Last Updated: Sep 2026
Data Processing Addendum(DPA)
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between Logbase Technologies ("Logbase", "Processor", "we", "us") and the Merchant ("Controller", "you").
This DPA applies where Logbase processes Personal Data on behalf of the Merchant in connection with the Services. It sets out the terms and conditions governing such processing and defines the respective rights and obligations of the parties in accordance with applicable data protection laws.
This DPA is intended to ensure compliance with applicable data protection regulations, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and, where applicable, other privacy laws such as the California Consumer Privacy Act ("CCPA").
In the event of any conflict between the terms of this DPA and the Agreement, the terms of this DPA shall prevail solely with respect to the processing of Personal Data.
By installing, accessing, or using the Services, the Merchant agrees to be bound by the terms of this DPA.
1.1 PREAMBLE
1.1.1 This Data Processing Addendum ("DPA") applies to all processing of Personal Data carried out by Logbase on behalf of the Merchant in connection with the Services.
1.1.2 This DPA forms an integral part of the Agreement and governs the rights and obligations of the parties with respect to such processing.
1.1.3 Logbase processes Personal Data solely on behalf of and in accordance with the Merchant's instructions and applicable data protection laws.
1.1.4 Logbase provides sufficient guarantees to implement appropriate technical and organizational measures to ensure that processing complies with applicable data protection laws, including the GDPR.
1.1.5 Terms used in this DPA shall have the meanings given under applicable data protection laws.
1.1.6 The parties agree that this DPA is intended to ensure compliance with applicable data protection laws and to implement appropriate safeguards to protect the rights of Data Subjects.
2. ROLES OF THE PARTIES
2.1 The Merchant acts as the Controller of Personal Data processed through the Services and determines the purposes and means of such processing.
2.2 Logbase acts as the Processor and processes Personal Data on behalf of the Merchant in accordance with the Agreement, this DPA, and applicable data protection laws.
2.3 The Merchant is responsible for ensuring that it has a valid legal basis for the processing of Personal Data and for providing any required notices to Data Subjects in accordance with applicable data protection laws.
2.4 Logbase shall process Personal Data only on documented instructions from the Merchant, unless required to do so by applicable law, in which case Logbase shall inform the Merchant of such legal requirement unless prohibited by law.
2.5 Logbase shall not process Personal Data for its own purposes and shall not sell, rent, or otherwise disclose Personal Data except as necessary to provide the Services or as required by law.
2.6 Logbase shall not use Personal Data to train general-purpose AI or machine learning models.
3. SUBJECT MATTER AND DURATION
3.1 Subject Matter
The subject matter of the processing is the provision of the Services by Logbase to the Merchant, including Shopify applications and related functionalities such as order management, scheduling, shipping rate calculation, customer interaction, analytics, and AI-powered assistance.
3.2 Duration of Processing
Processing of Personal Data shall take place for the duration of the Merchant's use of the Services and until Personal Data is deleted or anonymized in accordance with this DPA.
3.3 Nature of Processing
Logbase processes Personal Data as necessary to provide the Services, including:
- Collection of Personal Data through integrations with the Merchant's store
- Recording, organization, and structuring of data within the application
- Storage and retrieval of data to support application functionality
- Use of data to generate outputs, including analytics, reports, and automated responses
- Transmission of data to subprocessors as required to provide the Services
- Deletion or anonymization of data upon uninstall or when no longer required.
3.4 Purpose of Processing
Personal Data is processed for the following purposes:
- To provide application functionality, including scheduling, booking, shipping rate calculation, order tracking, and upsell recommendations
- To enable communication with Merchant Customers, including notifications and transactional messaging
- To generate analytics, reports, and performance insights for Merchants
- To support billing, usage tracking, and account management
- To enable AI-powered features, including automated customer assistance and recommendation.
3.5 Categories of Data Subjects
Personal Data processed may relate to:
- Merchants, including store owners and authorized users
- Merchant Customers, including individuals interacting with the Merchant's store.
3.6 Categories of Personal Data
Personal Data processed include:
- Merchant Data: name, email address, phone number, and address
- Merchant Customer Data: name, email address, phone number, address, order information, and booking-related data
- Usage Data: logs, analytics data, and system-generated information
- Uploaded Content: images and generated outputs, where applicable
3.7 Data Minimization and Purpose Limitation
Logbase processes only the Personal Data necessary to provide the Services and does not process Personal Data beyond what is required for the specified purposes.
3.8 AI Processing
Logbase does not use Personal Data processed through the Services to train general-purpose AI or machine learning models.
3.9 Additional Details
Further details regarding application-specific processing activities, including data access, purpose, storage, and retention practices, are set out in Annex I.
4. PROCESSING DETAILS
Logbase implements industry-standard security measures including encryption, access control, monitoring, and secure infrastructure.
4.1 Processing Instructions
Logbase shall process Personal Data only on documented instructions from the Merchant, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law. In such a case, Logbase shall inform the Merchant of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
4.2 Purpose Limitation
Logbase shall process Personal Data solely for the purposes specified in the Agreement and this DPA and shall not process Personal Data for its own purposes.
4.3 Data Minimization
Logbase shall process only the Personal Data that is necessary to provide the Services and shall not collect or process Personal Data beyond what is required for the specified purposes.
4.4 Accuracy
Logbase shall take reasonable steps to ensure that Personal Data is processed accurately and remains up to date, based on the information provided by the Merchant.
4.5 Confidentiality of Processing
Logbase shall ensure that any person authorized to process Personal Data is subject to appropriate confidentiality obligations and processes Personal Data only as necessary to perform their duties.
