Auftragsverarbeitungsvertrag (AVV) / Data Processing Agreement

Concluded under Article 28 GDPR between the controller and the processor named below, and applicable for as long as the application is installed.

Parties

Processor

IWV Digitalagentur Nikolaos Valkanis Kurhessenstr. 60 60431 Frankfurt am Main Germany Telefon +49 69 66 77 40 121 · kontakt@iwv-online.com · support@iwv-plugins.de

Controller: the merchant who installs the IWV// GARAN Label & EU Notice application in their Shopify store. The agreement is entered into on installation.

1. Subject matter and duration

The processor operates a Shopify application that publishes statutory legal-guarantee information under Regulation (EU) 2025/1960 to the controller's storefront, and records what that information was at the time of each sale. Processing lasts for as long as the application is installed, plus the deletion period described in clause 9.

2. Nature and purpose of processing

Storage and publication of merchant-entered guarantee configuration; retrieval of the controller's product catalogue from Shopify in order to attach that configuration to it; generation and upload of the GARAN durability label; and the capture of an immutable per-order record of the guarantee terms in force at the moment of purchase.

3. Categories of data and data subjects

Data. Shop identification (domain, identifier, name, shop email address, shop language); an encrypted Shopify API access token; merchant-entered guarantee configuration for products, variants and vendors; publication state, generated labels and validation results; and, per order, an immutable record of the guarantee terms that applied at the time of purchase — order identifier, order name, order timestamp, the Shopify customer identifier, and per line the product, the quantity and the guarantee facts as they then stood.

Data subjects. The controller's staff, in so far as they enter configuration, and the controller's customers, limited to the identifier Shopify assigns them. No names, addresses, contact details or payment information are processed. The customer identifier is retained solely so that a customers/redact request can locate and erase the corresponding records.

Protected customer data. The order data above is Shopify protected customer data. The processor uses the minimum field set listed, for the purpose stated in clause 2, for the retention period in clause 9, and erases it as described in clause 9.

4. Controller instructions

The processor processes personal data only on the documented instructions of the controller. The controller's instructions are given by the configuration entered in the application and by this agreement. The processor informs the controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

5. Confidentiality

The processor ensures that persons authorised to process the personal data are bound by confidentiality, and grants access only to those who need it to provide and support the application.

6. Technical and organisational measures

Measures implemented in the application itself:

  • The Shopify access token is stored encrypted and is never written to logs or to the published metafield projection.
  • Every authenticated surface verifies a Shopify signature or session token on each request; the session cookie is a convenience and never the authentication mechanism, and the application is reachable only over the routes it declares.
  • Webhook authenticity is verified by HMAC over the raw request body before any work is done.
  • Only the resolved information the storefront has to display is published to the shop's metafields; the producer confirmation facts and the validity window remain in the database.
  • Erasure is performed in a single database transaction, is idempotent, and is protected against late-arriving webhooks recreating erased records.
  • The published legal texts and the application configuration are versioned together, so what was disclosed at any date is verifiable.

Measures that depend on the hosting arrangement — physical and network security, encryption at rest below the application layer, backup and restore, availability and separation of environments — are stated here once the hosting arrangement is confirmed. They are omitted rather than asserted, because a technical and organisational measure that is described but not operated is worse than one that is not described.

7. Sub-processors

The controller grants general authorisation for the engagement of sub-processors. Engaged today:

  • Shopify International Ltd, Ireland — platform operator.
  • Shopify Inc, Canada — platform operator.

The hosting provider and the outbound mail transport are named here once confirmed. The processor informs the controller of any intended addition or replacement of a sub-processor in good time, and the controller may object.

8. Assistance

The processor assists the controller, taking into account the nature of the processing:

  • Data subject requests. On customers/data_request the processor records receipt of the request; the order records held for that customer are visible to the controller in the application's order screens, so the controller can answer the request. On customers/redact the processor erases them.
  • Personal data breach. The processor notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, with the information the controller needs for its own notification under Articles 33 and 34 GDPR.
  • Articles 32 to 36 GDPR. The processor assists with security, breach notification and data protection impact assessment obligations in respect of the processing described here.

9. Retention, return and deletion

On customers/redact the order records belonging to that customer are erased immediately and irreversibly.

On uninstall the access token is destroyed immediately. Shopify sends shop/redact 48 hours after uninstall, and that webhook deletes all remaining data of the shop irreversibly. If the webhook does not arrive, a scheduled retention run deletes the same data 3 days after uninstall — the 48 hours Shopify waits, plus one day of slack so the run never races the webhook.

The controller may export or delete its configuration at any time while the application is installed.

Deletion is recorded in an append-only audit log. Those records demonstrate compliance without carrying identifying information: the shop domain and every subject identifier are set to null as part of the erasure itself, so what remains is the event, its time, the actor and the per-category deletion counts, and no shop-derived value of any kind — keyed or unkeyed — is retained with it.

Separately from the audit log, and not part of it, the processor retains two keyed one-way digests: one derived from the shop domain, to serialise erasure against delayed webhooks, and one derived from the shop domain and customer identifier, to prevent a delayed webhook from recreating erased order records. These digests are pseudonymous rather than anonymous, and are used for no purpose other than coordinating erasure and blocking late writes.

10. Audit

The processor makes available to the controller the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates. The application's source code, its schema and these published texts are versioned together and are the primary evidence offered.

11. Third countries

Processing takes place within the European Union, save for the platform operator's own processing by Shopify Inc in Canada, for which an adequacy decision of the European Commission applies to recipients subject to PIPEDA.

IWV// GARAN Label & EU Notice · Datenschutz · AVV · Impressum