Data Processing Agreement
This is the permanent copy of version 2026-09-13. It will not be edited.
The current version is always at /giftcardgenerator/dpa.
This Schedule forms part of the Terms of Service.
This Schedule forms part of the Terms of Service between you and Software Etc. Limited, a company registered in England and Wales under company number 17455166 ("we", "us"). It applies where we process personal data on your behalf. You are the controller; we are the processor.
1. Subject matter and duration
We process personal data to provide the App, for as long as the App is installed, plus any retention period stated in section 6.
2. Nature and purpose
Creating gift cards in your Shopify store at your instruction, producing encrypted export files, and maintaining a record of actions taken in the App.
3. Categories of data subject and personal data
Data subjects: your staff who use the App.
Personal data: the identity of the staff member associated with each action taken in the App, taken from their authenticated Shopify session, together with your store identifier.
We do not process your customers' personal data. Gift cards created by the App have no recipient attached.
4. Our obligations
We will:
(a) process personal data only on your documented instructions, including as given through the App, unless required otherwise by law — in which case we will inform you unless prohibited from doing so;
(b) ensure that persons authorised to process the data are subject to a duty of confidentiality;
(c) implement appropriate technical and organisational security measures, as described in section 5;
(d) engage sub-processors only as permitted by section 6;
(e) assist you, so far as reasonably possible, in responding to requests from data subjects exercising their rights;
(f) assist you in meeting your obligations relating to security of processing, breach notification, data protection impact assessments and prior consultation;
(g) notify you without undue delay on becoming aware of a personal data breach affecting personal data processed on your behalf;
(h) delete or return personal data on termination, as described in section 7;
(i) make available information necessary to demonstrate compliance with this Schedule and, on reasonable notice and subject to confidentiality, allow for audits or inspections.
5. Security measures
- Gift card codes encrypted at rest, with encryption keys held separately from the data
- Export files encrypted with AES-256 and protected by a password not retained by us
- Decryption restricted and recorded in an audit log
- Access to the App restricted to your authenticated Shopify session
- Error reports automatically filtered to remove gift card codes, export passwords and access credentials
- Gift card codes and export files deleted seven days after batch creation
- Data hosted within the European Economic Area
6. Sub-processors
You authorise the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway | Hosting and database | Netherlands (EEA) |
| Sentry | Error monitoring | Frankfurt, Germany (EEA) |
We will inform you before adding or replacing a sub-processor. You may object on reasonable data protection grounds, in which case you may terminate by uninstalling the App.
We remain liable for our sub-processors' performance of their obligations under this Schedule.
7. Deletion on termination
On uninstallation we delete gift card codes and export files for your store immediately, and other personal data processed on your behalf in accordance with the Privacy Policy.
Code fingerprints are retained. These are one-way cryptographic values that cannot be reversed to produce a code and contain no information about your store or any individual.
8. International transfers
All personal data processed under this Schedule is held within the European Economic Area — hosting and database in Amsterdam, the Netherlands, and error monitoring in Frankfurt, Germany. No personal data is transferred outside the EEA.