4.6 AI Processing
Where Personal Data is processed through AI-powered features, such processing is limited to generating outputs necessary for the Services. Logbase does not use Personal Data processed through the Services to train general-purpose AI or machine learning models.
4.7 Processing Transparency
Logbase shall provide information reasonably necessary to demonstrate compliance with this DPA and applicable data protection laws, upon reasonable request by the Merchant.
4.8 Compliance with Laws
Logbase shall comply with all applicable data protection laws in the processing of Personal Data and shall implement appropriate technical and organizational measures to ensure such compliance.
4.9 Merchant Responsibility
The Merchant is responsible for ensuring that Personal Data provided to Logbase is accurate, lawful, and collected in compliance with applicable data protection laws.
5. INSTRUCTIONS
5.1 Documented Instructions
Logbase shall process Personal Data only on documented instructions from the Merchant, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law.
5.2 Legal Requirement Exception
If Logbase is required by applicable law to process Personal Data other than as instructed by the Merchant, Logbase shall inform the Merchant of such legal requirement prior to processing, unless that law prohibits such notification on important grounds of public interest.
5.3 Scope of Instructions
The Agreement, this DPA, and the Merchant's use and configuration of the Services constitute the Merchant's documented instructions to Logbase.
5.4 Invalid or Unlawful Instructions
If Logbase believes that any instruction from the Merchant violates applicable data protection laws, Logbase shall promptly inform the Merchant and may suspend the relevant processing until the issue is resolved.
5.5 No Processing for Own Purposes
Logbase shall not process Personal Data for its own purposes and shall not sell, rent, or otherwise disclose Personal Data except as necessary to provide the Services or as required by applicable law.
5.6 Merchant Responsibility
The Merchant is responsible for ensuring that its instructions comply with applicable data protection laws and that it has obtained all necessary rights, consents, and authorizations required for Logbase to process Personal Data.
6. CONFIDENTIALITY
6.1 Confidentiality Obligation
Logbase shall ensure that all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory.
6.2 Authorized Access
Logbase shall ensure that access to Personal Data is limited to personnel who require such access to perform their job responsibilities in connection with the Services.
6.3 Processing on Instructions
Authorized personnel shall process Personal Data only on documented instructions from the Merchant, unless required to do so by applicable law.
6.4 Ongoing Obligation
The confidentiality obligations set out in this Section shall continue after the termination of the Agreement or cessation of processing activities.
6.5 Training and Awareness
Logbase takes reasonable steps to ensure that personnel handling Personal Data are informed of their data protection obligations and receive appropriate training where necessary.
7. SECURITY OF PROCESSING
7.1 General Security Obligations
Logbase implements and shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, taking into account the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects.
7.2 Technical and Organizational Measures
Logbase implements and maintains appropriate security measures, including:
- Encryption of Personal Data in transit and at rest, where applicable
- Access controls, including role-based access restrictions and authentication mechanisms
- Monitoring and logging of system activities to detect and prevent unauthorized access
- Secure infrastructure hosted on trusted cloud providers, including Amazon Web Services (AWS) and Google Cloud
- Network and application security controls designed to protect against unauthorized access, disclosure, alteration, or destruction of Personal Data
- Regular review and updates of security practices and procedures
7.3 Access Control
Logbase ensures that access to Personal Data is limited to authorized personnel who require such access to perform their job responsibilities. Such personnel are subject to confidentiality obligations.
7.4 Incident Detection and Response
Logbase maintains processes to detect, investigate, and respond to security incidents and potential Personal Data Breaches in a timely manner.
7.5 Security Testing and Evaluation
Logbase periodically reviews and evaluates the effectiveness of its technical and organizational measures to ensure ongoing security of Personal Data.
7.6 Subprocessor Security
Logbase ensures that any Subprocessors engaged to process Personal Data implement appropriate technical and organizational measures and are subject to contractual obligations consistent with this DPA.
7.7 Data Segregation
Logbase implements logical separation of data between different Merchants to ensure that Personal Data is accessible only to the relevant Merchant.
7.8 Backup and Recovery
Logbase maintains backup and recovery procedures designed to ensure the availability and integrity of Personal Data in the event of system failure or disruption.
8. SUBPROCESSORS
8.1 Appointment of Subprocessors
The Merchant acknowledges and agrees that Logbase may engage third-party subprocessors to process Personal Data on its behalf in connection with the provision of the Services.
8.2 Authorization
The Merchant provides general authorization for Logbase to engage subprocessors, provided that Logbase complies with the requirements set out in this Section.
8.3 Subprocessor Obligations
Logbase shall ensure that each subprocessor is subject to contractual obligations that provide at least the same level of data protection as those set out in this DPA, including obligations relating to confidentiality, security, and data protection.
8.4 Responsibility for Subprocessors
Logbase shall remain responsible for the acts and omissions of its subprocessors to the same extent as if Logbase were performing the services of each subprocessor directly.
8.5 Changes to Subprocessors
Logbase may update or replace subprocessors from time to time. Where required by applicable law, Logbase shall provide notice of such changes through its website, documentation, or other reasonable means.
8.6 Current Subprocessors
A current list of subprocessors is maintained and made available by Logbase, including:
- Amazon Web Services (AWS) – Cloud hosting, storage, infrastructure, and email services
- Google Cloud – Analytics, storage, monitoring, and AI/ML processing
- HubSpot – Customer relationship management, tickets and support
- Gleap – Customer relationship management, tickets and support
- Google Analytics – Website and application analytics
- OpenAI – AI processing for conversational features
- Tawk – Customer support chat
- Calendly – Scheduling and meeting management
- PostHog - Product analytics and feature usage tracking
8.7 Subprocessor Location
Subprocessors may process Personal Data in various jurisdictions. Logbase ensures that appropriate safeguards are implemented for any international data transfers in accordance with applicable data protection laws.
