Data Processing Addendum
Last updated: 2026-07-07
This Data Processing Addendum ("DPA") forms part of the agreement between International Supply Consulting ("Provider") and the merchant ("Merchant") who installs SweetRelease Pre-orders (the "App"). It governs personal data the Provider processes on the Merchant's behalf.
1. Roles
The Merchant is the data controller; the Provider is a data processor that processes personal data only to provide the App and only on the Merchant's documented instructions (installing and using the App constitutes those instructions).
2. Purpose & duration
Personal data is processed to detect preorders, hold and move their fulfillment orders at a gated location, and present them in an operator release queue. Processing lasts while the App is installed, plus the limited retention period below.
3. Personal data & data subjects
Data subjects: the Merchant's customers who place preorders. Personal data: customer name (from the order's shipping/billing address) and email; order and fulfillment data (order number, item summary, fulfillment/location/hold state). The Provider does not process payment card data or the Shopify read_customers resource, and does not use personal data for marketing, profiling, or resale.
4. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Shopify | Source platform / API + webhooks | US / global |
| Neon (Postgres) | Encrypted application database | US |
| Vercel | Application hosting | US |
5. Security
Encryption at rest (database + backups) and in transit (TLS); least-privilege access with MFA on administrative accounts; data minimization; test/production data separation; infrastructure access logging; and incident response.
6. Retention & deletion
Personal data is retained only as long as needed and purged on a retention schedule. On the Shopify customers/redact and shop/redact webhooks, and on app uninstall, associated personal data is deleted.
7. Data-subject requests
The Provider implements Shopify's compliance webhooks — customers/data_request, customers/redact, and shop/redact — to help the Merchant respond to data-subject requests.
8. Personal data breach
The Provider will notify the Merchant without undue delay after becoming aware of a personal data breach, with the information the Merchant needs for its own notification obligations (including, where applicable, the GDPR 72-hour requirement).
9. International transfers & audit
Cross-border transfers rely on an appropriate mechanism (e.g., Standard Contractual Clauses). On reasonable written request, the Provider will provide information necessary to demonstrate compliance with this DPA.
10. Contact
Questions or requests: patrickward@isc-na.com.