Data Processing Agreement
Last updated: August 2026. Contact apollo@ebrandsglobal.com for a signed copy.
1. Scope and acceptance
This Data Processing Agreement ("DPA") governs personal data that eBrands Holdings Oy ("eBrands") processes on behalf of a merchant ("Customer") who installs the Apollo Shopify app, where eBrands acts as the Customer's processor as described in our privacy policy. It applies from the point of installation, is incorporated into the terms governing that use, and forms the parties' agreement under Article 28(3) GDPR for that processing. It does not apply to processing for which eBrands is itself the controller, which the privacy policy identifies separately. A countersigned copy is available on request from apollo@ebrandsglobal.com.
The Customer warrants that it has a lawful basis for the personal data it makes available to eBrands and that it has given its own customers the information required by Article 13 GDPR.
2. Subject matter and duration
Processing continues for the duration of the Customer's use of the service, and thereafter only for as long as needed to evidence compliance with this DPA or as required by law.
3. Nature and purpose of processing
eBrands processes Shopify order, catalogue, inventory and settlement data to operate the Apollo platform for the Customer's store.
For stores activated as eBrands brands, eBrands additionally forwards Shopify order events, and the refunds and returns associated with them, into the enterprise resource planning and fulfilment systems eBrands operates centrally for the brands it runs, which eBrands' operations personnel access to fulfil and account for those orders. Where this applies it is the reason personal data — buyer name and address — is required: those fields are necessary to create a fulfillable order in that system. Activation is a deliberate per-brand step: a store that installs the app from the Shopify App Store is not forwarded there unless eBrands activates it.
4. Instructions and confidentiality
eBrands processes personal data only on the Customer's documented instructions, including with regard to transfers outside the EEA, unless required to do otherwise by EU or Member State law; in that case eBrands informs the Customer of the requirement before processing, unless the law prohibits it. eBrands informs the Customer if, in its opinion, an instruction infringes applicable data protection law. eBrands ensures that persons authorised to process the personal data are bound by an obligation of confidentiality.
5. Categories of data subjects and personal data
Data subjects: the Customer's store customers, and the Customer's staff who administer the connection. Personal data: the customer record attached to an order — name, email, phone where present, and shipping and billing address — together with order details; and, for administering staff, account and contact data.
6. Sub-processors
The Customer gives eBrands general written authorisation to engage sub-processors for the purposes described in section 3. A current and complete list of sub-processors is available on request from apollo@ebrandsglobal.com. eBrands informs the Customer in advance of an intended change to the sub-processors that handle the Customer's personal data and gives the Customer a reasonable opportunity to object. eBrands requires protections equivalent to those in this DPA where it contracts with a sub-processor directly.
7. Data-subject rights and compliance webhooks
eBrands assists the Customer, taking into account the nature of the processing, in responding to data-subject requests.
customers/data_request: within 30 days of the request, eBrands provides the Customer with the personal data it holds for the identified customer. For a store eBrands has not activated, no such data is retained, and eBrands confirms that.customers/redact: within 30 days of the request, eBrands deletes or irreversibly de-identifies the personal data it holds for the identified customer, except where retention is required by law.shop/redact:eBrands destroys the store's stored credential, stops processing the store's data, and within 30 days of the request deletes or de-identifies the data it holds for the store, subject to the retention periods required by tax, accounting and other legal obligations.
Every request is authenticated and recorded, with its outcome, in an append-only audit trail.
8. Security incidents
eBrands notifies the Customer without undue delay after confirming a personal-data breach affecting the Customer's data, with the information available at the time, and supplements it as more becomes known.
9. Security measures
eBrands implements technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or higher) and encryption at rest, least-privilege access control with multi-factor authentication on internal dashboards, logical separation of each merchant's data, logging with redaction of sensitive fields, and periodic access review. Further information about these measures is available to the Customer on reasonable request.
10. International transfers
Personal data is processed primarily inside the EEA. Where a transfer outside the EEA is necessary, eBrands relies on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism. Details of the mechanism relied on are available on request.
11. Information and audits
eBrands makes available to the Customer, on reasonable notice and no more than once in any twelve-month period, the information necessary to demonstrate compliance with this DPA. Where that information is not sufficient, eBrands allows for and contributes to an audit conducted by the Customer or an auditor mandated by the Customer, on reasonable notice, at the Customer's cost, and in a manner that does not disclose the confidential information or personal data of any other customer.
12. Deletion or return on termination
Upon termination, eBrands deletes or, at the Customer's request, returns the personal data it holds for the Customer, except where retention is required by law — including the order and accounting records created when orders are forwarded into eBrands' fulfilment and accounting systems, which are retained for their statutory period.
13. Liability, changes and contact
Each party's total liability under this DPA is limited to the fees paid for the service in the twelve months preceding the claim. eBrands may update this DPA to reflect changes in law, sub-processors, or service scope; material changes are communicated to active Customers by email in advance of taking effect. Privacy contact: apollo@ebrandsglobal.com.