Logo of Logbase technologies
Home
Products
SelleasyShipXPickeasyBookXDealeasyDibsAskTimmy
Resources
BlogsGuidesComparisonsCase studiesAlternatives
About Us
Start a free trial
Data Processing Addendum
1. Preamble2. Roles of the Parties3. Subject Matter and Duration4. Processing Details5. Instructions6. Confidentiality7. Security of Processing8. Subprocessors9. International Data Transfers10. Data Subject Rights11. Data Retention and Deletion12. Data Breach Notification13. Assistance and Compliance14. Audit Rights15. Liability16. Termination17. ContactAnnex I — Processing Details & RetentionAnnex II — Security MeasuresAnnex III — SubprocessorsAnnex IV — Standard Contractual ClausePart 1 — EU Standard Contractual ClausesPart 2 — UK International Data Transfer Addendum

Last Updated: Sep 2026

Data Processing Addendum(DPA)

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement (the "Agreement") between Logbase Technologies ("Logbase", "Processor", "we", "us") and the Merchant ("Controller", "you").

This DPA applies where Logbase processes Personal Data on behalf of the Merchant in connection with the Services. It sets out the terms and conditions governing such processing and defines the respective rights and obligations of the parties in accordance with applicable data protection laws.

This DPA is intended to ensure compliance with applicable data protection regulations, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and, where applicable, other privacy laws such as the California Consumer Privacy Act ("CCPA").

In the event of any conflict between the terms of this DPA and the Agreement, the terms of this DPA shall prevail solely with respect to the processing of Personal Data.

By installing, accessing, or using the Services, the Merchant agrees to be bound by the terms of this DPA.

1.1 PREAMBLE

1.1.1 This Data Processing Addendum ("DPA") applies to all processing of Personal Data carried out by Logbase on behalf of the Merchant in connection with the Services.

1.1.2 This DPA forms an integral part of the Agreement and governs the rights and obligations of the parties with respect to such processing.

1.1.3 Logbase processes Personal Data solely on behalf of and in accordance with the Merchant's instructions and applicable data protection laws.

1.1.4 Logbase provides sufficient guarantees to implement appropriate technical and organizational measures to ensure that processing complies with applicable data protection laws, including the GDPR.

1.1.5 Terms used in this DPA shall have the meanings given under applicable data protection laws.

1.1.6 The parties agree that this DPA is intended to ensure compliance with applicable data protection laws and to implement appropriate safeguards to protect the rights of Data Subjects.

2. ROLES OF THE PARTIES

2.1 The Merchant acts as the Controller of Personal Data processed through the Services and determines the purposes and means of such processing.

2.2 Logbase acts as the Processor and processes Personal Data on behalf of the Merchant in accordance with the Agreement, this DPA, and applicable data protection laws.

2.3 The Merchant is responsible for ensuring that it has a valid legal basis for the processing of Personal Data and for providing any required notices to Data Subjects in accordance with applicable data protection laws.

2.4 Logbase shall process Personal Data only on documented instructions from the Merchant, unless required to do so by applicable law, in which case Logbase shall inform the Merchant of such legal requirement unless prohibited by law.

2.5 Logbase shall not process Personal Data for its own purposes and shall not sell, rent, or otherwise disclose Personal Data except as necessary to provide the Services or as required by law.

2.6 Logbase shall not use Personal Data to train general-purpose AI or machine learning models.

3. SUBJECT MATTER AND DURATION

3.1 Subject Matter

The subject matter of the processing is the provision of the Services by Logbase to the Merchant, including Shopify applications and related functionalities such as order management, scheduling, shipping rate calculation, customer interaction, analytics, and AI-powered assistance.

3.2 Duration of Processing

Processing of Personal Data shall take place for the duration of the Merchant's use of the Services and until Personal Data is deleted or anonymized in accordance with this DPA.

3.3 Nature of Processing

Logbase processes Personal Data as necessary to provide the Services, including:

  • Collection of Personal Data through integrations with the Merchant's store
  • Recording, organization, and structuring of data within the application
  • Storage and retrieval of data to support application functionality
  • Use of data to generate outputs, including analytics, reports, and automated responses
  • Transmission of data to subprocessors as required to provide the Services
  • Deletion or anonymization of data upon uninstall or when no longer required.

3.4 Purpose of Processing

Personal Data is processed for the following purposes:

  • To provide application functionality, including scheduling, booking, shipping rate calculation, order tracking, and upsell recommendations
  • To enable communication with Merchant Customers, including notifications and transactional messaging
  • To generate analytics, reports, and performance insights for Merchants
  • To support billing, usage tracking, and account management
  • To enable AI-powered features, including automated customer assistance and recommendation.

3.5 Categories of Data Subjects

Personal Data processed may relate to:

  • Merchants, including store owners and authorized users
  • Merchant Customers, including individuals interacting with the Merchant's store.

3.6 Categories of Personal Data

Personal Data processed include:

  • Merchant Data: name, email address, phone number, and address
  • Merchant Customer Data: name, email address, phone number, address, order information, and booking-related data
  • Usage Data: logs, analytics data, and system-generated information
  • Uploaded Content: images and generated outputs, where applicable

3.7 Data Minimization and Purpose Limitation

Logbase processes only the Personal Data necessary to provide the Services and does not process Personal Data beyond what is required for the specified purposes.

3.8 AI Processing

Logbase does not use Personal Data processed through the Services to train general-purpose AI or machine learning models.

3.9 Additional Details

Further details regarding application-specific processing activities, including data access, purpose, storage, and retention practices, are set out in Annex I.

4. PROCESSING DETAILS

Logbase implements industry-standard security measures including encryption, access control, monitoring, and secure infrastructure.

4.1 Processing Instructions

Logbase shall process Personal Data only on documented instructions from the Merchant, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law. In such a case, Logbase shall inform the Merchant of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

4.2 Purpose Limitation

Logbase shall process Personal Data solely for the purposes specified in the Agreement and this DPA and shall not process Personal Data for its own purposes.