9. INTERNATIONAL DATA TRANSFERS
9.1 Transfer of Personal Data
The Merchant acknowledges that Personal Data may be transferred to and processed in countries outside the jurisdiction in which it was originally collected, including countries that may not provide the same level of data protection as the country of origin.
9.2 Data Location
Logbase primarily processes and stores Personal Data in data centers located in the United States. However, Personal Data may be processed in other jurisdictions where Logbase or its subprocessors operate, in accordance with this DPA and applicable data protection laws
9.3 Safeguards
Logbase implements appropriate safeguards for international data transfers in accordance with applicable data protection laws. Such safeguards may include contractual commitments with subprocessors and service providers to ensure an adequate level of protection for Personal Data.
9.4 Subprocessor Transfers
Where subprocessors process Personal Data in jurisdictions outside the Merchant's region, Logbase ensures that such subprocessors are subject to appropriate data protection obligations consistent with this DPA.
9.5 Compliance with Applicable Laws
Logbase shall comply with applicable data protection laws relating to international data transfers and shall take reasonable steps to ensure that Personal Data is protected in accordance with this DPA.
9.6 Standard Contractual Clauses
Where the transfer of Personal Data from the Merchant (or from within the European Economic Area or United Kingdom) to Logbase or its subprocessors involves a Restricted Transfer (as defined in Annex IV), the parties shall rely on the Standard Contractual Clauses set out in Annex IV of this DPA, which are hereby incorporated by reference and form an integral part of this DPA. The Standard Contractual Clauses shall apply automatically to any such Restricted Transfer without requiring further action by either party. The relevant module, governing law, and supervisory authority shall be as specified in Annex IV. Where the UK GDPR applies, the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses shall apply as set out in Annex IV, Part 2.
10. DATA SUBJECT RIGHTS
10.1 Assistance with Data Subject Requests
Logbase shall, taking into account the nature of the processing, provide reasonable assistance to the Merchant to enable the Merchant to respond to requests from Data Subjects to exercise their rights under applicable data protection laws.
10.2 Scope of Assistance
Such assistance may include, where applicable:
- Providing access to relevant Personal Data processed by Logbase
- Supporting correction, deletion, or restriction of Personal Data
- Assisting with data portability requests
- Providing information necessary to respond to Data Subject requests
10.3 Responsibility of the Merchant
The Merchant is responsible for responding to Data Subject requests and for ensuring compliance with applicable data protection laws, including determining whether such requests are valid.
10.4 Direct Requests
If Logbase receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Merchant, Logbase shall, where appropriate, direct the Data Subject to the Merchant or notify the Merchant of the request, unless required to respond directly under applicable law.
10.5 Limitations
Logbase shall not be required to respond directly to Data Subject requests unless required to do so under applicable law.
10.6 Verification
The Merchant is responsible for verifying the identity of the Data Subject before requesting Logbase to take any action in relation to Personal Data.
10.7 Compliance with Applicable Laws
Logbase shall provide assistance to the extent required under applicable data protection laws and subject to the Merchant's documented instructions.
10.8 Reasonable Efforts
Logbase shall provide such assistance using appropriate technical and organizational measures, taking into account the nature of the processing and the information available to Logbase.
11. DATA RETENTION AND DELETION
11.1 Retention Period
Logbase retains Personal Data only for as long as necessary to provide the Services and fulfill the purposes described in the Agreement and this DPA, unless a longer retention period is required or permitted by applicable law.
11.2 Application-Specific Retention
Retention periods may vary depending on the application and its functionality. Detailed information regarding application-specific retention practices is set out in Annex I.
11.3 Deletion Upon Termination
Upon termination of the Agreement or uninstall of the Services, Logbase shall delete or anonymize applicable Personal Data from its active systems upon receipt of the relevant Shopify GDPR deletion webhook, unless retention is required for legal, regulatory, or security purposes. Any residual copies remaining in backup systems will be automatically deleted or overwritten within 30 days in accordance with Logbase's backup retention and rotation processes.
11.4 Backup Retention
Personal Data may be retained in backup systems for a limited period and will be securely deleted or overwritten in accordance with Logbase's data lifecycle management processes.
11.5 Legal Retention Obligations
Logbase may retain Personal Data where required to comply with applicable laws, legal obligations, or to establish, exercise, or defend legal claims.
11.6 Deletion Requests
Logbase shall, upon documented instructions from the Merchant, delete or return Personal Data to the Merchant, unless applicable law requires storage of the Personal Data.
11.7 Anonymization
Where appropriate, Personal Data may be anonymized or de-identified so that it can no longer be used to identify an individual.
11.8 Data Minimization
Logbase shall take reasonable steps to ensure that Personal Data is not retained longer than necessary for the purposes for which it was processed.
12. DATA BREACH NOTIFICATION
12.1 Notification of Breach
Logbase shall notify the Merchant without undue delay and, in any event, within 72 hours after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Merchant. Where notification cannot be made within 72 hours, Logbase shall provide the notification as soon as reasonably possible and shall include, along with the notification, the reasons for the delay.
12.2 Information Provided
Such notification shall include, to the extent reasonably available:
- A description of the nature of the Personal Data Breach, including the categories and approximate number of affected Data Subjects and records
- The likely consequences of the Personal Data Breach
- The measures taken or proposed to be taken by Logbase to address the Personal Data Breach and mitigate its possible adverse effects
12.3 Ongoing Updates
Where it is not possible to provide all information at the same time, Logbase may provide such information in phases as it becomes available.
