Data Processing Agreement (DPA)
Version: 2026-09-24.2
This Data Processing Agreement under Art. 28 GDPR governs the processing of personal data by IWV DIGITALAGENTUR on behalf of the merchant who uses the Shopify app "IWV// CSV Exporter Orders" (the "App"). It supplements the privacy policy and the provider identification in the Impressum. A German version is published at /avv.
1. Parties and roles
Controller: the merchant who installs the App in their Shopify store ("Merchant"). The Merchant decides which orders are exported, in which layout, and where the files are sent.
Processor: IWV DIGITALAGENTUR, Nikolaos Valkanis, Unter den Linden 4, 72762 Reutlingen, Germany, kontakt@iwv-online.com ("IWV"). Contact for this App and for data protection questions: support@iwv-plugins.de.
IWV remains a controller in its own right for data it processes to run, secure, bill and support the App and to communicate with the Merchant (see the privacy policy).
2. Subject matter, nature and purpose
The App reads the Merchant's orders from Shopify through the Shopify Admin API, turns them into CSV files in a layout the Merchant defines, stores those files for download, and — where the Merchant configures a schedule and a destination — sends them to that destination by SFTP, FTPS, FTP or email.
The data is processed solely to provide these exports to the Merchant. It is not used for advertising, profiling, sale, training of AI models or any other purpose.
3. Types of personal data
Depending on the columns the Merchant chooses, an export file can contain:
- customer and recipient names, email addresses and phone numbers;
- billing and shipping addresses (address lines, city, region, postal code, country);
- order data: order numbers and ids, dates, products, quantities, prices, taxes, discounts, payment and fulfilment status, shipping method, order notes, tags and custom attributes.
In addition the App stores:
- the Shopify ids of orders already exported by a profile ("export history"), when the Merchant switches on "only orders not exported before";
- for a customer data request received from Shopify, the Shopify customer id and the ids of the orders it names;
- an audit trail of who generated, downloaded, delivered or deleted an export (the Shopify staff user id and IP address of the Merchant's staff member; no customer data).
4. Categories of data subjects
The Merchant's customers and the recipients of their orders; the Merchant's staff who use the App.
5. Duration and retention
This DPA applies for as long as the App is installed. Within that time, data is kept only for these periods, which are enforced by an automated nightly job:
| Data | Retention |
|---|---|
| Export files | 30 days after creation |
| Export history (order ids) | 400 days after the export |
| Audit trail | 365 days |
| Answered customer data requests | 365 days after they were answered |
Delivered files are held by the destinations the Merchant configured; their retention is the Merchant's responsibility.
6. Instructions
IWV processes personal data only on the Merchant's documented instructions. The Merchant's configuration of the App — profiles, schedules, destinations and settings — constitutes those instructions. IWV informs the Merchant without undue delay if it considers an instruction to infringe data protection law.
7. Confidentiality
Everyone at IWV with access to the App's data is bound to confidentiality.
8. Technical and organisational measures (Art. 32 GDPR)
- Encryption in transit: all communication with Shopify and with the App's admin uses TLS. The Merchant can deliver by SFTP or FTPS; plain FTP and email are not end-to-end encrypted, are labelled as such in the App, and are used only when the Merchant chooses them.
- Encryption at rest: export files are encrypted with XChaCha20-Poly1305 (libsodium secretstream), so any alteration is detected. Shopify access tokens and the passwords and keys the Merchant enters for delivery are encrypted as well. The key is held outside the database.
- Access control: the App's admin is only reachable from inside the Merchant's Shopify admin and authenticates every request with a Shopify session token or signature. Every file and record is scoped to one shop; export files are stored outside the web server's document root and served only through that authenticated check, with caching disabled.
- Integrity of webhooks: every Shopify webhook is verified by its HMAC signature before it is processed.
- Logging: downloads, deliveries, deletions, delivery connection changes and privacy requests are recorded in an audit trail that contains no customer data.
- Minimisation: the App keeps no customer records of its own beyond the export files, the export history and data requests described above, each with the retention period in section 5.
- Exported files are safe to open: values that a spreadsheet would execute as a formula are neutralised.
9. Subprocessors
The Merchant gives general authorisation for IWV to use subprocessors for hosting, database, file storage and email delivery of the App, provided they are bound by data protection obligations equivalent to this DPA. IWV provides the current list of subprocessors, with their location of processing, on request to support@iwv-plugins.de, and informs the Merchant of any intended change in advance; the Merchant may object on reasonable data protection grounds.
Shopify is not a subprocessor of IWV: the data originates in the Merchant's Shopify store under the Merchant's own agreement with Shopify. Destinations the Merchant configures (their SFTP, FTP or mail servers) are the Merchant's own recipients, not subprocessors of IWV.
10. Data subject rights
IWV supports the Merchant in answering data subject requests. When Shopify sends a customer data request, IWV records it, and within Shopify's 30-day deadline tells the Merchant which exports contained that customer's orders and where they were delivered. When Shopify sends a customer redaction request, the App deletes those orders from its export history immediately; export files are deleted when their retention period ends.
11. Personal data breaches
IWV notifies the Merchant without undue delay after becoming aware of a personal data breach affecting the Merchant's data, with the information the Merchant needs to meet its own obligations under Art. 33 and 34 GDPR.
12. Deletion at the end of processing
When the Merchant uninstalls the App, Shopify sends a shop erasure request 48 hours later. On receipt the App deletes all of the shop's export files, profiles, schedules, delivery connections, settings, export history, data requests, audit trail and the shop record itself.
13. Evidence and audits
IWV makes available to the Merchant the information necessary to demonstrate compliance with this DPA and allows for audits, by arrangement, during normal business hours and without compromising the confidentiality of other merchants' data.
14. Acceptance and changes
The Merchant accepts this DPA in the App's admin before using the App. IWV records the version, a fingerprint of the accepted text, the time, and the accepting staff member. When this DPA changes, the App asks for acceptance of the new version.