4.3 Data Minimization

Logbase shall process only the Personal Data that is necessary to provide the Services and shall not collect or process Personal Data beyond what is required for the specified purposes.

4.4 Accuracy

Logbase shall take reasonable steps to ensure that Personal Data is processed accurately and remains up to date, based on the information provided by the Merchant.

4.5 Confidentiality of Processing

Logbase shall ensure that any person authorized to process Personal Data is subject to appropriate confidentiality obligations and processes Personal Data only as necessary to perform their duties.

4.6 AI Processing

Where Personal Data is processed through AI-powered features, such processing is limited to generating outputs necessary for the Services. Logbase does not use Personal Data processed through the Services to train general-purpose AI or machine learning models.

4.7 Processing Transparency

Logbase shall provide information reasonably necessary to demonstrate compliance with this DPA and applicable data protection laws, upon reasonable request by the Merchant.

4.8 Compliance with Laws

Logbase shall comply with all applicable data protection laws in the processing of Personal Data and shall implement appropriate technical and organizational measures to ensure such compliance.

4.9 Merchant Responsibility

The Merchant is responsible for ensuring that Personal Data provided to Logbase is accurate, lawful, and collected in compliance with applicable data protection laws.

5. INSTRUCTIONS

5.1 Documented Instructions

Logbase shall process Personal Data only on documented instructions from the Merchant, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law.

5.2 Legal Requirement Exception

If Logbase is required by applicable law to process Personal Data other than as instructed by the Merchant, Logbase shall inform the Merchant of such legal requirement prior to processing, unless that law prohibits such notification on important grounds of public interest.

5.3 Scope of Instructions

The Agreement, this DPA, and the Merchant's use and configuration of the Services constitute the Merchant's documented instructions to Logbase.

5.4 Invalid or Unlawful Instructions

If Logbase believes that any instruction from the Merchant violates applicable data protection laws, Logbase shall promptly inform the Merchant and may suspend the relevant processing until the issue is resolved.

5.5 No Processing for Own Purposes

Logbase shall not process Personal Data for its own purposes and shall not sell, rent, or otherwise disclose Personal Data except as necessary to provide the Services or as required by applicable law.

5.6 Merchant Responsibility

The Merchant is responsible for ensuring that its instructions comply with applicable data protection laws and that it has obtained all necessary rights, consents, and authorizations required for Logbase to process Personal Data.

6. CONFIDENTIALITY

6.1 Confidentiality Obligation

Logbase shall ensure that all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory.

6.2 Authorized Access

Logbase shall ensure that access to Personal Data is limited to personnel who require such access to perform their job responsibilities in connection with the Services.

6.3 Processing on Instructions

Authorized personnel shall process Personal Data only on documented instructions from the Merchant, unless required to do so by applicable law.

6.4 Ongoing Obligation

The confidentiality obligations set out in this Section shall continue after the termination of the Agreement or cessation of processing activities.

6.5 Training and Awareness

Logbase takes reasonable steps to ensure that personnel handling Personal Data are informed of their data protection obligations and receive appropriate training where necessary.

7. SECURITY OF PROCESSING

7.1 General Security Obligations

Logbase implements and shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, taking into account the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects.

7.2 Technical and Organizational Measures

Logbase implements and maintains appropriate security measures, including:

  • Encryption of Personal Data in transit and at rest, where applicable
  • Access controls, including role-based access restrictions and authentication mechanisms
  • Monitoring and logging of system activities to detect and prevent unauthorized access
  • Secure infrastructure hosted on trusted cloud providers, including Amazon Web Services (AWS) and Google Cloud
  • Network and application security controls designed to protect against unauthorized access, disclosure, alteration, or destruction of Personal Data
  • Regular review and updates of security practices and procedures

7.3 Access Control

Logbase ensures that access to Personal Data is limited to authorized personnel who require such access to perform their job responsibilities. Such personnel are subject to confidentiality obligations.

7.4 Incident Detection and Response

Logbase maintains processes to detect, investigate, and respond to security incidents and potential Personal Data Breaches in a timely manner.

7.5 Security Testing and Evaluation

Logbase periodically reviews and evaluates the effectiveness of its technical and organizational measures to ensure ongoing security of Personal Data.

7.6 Subprocessor Security

Logbase ensures that any Subprocessors engaged to process Personal Data implement appropriate technical and organizational measures and are subject to contractual obligations consistent with this DPA.

7.7 Data Segregation

Logbase implements logical separation of data between different Merchants to ensure that Personal Data is accessible only to the relevant Merchant.

7.8 Backup and Recovery

Logbase maintains backup and recovery procedures designed to ensure the availability and integrity of Personal Data in the event of system failure or disruption.

8. SUBPROCESSORS

8.1 Appointment of Subprocessors

The Merchant acknowledges and agrees that Logbase may engage third-party subprocessors to process Personal Data on its behalf in connection with the provision of the Services.

8.2 Authorization

The Merchant provides general authorization for Logbase to engage subprocessors, provided that Logbase complies with the requirements set out in this Section.

8.3 Subprocessor Obligations

Logbase shall ensure that each subprocessor is subject to contractual obligations that provide at least the same level of data protection as those set out in this DPA, including obligations relating to confidentiality, security, and data protection.

8.4 Responsibility for Subprocessors

Logbase shall remain responsible for the acts and omissions of its subprocessors to the same extent as if Logbase were performing the services of each subprocessor directly.

8.5 Changes to Subprocessors

Logbase may update or replace subprocessors from time to time. Where required by applicable law, Logbase shall provide notice of such changes through its website, documentation, or other reasonable means.