12.4 Cooperation
Logbase shall provide reasonable assistance to the Merchant in investigating the Personal Data Breach and in fulfilling any applicable breach notification obligations under data protection laws.
12.5 Responsibility of the Merchant
The Merchant is responsible for determining whether to notify affected Data Subjects or supervisory authorities and for fulfilling any such obligations under applicable data protection laws.
12.6 No Admission of Fault
Notification of a Personal Data Breach by Logbase shall not be construed as an admission of fault or liability.
12.7 Incident Response
Logbase maintains internal processes and procedures to detect, investigate, and respond to Personal Data Breaches in a timely manner.
13. ASSISTANCE AND COMPLIANCE
13.1 General Assistance
Logbase shall provide reasonable assistance to the Merchant in fulfilling the Merchant's obligations under applicable data protection laws, taking into account the nature of the processing and the information available to Logbase.
13.2 Data Protection Impact Assessments
Where required under applicable data protection laws, Logbase shall provide reasonable assistance to the Merchant in carrying out data protection impact assessments (DPIAs) and, where applicable, prior consultations with supervisory authorities, to the extent that such assistance relates to the processing of Personal Data by Logbase.
13.3 Information for Compliance
Logbase shall make available to the Merchant information reasonably necessary to demonstrate compliance with the obligations set out in this DPA.
13.4 Limitations
Logbase's obligation to provide assistance under this Section shall be limited to what is reasonable and proportionate, taking into account the nature of the processing and the information available to Logbase.
13.5 Costs
Where permitted by applicable law, Logbase may charge a reasonable fee for providing assistance beyond what is required to comply with its legal obligations under applicable data protection laws.
13.6 Records of Processing
Logbase shall maintain records of processing activities as required under applicable data protection laws.
14. AUDIT RIGHTS
14.1 Information Availability
Logbase shall make available to the Merchant information reasonably necessary to demonstrate compliance with this DPA, upon reasonable request.
14.2 Method of Compliance
Logbase may satisfy its obligations under this Section by providing written responses, summaries of its data protection practices, or other relevant information, at its discretion.
14.3 Limitations
The Merchant acknowledges that Logbase does not permit on-site audits or direct access to its systems. Any information provided shall be limited to what is reasonably necessary to demonstrate compliance and shall be subject to confidentiality obligations.
14.4 Reasonableness
All requests under this Section shall be reasonable in scope, proportionate, and shall not unreasonably interfere with Logbase's business operations.
15. LIABILITY
15.1 Limitation of Liability
The liability of each party arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement.
15.2 No Expansion of Liability
Nothing in this DPA shall be construed as increasing or expanding the liability of either party beyond the limits agreed in the Agreement.
15.3 Allocation of Responsibility
Each party shall be responsible for its own compliance with applicable data protection laws. The Merchant is responsible for ensuring that Personal Data is collected and processed lawfully, including obtaining any required consents or providing appropriate notices to Data Subjects.
15.4 Indirect Damages
Neither party shall be liable for any indirect, incidental, special, or consequential damages arising out of or in connection with this DPA, except as required under applicable law.
16. TERMINATION
16.1 Termination of Processing
This DPA shall remain in effect for as long as Logbase processes Personal Data on behalf of the Merchant in connection with the Services.
16.2 Effect of Termination
Upon termination of the Agreement or uninstall of the Services, Logbase shall cease processing Personal Data, except as required to comply with applicable laws or to fulfill its obligations under this DPA.
16.3 Deletion of Personal Data
Following termination, Logbase shall delete or anonymize Personal Data in accordance with Section 11 of this DPA, unless retention is required for legal, regulatory, security, or legitimate business purposes.
16.4 Survival
The provisions of this DPA that by their nature are intended to survive termination, including but not limited to confidentiality, security, liability, and data protection obligations, shall continue in effect after termination of the Agreement.
17. CONTACT
ANNEX I — PROCESSING DETAILS & RETENTION
1. Categories of Data Subjects
- Merchants (store owners and authorized users)
- Merchant Customers (individuals interacting with the Merchant's store)
2. Categories of Personal Data
- Merchant Data: name, email address, phone number, and address
- Merchant Customer Data: name, email address, phone number, address, order information, and booking-related data
- Usage Data: logs, analytics data, and system-generated information
- Uploaded Content: images and generated outputs (where applicable)
3. Application-Specific Processing
Shopify GDPR Webhook Compliance
Logbase implements Shopify's GDPR-compliant webhook mechanisms to support data deletion and privacy requests.
shop/redact
- Shopify sends this event 48 hours after a merchant uninstalls the application.
- Upon receiving this event, Logbase automatically deletes or anonymizes applicable Personal Data associated with the merchant from its active systems, except where retention is required for legal, regulatory, or security purposes.
- Any residual copies remaining in backup systems are automatically deleted or overwritten within 30 days in accordance with Logbase's backup retention and rotation processes.
customers/redact
- Shopify sends this event 10 days after a customer requests deletion or when a merchant deletes a customer.
- Upon receiving this event, Logbase automatically deletes or anonymizes applicable Personal Data related to the specified customer from its active systems, where such data is identifiable and stored.
- Any residual copies remaining in backup systems are automatically deleted or overwritten within 30 days in accordance with Logbase's backup retention and rotation processes.
These processes ensure compliance with applicable data protection laws and Shopify platform requirements.
Selleasy (Upsell & Cross-Sell)
Selleasy enables merchants to create upsell and cross-sell offers, customer-targeted campaigns, and recommendation workflows. Personal Data is processed solely as necessary to provide the Services.
