Orumio — Standing Orders
Data Processing Agreement
This Data Processing Agreement (“DPA”) governs our processing of personal data on your behalf when you install and use Orumio — Standing Orders. It takes effect automatically when you install the app, and no signature is required for it to bind us.
If your organisation requires a countersigned copy, or a copy on your own paper, write to support@orumio.com and we will provide one.
1. Parties and definitions
“Processor”, “we”, “us”: Orumio, represented by Masanori Iwata, Mitsuhashi Building 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan, contact support@orumio.com.
“Controller”, “you”, “Merchant”: the operator of the Shopify store in which the app is installed.
“App”: Orumio — Standing Orders. “Personal Data”, “Processing”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. “Data Protection Law” means every privacy or data protection law applicable to the Processing under this DPA, including the EU GDPR, the UK GDPR, Japan’s Act on the Protection of Personal Information (APPI), and the US state privacy laws addressed in Annex IV.
2. Roles and scope
You are the Controller of the Personal Data in your Shopify store. We are your Processor, and we process that Personal Data only to provide the App to you.
Shopify is an independent party to this DPA. Your relationship with Shopify, including Shopify’s own role in respect of your store data, is governed by your agreement with Shopify and not by this document.
This DPA applies for as long as the App is installed in your store and survives uninstallation for as long as we hold any of your Personal Data.
3. Instructions
We process Personal Data only on your documented instructions, including in respect of transfers to a third country. Your instructions are: (a) this DPA, including Annex I; (b) the App’s documented functionality, which you direct by configuring standing orders in your store; and (c) any further written instruction you give us that we accept.
We will tell you if, in our opinion, an instruction infringes Data Protection Law. We will not process Personal Data for our own purposes, and specifically not for marketing, advertising, profiling, resale, or the training of machine-learning models.
If we are required by law to process Personal Data beyond your instructions, we will inform you of that legal requirement before processing, unless the law forbids us from doing so on important grounds of public interest.
4. Confidentiality
The App is operated by a single person, who is bound by a duty of confidentiality in respect of all Personal Data processed under this DPA. There are no staff accounts, contractors, or support agents with access to Merchant data. If that ever changes, we will ensure that any person authorised to process Personal Data is placed under an equivalent obligation of confidentiality before access is granted.
5. Security
We implement and maintain the technical and organisational measures set out in Annex II, which are appropriate to the risk, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing.
The primary measure is minimisation: the App does not store the Personal Data of your buyers at all. We may update the measures in Annex II over time, but we will not reduce the overall level of security.
6. Sub-processors
You give us general written authorisation to engage sub-processors. The sub-processors engaged as at the effective date of this DPA are listed in Annex III.
Before we add or replace a sub-processor we will update Annex III and notify you by email at the notification address on file, at least 30 days in advance. You may object on reasonable data protection grounds within that period; if we cannot resolve your objection, you may terminate by uninstalling the App, and we will delete your data in accordance with §10.
We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for each sub-processor’s performance.
7. Assistance with data subject rights
Because the App stores no buyer Personal Data, requests to access, rectify, erase, restrict, port, or object usually require no action from us — the data lives in Shopify, under your control.
Where a Data Subject nonetheless contacts us directly, we will not respond substantively ourselves. We will refer them to you, and tell you promptly. Taking account of the nature of the Processing, we will assist you by appropriate technical and organisational measures, so far as possible, in fulfilling your obligation to respond.
We honour the Shopify mandatory compliance webhooks: customers/data_request (we return nothing, because we hold nothing), customers/redact (no action required, for the same reason), and shop/redact (we delete your entire tenant, per §10).
8. Personal data breach
We will notify you of a Personal Data Breach affecting your Personal Data without undue delay after becoming aware of it, and in any event targeting within 72 hours of confirming it. The notification will describe, so far as it is known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information cannot be provided at once, we will provide it in phases without further undue delay rather than waiting for a complete root-cause analysis.
We maintain a written security incident response policy covering detection, containment, assessment, notification, remediation and post-incident review, and we review it after every significant incident.
9. Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a Supervisory Authority.