8.6 Current Subprocessors

A current list of subprocessors is maintained and made available by Logbase, including:

  • Amazon Web Services (AWS) – Cloud hosting, storage, infrastructure, and email services
  • Google Cloud – Analytics, storage, monitoring, and AI/ML processing
  • HubSpot – Customer relationship management, tickets and support
  • Gleap – Customer relationship management, tickets and support
  • Google Analytics – Website and application analytics
  • OpenAI – AI processing for conversational features
  • Tawk – Customer support chat
  • Calendly – Scheduling and meeting management
  • PostHog - Product analytics and feature usage tracking

8.7 Subprocessor Location

Subprocessors may process Personal Data in various jurisdictions. Logbase ensures that appropriate safeguards are implemented for any international data transfers in accordance with applicable data protection laws.

9. INTERNATIONAL DATA TRANSFERS

9.1 Transfer of Personal Data

The Merchant acknowledges that Personal Data may be transferred to and processed in countries outside the jurisdiction in which it was originally collected, including countries that may not provide the same level of data protection as the country of origin.

9.2 Data Location

Logbase primarily processes and stores Personal Data in data centers located in the United States. However, Personal Data may be processed in other jurisdictions where Logbase or its subprocessors operate, in accordance with this DPA and applicable data protection laws

9.3 Safeguards

Logbase implements appropriate safeguards for international data transfers in accordance with applicable data protection laws. Such safeguards may include contractual commitments with subprocessors and service providers to ensure an adequate level of protection for Personal Data.

9.4 Subprocessor Transfers

Where subprocessors process Personal Data in jurisdictions outside the Merchant's region, Logbase ensures that such subprocessors are subject to appropriate data protection obligations consistent with this DPA.

9.5 Compliance with Applicable Laws

Logbase shall comply with applicable data protection laws relating to international data transfers and shall take reasonable steps to ensure that Personal Data is protected in accordance with this DPA.

9.6 Standard Contractual Clauses

Where the transfer of Personal Data from the Merchant (or from within the European Economic Area or United Kingdom) to Logbase or its subprocessors involves a Restricted Transfer (as defined in Annex IV), the parties shall rely on the Standard Contractual Clauses set out in Annex IV of this DPA, which are hereby incorporated by reference and form an integral part of this DPA. The Standard Contractual Clauses shall apply automatically to any such Restricted Transfer without requiring further action by either party. The relevant module, governing law, and supervisory authority shall be as specified in Annex IV. Where the UK GDPR applies, the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses shall apply as set out in Annex IV, Part 2.

10. DATA SUBJECT RIGHTS

10.1 Assistance with Data Subject Requests

Logbase shall, taking into account the nature of the processing, provide reasonable assistance to the Merchant to enable the Merchant to respond to requests from Data Subjects to exercise their rights under applicable data protection laws.

10.2 Scope of Assistance

Such assistance may include, where applicable:

  • Providing access to relevant Personal Data processed by Logbase
  • Supporting correction, deletion, or restriction of Personal Data
  • Assisting with data portability requests
  • Providing information necessary to respond to Data Subject requests

10.3 Responsibility of the Merchant

The Merchant is responsible for responding to Data Subject requests and for ensuring compliance with applicable data protection laws, including determining whether such requests are valid.

10.4 Direct Requests

If Logbase receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Merchant, Logbase shall, where appropriate, direct the Data Subject to the Merchant or notify the Merchant of the request, unless required to respond directly under applicable law.

10.5 Limitations

Logbase shall not be required to respond directly to Data Subject requests unless required to do so under applicable law.

10.6 Verification

The Merchant is responsible for verifying the identity of the Data Subject before requesting Logbase to take any action in relation to Personal Data.

10.7 Compliance with Applicable Laws

Logbase shall provide assistance to the extent required under applicable data protection laws and subject to the Merchant's documented instructions.

10.8 Reasonable Efforts

Logbase shall provide such assistance using appropriate technical and organizational measures, taking into account the nature of the processing and the information available to Logbase.

11. DATA RETENTION AND DELETION

11.1 Retention Period

Logbase retains Personal Data only for as long as necessary to provide the Services and fulfill the purposes described in the Agreement and this DPA, unless a longer retention period is required or permitted by applicable law.

11.2 Application-Specific Retention

Retention periods may vary depending on the application and its functionality. Detailed information regarding application-specific retention practices is set out in Annex I.

11.3 Deletion Upon Termination

Upon termination of the Agreement or uninstall of the Services, Logbase shall delete or anonymize applicable Personal Data from its active systems upon receipt of the relevant Shopify GDPR deletion webhook, unless retention is required for legal, regulatory, or security purposes. Any residual copies remaining in backup systems will be automatically deleted or overwritten within 30 days in accordance with Logbase's backup retention and rotation processes.

11.4 Backup Retention

Personal Data may be retained in backup systems for a limited period and will be securely deleted or overwritten in accordance with Logbase's data lifecycle management processes.

11.5 Legal Retention Obligations

Logbase may retain Personal Data where required to comply with applicable laws, legal obligations, or to establish, exercise, or defend legal claims.

11.6 Deletion Requests

Logbase shall, upon documented instructions from the Merchant, delete or return Personal Data to the Merchant, unless applicable law requires storage of the Personal Data.

11.7 Anonymization

Where appropriate, Personal Data may be anonymized or de-identified so that it can no longer be used to identify an individual.

11.8 Data Minimization

Logbase shall take reasonable steps to ensure that Personal Data is not retained longer than necessary for the purposes for which it was processed.

12. DATA BREACH NOTIFICATION

12.1 Notification of Breach

Logbase shall notify the Merchant without undue delay and, in any event, within 72 hours after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Merchant. Where notification cannot be made within 72 hours, Logbase shall provide the notification as soon as reasonably possible and shall include, along with the notification, the reasons for the delay.

