1. Parties, roles and precedence
This agreement supplements the accepted CollectionPilot service terms between the merchant and David Duff, trading as Studio8022, Asprou Potamou 1, Oikia 2, Agios Georgios Peyias, 8570, Cyprus. It takes precedence for personal information processed on the merchant’s instructions. It applies for the processing period, including protected return/deletion after the service ends.
The merchant is the controller, or a processor authorised by its controller to appoint us. Studio8022 acts as processor (or subprocessor) for that instructed processing. For our own merchant relationship, security and support records we act as controller as described in the privacy notice. Roles depend on the actual purpose, not the label alone.
2. Processing schedule
Purpose and operations: Authenticate access; import catalogue information; save rules and previews; publish, verify and restore collection ordering; run merchant-enabled schedules; aggregate optional consent-aware product activity; support, export and delete shop records.
People concerned: Shop owners and support contacts; storefront visitors whose consent-eligible product actions are recorded when the merchant enables optional insights.
Information: Shop domain and timezone; authentication credentials and owner identity supplied by Shopify, including available name, email and user ID; subscription status and trial cutoff; products, tags, variants, inventory locations, collection order, rules and publishing records. Optional event payloads contain event name, product ID, timestamp, event ID and shop routing identifier. Event IDs are hashed for duplicate detection; no persistent visitor profile is created. No customer contact details, customer or persistent visitor IDs, URLs, complete carts, orders or payment credentials are sent in the analytics payload.
Duration and deletion triggers: Daily counts: 31 days. Hashed event receipts: up to two days plus the hourly cleanup interval. Expired previews: removed after one day. Full arrangement data: up to 30 days and the latest 100 arrangements per collection; completed summaries: 90 days. Unresolved publishing records remain until resolved. Authenticated uninstall stops work and removes sessions; the trial cutoff is retained against repeated trials. Authenticated shop-redaction removes stored shop records. Merchants may request export or earlier deletion. Failed callbacks can delay automatic deletion.
The merchant chooses lawful purposes, provides instructions and appropriate notices, controls authorised users and may request information, correction, return or deletion. Do not intentionally provide special-category data, criminal-record information or payment credentials; contact us before proposing processing outside this schedule.
3. Documented instructions
We will process instructed information only for this schedule and documented lawful instructions, including authorised configuration, support requests and permitted transfers, unless applicable law requires otherwise. We will notify you of a legal requirement before processing unless the law prohibits it, and inform you if we consider an instruction to infringe applicable data-protection law. We will seek clarification or suspend the affected operation rather than knowingly carry out an unlawful instruction.
4. Confidentiality and security
We will ensure authorised people are bound by confidentiality and limit access to what their work requires. We will maintain technical and organisational safeguards appropriate to the risks, including encrypted transport, restricted administration, authenticated shop-bound access, credential protection, separation of shops and controlled recovery/deletion procedures. We will assess safeguards and address identified weaknesses; no security certification or absolute prevention of incidents is promised.
The app privacy notice describes implemented controls and their limits. We will not materially reduce the agreed protection during the processing period. You must protect your users, devices and merchant-selected destinations and notify us promptly of suspected compromised access.
5. Subprocessors and merchant-selected recipients
The agreed provider schedule is published on the providers and integrations page. OVHcloud supplies infrastructure and email processing. Shopify also operates the merchant’s platform under its separate relationship. Appointing a tool does not authorise unrelated disclosures.
We will obtain prior specific or general written authorisation for subprocessors, impose equivalent applicable data-protection obligations in writing, and remain responsible for their performance of those obligations. Under general authorisation we will give advance notice of intended additions or replacements and a reasonable opportunity to object on data-protection grounds before the affected processing begins. We will work to resolve an objection; if it cannot be resolved, the affected service may be ended, with any unused prepaid affected service refunded where applicable.
6. International transfers
We operate from Cyprus. Provider processing and merchant-selected destinations can involve other countries; this agreement does not assert that all data stays in the EEA. We will make restricted transfers only on documented instructions and with safeguards required by applicable law, such as a valid adequacy decision or applicable standard contractual clauses and necessary supplementary measures. A provider privacy-policy link alone is not a transfer safeguard. Contact support@studio8022.com for relevant provider, location and safeguard information or a copy subject to lawful redactions.
7. Rights, incidents and assistance
Taking account of the processing and information available, we will assist you with individual rights requests, security obligations, breach notifications, impact assessments and required regulator consultation. We will refer requests concerning instructed merchant records to you unless law requires us to respond directly.
We will notify you without undue delay after becoming aware of a personal-data breach affecting instructed information, provide available information about its nature, likely consequences, affected data and mitigation, and supplement it as the investigation progresses. We will cooperate on containment and required notifications. This does not replace either party’s independent statutory duties.
8. Return, deletion and recovery copies
At the end of the processing, you may choose return or deletion of instructed personal information, and deletion of remaining copies, unless applicable law requires retention. Contact support@studio8022.com with the app and shop; we verify authority and agree a secure delivery method. Where law requires retention we will explain the basis where permitted and isolate information from ordinary use.
Automatic uninstall/redaction behaviour is described in the schedule and privacy notice; a failed callback is not completed deletion. Recovery copies that cannot practicably be selectively erased immediately must be put beyond normal use and expire through the applicable retention/deletion cycle. Applicable deletion instructions must be reapplied before recovered records return to service. Information already delivered to independent merchant-selected recipients is controlled under their arrangements; we will assist where appropriate.
9. Assurance and contact
We will provide information needed to demonstrate compliance and allow and contribute to appropriate audits and inspections by you or your appointed auditor. Arrangements may protect security, confidentiality and other merchants’ information, but must not defeat statutory audit rights. We will cooperate with competent supervisory authorities. Contact support@studio8022.com about instructions, assurance, provider changes, incidents or return/deletion.