Data Processing Agreement
Last updated August 16, 2026 · Dhavira LLC, a North Carolina limited liability company
Early access — Delink is available in selected markets. Features, terms, data handling, and market availability may change before general availability.
Pre-counsel DPA — not reviewed by qualified counsel and not legal advice. It governs Customer Personal Data when the Customer affirmatively accepts the then-current version at checkout. Restricted transfers require a separately completed transfer addendum.
1. Parties and roles
This DPA is between Dhavira LLC ("Delink") and the entity that accepts it ("Customer") when subscribing to Delink. It supplements our Terms and Privacy Policy.
In typical use, the merchant is the data controller, you (the app developer) are a processor or sub-processor, and Delink is your subprocessor for compliance webhook ingest and logging. Delink processes limited personal data on your behalf to provide compliance webhook ingest, verification, logging, and console features. You remain responsible for fulfilling data subject requests in your systems.
"Customer Personal Data" means personal data Delink processes on Customer's behalf. "Data Protection Laws" means privacy and data-protection laws applicable to that processing, including, where applicable, the GDPR, UK GDPR, Swiss data-protection law, Canadian private-sector privacy law, and U.S. state privacy laws.
2. Processing scope
This DPA applies only to Customer Personal Data Delink processes on Customer's behalf to provide the Service, for the duration of the subscription and documented post-termination retention. It does not govern account, billing, support, or security data for which Delink independently determines purposes and means; the Privacy Policy governs that Delink Controller Data.
Data categories and minimization rules are described in the Privacy Policy (§3–4). Delink does not persist customer contact information from webhook payloads at rest.
- Subject matter and purpose: hosted compliance-webhook ingest, HMAC verification, operational records, workflow status, exports, security, and support;
- Duration: the subscription plus documented post-termination retention and deletion periods;
- Data subjects: Customer personnel, Shopify merchants and their personnel, store customers, and other people represented in a compliance request;
- Data: registered app identifiers, shop domain, webhook topic, timestamps, Shopify resource identifiers, workflow/audit data, optional pseudonymous subject hash, and transient payload fields used during verification;
- Special data: not intentionally requested; Customer must not intentionally submit special-category, biometric, precise-geolocation, or similarly sensitive data beyond fields Shopify supplies in mandatory webhooks;
- Frequency: continuous or event-driven, as Customer and Shopify use the Service.
3. Customer instructions
Delink processes personal data on your instructions as set out in this DPA, the Terms, Privacy Policy, and your Service configuration, unless required by applicable law — in which case we will inform you unless prohibited.
Customer is responsible for the lawfulness, accuracy, and transparency of its instructions, for required notices and consents, and for determining whether the Service is appropriate for its processing. Delink will promptly inform Customer if, in our reasonable opinion, an instruction infringes applicable Data Protection Laws and may suspend that instruction while the parties resolve it.
4. Delink obligations
Delink will:
- process Customer Personal Data only on documented instructions, including for international transfers, unless law requires otherwise;
- implement and maintain the technical and organizational measures in §8;
- bind authorized personnel to confidentiality;
- taking account of the nature of processing, reasonably assist with data-subject requests and Customer's security, breach, DPIA, and regulator-consultation obligations;
- notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, provide then-available information needed for Customer's response, and supplement or correct that information as the investigation develops;
- maintain records required of processors and cooperate with competent regulators as required by law; and
- at Customer's choice and on authenticated written instruction, either (a) delete all Customer Personal Data or (b) return Customer Personal Data using the compliance event-record export format supported by the Service at that time and then delete existing copies, except where law requires retention. Protected backup copies will remain unavailable for ordinary use and expire under the documented backup lifecycle. Delink will confirm completion and explain legally retained data. Delink maintains documented deletion and export procedures for this workflow and reviews them periodically.
Delink's notice of or response to an incident is not an admission of fault. Customer remains responsible for notifications to individuals and authorities unless law assigns that duty directly to Delink.