12.2 Information Provided

Such notification shall include, to the extent reasonably available:

  • A description of the nature of the Personal Data Breach, including the categories and approximate number of affected Data Subjects and records
  • The likely consequences of the Personal Data Breach
  • The measures taken or proposed to be taken by Logbase to address the Personal Data Breach and mitigate its possible adverse effects

12.3 Ongoing Updates

Where it is not possible to provide all information at the same time, Logbase may provide such information in phases as it becomes available.

12.4 Cooperation

Logbase shall provide reasonable assistance to the Merchant in investigating the Personal Data Breach and in fulfilling any applicable breach notification obligations under data protection laws.

12.5 Responsibility of the Merchant

The Merchant is responsible for determining whether to notify affected Data Subjects or supervisory authorities and for fulfilling any such obligations under applicable data protection laws.

12.6 No Admission of Fault

Notification of a Personal Data Breach by Logbase shall not be construed as an admission of fault or liability.

12.7 Incident Response

Logbase maintains internal processes and procedures to detect, investigate, and respond to Personal Data Breaches in a timely manner.

13. ASSISTANCE AND COMPLIANCE

13.1 General Assistance

Logbase shall provide reasonable assistance to the Merchant in fulfilling the Merchant's obligations under applicable data protection laws, taking into account the nature of the processing and the information available to Logbase.

13.2 Data Protection Impact Assessments

Where required under applicable data protection laws, Logbase shall provide reasonable assistance to the Merchant in carrying out data protection impact assessments (DPIAs) and, where applicable, prior consultations with supervisory authorities, to the extent that such assistance relates to the processing of Personal Data by Logbase.

13.3 Information for Compliance

Logbase shall make available to the Merchant information reasonably necessary to demonstrate compliance with the obligations set out in this DPA.

13.4 Limitations

Logbase's obligation to provide assistance under this Section shall be limited to what is reasonable and proportionate, taking into account the nature of the processing and the information available to Logbase.

13.5 Costs

Where permitted by applicable law, Logbase may charge a reasonable fee for providing assistance beyond what is required to comply with its legal obligations under applicable data protection laws.

13.6 Records of Processing

Logbase shall maintain records of processing activities as required under applicable data protection laws.

14. AUDIT RIGHTS

14.1 Information Availability

Logbase shall make available to the Merchant information reasonably necessary to demonstrate compliance with this DPA, upon reasonable request.

14.2 Method of Compliance

Logbase may satisfy its obligations under this Section by providing written responses, summaries of its data protection practices, or other relevant information, at its discretion.

14.3 Limitations

The Merchant acknowledges that Logbase does not permit on-site audits or direct access to its systems. Any information provided shall be limited to what is reasonably necessary to demonstrate compliance and shall be subject to confidentiality obligations.

14.4 Reasonableness

All requests under this Section shall be reasonable in scope, proportionate, and shall not unreasonably interfere with Logbase's business operations.

15. LIABILITY

15.1 Limitation of Liability

The liability of each party arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement.

15.2 No Expansion of Liability

Nothing in this DPA shall be construed as increasing or expanding the liability of either party beyond the limits agreed in the Agreement.

15.3 Allocation of Responsibility

Each party shall be responsible for its own compliance with applicable data protection laws. The Merchant is responsible for ensuring that Personal Data is collected and processed lawfully, including obtaining any required consents or providing appropriate notices to Data Subjects.

15.4 Indirect Damages

Neither party shall be liable for any indirect, incidental, special, or consequential damages arising out of or in connection with this DPA, except as required under applicable law.

16. TERMINATION

16.1 Termination of Processing

This DPA shall remain in effect for as long as Logbase processes Personal Data on behalf of the Merchant in connection with the Services.

16.2 Effect of Termination

Upon termination of the Agreement or uninstall of the Services, Logbase shall cease processing Personal Data, except as required to comply with applicable laws or to fulfill its obligations under this DPA.

16.3 Deletion of Personal Data

Following termination, Logbase shall delete or anonymize Personal Data in accordance with Section 11 of this DPA, unless retention is required for legal, regulatory, security, or legitimate business purposes.

16.4 Survival

The provisions of this DPA that by their nature are intended to survive termination, including but not limited to confidentiality, security, liability, and data protection obligations, shall continue in effect after termination of the Agreement.

17. CONTACT

connect@logbase.io

ANNEX I — PROCESSING DETAILS & RETENTION

1. Categories of Data Subjects

  • Merchants (store owners and authorized users)
  • Merchant Customers (individuals interacting with the Merchant's store)

2. Categories of Personal Data

  • Merchant Data: name, email address, phone number, and address
  • Merchant Customer Data: name, email address, phone number, address, order information, and booking-related data
  • Usage Data: logs, analytics data, and system-generated information
  • Uploaded Content: images and generated outputs (where applicable)

3. Application-Specific Processing

Shopify GDPR Webhook Compliance

Logbase implements Shopify's GDPR-compliant webhook mechanisms to support data deletion and privacy requests.

shop/redact

  • Shopify sends this event 48 hours after a merchant uninstalls the application.
  • Upon receiving this event, Logbase automatically deletes or anonymizes applicable Personal Data associated with the merchant from its active systems, except where retention is required for legal, regulatory, or security purposes.
  • Any residual copies remaining in backup systems are automatically deleted or overwritten within 30 days in accordance with Logbase's backup retention and rotation processes.

customers/redact

  • Shopify sends this event 10 days after a customer requests deletion or when a merchant deletes a customer.
  • Upon receiving this event, Logbase automatically deletes or anonymizes applicable Personal Data related to the specified customer from its active systems, where such data is identifiable and stored.
  • Any residual copies remaining in backup systems are automatically deleted or overwritten within 30 days in accordance with Logbase's backup retention and rotation processes.

These processes ensure compliance with applicable data protection laws and Shopify platform requirements.

Selleasy (Upsell & Cross-Sell)

Selleasy enables merchants to create upsell and cross-sell offers, customer-targeted campaigns, and recommendation workflows. Personal Data is processed solely as necessary to provide the Services.