10. Deletion and return
Because no buyer Personal Data is retained, there is nothing of that kind to return or delete at the end of the relationship. For the data we do hold:
- On uninstallation, we immediately revoke the stored Shopify credentials and cancel every scheduled occurrence that has not yet run, so no further Processing can occur.
- On receipt of Shopify’s
shop/redactrequest (approximately 48 hours after uninstallation), we delete your installation record and everything attached to it — entitlement, standing orders, order lines, execution records and activity events. - As a backstop against a lost webhook, the App deletes any installation that has been uninstalled for more than 30 days, with the same cascade.
- You may request earlier deletion at any time by writing to support@orumio.com.
Operational logs contain identifiers, classifications, counts and timestamps only, and no buyer Personal Data; they expire on our hosting provider’s ordinary schedule.
11. Audits and information
We will make available to you all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we will respond to a reasonable written request with our data protection policy, our incident response policy, and a written description of the measures in Annex II. An on-site inspection may be requested where that is not sufficient, on reasonable notice, no more than once in any twelve-month period except following a Personal Data Breach, and subject to confidentiality.
12. International transfers
We are established in Japan, and the App’s database and application servers are located in the United States (Annex III).
Where Personal Data protected by the EU GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), Module Two (controller to processor) are incorporated into this DPA by reference and take precedence over it in the event of conflict. For the purposes of those Clauses: you are the data exporter and we are the data importer; the optional docking clause applies; the general authorisation for sub-processors in §6 applies with 30 days’ notice; the governing law is that of Ireland; disputes are resolved in the courts of Ireland; and Annexes I, II and III below serve as Annexes I, II and III to the Clauses.
Where Personal Data protected by the UK GDPR is transferred, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) is incorporated by reference, with the information in Annexes I–III below completing its Tables.
Japan has received an adequacy decision from the European Commission, and the United Kingdom has made an equivalent finding.
13. Japan (APPI)
Where Japan’s Act on the Protection of Personal Information applies, we act as a party entrusted with the handling of personal data (委託先) under Article 27(5)(i), and you retain the supervisory obligation under Article 25. The measures in Annex II are the measures we take for that purpose, and §12 records the locations of the servers on which the data is held.
14. Term, precedence and liability
This DPA takes effect when you install the App and continues until we hold no Personal Data of yours. Where it conflicts with any other agreement between us, this DPA prevails on data protection matters; where it conflicts with the Standard Contractual Clauses, those Clauses prevail.
Nothing in this DPA limits either party’s liability to a Data Subject or to a Supervisory Authority under Data Protection Law.
15. Governing law
This DPA is governed by the laws of Japan, and the Tokyo District Court has exclusive jurisdiction as the court of first instance over any dispute arising from it. §12 governs the law and forum applicable to the Standard Contractual Clauses themselves.
Annex I — Details of the processing
A. Parties
Data exporter / Controller: the Merchant, being the operator of the Shopify store in which the App is installed. Contact details are those held in the Merchant’s Shopify account. Role: controller.
Data importer / Processor: Orumio, represented by Masanori Iwata, Mitsuhashi Building 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan, contact support@orumio.com. Activities: providing the Orumio — Standing Orders application. Role: processor.
B. Description of the processing
| Categories of Data Subjects | Company contacts (B2B buyers) at the Merchant’s company locations; the Merchant’s own staff who use the App |
|---|---|
| Categories of Personal Data | Company contact name and email address, read from Shopify and displayed to the Merchant, never stored; the Merchant’s notification email address, stored. Phone numbers and addresses are not requested and are never read |
| Sensitive data | None. The App neither requests nor processes special categories of data |
| Frequency | Continuous while the App is installed: on demand when the Merchant opens the standing order editor, and on the schedule the Merchant configured |
| Nature and purpose | Store management, and creating scheduled B2B draft orders for the Merchant’s company locations on the Merchant’s behalf. Contact name and email are processed solely so the Merchant can identify and select the correct buyer |
| Retention | Buyer Personal Data: not retained. Merchant configuration and history: for the duration of installation, then deleted per §10 (Shopify redaction at approximately 48 hours; 30-day backstop) |
| Sub-processor processing | As set out in Annex III, for the duration of the relationship |
C. Competent supervisory authority
The supervisory authority of the EU/EEA Member State in which the Merchant, as data exporter, is established; or, where the Merchant is not established in the EU/EEA but is subject to the GDPR under Article 3(2), the supervisory authority of the Member State in which the Merchant’s Article 27 representative is established.
