This Data Processing Agreement (“DPA”) forms part of the agreement between Dragon Apps (“Processor”, “we”, “us”) and the merchant installing the Shopify app Request a Quote, Hide Price (the “App”) (“Controller”, “you”) governing our provision of the App (the “Principal Agreement”).
By installing or using the App you accept this DPA. Where it conflicts with the Principal Agreement, this DPA prevails in respect of the processing of Personal Data.
1. Definitions
“Data Protection Law” means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, and, where applicable, the California Consumer Privacy Act as amended (“CCPA”).
“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing” and “Personal Data Breach” have the meanings given in the GDPR.
“Sub-processor” means any third party engaged by us to process Personal Data on your behalf.
“Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
2. Roles of the parties
You are the Controller of the Personal Data submitted through the App by shoppers on your storefront. We are your Processor in respect of that Personal Data. Each party will comply with its own obligations under Data Protection Law.
You are responsible for the lawfulness of the Personal Data you collect through the App, including establishing a valid legal basis, providing any required notices to Data Subjects, and obtaining any required consent. We rely on you for this, because you — not we — design the quote form and decide what it asks.
For the purposes of the CCPA, we are a “service provider”. We do not “sell” or “share” Personal Data as those terms are defined in the CCPA, and we will not retain, use or disclose Personal Data for any purpose other than performing the services, or otherwise outside the direct business relationship with you.
3. Scope and details of processing
The subject matter, duration, nature and purpose of the processing, and the categories of Data Subjects and Personal Data, are set out in Annex I.
4. Our obligations
We will:
- (a) process Personal Data only on your documented instructions, including as to international transfers, unless required to do otherwise by law — in which case we will inform you before processing unless that law prohibits it. Your use of the App, together with this DPA and the Principal Agreement, constitutes your complete documented instructions;
- (b) ensure that personnel authorised to process Personal Data are bound by confidentiality obligations;
- (c) implement and maintain the technical and organisational measures set out in Annex II;
- (d) engage Sub-processors only in accordance with Section 6;
- (e) assist you, taking into account the nature of the processing and the information available to us, in fulfilling your obligations to respond to Data Subject requests (Section 7) and in respect of security, breach notification and data protection impact assessments (Sections 8 and 9);
- (f) delete or return Personal Data at the end of the provision of services, as set out in Section 11; and
- (g) make available to you the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits under Section 12.
We will immediately inform you if, in our opinion, an instruction from you infringes Data Protection Law.
5. Your obligations
You will:
- (a) ensure you have a lawful basis for the collection and processing of all Personal Data submitted through the App, and provide all required privacy notices to Data Subjects;
- (b) ensure that your quote forms request only Personal Data that is adequate, relevant and limited to what is necessary for your purposes;
- (c) not use the App's forms to collect special categories of personal data as defined in Article 9 GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation), nor data relating to criminal convictions, government identification numbers, or payment card details. The App's forms are free-text and technically permit any question; this restriction is a contractual one, and you are responsible for observing it;
- (d) configure the App's data retention setting in a manner consistent with your own retention obligations; and
- (e) respond to Data Subject requests relating to Personal Data you control.
6. Sub-processors
You give general authorisation for us to engage the Sub-processors listed in Annex III.
We will impose on each Sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the performance of each Sub-processor's obligations.
We will give you at least 30 days' notice before adding or replacing a Sub-processor, by email to the address on your account and by updating our sub-processor page. If you reasonably object on data protection grounds within that period, we will work with you in good faith to find a resolution. If none is found, you may terminate the Principal Agreement by uninstalling the App, without penalty.
7. Data Subject rights
The App gives you direct access to the Personal Data it holds for you: you can view and delete individual quote records at any time through the App's interface, download any quote as a PDF, and configure the retention period after which Personal Data is automatically anonymised. On written request we will provide the Personal Data we hold for you in a structured, commonly used, machine-readable format within 30 days.
In addition, we support Shopify's mandatory compliance webhooks:
customers/data_request— we compile the Personal Data we hold relating to the Data Subject so you can respond to their access request;customers/redact— we permanently anonymise that Data Subject's Personal Data in every matching quote record;shop/redact— we delete all data belonging to your store.
Where a Data Subject contacts us directly about data we process on your behalf, we will not respond substantively to that request ourselves, but will forward it to you without undue delay and assist you in responding.
8. Personal Data Breach
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not available at once, we will provide it in phases as it becomes available.
We will assist you in meeting your own breach notification obligations to supervisory authorities and Data Subjects.
9. Data protection impact assessments
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with any data protection impact assessment and any prior consultation with a supervisory authority that you are required to carry out under Articles 35 and 36 GDPR.
10. International transfers
You authorise us to transfer Personal Data to the Sub-processors and locations listed in Annex III.
Where a transfer is made from the EEA, the UK or Switzerland to a country not subject to an adequacy decision, that transfer is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference, on the following basis:
- Module Two (Controller to Processor) applies;
- Clause 7 (docking clause) applies;
- Clause 9: Option 2 (general written authorisation) applies, with the notice period in Section 6 of this DPA;
- Clause 11: the optional independent dispute resolution language does not apply;
- Clause 17: the SCCs are governed by the law of Ireland;
- Clause 18(b): disputes will be resolved before the courts of Ireland;
- Annexes I, II and III to the SCCs are populated by Annexes I, II and III to this DPA.
For transfers from the UK, the SCCs are supplemented by the UK International Data Transfer Addendum issued by the Information Commissioner. For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
11. Deletion and return
Personal Data is deleted or anonymised as follows:
- On your instruction — deleting a quote in the App deletes that record and its line items immediately.