Merchant Data

FieldDetails
EmailAccess: CRM, merchant communication, and operational notifications
Retrieval: To contact merchants, support communication workflows, and manage account-related activities
Storage: Stored for communication, CRM, and operational support purposes
Retention: While the merchant's store remains active
PhoneAccess: CRM and merchant communication
Retrieval: Not retrieved by the application
Storage: Not stored
Retention: Not retained
NameAccess: CRM and merchant communication
Retrieval: Not retrieved by the application
Storage: Stored temporarily as part of campaign configuration. Not retained in identifiable form after campaign processing
Retention: Not retained in identifiable form. Stored only for the duration of campaign configuration
AddressAccess: CRM and merchant communication
Retrieval: Not retrieved by the application
Storage: Not stored
Retention: Not retained

Merchant Customer Data

FieldDetails
EmailAccess: To support customer-targeted campaign creation and upsell/cross-sell workflows
Retrieval: To enable merchants to filter and select customers within the admin panel for campaign targeting
Storage: Not stored
Retention: Not retained
PhoneAccess: Not required for application functionality
Retrieval: Not retrieved by the application
Storage: Not stored
Retention: Not retained
NameAccess: To support customer-targeted campaign creation and recommendation workflows
Retrieval: To enable merchants to identify and select customers within campaign workflows
Storage: Stored as part of campaign configuration to support customer targeting functionality
Retention: Not retained as an identifiable customer.
AddressAccess: To support usage-based billing, analytics, and recommendation functionality
Retrieval: To calculate usage-based billing and support upsell/cross-sell recommendation workflows
Storage: Only aggregated order count is stored for billing and analytics purposes.
Retention: Not retained

Pickeasy (Pickup & Delivery Date)

Pickeasy enables merchants to manage pickup and delivery scheduling workflows, delivery eligibility rules, location-based configurations, and customer order scheduling. Personal Data is processed solely as necessary to provide the Services.

Merchant Data

FieldDetails
EmailAccess: CRM, location management, analytics, and communication
Retrieval: To manage merchant communication, send order status updates, and support in-app location configuration
Storage: Stored for CRM, communication, operational management, and notification workflows
Retention: While the merchant's store remains active
PhoneAccess: CRM and location management
Retrieval: To support merchant communication and in-app location configuration
Storage: Stored for CRM and location management purposes
Retention: While the merchant's store remains active
NameAccess: CRM and merchant identification
Retrieval: To identify merchants and support CRM activities
Storage: Stored for CRM and merchant identification purposes
Retention: While the merchant's store remains active
Address / LocationAccess: Location management and operational configuration
Retrieval: To configure and manage pickup and delivery locations within the application
Storage: Stored to support location setup and operational workflows
Retention: While the merchant's store remains active

Merchant Customer Data

FieldDetails
EmailAccess: Order management and customer communication
Retrieval: To display customer contact details within order views and support communication workflows
Storage: Stored to provide historical visibility in the admin interface and support troubleshooting
Retention: Up to 90 days
PhoneAccess: Order management and customer communication
Retrieval: To display customer contact details within order views
Storage: Stored to support historical visibility and troubleshooting
Retention: Up to 90 days
NameAccess: Order management and customer identification
Retrieval: To display customer details within order views and identify customers
Storage: Stored to support historical visibility and troubleshooting
Retention: Up to 90 days
AddressAccess: Delivery eligibility and logistics workflows
Retrieval: To determine delivery zones, calculate distance or zipcode-based rules, and apply slot and rate logic
Storage: Stored to support delivery calculations, logistics workflows, and troubleshooting
Retention: Up to 90 days
Order InformationAccess: Order management, scheduling, and fulfillment workflows
Retrieval: To display order information and support slot selection, delivery scheduling, and operational workflows
Storage: Stored to support processing, historical visibility, and troubleshooting
Retention: Up to 90 days

ShipX (Shipping Rates)

ShipX enables merchants to configure shipping rules, calculate shipping rates, manage logistics workflows, and apply delivery-related conditions based on customer and order data. Personal Data is processed solely as necessary to provide the Services.

Merchant Data

FieldDetails
EmailAccess: Account management, CRM, analytics, and merchant communication
Retrieval: To perform analytics, manage merchant accounts, and send operational updates such as import/export status notifications
Storage: Stored for account management, analytics, communication workflows, and operational support
Retention: While the merchant's store remains active
PhoneAccess: CRM, analytics, and emergency contact
Retrieval: To support account management, analytics, and communication workflows
Storage: Stored for account management and communication purposes
Retention: While the merchant's store remains active
NameAccess: CRM and analytics
Retrieval: To identify merchants and support CRM and analytics activities
Storage: Stored for account identification and communication purposes
Retention: While the merchant's store remains active
AddressAccess: Analytics and operational context
Retrieval: To provide contextual insights for analytics and operational workflows
Storage: Not used for core application functionality and not retained for application use. May include personal data depending on merchant type
Retention: Not retained for application use

Merchant Customer Data

FieldDetails
EmailAccess: Shipping rule evaluation and application logic execution
Retrieval: To evaluate configured shipping conditions and execute application workflows
Storage: Stored to support shipping rate calculation, historical visibility, and troubleshooting
Retention: Up to 60 days
PhoneAccess: Shipping rule evaluation and application logic execution
Retrieval: To evaluate configured shipping conditions and execute application workflows
Storage: Stored to support processing, historical visibility, and troubleshooting
Retention: Up to 60 days
AddressAccess: Shipping calculations and logistics workflows
Retrieval: To determine destination shipping zones and execute shipping logic
Storage: Stored to support shipping calculations, logistics workflows, and troubleshooting
Retention: Up to 60 days
Order InformationAccess: Shipping rule evaluation and rate calculation
Retrieval: To validate configured conditions and calculate shipping rates
Storage: Stored to support shipping calculations, order processing, historical visibility, and troubleshooting
Retention: Up to 60 days

AskTimmy (AI Customer Assistant)

AskTimmy enables merchants to automate customer support through AI-powered conversations, product recommendations, lead capture, order lookup workflows, and customer interaction management. Personal Data is processed solely as necessary to provide the Services. Merchant and customer data, including uploaded content, is not used to train general-purpose AI or machine learning models.