Merchant Data
| Field | Details |
|---|---|
| Access: CRM, merchant communication, and operational notifications Retrieval: To contact merchants, support communication workflows, and manage account-related activities Storage: Stored for communication, CRM, and operational support purposes Retention: While the merchant's store remains active | |
| Phone | Access: CRM and merchant communication Retrieval: Not retrieved by the application Storage: Not stored Retention: Not retained |
| Name | Access: CRM and merchant communication Retrieval: Not retrieved by the application Storage: Stored temporarily as part of campaign configuration. Not retained in identifiable form after campaign processing Retention: Not retained in identifiable form. Stored only for the duration of campaign configuration |
| Address | Access: CRM and merchant communication Retrieval: Not retrieved by the application Storage: Not stored Retention: Not retained |
Merchant Customer Data
| Field | Details |
|---|---|
| Access: To support customer-targeted campaign creation and upsell/cross-sell workflows Retrieval: To enable merchants to filter and select customers within the admin panel for campaign targeting Storage: Not stored Retention: Not retained | |
| Phone | Access: Not required for application functionality Retrieval: Not retrieved by the application Storage: Not stored Retention: Not retained |
| Name | Access: To support customer-targeted campaign creation and recommendation workflows Retrieval: To enable merchants to identify and select customers within campaign workflows Storage: Stored as part of campaign configuration to support customer targeting functionality Retention: Not retained as an identifiable customer. |
| Address | Access: To support usage-based billing, analytics, and recommendation functionality Retrieval: To calculate usage-based billing and support upsell/cross-sell recommendation workflows Storage: Only aggregated order count is stored for billing and analytics purposes. Retention: Not retained |
Pickeasy (Pickup & Delivery Date)
Pickeasy enables merchants to manage pickup and delivery scheduling workflows, delivery eligibility rules, location-based configurations, and customer order scheduling. Personal Data is processed solely as necessary to provide the Services.
Merchant Data
| Field | Details |
|---|---|
| Access: CRM, location management, analytics, and communication Retrieval: To manage merchant communication, send order status updates, and support in-app location configuration Storage: Stored for CRM, communication, operational management, and notification workflows Retention: While the merchant's store remains active | |
| Phone | Access: CRM and location management Retrieval: To support merchant communication and in-app location configuration Storage: Stored for CRM and location management purposes Retention: While the merchant's store remains active |
| Name | Access: CRM and merchant identification Retrieval: To identify merchants and support CRM activities Storage: Stored for CRM and merchant identification purposes Retention: While the merchant's store remains active |
| Address / Location | Access: Location management and operational configuration Retrieval: To configure and manage pickup and delivery locations within the application Storage: Stored to support location setup and operational workflows Retention: While the merchant's store remains active |
Merchant Customer Data
| Field | Details |
|---|---|
| Access: Order management and customer communication Retrieval: To display customer contact details within order views and support communication workflows Storage: Stored to provide historical visibility in the admin interface and support troubleshooting Retention: Up to 90 days | |
| Phone | Access: Order management and customer communication Retrieval: To display customer contact details within order views Storage: Stored to support historical visibility and troubleshooting Retention: Up to 90 days |
| Name | Access: Order management and customer identification Retrieval: To display customer details within order views and identify customers Storage: Stored to support historical visibility and troubleshooting Retention: Up to 90 days |
| Address | Access: Delivery eligibility and logistics workflows Retrieval: To determine delivery zones, calculate distance or zipcode-based rules, and apply slot and rate logic Storage: Stored to support delivery calculations, logistics workflows, and troubleshooting Retention: Up to 90 days |
| Order Information | Access: Order management, scheduling, and fulfillment workflows Retrieval: To display order information and support slot selection, delivery scheduling, and operational workflows Storage: Stored to support processing, historical visibility, and troubleshooting Retention: Up to 90 days |
ShipX (Shipping Rates)
ShipX enables merchants to configure shipping rules, calculate shipping rates, manage logistics workflows, and apply delivery-related conditions based on customer and order data. Personal Data is processed solely as necessary to provide the Services.
Merchant Data
| Field | Details |
|---|---|
| Access: Account management, CRM, analytics, and merchant communication Retrieval: To perform analytics, manage merchant accounts, and send operational updates such as import/export status notifications Storage: Stored for account management, analytics, communication workflows, and operational support Retention: While the merchant's store remains active | |
| Phone | Access: CRM, analytics, and emergency contact Retrieval: To support account management, analytics, and communication workflows Storage: Stored for account management and communication purposes Retention: While the merchant's store remains active |
| Name | Access: CRM and analytics Retrieval: To identify merchants and support CRM and analytics activities Storage: Stored for account identification and communication purposes Retention: While the merchant's store remains active |
| Address | Access: Analytics and operational context Retrieval: To provide contextual insights for analytics and operational workflows Storage: Not used for core application functionality and not retained for application use. May include personal data depending on merchant type Retention: Not retained for application use |
Merchant Customer Data
| Field | Details |
|---|---|
| Access: Shipping rule evaluation and application logic execution Retrieval: To evaluate configured shipping conditions and execute application workflows Storage: Stored to support shipping rate calculation, historical visibility, and troubleshooting Retention: Up to 60 days | |
| Phone | Access: Shipping rule evaluation and application logic execution Retrieval: To evaluate configured shipping conditions and execute application workflows Storage: Stored to support processing, historical visibility, and troubleshooting Retention: Up to 60 days |
| Address | Access: Shipping calculations and logistics workflows Retrieval: To determine destination shipping zones and execute shipping logic Storage: Stored to support shipping calculations, logistics workflows, and troubleshooting Retention: Up to 60 days |
| Order Information | Access: Shipping rule evaluation and rate calculation Retrieval: To validate configured conditions and calculate shipping rates Storage: Stored to support shipping calculations, order processing, historical visibility, and troubleshooting Retention: Up to 60 days |
AskTimmy (AI Customer Assistant)
AskTimmy enables merchants to automate customer support through AI-powered conversations, product recommendations, lead capture, order lookup workflows, and customer interaction management. Personal Data is processed solely as necessary to provide the Services. Merchant and customer data, including uploaded content, is not used to train general-purpose AI or machine learning models.
