Data processing agreement

Last updated 2026-07-20. Draft — to be finalised before App Store submission.

This agreement applies automatically when a merchant installs Duebook. The merchant is the controller; Duebook is the processor (GDPR Art. 28).

Scope of processing

Subprocessors

Merchants are notified before any new subprocessor is added.

Security measures

EU-hosted infrastructure, TLS in transit, encrypted off-site backups with 14-day rotation, access limited to a single operator with logged access, no use of merchant data for model training, and a written incident-response policy.

Deletion and assistance

On uninstall, all shop data is deleted within 48 hours. Shopify'scustomers/redact, shop/redact and customers/data_requestwebhooks are honoured. Requests: support@duebook.app.