- On expiry of the retention period you configure (default 730 days / 24 months) — the Personal Data on affected quote records is permanently anonymised, while the non-personal business record is retained for you.
- On a
customers/redactrequest from Shopify — as described in Section 7. - On uninstallation, or a
shop/redactrequest — we delete all data belonging to your store, including quotes, line items, staff records, forms, display rules, settings, notification logs and access tokens.
You may request a copy of your data under Section 7 at any time before uninstalling. After deletion we retain no copy, save for any copy in routine encrypted backups, which are overwritten on a rolling 30-day cycle and remain subject to this DPA until overwritten, or where retention is required by law.
12. Audit
We will make available to you all information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you mandate.
You agree to exercise this right no more than once in any 12-month period (unless required by a supervisory authority or following a Personal Data Breach), on at least 30 days' written notice, during business hours, without unreasonable disruption to our operations, and subject to confidentiality obligations. Where the information we make available reasonably satisfies your request, you agree to accept it in place of an on-site audit.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.
14. Term, governing law and jurisdiction
This DPA takes effect when you install the App and continues until all Personal Data has been deleted or returned in accordance with Section 11.
This DPA is governed by the laws of Queensland, Australia, and the courts of Queensland, Australia have exclusive jurisdiction, except that the SCCs are governed as set out in Section 10.
Annex I — Details of the processing
Data exporter: the Controller — the merchant installing the App.
Data importer: Dragon Apps, PO Box 2210, Sunnybank Hills QLD 4109, Australia, contact [email protected].
Categories of Data Subjects
- Shoppers and prospective customers who submit a quote request on the Controller's storefront.
- The Controller's own staff whom it nominates to receive lead alerts.
Categories of Personal Data
| Category | Detail |
|---|---|
| Contact details | Email address (mandatory); name, telephone number and company name (optional) |
| Shopify identifier | Shopify customer ID, where the shopper was logged in |
| Form responses | Free-text and selected answers to questions defined by the Controller |
| Commercial detail | Products and quantities requested; notes written by the shopper or the Controller |
| Staff details | Name and email address of the Controller's nominated staff |
Special categories of data: none. The Controller is contractually prohibited from collecting special category data through the App (Section 5(c)).
Nature and purpose of processing
Collection, storage, organisation, retrieval, use, transmission, anonymisation and erasure, for the purpose of: recording quote requests; notifying the Controller's staff; generating quote PDF documents; creating Shopify draft orders; and providing support to the Controller.
Frequency: continuous, for the duration of the Principal Agreement.
Duration of processing: for the term of the Principal Agreement, plus the retention period configured by the Controller (default 730 days), subject to Section 11.
Sub-processor processing: as set out in Annex III, for the duration of the Principal Agreement.
Competent supervisory authority (SCC Annex I.C): the supervisory authority of the EEA Member State in which the Controller is established or, where the Controller is not established in the EEA, the supervisory authority of the Member State in which the Controller's Article 27 representative is located. For transfers from the United Kingdom, the Information Commissioner's Office.
Annex II — Technical and organisational measures
Encryption
- All data in transit is encrypted using TLS. The App is served only over HTTPS, and connections to Shopify, Amazon SES, Slack and the database are encrypted.
- All data at rest is stored on volumes encrypted with AES-256 by our hosting provider.
Access control and tenant isolation
- Every request to the App is authenticated using a Shopify session token; the App does not rely on cookies for authentication.
- Every database query is scoped to the requesting store, so data belonging to one merchant cannot be reached from another merchant's session.
- Shopify API credentials are short-lived, expiring access tokens with rotating refresh tokens.
- Administrative access to production systems is restricted to authorised personnel on the principle of least privilege, and protected by multi-factor authentication.
Data minimisation
- The App requests only the Shopify API permissions it requires, and holds no permission to read customer records from the merchant's store.
- Application logs record identifiers and counts only, never names, email addresses, telephone numbers or form responses.
Integrity and availability
- Data is stored in a managed PostgreSQL database with automated backups.
- Documents linking to Personal Data are served through short-lived, cryptographically signed URLs that expire automatically.
Governance
- Personnel with access to Personal Data are bound by written confidentiality obligations.
- Changes are version-controlled and reviewed before deployment, and the App is covered by an automated test suite.
- Sub-processors are assessed for security and data protection before engagement.
Assistance to the Controller
- Shopify's mandatory compliance webhooks are implemented, enabling data access, customer redaction and shop redaction requests to be actioned automatically.
- A configurable retention period automatically anonymises Personal Data that is no longer needed.
Annex III — Approved Sub-processors
| Sub-processor | Purpose | Personal Data processed | Location |
|---|---|---|---|
| Shopify Inc. | Hosts the Controller's store; the App runs within Shopify Admin | All categories in Annex I | Canada and United States |
| Railway Corp. | Application and database hosting | All categories in Annex I | United States |
| Amazon Web Services, Inc. (Simple Email Service) | Delivery of lead alert and staff verification emails | Staff email addresses; requester name and quote reference within the message body | United States |
| Slack Technologies, LLC | Delivery of lead alerts — only where the Controller enables a Slack webhook | Requester details and quote reference within the message body | United States |
The current list is maintained at dragonapps.io/request-a-quote-subprocessors.
Contact
Company: Dragon Apps
Registered address: PO Box 2210, Sunnybank Hills QLD 4109, Australia
Email: [email protected]
Website: https://dragonapps.io
See also our Privacy Policy.