Merchant Data
| Field | Details |
|---|---|
| Access: Support identification, CRM, and application notifications Retrieval: To identify merchants in support tools, manage communication workflows, and send operational updates Storage: Stored for merchant identification, communication, and support workflows Retention: While the merchant's store remains active | |
| Phone | Access: Store configuration and operational management Retrieval: To support store setup and operational configuration workflows Storage: Stored as part of store configuration and operational setup data Retention: While the merchant's store remains active |
| Name | Access: Support identification and store configuration Retrieval: To identify merchants and support configuration and support workflows Storage: Stored for merchant identification and configuration workflows Retention: While the merchant's store remains active |
| Address | Access: Store location configuration and operational setup Retrieval: To configure store locations and operational workflows within the application Storage: Stored as part of store configuration and operational setup data Retention: While the merchant's store remains active |
Merchant Customer Data
| Field | Details |
|---|---|
| Access: Customer personalization, lead capture, and order lookup workflows Retrieval: To identify returning customers, enable order lookups, and support lead generation workflows Storage: Stored as part of conversation history, analytics, and merchant support workflows Retention: Up to 60 days | |
| Phone | Access: Lead capture and customer interaction workflows Retrieval: To capture customer contact details for lead generation and communication workflows Storage: Stored as part of conversation records and lead management workflows Retention: Up to 60 days |
| Name | Access: Customer personalization and identification Retrieval: To personalize interactions and identify customers within conversation workflows Storage: Stored as part of conversation records and analytics workflows Retention: Up to 60 days |
| Address | Access: Order-related customer support workflows Retrieval: To provide order-related information during customer interactions Storage: Stored as part of conversation records where required for support workflows Retention: Up to 60 days |
| Order Information | Access: Order lookup and customer support workflows Retrieval: To validate and display order status, fulfillment details, and tracking information Storage: Stored as part of conversation history and support workflows Retention: Up to 60 days |
| Customer Uploaded Images (Photo Search) | Access: Visual product search workflows Retrieval: To extract visual attributes from uploaded images and match them against the product catalog Storage: Stored for processing, search history, analytics, and debugging workflows. Image references may be retained for troubleshooting purposes Retention: Up to 60 days |
BookX (Booking & Appointment)
BookX enables merchants to manage appointment scheduling, booking workflows, customer notifications, and booking-related operational processes. Personal Data is processed solely as necessary to provide the Services.
Merchant Data
| Field | Details |
|---|---|
| Access: CRM, merchant communication, and support workflows Retrieval: To identify merchants, manage communication, and support CRM-related activities Storage: Stored for merchant identification, communication workflows, and CRM purposes Retention: While the merchant's store remains active | |
| Phone | Access: CRM, analytics, and operational communication Retrieval: To support communication and operational workflows Storage: Stored for CRM, analytics, and communication purposes Retention: While the merchant's store remains active |
| Name | Access: CRM and merchant identification Retrieval: To identify merchants and support CRM workflows Storage: Stored for merchant identification and communication purposes Retention: While the merchant's store remains active |
| Address | Access: Operational context and analytics Retrieval: To support operational workflows and analytics Storage: Stored for operational management and analytics purposes Retention: While the merchant's store remains active |
Merchant Customer Data
| Field | Details |
|---|---|
| Access: Booking management and customer communication Retrieval: To create and manage booking records and send booking confirmations and notifications Storage: Stored as part of booking records to support application functionality and booking workflows Retention: Up to 365 days | |
| Phone | Access: Booking management and customer communication Retrieval: To display booking details and enable merchant-to-customer communication Storage: Stored as part of booking records to support application functionality and operational workflows Retention: Up to 365 days |
| Name | Access: Booking management and customer identification Retrieval: To display booking details and identify customers within booking workflows Storage: Stored as part of booking records to support booking functionality and customer identification Retention: Up to 365 days |
| Address | Access: Booking management and customer interaction workflows Retrieval: To display booking details and support customer interaction workflows Storage: Stored as part of booking records to support operational workflows Retention: Up to 365 days |
| Order Information | Access: Booking reference and operational workflows Retrieval: To display order or booking identifiers within the application and support booking-related workflows Storage: Stored to support navigation, booking references, and operational workflows Retention: Up to 365 days |
Dealeasy (Volume Discount)
Dealeasy enables merchants to create volume discounts, tiered pricing, bundle offers, and promotional workflows such as buy-one-get-one (BOGO) campaigns. Personal Data is processed solely as necessary to provide the Services.
Merchant Data
| Field | Details |
|---|---|
| Access: Merchant identification, CRM, analytics, and support workflows Retrieval: To identify merchants, support communication workflows, and manage CRM-related activities Storage: Stored to support merchant identification, communication, analytics, and support workflows Retention: While the merchant's store remains active | |
| Phone | Access: Analytics and reporting workflows Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
| Name | Access: CRM and merchant communication workflows Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
| Address | Access: Analytics and reporting workflows Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
Merchant Customer Data
| Field | Details |
|---|---|
| Access: Discount eligibility and campaign execution workflows Retrieval: To evaluate customer eligibility for discount rules and support targeted promotional workflows Storage: Not stored. Used only for real-time processing within the application Retention: Not retained | |
| Phone | Access: Analytics workflows Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
| Name | Access: Discount eligibility and campaign execution workflows Retrieval: To evaluate customer eligibility and display customer details within promotional workflows Storage: Not stored. Used only for real-time processing within the application Retention: Not retained |
| Address | Access: Analytics workflows Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
| Order Information | Access: Analytics, promotional workflows, and subscription billing Retrieval: To support analytics, usage-based billing calculations, and promotional rule execution Storage: Only limited aggregated data (such as order count and country-level analytics) may be retained for billing and analytics purposes Retention: Not retained in identifiable form |
Dibs (Preorder)
Dibs enables merchants to manage preorders and backorders for pre-launch and out-of-stock products. The application supports preorder workflows, partial payments, automated payment reminders, and order-related notification functionality. Personal Data is processed solely as necessary to provide the Services.