Merchant Data

FieldDetails
EmailAccess: Support identification, CRM, and application notifications
Retrieval: To identify merchants in support tools, manage communication workflows, and send operational updates
Storage: Stored for merchant identification, communication, and support workflows
Retention: While the merchant's store remains active
PhoneAccess: Store configuration and operational management
Retrieval: To support store setup and operational configuration workflows
Storage: Stored as part of store configuration and operational setup data
Retention: While the merchant's store remains active
NameAccess: Support identification and store configuration
Retrieval: To identify merchants and support configuration and support workflows
Storage: Stored for merchant identification and configuration workflows
Retention: While the merchant's store remains active
AddressAccess: Store location configuration and operational setup
Retrieval: To configure store locations and operational workflows within the application
Storage: Stored as part of store configuration and operational setup data
Retention: While the merchant's store remains active

Merchant Customer Data

FieldDetails
EmailAccess: Customer personalization, lead capture, and order lookup workflows
Retrieval: To identify returning customers, enable order lookups, and support lead generation workflows
Storage: Stored as part of conversation history, analytics, and merchant support workflows
Retention: Up to 60 days
PhoneAccess: Lead capture and customer interaction workflows
Retrieval: To capture customer contact details for lead generation and communication workflows
Storage: Stored as part of conversation records and lead management workflows
Retention: Up to 60 days
NameAccess: Customer personalization and identification
Retrieval: To personalize interactions and identify customers within conversation workflows
Storage: Stored as part of conversation records and analytics workflows
Retention: Up to 60 days
AddressAccess: Order-related customer support workflows
Retrieval: To provide order-related information during customer interactions
Storage: Stored as part of conversation records where required for support workflows
Retention: Up to 60 days
Order InformationAccess: Order lookup and customer support workflows
Retrieval: To validate and display order status, fulfillment details, and tracking information
Storage: Stored as part of conversation history and support workflows
Retention: Up to 60 days
Customer Uploaded Images (Photo Search)Access: Visual product search workflows
Retrieval: To extract visual attributes from uploaded images and match them against the product catalog
Storage: Stored for processing, search history, analytics, and debugging workflows. Image references may be retained for troubleshooting purposes
Retention: Up to 60 days

BookX (Booking & Appointment)

BookX enables merchants to manage appointment scheduling, booking workflows, customer notifications, and booking-related operational processes. Personal Data is processed solely as necessary to provide the Services.

Merchant Data

FieldDetails
EmailAccess: CRM, merchant communication, and support workflows
Retrieval: To identify merchants, manage communication, and support CRM-related activities
Storage: Stored for merchant identification, communication workflows, and CRM purposes
Retention: While the merchant's store remains active
PhoneAccess: CRM, analytics, and operational communication
Retrieval: To support communication and operational workflows
Storage: Stored for CRM, analytics, and communication purposes
Retention: While the merchant's store remains active
NameAccess: CRM and merchant identification
Retrieval: To identify merchants and support CRM workflows
Storage: Stored for merchant identification and communication purposes
Retention: While the merchant's store remains active
AddressAccess: Operational context and analytics
Retrieval: To support operational workflows and analytics
Storage: Stored for operational management and analytics purposes
Retention: While the merchant's store remains active

Merchant Customer Data

FieldDetails
EmailAccess: Booking management and customer communication
Retrieval: To create and manage booking records and send booking confirmations and notifications
Storage: Stored as part of booking records to support application functionality and booking workflows
Retention: Up to 365 days
PhoneAccess: Booking management and customer communication
Retrieval: To display booking details and enable merchant-to-customer communication
Storage: Stored as part of booking records to support application functionality and operational workflows
Retention: Up to 365 days
NameAccess: Booking management and customer identification
Retrieval: To display booking details and identify customers within booking workflows
Storage: Stored as part of booking records to support booking functionality and customer identification
Retention: Up to 365 days
AddressAccess: Booking management and customer interaction workflows
Retrieval: To display booking details and support customer interaction workflows
Storage: Stored as part of booking records to support operational workflows
Retention: Up to 365 days
Order InformationAccess: Booking reference and operational workflows
Retrieval: To display order or booking identifiers within the application and support booking-related workflows
Storage: Stored to support navigation, booking references, and operational workflows
Retention: Up to 365 days

Dealeasy (Volume Discount)

Dealeasy enables merchants to create volume discounts, tiered pricing, bundle offers, and promotional workflows such as buy-one-get-one (BOGO) campaigns. Personal Data is processed solely as necessary to provide the Services.

Merchant Data

FieldDetails
EmailAccess: Merchant identification, CRM, analytics, and support workflows
Retrieval: To identify merchants, support communication workflows, and manage CRM-related activities
Storage: Stored to support merchant identification, communication, analytics, and support workflows
Retention: While the merchant's store remains active
PhoneAccess: Analytics and reporting workflows
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained
NameAccess: CRM and merchant communication workflows
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained
AddressAccess: Analytics and reporting workflows
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained

Merchant Customer Data

FieldDetails
EmailAccess: Discount eligibility and campaign execution workflows
Retrieval: To evaluate customer eligibility for discount rules and support targeted promotional workflows
Storage: Not stored. Used only for real-time processing within the application
Retention: Not retained
PhoneAccess: Analytics workflows
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained
NameAccess: Discount eligibility and campaign execution workflows
Retrieval: To evaluate customer eligibility and display customer details within promotional workflows
Storage: Not stored. Used only for real-time processing within the application
Retention: Not retained
AddressAccess: Analytics workflows
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained
Order InformationAccess: Analytics, promotional workflows, and subscription billing
Retrieval: To support analytics, usage-based billing calculations, and promotional rule execution
Storage: Only limited aggregated data (such as order count and country-level analytics) may be retained for billing and analytics purposes
Retention: Not retained in identifiable form

Dibs (Preorder)

Dibs enables merchants to manage preorders and backorders for pre-launch and out-of-stock products. The application supports preorder workflows, partial payments, automated payment reminders, and order-related notification functionality. Personal Data is processed solely as necessary to provide the Services.

