Data Processing Agreement
Effective date: July 30, 2026 · Last updated: July 30, 2026
Scope and roles
This Data Processing Agreement ("DPA") forms part of the Terms of Service between AwesomeSoft ("Poby", "we", "processor") and the merchant installing the app ("you", "controller"). It applies where you use Poby to process personal data relating to your customers. You are the controller of that data and determine the purposes of processing; we act solely as your processor. Where the GDPR, UK GDPR, or comparable law applies to your use of Poby, this DPA governs that processing. By installing Poby you agree to this DPA.
Subject matter, nature, purpose and duration
The subject matter is the operation of the Poby post-purchase feedback app. The nature and purpose of processing is to collect feedback a shopper voluntarily submits after an order, attribute it to the order and customer so you can identify and respond to it, and present it to you as individual responses and aggregate analytics. Processing lasts for as long as Poby is installed on your store, plus the retention period described below.
Categories of data subjects and personal data
Data subjects are the customers of your Shopify store who complete a Poby feedback form. The personal data processed is: the customer’s first name, last name, and email address (read from the Shopify order); the Shopify customer identifier; the Shopify order identifier; and the content of the feedback itself — star ratings, free-text comments, issue tags, and the "how did you hear about us?" answer. We do not process phone numbers, postal addresses, payment details, or any special categories of personal data.
Processing on documented instructions
We process personal data only on your documented instructions, which comprise this DPA, the Terms of Service, and your configuration of the app. We will not process it for any other purpose — in particular we do not sell it, use it for advertising, or use it to train models. If we are required by law to process it otherwise, we will inform you before doing so unless that law prohibits such notice.
Confidentiality
Access to personal data is limited to personnel who need it to operate or support the service. Those personnel are bound by confidentiality obligations and are subject to the access controls described below.
Security measures
We implement appropriate technical and organisational measures, including: encryption of data in transit and at rest; encrypted backups; separation of test and production environments; restriction of production access to named personnel with a business need; strong passwords and two-factor authentication on accounts with production access; and an audit log recording every access to a customer’s name or email address, capturing which record was accessed and when. Authentication between the app and Shopify uses Shopify session tokens. We maintain a documented security incident response policy and review these measures at least annually.
Sub-processors
You give us general authorisation to engage sub-processors to provide the service. Our current sub-processors are: Vultr Holdings LLC / The Constant Company, LLC — hosting for the Poby application and its database, in its Piscataway, New Jersey facility in the United States; and Vercel Inc. — hosting for the getpoby.com marketing site, which is static and processes no customer personal data. Each is bound by data protection obligations no less protective than those in this DPA. We will give you notice of any intended addition or replacement of a sub-processor, and you may object on reasonable data protection grounds.
Assisting you with data subject rights
Poby implements Shopify’s mandatory GDPR compliance webhooks. When Shopify sends a customer data request, we return the personal data we hold for that customer; when Shopify sends a customer redaction request, we delete it. These run automatically, so a request a customer makes to you through Shopify reaches us without manual steps. Where you need further assistance responding to an access, rectification, erasure, restriction, portability, or objection request, we will provide it taking into account the nature of the processing.
Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and no later than 24 hours after confirming it. Our notice will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. We will assist you in meeting your own notification obligations to supervisory authorities and data subjects. We also notify Shopify as required by the Shopify Partner Program.
Deletion and return of data
When you uninstall Poby, Shopify sends a shop redaction webhook and we delete your store’s data in response. Feedback records are in any case deleted 30 days after uninstall — retained briefly only so that a reinstall does not lose your history. On written request we will delete or return personal data sooner, except where we are required by law to retain it.
Audits and information
We will make available to you the information reasonably necessary to demonstrate compliance with this DPA and, where required, allow for and contribute to audits conducted by you or an auditor you mandate. Requests should be sent to support@getpoby.com, and audits will be scheduled at a mutually agreed time so as not to disrupt the service.
International transfers
Personal data processed through Poby is stored in the United States (see Sub-processors), and is accessed for support and maintenance by AwesomeSoft personnel in Bangladesh. Where personal data originates in the European Economic Area, the United Kingdom, or Switzerland, transfers out of those territories — to the United States and to Bangladesh — rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum for data originating in the United Kingdom. Those clauses are incorporated into this DPA by reference and take effect when you install Poby.
Governing law, liability, term and changes
This DPA takes effect when you install Poby and continues for as long as we process personal data on your behalf. Liability is subject to the limitations in the Terms of Service. This DPA is governed by the laws of Bangladesh, and the courts of Bangladesh have jurisdiction — without prejudice to any mandatory rights you or a data subject have under the law of your own country. We may update this DPA to reflect changes in the service or in applicable law; material changes will be reflected by the "Last updated" date above.
Contact
Questions about this DPA, or requests under it, go to support@getpoby.com.
Questions about this agreement? Email support@getpoby.com. Poby is built and operated by AwesomeSoft — awesomesoft.io.