5. Subprocessors
You authorize Delink to use subprocessors on our Subprocessor list. Delink provides direct email or in-product notice of material subprocessor changes to the account contact and retains delivery evidence where practicable. We will provide at least 30 days' notice before an intended addition or replacement. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available within a reasonable time, Customer may terminate the subscription and Delink will stop processing Customer Personal Data through the objected-to subprocessor, except as needed to complete an orderly export or deletion. Delink will impose materially equivalent data-protection obligations on subprocessors and remains responsible for their performance to the extent required by law.
6. International transfers
The Service is operated from the United States. This online DPA alone does not complete the party details, selections, annexes, governing law, forum, competent authority, signatures, or transfer assessment required for the European Commission Standard Contractual Clauses or the UK International Data Transfer Addendum.
Before Customer makes a restricted EEA, UK, or Swiss transfer to Delink that is not covered by another lawful mechanism, the parties must execute a transfer addendum containing the applicable completed SCC Module Two or Three, the approved UK Addendum where applicable, Swiss adaptations, and completed transfer annexes. Contact us before enabling such processing. Delink will provide reasonable information for Customer's transfer assessment and implement agreed supplementary measures appropriate to the risk.
7. U.S. state privacy terms
For Customer Personal Data governed by U.S. state privacy law, Delink acts as a service provider or contractor. Customer discloses data only for the limited and specified business purposes in §2. Delink will not sell or share it; retain, use, or disclose it outside those purposes or the direct business relationship except as permitted by law; or combine it with personal information from other persons or our own consumer interactions except as legally permitted to provide and secure the Service. Delink will provide the same level of privacy protection required by applicable law, allow reasonable steps to verify compliance, notify Customer if we can no longer meet these obligations, and cooperate with reasonable steps to stop and remediate unauthorized use.
8. Security measures
Delink maintains the following measures while processing Customer Personal Data, taking account of risk, implementation cost, and the nature of processing:
- TLS in transit; provider-supported encryption at rest for managed database and object storage; Cloud KMS envelope encryption for Shopify client secrets;
- tenant-scoped authorization, least-privilege production access via cloud IAM, confidentiality obligations, and administrative action logging;
- HMAC verification, webhook body size limits, webhook deduplication, CSRF controls on the console, secure session cookies, security headers, and production configuration validation;
- data minimization that avoids persisting raw webhook bodies and customer contact fields, plus documented retention and weekly purge routines;
- structured operational logging, health checks, monitoring dashboards, alerts, and dependency updates and vulnerability scanning for application components where automated tooling is in use;
- periodic review of safeguards and incident-response procedures. Delink may update controls without materially reducing overall protection.
9. Audit, liability, and order of precedence
Upon reasonable written request, Delink will make available information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire and, when available, summaries of third-party assessments or penetration tests relevant to the Service. Customer will use such documentation before requesting further review.
If documentation is insufficient and applicable Data Protection Laws require additional verification, Customer may appoint an independent auditor bound by confidentiality to review Delink's relevant controls remotely on reasonable notice. Such reviews are normally limited to once every twelve (12) months and do not include on-site access to Delink's facilities except where mandatory law requires it and the parties agree in writing in advance. That limit does not apply where required by a supervisory authority, following a confirmed material breach affecting Customer Personal Data, or where credible evidence indicates material noncompliance by Delink. Reviews must minimize disruption, protect other customers' confidentiality, and occur at Customer's expense unless they identify material noncompliance attributable to Delink.
Liability caps in the Terms apply except to the extent Data Protection Laws or an executed transfer addendum prohibit that limitation. If this DPA conflicts with the Terms regarding Customer Personal Data, this DPA controls; an executed transfer addendum controls for restricted transfers.
10. Acceptance
You accept this DPA when you check the agreement box before your first paid subscription checkout or when you otherwise indicate acceptance in writing. Current version: 2026-08-16 (effective August 16, 2026).
Material DPA changes will be communicated directly to the account contact before taking effect. Delink will require affirmative reacceptance before a materially changed DPA governs existing Customer Personal Data, except an urgent change strictly required by law may take effect when required with prompt notice.
11. Contact
DPA questions: support@getdelink.com.
Questions? support@getdelink.com