Merchant Data

FieldDetails
EmailAccess: Email notifications, merchant communication, and CRM workflows
Retrieval: To send order and payment-related notifications using the configured sender email and support merchant communication workflows
Storage: Stored to support notification workflows, merchant communication, and support-related activities
Retention: While the merchant's store remains active
PhoneAccess: Not required for application functionality
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained
NameAccess: Merchant communication and notification workflows
Retrieval: To support merchant identification and notification-related workflows
Storage: Stored to support notification workflows and merchant identification
Retention: While the merchant's store remains active
AddressAccess: Partial payment configuration and operational validation
Retrieval: To determine country-level eligibility for partial payment functionality
Storage: Stored to support configuration and operational validation workflows
Retention: While the merchant's store remains active

Merchant Customer Data

FieldDetails
EmailAccess: Order and payment notification workflows
Retrieval: To send preorder, backorder, and payment-related notifications to customers
Storage: Not stored. Used only for real-time notification processing
Retention: Not retained
PhoneAccess: Not required for application functionality
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained
NameAccess: Not required for application functionality
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained
AddressAccess: Not required for application functionality
Retrieval: Not retrieved or used by the application
Storage: Not stored
Retention: Not retained
Order InformationAccess: Order management, preorder workflows, and analytics
Retrieval: To display preorder and backorder details within the Orders page and support operational metrics
Storage: Not stored. Used only for real-time processing within the application
Retention: Not retained

DecorGenie (Shop Minis)

DecorGenie enables users to generate room visualizations and interior design previews using user-uploaded images. The application processes uploaded content solely to generate visualization outputs and display historical results within the application.

DecorGenie does not access or process merchant account data, merchant customer personal data, order information, or Shopify customer records.

Uploaded content is processed solely to provide the requested visualization functionality and is not used to train general-purpose AI or machine learning models.

FieldDetails
User Uploaded ImagesAccess: Visualization generation and image processing workflows
Retrieval: To generate room visualizations and interior design outputs based on user-uploaded images
Storage: Stored to support visualization history, generated results display, analytics, and troubleshooting workflows
Retention: Up to 90 days
Generated Visualization ResultsAccess: Visualization history and user experience workflows
Retrieval: To display previously generated room visualization results to users
Storage: Stored to support visualization history and operational workflows
Retention: Up to 90 days

FitGenie (Shop Minis)

FitGenie enables users to generate virtual try-on experiences using user-uploaded images and AI-powered visualization workflows. The application processes uploaded content solely to generate try-on outputs and display historical results within the application.

FitGenie does not access or process merchant data or merchant customer personal data.

FieldDetails
User Uploaded ImagesAccess: Virtual try-on generation and image processing workflows
Retrieval: To generate virtual try-on outputs based on user-uploaded images
Storage: Stored to support try-on history, generated results display, analytics, and troubleshooting workflows
Retention: Up to 90 days
Generated Try-On ResultsAccess: Try-on history and user experience workflows
Retrieval: To display previously generated try-on results to users
Storage: Stored to support try-on history and operational workflows
Retention: Up to 90 days

ANNEX II — SECURITY MEASURES

Logbase implements and maintains appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.

1. Access Control

  • Access to Personal Data is restricted to authorized personnel based on role and necessity
  • Role-based access controls are implemented to limit access to only what is required for job responsibilities
  • Authentication mechanisms are used to protect access to systems and data

2. Data Protection

  • Personal Data is encrypted in transit using industry-standard protocols
  • Personal Data is encrypted at rest, where applicable
  • Data is processed only as necessary to provide the Services

3. Infrastructure Security

  • Systems are hosted on secure cloud infrastructure providers, including Amazon Web Services (AWS) and Google Cloud
  • Cloud providers implement physical, network, and infrastructure-level security controls
  • Network security measures are in place to protect against unauthorized access

4. Monitoring and Logging

  • System activity is monitored to detect unauthorized access or unusual activity
  • Logs are maintained to support incident detection and investigation
  • Alerts may be generated for suspicious or abnormal system behavior

5. Incident Management

  • Processes are in place to detect, investigate, and respond to security incidents
  • Personal Data Breaches are handled in accordance with Section 12 of this DPA
  • Appropriate remediation steps are taken to mitigate potential impact

6. Subprocessor Security

  • Subprocessors are selected based on their ability to provide appropriate security measures
  • Contractual agreements require subprocessors to implement data protection and security controls consistent with this DPA
  • Subprocessor practices are reviewed as part of vendor management processes

7. Data Segregation

Logical separation of data is maintained between different Merchants to prevent unauthorized access across accounts

8. Backup and Recovery

  • Backup mechanisms are implemented to ensure availability and integrity of data
  • Data may be restored in the event of system failure or disruption

9. Security Maintenance

  • Security measures are reviewed and updated periodically
  • Reasonable steps are taken to ensure continued effectiveness of technical and organizational measures

ANNEX III — SUBPROCESSORS

The following is a list of subprocessors that may process Personal Data on behalf of Logbase in connection with the Services.

Logbase ensures that each subprocessor is subject to data protection obligations consistent with this DPA.

Subprocessors may process Personal Data in the United States and other jurisdictions where they operate, in accordance with applicable data protection laws.

1. Common Subprocessors

These subprocessors are used across Logbase applications, depending on the functionality and services used.

