Skip to document
STUDIO8022 / CHECKOUTPILOT

CheckoutPilot — Data-processing agreement

Version 2026-10-04 · David Duff, trading as Studio8022

← Main websiteAll app agreementsPrivacyService termsData processingBusiness details

1. Parties, roles and precedence

This agreement supplements the accepted CheckoutPilot service terms between the merchant and David Duff, trading as Studio8022, Asprou Potamou 1, Oikia 2, Agios Georgios Peyias, 8570, Cyprus. It takes precedence for personal information processed on the merchant’s instructions. It applies for the processing period, including protected return/deletion after the service ends.

The merchant is the controller, or a processor authorised by its controller to appoint us. Studio8022 acts as processor (or subprocessor) for that instructed processing. For our own merchant relationship, security and support records we act as controller as described in the privacy notice. Roles depend on the actual purpose, not the label alone.

2. Processing schedule

Purpose and operations: Authenticate access; prepare, simulate, save and release merchant rules; evaluate permitted checkout conditions inside Shopify; support, export and delete configuration. The optional cart-offer block uses Shopify product/cart facilities in the browser, not a separate CheckoutPilot advertising or customer-analytics service.

People concerned: Shop owners, authorised administrators, support contacts and shoppers whose cart is evaluated inside Shopify.

Information: Shop identity, authentication credentials and supplied staff identity/contact information; subscription status, product/variant references, payment-method names, drafts, revisions and release/recovery state. Cart/product/amount/currency/quantity/country and available-payment-method data is evaluated by Functions within Shopify. The app does not maintain customer profiles, order history or a payment-card database.

Duration and deletion triggers: Successful authenticated uninstall or shop-redaction processing deletes shop sessions, drafts and release state from the active app database. Processing failures can delay deletion. Recovery copies are restricted to recovery, with deletion instructions reapplied before reuse.

The merchant chooses lawful purposes, provides instructions and appropriate notices, controls authorised users and may request information, correction, return or deletion. Do not intentionally provide special-category data, criminal-record information or payment credentials; contact us before proposing processing outside this schedule.

3. Documented instructions

We will process instructed information only for this schedule and documented lawful instructions, including authorised configuration, support requests and permitted transfers, unless applicable law requires otherwise. We will notify you of a legal requirement before processing unless the law prohibits it, and inform you if we consider an instruction to infringe applicable data-protection law. We will seek clarification or suspend the affected operation rather than knowingly carry out an unlawful instruction.

4. Confidentiality and security

We will ensure authorised people are bound by confidentiality and limit access to what their work requires. We will maintain technical and organisational safeguards appropriate to the risks, including encrypted transport, restricted administration, authenticated shop-bound access, credential protection, separation of shops and controlled recovery/deletion procedures. We will assess safeguards and address identified weaknesses; no security certification or absolute prevention of incidents is promised.

The app privacy notice describes implemented controls and their limits. We will not materially reduce the agreed protection during the processing period. You must protect your users, devices and merchant-selected destinations and notify us promptly of suspected compromised access.

5. Subprocessors and merchant-selected recipients

The agreed provider schedule is published on the providers and integrations page. OVHcloud supplies infrastructure and email processing. Shopify also operates the merchant’s platform under its separate relationship. Appointing a tool does not authorise unrelated disclosures.

We will obtain prior specific or general written authorisation for subprocessors, impose equivalent applicable data-protection obligations in writing, and remain responsible for their performance of those obligations. Under general authorisation we will give advance notice of intended additions or replacements and a reasonable opportunity to object on data-protection grounds before the affected processing begins. We will work to resolve an objection; if it cannot be resolved, the affected service may be ended, with any unused prepaid affected service refunded where applicable.

6. International transfers

We operate from Cyprus. Provider processing and merchant-selected destinations can involve other countries; this agreement does not assert that all data stays in the EEA. We will make restricted transfers only on documented instructions and with safeguards required by applicable law, such as a valid adequacy decision or applicable standard contractual clauses and necessary supplementary measures. A provider privacy-policy link alone is not a transfer safeguard. Contact support@studio8022.com for relevant provider, location and safeguard information or a copy subject to lawful redactions.

7. Rights, incidents and assistance

Taking account of the processing and information available, we will assist you with individual rights requests, security obligations, breach notifications, impact assessments and required regulator consultation. We will refer requests concerning instructed merchant records to you unless law requires us to respond directly.

We will notify you without undue delay after becoming aware of a personal-data breach affecting instructed information, provide available information about its nature, likely consequences, affected data and mitigation, and supplement it as the investigation progresses. We will cooperate on containment and required notifications. This does not replace either party’s independent statutory duties.

8. Return, deletion and recovery copies

At the end of the processing, you may choose return or deletion of instructed personal information, and deletion of remaining copies, unless applicable law requires retention. Contact support@studio8022.com with the app and shop; we verify authority and agree a secure delivery method. Where law requires retention we will explain the basis where permitted and isolate information from ordinary use.

Automatic uninstall/redaction behaviour is described in the schedule and privacy notice; a failed callback is not completed deletion. Recovery copies that cannot practicably be selectively erased immediately must be put beyond normal use and expire through the applicable retention/deletion cycle. Applicable deletion instructions must be reapplied before recovered records return to service. Information already delivered to independent merchant-selected recipients is controlled under their arrangements; we will assist where appropriate.

9. Assurance and contact

We will provide information needed to demonstrate compliance and allow and contribute to appropriate audits and inspections by you or your appointed auditor. Arrangements may protect security, confidentiality and other merchants’ information, but must not defeat statutory audit rights. We will cooperate with competent supervisory authorities. Contact support@studio8022.com about instructions, assurance, provider changes, incidents or return/deletion.

David Duff, trading as Studio8022
Asprou Potamou 1, Oikia 2, Agios Georgios Peyias, 8570, Cyprus
support@studio8022.com

Legal & privacy · Help & support · Main website

Independent of Shopify.