest 90 days after termination.
(4) Statutory retention obligations remain unaffected.
§ 10 Evidence and audits
(1) On request, the Provider makes available to the Customer in text form all information necessary to demonstrate compliance with the obligations under this agreement.
(2) The Customer is entitled to satisfy itself that the agreed measures are being complied with. Audits take place after reasonable prior notice during normal business hours and no more than once per year; beyond that, following a personal data breach. The Provider may primarily furnish evidence by way of current certifications, audit reports or self-assessments.
(3) The cost of an on-site audit requested by the Customer is borne by the Customer.
§ 11 Transfers to third countries
(1) In the course of hosting by the sub-processor named in Annex 3, processing takes place in Canada and in the USA.
(2) An adequacy decision of the European Commission is in place for Canada. For transfers to the USA, the Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914, Modules 2 and 3) are relied upon as appropriate safeguards under Art. 46(2)(c) GDPR. The Provider has concluded corresponding agreements with the sub-processor.
(3) Should a transfer mechanism subsequently be amended, revoked or declared invalid, the parties undertake to suspend the transfer or to agree on a suitable replacement mechanism.
§ 12 Liability
Art. 82 GDPR applies. In all other respects, liability is governed by the usage agreement and the Disclaimer.
§ 13 Final provisions
(1) Amendments and supplements to this agreement must be made in text form. This also applies to any waiver of this form requirement.
(2) Should any provision be or become invalid, the validity of the remaining provisions remains unaffected. The parties will replace the invalid provision with a valid one that comes closest to its economic purpose.
(3) The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods. The place of jurisdiction for disputes with merchants is the Provider's registered office.
Signature, name in block capitals
Janine Fabienne Eicker, JRMedia
Annex 1 — Subject matter of the processing
Subject matter
Provision of the Shopify app PriceCalc Pro for
calculating cost and selling prices, markup factors, margins and VAT rates, and for
writing the results back to the Customer's Shopify store.
Nature of the processing
Collection, retrieval, storage,
alteration, transmission and erasure to the extent required to provide the app.
Purpose
Performance of the usage agreement for the app.
Categories of data subjects
- The Customer and its staff who use the app within the Shopify Admin
- Where applicable, natural persons whose details the Customer has entered in product, supplier or vendor fields of its shop
Categories of personal data
- Shop master data: shop identifier, myshopify domain, shop name, owner's name, shop email address, country, Shopify plan
- Contents of product and price fields, insofar as the Customer maintains personal details there (such as names of suppliers or vendors)
Not processed
Personal data of the Customer's end customers. The
app requests no Shopify permissions for customer or order data; the permissions granted
are limited to reading and writing products and inventory and reading locations and
locales. Payment and bank data is not processed; billing runs exclusively through
Shopify.
Duration
For as long as the app is installed, plus the deletion
periods set out in § 9.
Annex 2 — Technical and organisational measures
Confidentiality
- Access to the app is only possible through an authenticated Shopify session within the embedded Shopify Admin.
- Tenant separation: access rules restrict every request to the requesting shop; access to other shops' data is excluded.
- Least privilege: the app requests only the Shopify permissions required for operation. No permissions for customer or order data exist.
- The Provider's internal administration area is technically restricted to designated administrator shops.
- Development and production environments are fully separated.
Integrity
- All transmission between browser, app, hosting platform and Shopify is encrypted via HTTPS/TLS.
- Changes to prices and metafields are made through the Shopify Admin API and are traceable in the Customer's shop history.
- The app integrates no analytics, tracking, advertising or email marketing services.
Availability and resilience
- Operation, redundancy, backup and restoration are the responsibility of the sub-processor named in Annex 3, according to its security standards.
- Calculation results are stored as metafields in the Customer's Shopify store and are therefore covered by the Customer's own backup.
- The app additionally offers a manual export of pricing data as a JSON file.
- Per-plan usage quotas limit the load caused by individual shops.
Regular review
- Automated test suite and static type checking before every production release.
- Configuration and permission checks before every deployment.
- Annual review of the measures, the sub-processors and the legal texts.
Data minimisation
- Product and price data is not stored permanently by the Provider; it is read from Shopify, processed and written back there.
- User settings remain in the browser's local storage.
- Abuse prevention counters are reset monthly.
Annex 3 — Sub-processors
The Provider engages one sub-processor:
| Company | Service | Registered office and processing location |
|---|---|---|
| Gadget Software Inc. Vancouver, Canada |
Hosting and operation of the application including the database | Canada (adequacy decision), USA (Standard Contractual Clauses) |
A Data Processing Addendum including the EU Standard Contractual Clauses (Modules 2 and 3) is in place with Gadget Software Inc.
Gadget in turn engages the sub-processors listed below. The table reflects the list published by Gadget as at 26 August 2026; the current list is published by Gadget at gadget.dev/privacy.
| Company | Service | Location |
|---|---|---|
| Google Cloud | Infrastructure and data hosting | USA |
| Cloudflare (incl. Cloudflare Analytics) | CDN, security, web activity logs | USA |
| Crunchy Data | Database operations and logs | USA |
| Axiom | Product and operational logs | USA |
| Humio | Operational logs and web activity logs | USA |
| HubSpot | Email marketing (contact details of the Provider account) | USA |
| LaunchDarkly | Feature flags | USA |
| Fivetran | Business intelligence and warehousing | USA |
HubSpot and LaunchDarkly process only the contact details of the Provider's Gadget account. No data of the Customer, its shop or its end customers is transmitted to these two services.