Data Processing Addendum
1. Subject matter and duration
Processing of personal data by Navrel on the Merchant’s behalf for the duration the app is installed, to provide the automation service described in the Terms.
2. Nature and purpose of processing
Reading store events (orders, customers, checkouts) and executing merchant-configured automations (conditions and actions) over the personal data below.
3. Categories of data subjects and personal data
- Data subjects: the Merchant’s customers.
- Personal data: name, email, phone, address; plus order/checkout data that can be linked to a customer. No special-category data is required or requested.
4. Processor obligations
3Bit Machine LLC will:
- Process personal data only on the Merchant’s documented instructions (the automations the Merchant configures), including for transfers.
- Ensure persons authorized to process are bound by confidentiality.
- Implement appropriate technical and organizational measures (see Annex A).
- Not engage another sub-processor without the Merchant’s general authorization and notice of changes (Annex B); flow down equivalent obligations.
- Assist the Merchant in responding to data subject requests via Shopify’s privacy webhooks.
- Assist with security, breach notification, DPIAs and regulator engagement.
- Delete or return personal data at the end of provision of services (on uninstall /
shop/redact), subject to legal retention. - Make available information to demonstrate compliance and allow reasonable audits.
5. Security & breach notification
Measures per Annex A. On becoming aware of a personal-data breach, 3Bit Machine LLC notifies the Merchant without undue delay and within 72 hours with the available detail.
6. International transfers
Personal data is processed in the United States (AWS us-east-1). Where required, the parties rely on Standard Contractual Clauses or another lawful transfer mechanism.
Annex A — Technical & organizational measures
Encryption in transit and at rest; encrypted backups; network isolation (private subnets, security-group-to-security-group access); least-privilege IAM; separation of test and production data; audit logging (CloudTrail); restricted staff access with MFA; documented incident response.
Annex B — Sub-processors
Amazon Web Services (hosting/storage, US); Amazon SES (email delivery); Shopify (platform). Merchant-designated action destinations (Slack/Discord/webhook) receive only what the Merchant configures.