This addendum forms part of the Terms of Service between Monochrome and you, the merchant. It applies whenever we process personal data on your behalf, and it takes effect the moment you accept those terms.
There is nothing separate to sign. If your legal team needs a countersigned copy on paper, write to hello@monochrome.digital and we will provide one, but this document is already in force without it.
Terms in initial capitals that are not defined here have the meaning given in the UK GDPR and in Regulation (EU) 2016/679.
1. Roles
You are the controller. We are your processor.
You decide what is recorded about the items you make and why. We process it to provide the app and for no other purpose.
Where we determine the purposes ourselves, we are a controller instead. That is limited to two things and both are outside this addendum: the account information we hold about you as our customer, and the technical logs described in the Privacy Policy.
2. What is processed
This is a short list, and the shortness is the point.
| Category | Data | Data subjects |
|---|---|---|
| Merchant account | Shop domain, shop name, plan, country, locale | You |
| Staff | Name, email address, Shopify user ID | Your staff |
| Product data | Titles, options, images, product and variant IDs | None |
| Order data | Order and fulfilment identifiers, and the fact of fulfilment | None |
| Item register | Identifiers, dates, edition numbers, status, event history | None |
No customer personal data is processed. The app requests no Shopify permission touching customers, holds no owner records, and writes nothing identifying a person into your register. Rows in the table above marked "None" contain no personal data at all: they describe products and objects.
The processing lasts for as long as the app is installed, plus the 48 hours described in section 7.
3. Our obligations
We will:
- process personal data only on your documented instructions, of which this addendum and your use of the app are the instructions;
- tell you if we believe an instruction breaches data protection law, and suspend the processing until it is resolved;
- ensure everyone we authorise to process the data is bound by confidentiality;
- implement the measures in section 6;
- assist you with data subject requests, with data protection impact assessments, and with any consultation of a supervisory authority, taking account of the nature of the processing and what we have available;
- make available the information needed to demonstrate compliance with Article 28, and allow audits as described in section 8;
- delete or return the data at the end of the service, as in section 7.
4. Your obligations
You will:
- have a lawful basis for the processing you instruct;
- give the people whose data is involved the information they are entitled to, including in your own privacy notice. There is wording you can adapt;
- not instruct us to process special category data, criminal offence data, or data about children, none of which this app is designed for or capable of handling appropriately;
- not write personal data into your register. The register is publicly readable by anyone holding an identifier. If you use the Shopify Admin API to add a field containing personal data to the metaobject definition the app created, you are publishing it to the world, and that is your act rather than ours.
5. Sub-processors
You give general authorisation for us to engage sub-processors. Each one is bound by written terms no less protective than these, and we remain liable for what they do.
The current list is at Sub-processors, with each one's role and location. We give 30 days' notice before adding or replacing one. If you object on reasonable data protection grounds within that period, tell us; if we cannot resolve it, you may terminate without penalty.
6. Security
- Encryption in transit, by TLS, everywhere.
- Encryption at rest for the database.
- Access limited to the people who need it, over multi-factor authentication.
- Every request from a Shopify surface verified cryptographically before it is answered, so a request that did not come from your store cannot read or write anything.
- Separation of the register from anything identifying a person, enforced by the design of the app rather than by policy: there is no field to put a name in.
- Regular patching of dependencies, and a private repository.
We are a small studio and we say so plainly rather than implying a certification we do not hold. We have no ISO 27001 certificate and no SOC 2 report. If your procurement requires one, say so before you install rather than after.
7. Deletion and return
You can export your data from the app at any time while you are installed.
On uninstall, Shopify notifies us, and we delete what we hold about your store 48 hours later, on Shopify's shop/redact webhook. Sessions and access tokens go immediately at uninstall rather than waiting for it.
Operational logs are held by our hosting providers and expire on their schedule, within days. We operate no log store of our own and take no copy.
The copy of your item records held as metaobjects in your own Shopify admin is not deleted, because it is yours and it is not ours to delete. It stays in your store under Shopify's terms. If you want it gone, remove it from your Shopify admin.
8. Audits
We will answer reasonable written questions about our processing, and provide what we have, within 30 days.
An on-site audit may be requested once in any twelve-month period, on 30 days' notice, at your cost, subject to confidentiality, and arranged so that it does not disrupt the service for other merchants.
9. Personal data breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data. The notice will describe what we know, what we are doing, and what we recommend you do.
We will not delay a notification in order to make it complete.
10. International transfers
Data is stored in the European Union. Some sub-processors listed in Sub-processors may process data in the United States, and Monochrome itself operates from Lebanon, which does not have a European Commission adequacy decision.
For those transfers, the Standard Contractual Clauses apply, as set out below. This is not a footnote: it is the mechanism that makes the arrangement lawful, and it is why this section is as specific as it is.
The Standard Contractual Clauses
The clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this addendum by reference, and are completed as follows.
Module. Module Two, controller to processor.
Clause 7, docking. Applies.
Clause 9, sub-processors. Option 2, general written authorisation, with a notice period of 30 days.
Clause 11, redress. The optional independent dispute resolution body is not used.
Clause 17, governing law. The law of Ireland.
Clause 18, forum. The courts of Ireland.
Annex I.A, the parties. Data exporter: you, the merchant, acting as controller, at the address on your Shopify account. Data importer: Monochrome, acting as processor, at hello@monochrome.digital.
Annex I.B, description of the transfer. The categories of data subject, the categories of personal data and the duration are those in section 2 above. No special category data is transferred. The frequency is continuous for the duration of the service, and the purpose is providing the app.
Annex I.C, competent supervisory authority. The authority of the EU member state in which you are established, or, where you are not established in the EU, the Irish Data Protection Commission.
Annex II, technical and organisational measures. Those in section 6 above.
Annex III, sub-processors. The list at Sub-processors, as amended from time to time under Clause 9 and section 5 of this addendum.
The UK
For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0) applies to the clauses above. Tables 1 to 3 are completed by the details in this section, and in Table 4 the party that may end the addendum when the Approved Addendum changes is the data exporter.
Switzerland
For transfers subject to the Swiss FADP, references in the clauses to the GDPR are read as references to the FADP, the competent authority is the Federal Data Protection and Information Commissioner, and the term "member state" is read so that it does not prevent a data subject in Switzerland from bringing proceedings where they live.
11. Order of precedence
If this addendum conflicts with the Terms of Service, this addendum wins for matters of data protection. If it conflicts with the Standard Contractual Clauses, the clauses win.
12. Contact
hello@monochrome.digital, for anything in this document. We answer within 30 days and usually within two working days.