Skip to content

Legal

Data processing agreement

This agreement forms part of our terms and applies whenever a DiGiMAA app processes personal data on your instructions as a merchant.

Last updated 27 August 2026

TODOThis is a structural draft written by the DiGiMAA team and has not yet been reviewed by legal counsel. It describes how the apps actually work, but it is not final. If you need a signed, counsel-reviewed version for procurement, email support@digimaa.in.

1.Roles of the parties

You are the controller of shopper personal data processed through the apps. DiGiMAA (Binary Technology Solutions) is the processor. Shopify is a separate processor for the platform itself under its own terms.

2.Subject matter and duration

Processing is limited to what is necessary to provide the installed app, and lasts for the duration of the installation plus the deletion windows described in the privacy policy.

3.Categories of data and data subjects

Data subjects are your shoppers and your staff users. Categories of data by app:

  • Store Locator — store/location records you enter or import, and the search terms and approximate location a shopper submits to find a store. No shopper account data is required.
  • QwikAns AI — product questions submitted by shoppers, the answers published in reply, the product the question relates to, and the email address of a shopper who asks to be notified.
  • QuickForms — the form fields a merchant defines and the submissions shoppers send through them, including any contact details and file attachments the merchant chooses to collect.
  • SupportHub Helpdesk — ticket content, the messages exchanged on a ticket, and the Shopify order and customer reference the ticket is linked to.

You must not configure an app to collect special-category data or payment card data. Form fields are yours to define, so this is a configuration responsibility.

4.Processing instructions

We process personal data only to provide, secure and support the apps, and only on your documented instructions — which include your configuration choices in the app admin. We do not sell personal data and do not use shopper data to train our own or third-party models.

5.Sub-processors

You authorise the sub-processors listed in the privacy policy. We remain responsible for their performance and will give notice before adding a new one, giving you a reasonable period to object.

6.Security measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Least-privilege, individually named access with multi-factor authentication and access logging.
  • Environment separation between development and production, with production data not copied into development.
  • Dependency and vulnerability monitoring, with security patches prioritised over feature work.
  • Backups with defined retention, restore-tested periodically.

TODOTODO — attach the technical and organisational measures annex, the breach-notification timeline commitment, and the restore-test cadence once formally documented.

7.Assistance with data subject requests

We will assist you in responding to access, correction, deletion, portability, restriction and objection requests, including through Shopify's customers/data_request and customers/redact webhooks. Where a shopper contacts us directly, we refer them to you.

8.Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the facts known at the time, the likely consequences and the remediation taken.

9.International transfers

Where personal data is transferred outside the EEA or UK, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, and apply supplementary measures where required.

TODOTODO — confirm the transfer mechanism and complete the SCC annexes with the verified hosting regions.

10.Deletion and return of data

On expiry of the installation, or on your written request, we delete personal data within the windows stated in the privacy policy, except where retention is legally required. Export is available before uninstall so you keep your own copy.

11.Audit and information rights

On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information needed to demonstrate compliance with this agreement.