Merchant Data
| Field | Details |
|---|---|
| Access: Email notifications, merchant communication, and CRM workflows Retrieval: To send order and payment-related notifications using the configured sender email and support merchant communication workflows Storage: Stored to support notification workflows, merchant communication, and support-related activities Retention: While the merchant's store remains active | |
| Phone | Access: Not required for application functionality Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
| Name | Access: Merchant communication and notification workflows Retrieval: To support merchant identification and notification-related workflows Storage: Stored to support notification workflows and merchant identification Retention: While the merchant's store remains active |
| Address | Access: Partial payment configuration and operational validation Retrieval: To determine country-level eligibility for partial payment functionality Storage: Stored to support configuration and operational validation workflows Retention: While the merchant's store remains active |
Merchant Customer Data
| Field | Details |
|---|---|
| Access: Order and payment notification workflows Retrieval: To send preorder, backorder, and payment-related notifications to customers Storage: Not stored. Used only for real-time notification processing Retention: Not retained | |
| Phone | Access: Not required for application functionality Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
| Name | Access: Not required for application functionality Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
| Address | Access: Not required for application functionality Retrieval: Not retrieved or used by the application Storage: Not stored Retention: Not retained |
| Order Information | Access: Order management, preorder workflows, and analytics Retrieval: To display preorder and backorder details within the Orders page and support operational metrics Storage: Not stored. Used only for real-time processing within the application Retention: Not retained |
DecorGenie (Shop Minis)
DecorGenie enables users to generate room visualizations and interior design previews using user-uploaded images. The application processes uploaded content solely to generate visualization outputs and display historical results within the application.
DecorGenie does not access or process merchant account data, merchant customer personal data, order information, or Shopify customer records.
Uploaded content is processed solely to provide the requested visualization functionality and is not used to train general-purpose AI or machine learning models.
| Field | Details |
|---|---|
| User Uploaded Images | Access: Visualization generation and image processing workflows Retrieval: To generate room visualizations and interior design outputs based on user-uploaded images Storage: Stored to support visualization history, generated results display, analytics, and troubleshooting workflows Retention: Up to 90 days |
| Generated Visualization Results | Access: Visualization history and user experience workflows Retrieval: To display previously generated room visualization results to users Storage: Stored to support visualization history and operational workflows Retention: Up to 90 days |
FitGenie (Shop Minis)
FitGenie enables users to generate virtual try-on experiences using user-uploaded images and AI-powered visualization workflows. The application processes uploaded content solely to generate try-on outputs and display historical results within the application.
FitGenie does not access or process merchant data or merchant customer personal data.
| Field | Details |
|---|---|
| User Uploaded Images | Access: Virtual try-on generation and image processing workflows Retrieval: To generate virtual try-on outputs based on user-uploaded images Storage: Stored to support try-on history, generated results display, analytics, and troubleshooting workflows Retention: Up to 90 days |
| Generated Try-On Results | Access: Try-on history and user experience workflows Retrieval: To display previously generated try-on results to users Storage: Stored to support try-on history and operational workflows Retention: Up to 90 days |
ANNEX II — SECURITY MEASURES
Logbase implements and maintains appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.
1. Access Control
- Access to Personal Data is restricted to authorized personnel based on role and necessity
- Role-based access controls are implemented to limit access to only what is required for job responsibilities
- Authentication mechanisms are used to protect access to systems and data
2. Data Protection
- Personal Data is encrypted in transit using industry-standard protocols
- Personal Data is encrypted at rest, where applicable
- Data is processed only as necessary to provide the Services
3. Infrastructure Security
- Systems are hosted on secure cloud infrastructure providers, including Amazon Web Services (AWS) and Google Cloud
- Cloud providers implement physical, network, and infrastructure-level security controls
- Network security measures are in place to protect against unauthorized access
4. Monitoring and Logging
- System activity is monitored to detect unauthorized access or unusual activity
- Logs are maintained to support incident detection and investigation
- Alerts may be generated for suspicious or abnormal system behavior
5. Incident Management
- Processes are in place to detect, investigate, and respond to security incidents
- Personal Data Breaches are handled in accordance with Section 12 of this DPA
- Appropriate remediation steps are taken to mitigate potential impact
6. Subprocessor Security
- Subprocessors are selected based on their ability to provide appropriate security measures
- Contractual agreements require subprocessors to implement data protection and security controls consistent with this DPA
- Subprocessor practices are reviewed as part of vendor management processes
7. Data Segregation
Logical separation of data is maintained between different Merchants to prevent unauthorized access across accounts
8. Backup and Recovery
- Backup mechanisms are implemented to ensure availability and integrity of data
- Data may be restored in the event of system failure or disruption
9. Security Maintenance
- Security measures are reviewed and updated periodically
- Reasonable steps are taken to ensure continued effectiveness of technical and organizational measures
ANNEX III — SUBPROCESSORS
The following is a list of subprocessors that may process Personal Data on behalf of Logbase in connection with the Services.
