Legal
Data Processing Agreement
Last updated 12 September 2026. This DPA forms part of the agreement between the merchant that installs the Qinci app ("Controller") and Qinci ("Processor"). By installing the app the Controller accepts these terms.
1. Roles and scope
The Controller determines the purposes and means of processing personal data of its customers. The Processor processes that personal data only on the Controller’s documented instructions, which are: to generate product recommendations, to produce attribution and usage analytics for the Controller, and to send routine and refill emails as configured by the Controller.
2. Categories of data and data subjects
Data subjects: the Controller’s customers and storefront visitors. Personal data: customer email address, customer locale, order identifiers, order line items and totals, and Routine Planner quiz answers. No special-category data is processed.
3. Processor obligations
The Processor will: process personal data only per Section 1; ensure persons authorised to process it are bound by confidentiality; implement the technical and organisational measures in Section 5; assist the Controller with data-subject requests and with security, breach notification, and DPIA obligations; and make available the information needed to demonstrate compliance.
4. Sub-processors
The Controller authorises the Processor to engage the sub-processors listed in the Privacy Policy (Shopify; netcup GmbH for cloud hosting and the database; Hetzner Online GmbH for off-site encrypted backups; Mailjet; Sentry; PostHog). The Processor imposes data-protection terms on each sub-processor no less protective than this DPA and remains liable for their performance. The Processor will give notice of any intended change so the Controller can object.
5. Security measures
Encryption of personal data in transit (TLS) and at rest; access to production data limited to named personnel on a least-privilege basis; Shopify OAuth scopes limited to those the app functionally requires; access tokens stored server-side only; regular dependency and platform patching; logging of administrative access.
6. International transfers
Where personal data is transferred outside the EEA or UK, the transfer relies on an adequacy decision or the applicable Standard Contractual Clauses, which are incorporated into this DPA by reference.
7. Data-subject requests
The Processor actions Shopify’s customers/data_request and customers/redact webhooks automatically. For any request the Processor receives directly, it will refer the data subject to the Controller and, where legally permitted, notify the Controller without undue delay.
8. Return and deletion
On termination (app uninstall) the Processor deletes all personal data for that store within 48 hours, save where retention is required by law. Attribution records are in any case deleted 24 months after creation. Nightly disaster-recovery backups follow their own 30-day rolling retention regardless of when a deletion or redaction request is actioned on the live database, and are never used to restore data a deletion or redaction request has removed.
9. Breach notification
The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data, with the information the Controller needs to meet its own notification obligations.
Merchants with their own DPA requirements can contact qinci@qavlar.tech. This template should be reviewed by the Controller’s counsel before relying on it.
