Data processing agreement
Last updated 2026-07-20. Draft — to be finalised before App Store submission.
This agreement applies automatically when a merchant installs Duebook. The merchant is the controller; Duebook is the processor (GDPR Art. 28).
Scope of processing
- Subject matter: accounts-receivable record-keeping and payment reminders.
- Duration: while the app is installed, plus up to 48 hours for deletion.
- Categories of data subjects: the merchant's staff and the merchant's business customers' contacts.
- Categories of data: company contact name and email address only.
Subprocessors
- DigitalOcean LLC — hosting. Servers are located in Frankfurt, Germany, so personal data remains in the European Union at rest. DigitalOcean LLC is incorporated in the United States, so the arrangement relies on a data processing agreement and standard contractual clauses.
- Resend — transactional email delivery (US; DPA and standard contractual clauses in place).
- PostHog EU — aggregate product analytics; receives no customer personal data.
Merchants are notified before any new subprocessor is added.
Security measures
EU-hosted infrastructure, TLS in transit, encrypted off-site backups with 14-day rotation, access limited to a single operator with logged access, no use of merchant data for model training, and a written incident-response policy.
Deletion and assistance
On uninstall, all shop data is deleted within 48 hours. Shopify'scustomers/redact, shop/redact and customers/data_requestwebhooks are honoured. Requests: support@duebook.app.