Data Processing Addendum (DPA)

UpsellPilot AI by Fixiby Software Technologies (“Processor”)
For Shopify merchants (“Controller” / “Merchant”)
Contact: info@fixiby.com
Effective date: 27 July 2026 · Last updated: 27 July 2026

This DPA forms part of the Terms of Service and applies where Fixiby processes personal data on behalf of the Merchant in connection with UpsellPilot AI, in accordance with Article 28 GDPR / UK GDPR and analogous “service provider” obligations under the CCPA/CPRA.

1. Subject matter and duration

Processor provides the App described in the Terms. Processing lasts for the period the App is installed on the Merchant’s shop and any wind-down retention stated in the Privacy Policy, unless longer retention is required by law.

2. Nature and purpose of processing

Processing is limited to hosting and operating upsell/cross-sell configuration, delivering offer surfaces, coordinating Shopify discounts, computing privacy-first analytics, authenticating Admin API access, and fulfilling Shopify mandatory privacy webhooks—strictly to provide the App per Merchant instructions (configuration and Shopify platform events).

3. Types of personal data and data subjects

Data subjectsPersonal data (typical)
Merchant staff / store operators Shop domain, session tokens, settings, support emails
Shoppers (end customers) Generally limited to event metrics and technical signals; core App design avoids storing shopper contact or payment PII. Order identifiers may be processed for attribution/deduplication when order webhooks are enabled.

4. Processor obligations

Processor shall:

5. Controller obligations

Controller is responsible for the lawfulness of processing instructions, storefront notices/consent, and Shopify theme/cookie compliance toward shoppers.

6. Subprocessors

Controller generally authorizes Processor to use infrastructure subprocessors in these categories:

Processor will notify Controller of material subprocessor changes via email or App notice where practicable. Continued use after notice constitutes acceptance, subject to mandatory objection rights under GDPR.

7. International transfers

Where personal data is transferred outside the EEA/UK, Processor shall ensure an appropriate transfer mechanism (adequacy, SCCs, UK IDTA/Addendum) is in place with relevant providers.

8. Security incidents

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, and provide information reasonably available to help Controller meet its notification duties.

9. CCPA / CPRA service-provider terms

Processor is a “service provider” / “contractor” to Merchant. Processor will not sell or share personal information, retain/use/disclose it outside the business purpose of providing the App (or as otherwise permitted by the CCPA/CPRA), or combine it with other personal information except as allowed for that business purpose. Processor certifies that it understands these restrictions.

10. Order of precedence

If there is a conflict between this DPA and the Terms regarding data-protection obligations, this DPA prevails. The Privacy Policy describes Fixiby’s independent controller activities (e.g., support email handling).

11. Contact

Fixiby Software Technologies · info@fixiby.com