SubprocessorPurposeData Processed
Amazon Web Services (AWS)Cloud hosting, infrastructure, storage, database management, email servicesMerchant Data, Customer Data, Usage Data
HubSpotCustomer relationship management and supportMerchant Data
Google AnalyticsWebsite and application analyticsUsage Data
TawkCustomer support chatMerchant Data
CalendlyScheduling and meeting managementMerchant Data
GleapCustomer support and ticket managementMerchant Data
PostHogProduct analytics and feature usage trackingMerchant Data

2. Application-Specific Subprocessors

The following subprocessors are used only by applications or features that require the relevant processing functionality.

ApplicationSubprocessorPurposeData Processed
AskTimmyGoogle CloudAI/ML processing and supporting application servicesMerchant Data, Customer Data, Usage Data
AskTimmyOpenAIAI-powered conversational assistance and related AI processingLimited Merchant Customer Data and conversation content as required
SelleasyResendAccount management and email deliveryMerchant Data
DecorGenieGeminiAI image/visualization processingUser-uploaded images and generated outputs
FitGenieGeminiAI image/visualization processingUser-uploaded images and generated outputs

Logbase updates this list of subprocessors from time to time in accordance with Section 8 of this DPA.

ANNEX IV — STANDARD CONTRACTUAL CLAUSE

PART 1 — EU STANDARD CONTRACTUAL CLAUSES

The Standard Contractual Clauses set out in the European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs") are incorporated into this DPA by reference and apply to any Restricted Transfer of Personal Data subject to the EU GDPR

1. Definitions

"Restricted Transfer" means any transfer of Personal Data from the European Economic Area (EEA) to a country or territory outside the EEA that does not benefit from an adequacy decision by the European Commission pursuant to Article 45 of the GDPR.

"Data Exporter" means the Merchant (Controller) transferring Personal Data to Logbase.

"Data Importer" means Logbase Technologies (Processor) receiving Personal Data from the Merchant

2. Applicable Module

Module Two (Controller to Processor) of the EU SCCs shall apply to transfers under this DPA. Modules One, Three, and Four are not applicable and shall be deemed deleted

3. Optional Clauses

Clause 7 (Docking Clause): Does not apply.

Clause 9: Option 2 (General Written Authorisation) applies. The time period for prior notice of subprocessor changes is fifteen (15) days.

Clause 11 (Redress): The optional language relating to independent dispute resolution does not apply.

Clause 17 (Governing Law): The EU SCCs shall be governed by the law of Ireland.

Clause 18(b) (Choice of Forum): Disputes shall be resolved before the courts of Ireland

4. Annex 1 — Description of Transfer

FieldDetails
Data ExporterThe Merchant, as identified in the Agreement
Data ImporterLogbase Technologies, connect@logbase.io
Categories of Data SubjectsMerchants; Merchant Customers
Categories of Personal DataMerchant Data: name, email, phone, address Merchant Customer Data: name, email, phone, address, order/booking data Usage Data: logs, analytics, system data Uploaded Content: images and generated outputs
Sensitive DataNone
Frequency of TransferContinuous, for the duration of the Agreement
Nature of ProcessingAs set out in Sections 3.3–3.4 of this DPA
Purpose of TransferProvision of the Services as described in the Agreement
Retention PeriodAs set out in Section 11 and Annex I of this DPA
Competent Supervisory AuthorityThe supervisory authority of the EU Member State in which the Merchant is established, or, where the Merchant is not established in the EU, the Irish Data Protection Commission

5. Annex 2 Technical and Organisational Measures

The technical and organisational security measures applicable to the processing are as set out in Annex II of this DPA.

6. Annex 3 — List of Subprocessors

The list of subprocessors authorised to process Personal Data is as set out in Annex II of this DPA

PART 2 — UK INTERNATIONAL DATA TRANSFER ADDENDUM (IDTA)

Where the transfer of Personal Data is subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (ICO) on 21 March 2022 ("UK Addendum") shall apply, and is incorporated into this DPA by reference

1. Table 1 — Parties

FieldExporter (Merchant)Importer (Logbase)
Full Legal NameAs identified in the AgreementLogbase Technologies
Main AddressAs identified in the AgreementAs per Agreement
ContactAs identified in the Agreementconnect@logbase.io
Key ContactMerchant's DPO or legal contactconnect@logbase.io

2. Table 2 — Selected SCCs, Modules and Selected Clauses

Logbase Technologies As per Agreement connect@logbase.io. The UK Addendum is appended to and forms part of the EU SCCs set out in Part 1 of this Annex IV. Module Two (Controller to Processor) applies.

3. Table 3 — Appendix Information

The information required for Appendix 1 (Description of Transfer), Appendix 2 (Technical and Organisational Measures), and Appendix 3 (List of Subprocessors) of the EU SCCs is as set out in Annex 1, Annex 2, and Annex 3 of Part 1 of this Annex IV respectively.

4. Table 4 — Ending the Addendum

Neither party may end the UK Addendum when the Approved EU SCCs it is appended to change, in accordance with the provisions of Section 19 of the UK Addendum.

5. Supervisory Authority

For purposes of the UK Addendum, the competent supervisory authority is the UK Information Commissioner's Office (ICO).

Logo of logbase technologies
Products
Upsell & Cross Sell — Selleasy
Shipping Rates & Rules — ShipX
Pickup Delivery Date — Pickeasy
Appointment Booking — BookX
Volume Discounts — Dealeasy
Preorder & Backorder — Dibs
Company
Partners
Careers
Talk to Us
About us
Learn
BlogGuides
Legal
Terms Of Service
Privacy Policy
Data Processing Addendum(DPA)
Application Data & Functionality
Application Data Retention
Social
Logo of linked inLogo of YoutubeLogo of XLogo of instagramLogo of spotify
© 2026 All rights reserved by Logbase.