Logbase ensures that each subprocessor is subject to data protection obligations consistent with this DPA.
Subprocessors may process Personal Data in the United States and other jurisdictions where they operate, in accordance with applicable data protection laws.
1. Common Subprocessors
These subprocessors are used across Logbase applications, depending on the functionality and services used.
| Subprocessor | Purpose | Data Processed |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, infrastructure, storage, database management, email services | Merchant Data, Customer Data, Usage Data |
| HubSpot | Customer relationship management and support | Merchant Data |
| Google Analytics | Website and application analytics | Usage Data |
| Tawk | Customer support chat | Merchant Data |
| Calendly | Scheduling and meeting management | Merchant Data |
| Gleap | Customer support and ticket management | Merchant Data |
| PostHog | Product analytics and feature usage tracking | Merchant Data |
2. Application-Specific Subprocessors
The following subprocessors are used only by applications or features that require the relevant processing functionality.
| Application | Subprocessor | Purpose | Data Processed |
|---|---|---|---|
| AskTimmy | Google Cloud | AI/ML processing and supporting application services | Merchant Data, Customer Data, Usage Data |
| AskTimmy | OpenAI | AI-powered conversational assistance and related AI processing | Limited Merchant Customer Data and conversation content as required |
| Selleasy | Resend | Account management and email delivery | Merchant Data |
| DecorGenie | Gemini | AI image/visualization processing | User-uploaded images and generated outputs |
| FitGenie | Gemini | AI image/visualization processing | User-uploaded images and generated outputs |
Logbase updates this list of subprocessors from time to time in accordance with Section 8 of this DPA.
ANNEX IV — STANDARD CONTRACTUAL CLAUSE
PART 1 — EU STANDARD CONTRACTUAL CLAUSES
The Standard Contractual Clauses set out in the European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs") are incorporated into this DPA by reference and apply to any Restricted Transfer of Personal Data subject to the EU GDPR
1. Definitions
"Restricted Transfer" means any transfer of Personal Data from the European Economic Area (EEA) to a country or territory outside the EEA that does not benefit from an adequacy decision by the European Commission pursuant to Article 45 of the GDPR.
"Data Exporter" means the Merchant (Controller) transferring Personal Data to Logbase.
"Data Importer" means Logbase Technologies (Processor) receiving Personal Data from the Merchant
2. Applicable Module
Module Two (Controller to Processor) of the EU SCCs shall apply to transfers under this DPA. Modules One, Three, and Four are not applicable and shall be deemed deleted
3. Optional Clauses
Clause 7 (Docking Clause): Does not apply.
Clause 9: Option 2 (General Written Authorisation) applies. The time period for prior notice of subprocessor changes is fifteen (15) days.
Clause 11 (Redress): The optional language relating to independent dispute resolution does not apply.
Clause 17 (Governing Law): The EU SCCs shall be governed by the law of Ireland.
Clause 18(b) (Choice of Forum): Disputes shall be resolved before the courts of Ireland
4. Annex 1 — Description of Transfer
| Field | Details |
|---|---|
| Data Exporter | The Merchant, as identified in the Agreement |
| Data Importer | Logbase Technologies, connect@logbase.io |
| Categories of Data Subjects | Merchants; Merchant Customers |
| Categories of Personal Data | Merchant Data: name, email, phone, address Merchant Customer Data: name, email, phone, address, order/booking data Usage Data: logs, analytics, system data Uploaded Content: images and generated outputs |
| Sensitive Data | None |
| Frequency of Transfer | Continuous, for the duration of the Agreement |
| Nature of Processing | As set out in Sections 3.3–3.4 of this DPA |
| Purpose of Transfer | Provision of the Services as described in the Agreement |
| Retention Period | As set out in Section 11 and Annex I of this DPA |
| Competent Supervisory Authority | The supervisory authority of the EU Member State in which the Merchant is established, or, where the Merchant is not established in the EU, the Irish Data Protection Commission |
5. Annex 2 Technical and Organisational Measures
The technical and organisational security measures applicable to the processing are as set out in Annex II of this DPA.
6. Annex 3 — List of Subprocessors
The list of subprocessors authorised to process Personal Data is as set out in Annex II of this DPA
PART 2 — UK INTERNATIONAL DATA TRANSFER ADDENDUM (IDTA)
Where the transfer of Personal Data is subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (ICO) on 21 March 2022 ("UK Addendum") shall apply, and is incorporated into this DPA by reference
1. Table 1 — Parties
| Field | Exporter (Merchant) | Importer (Logbase) |
|---|---|---|
| Full Legal Name | As identified in the Agreement | Logbase Technologies |
| Main Address | As identified in the Agreement | As per Agreement |
| Contact | As identified in the Agreement | connect@logbase.io |
| Key Contact | Merchant's DPO or legal contact | connect@logbase.io |
2. Table 2 — Selected SCCs, Modules and Selected Clauses
Logbase Technologies As per Agreement connect@logbase.io. The UK Addendum is appended to and forms part of the EU SCCs set out in Part 1 of this Annex IV. Module Two (Controller to Processor) applies.
3. Table 3 — Appendix Information
The information required for Appendix 1 (Description of Transfer), Appendix 2 (Technical and Organisational Measures), and Appendix 3 (List of Subprocessors) of the EU SCCs is as set out in Annex 1, Annex 2, and Annex 3 of Part 1 of this Annex IV respectively.
4. Table 4 — Ending the Addendum
Neither party may end the UK Addendum when the Approved EU SCCs it is appended to change, in accordance with the provisions of Section 19 of the UK Addendum.
5. Supervisory Authority
For purposes of the UK Addendum, the competent supervisory authority is the UK Information Commissioner's Office (ICO).