Annex II — Technical and organisational measures
These are the measures actually implemented in the App, in order of how much risk each removes.
- Data minimisation as the primary control. Buyer Personal Data is never written to the database. Data that was never stored cannot be exfiltrated from storage, exposed in a backup, or disclosed by a database compromise. Phone and address fields are not even requested from Shopify.
- Encryption in transit. The App is served exclusively over HTTPS/TLS. The database connection requires TLS with channel binding.
- Encryption at rest. The database provider encrypts all data and backups at rest (AES-256, provider-managed). No self-managed backup, export or snapshot pipeline exists, so no unencrypted copy of the database exists anywhere.
- Application-layer encryption of credentials. Shopify offline access and refresh tokens are encrypted with AES-256-GCM before they reach the database, with the shop domain as additional authenticated data, so a record lifted into another tenant fails to decrypt.
- Tenant isolation. Row-level tenancy: every domain record reaches the installation record by foreign key and every query filters through it.
- Bounded egress. Server-side, the App communicates with the Shopify Admin API and the transactional email provider only. There is no analytics SDK, no error-reporting service receiving payloads, and no third-party script in the server path.
- Log hygiene. Logs record identifiers, classifications, counts and timestamps only. Token material, HMAC signatures, raw webhook bodies and buyer Personal Data are excluded by rule, and two automated layers enforce it: redaction of fields whose names indicate a credential, and scrubbing of credential patterns out of third-party error messages. Both are covered by automated tests.
- Access logging. Every read of a protected customer field records the purpose, the resource, the names of the fields read, whether a person or the scheduler triggered it, and the record count — never the values.
- Endpoint authorisation. Merchant routes require an authenticated Shopify admin session; internal scheduler endpoints require a bearer secret and return 401 rather than redirecting; webhook routes reject invalid HMAC signatures with 401.
- Client exposure boundary. Credentials never leave the server. Route loaders return only the fields the interface renders; raw platform responses are never shipped to the browser.
- Separation of test and production data. Production and development use separate database branches. The development branch was created before any Merchant had installed the App and has never contained production data. Production credentials exist only in the hosting provider’s environment configuration and are never written to a developer machine or to source control.
- Access control. Single operator; no staff accounts, contractors or support agents. Every account in scope is protected by two-factor authentication and a unique password generated and stored in a password manager. Access is reviewed whenever the operator set changes.
- Availability and incident detection. A health endpoint plus an independent external monitor detect a stalled or unreachable scheduler; runtime logs and error reporting surface failures; an environment kill switch halts all order creation without requiring a deployment.
- Governance. A written data protection policy and a written security incident response policy are maintained and reviewed at each release gate and after every significant incident.
Annex III — Sub-processors
| Sub-processor | Purpose | Location | Personal Data |
|---|---|---|---|
| Vercel | Application hosting and runtime logs | United States | Data in transit during a request; log identifiers as described in Annex II |
| Neon | Managed Postgres database | United States | Stored Merchant configuration, identifiers and the Merchant’s notification email address |
| Resend | Transactional email delivery | United States | The Merchant’s notification email address and the content of failure notifications |
| Checkly | Uptime monitoring | United States, United Kingdom | None. It requests a health endpoint that returns scheduler timing only |
Shopify is not listed as a sub-processor: it is the platform on which your store runs and the source from which we read, under your own separate agreement with Shopify.
Annex IV — United States state privacy laws
Where the California Consumer Privacy Act as amended (CCPA/CPRA) or a comparable US state privacy law applies, we act as a service provider (or processor, where that is the statutory term) and:
- we do not sell or share personal information, as those terms are defined in the CCPA, and we receive no consideration for it;
- we do not retain, use, or disclose personal information for any purpose other than the business purposes specified in this DPA, including not for our own commercial purposes;
- we do not combine personal information received from you with personal information received from any other source, except as permitted by the CCPA;
- we will notify you if we determine we can no longer meet these obligations;
- you may take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information.
The App performs no cross-context behavioural advertising, no profiling, and no automated decision-making producing legal or similarly significant effects.