Zizr Data Processing Agreement
Effective date: 21 May 2026
Last updated: 21 May 2026
Available at: https://www.zizr.com/legal/dpa
This Data Processing Agreement (“DPA”) is entered into between:
Zizr AS (“Processor”, “Zizr”, “we”, “us”, “our”), organisation number 922 796 556, having its registered office at Dronningens gate 38, 7011 Trondheim, Norway,
and
The Merchant (“Controller”, “Merchant”, “you”, “your”) who has installed the Zizr Shopify app and accepted the Zizr Merchant Agreement, together with this DPA, at the time of installation.
This DPA forms an integral part of the Zizr Merchant Agreement (the “Main Agreement”) and governs the processing of Personal Data by Zizr on behalf of the Merchant in accordance with Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK General Data Protection Regulation (“UK GDPR”), the Norwegian Personal Data Act, and, where applicable, the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914, “SCCs”).
By installing the Zizr app from the Shopify App Store and proceeding past the in-app acceptance screen, the Merchant acknowledges that it has read, understood, and agreed to be bound by this DPA. Zizr maintains records of acceptance, including the version accepted, the timestamp, and the Shopify shop identifier.
Table of Contents
- Definitions
- Roles and scope
- Processing instructions
- Purpose, nature, and duration of processing
- Categories of data subjects and personal data
- Security of processing
- Confidentiality
- Subprocessors
- International transfers
- Data retention and deletion
- Assistance with data subject rights
- Personal data breach notification
- Audit and inspection rights
- Compliance assistance
- Prohibited uses
- Liability
- Term and termination
- Miscellaneous
- Governing law and jurisdiction
Annex I: Description of the processing
Annex II: Technical and organisational measures
Annex III: List of subprocessors
Annex IV: Standard Contractual Clauses (incorporated by reference)
Annex V: Incident Response Procedure
1. Definitions
Terms defined in the GDPR have the same meaning in this DPA, including “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, and “Supervisory Authority”.
For the purposes of this DPA:
- “Applicable Data Protection Laws” means the GDPR, the UK GDPR, the Norwegian Personal Data Act, the Swiss Federal Act on Data Protection (FADP), the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively “CCPA/CPRA”), and any other privacy or data protection laws that apply to either Party’s processing of Personal Data under the Main Agreement.
- “Services” means the Zizr Shopify app and related services provided by Zizr to the Merchant under the Main Agreement.
- “Subprocessor” means any third party engaged by Zizr to process Personal Data on behalf of the Merchant in connection with the Services.
- “SCCs” means the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- “Shopper” or “End User” means a customer or visitor of the Merchant’s Shopify store whose Personal Data may be processed via the Services.
- “Customer Personal Data” means Personal Data that Zizr processes on behalf of the Merchant under this DPA, excluding any Personal Data that Zizr processes as an independent controller as set out in section 2.
2. Roles and scope
2.1 Appointment as Processor
The Merchant appoints Zizr as a Processor to process Customer Personal Data on the Merchant’s behalf in connection with the Services. This appointment is made in accordance with Article 28(1) GDPR. Each Party shall comply with its respective obligations under Applicable Data Protection Laws.
2.2 Scope of this DPA
This DPA applies only to Zizr’s processing of Customer Personal Data as a Processor on the Merchant’s behalf. It does not apply to:
- Zizr’s processing of Personal Data in its capacity as an independent controller for security and fraud prevention, algorithm improvement using pseudonymised or aggregated data, and benchmarking and infrastructure research and development.
- Zizr’s processing of Shopper Personal Data in connection with the optional Zizr ID account, where Zizr acts as a controller under separate Zizr ID Terms of Use and Privacy Notice that are agreed directly between Zizr and the Shopper.
- Zizr’s processing of the Merchant’s own Personal Data (for example contact details, billing information) for purposes of operating the commercial relationship under the Main Agreement, which is governed by our Privacy Policy.
2.3 Order of precedence
In case of any conflict between this DPA and the Main Agreement, this DPA shall prevail with respect to the processing of Customer Personal Data. In case of any conflict between this DPA and the SCCs incorporated in Annex IV, the SCCs shall prevail with respect to international transfers subject to Chapter V GDPR.
3. Processing instructions
3.1 Documented instructions
Zizr shall process Customer Personal Data only on the documented instructions of the Merchant, which include:
- This DPA and any amendments to it.
- The Main Agreement.
- The Merchant’s configuration of the Services through the Zizr admin or the Shopify admin (including which features are enabled, which scopes are granted, and which subprocessors are configured by the Merchant).
- Any written instructions sent by the Merchant to privacy@zizr.com.
- Instructions required to comply with applicable law, in which case Zizr shall, where permitted, inform the Merchant of that legal requirement before the processing begins.
This fulfils the requirements of Article 28(3)(a) GDPR and SCC Clause 8.1(a).
3.2 Notification of unlawful or impossible instructions
Zizr shall promptly notify the Merchant if Zizr considers that an instruction infringes Applicable Data Protection Laws, or if Zizr cannot comply with an instruction due to technical limitations or legal requirements. Zizr has no obligation to actively monitor the Merchant’s compliance with Applicable Data Protection Laws.
3.3 Controller obligations
The Merchant warrants that:
- Its instructions to Zizr comply with Applicable Data Protection Laws.
- It has determined and documented the lawful basis for all processing activities for which it engages Zizr.
- It has obtained and will maintain all necessary consents, rights, and authorisations, and has given all necessary notices to Shoppers, to enable Zizr’s processing on its behalf.
- The Customer Personal Data made available to Zizr is accurate and lawfully obtained.
4. Purpose, nature, and duration of processing
4.1 Subject matter
The provision of the Services through the Zizr Shopify app, including size recommendations, FitBack, returns analytics, product data normalisation, and related features as enabled by the Merchant.
4.2 Purpose
Customer Personal Data shall be processed exclusively for the following purposes:
- To deliver the Services to the Merchant.
- To respond to data subject requests forwarded by the Merchant.
- To improve, troubleshoot, and secure the Services where strictly necessary and in accordance with this DPA.
- To comply with applicable legal obligations.
This fulfils the requirements of Article 28(3) GDPR and SCC Clause 8.1.
4.3 Nature of processing
Processing operations include:
- Collection of Customer Personal Data via Shopify Admin API, Shopify Customer Account API, Shopify webhooks, and storefront integrations (Web Pixels, Theme App Extensions, Customer Privacy API).
- Storage in Microsoft Azure infrastructure in France (France Central region).
- Use of pseudonymisation (for example hashing of identifiers) where feasible.
- Transmission of derived outputs (such as recommendations and analytics) back to the Merchant via Shopify or the Zizr admin.
- Deletion upon instruction or upon receipt of Shopify privacy webhooks.
4.4 Duration
Processing continues for the duration of the Merchant’s active Zizr subscription. Customer Personal Data is deleted or returned upon termination as set out in section 10.
Additional information required under Article 28(3) GDPR and Annex I.B of the SCCs is set out in Annex I.
5. Categories of data subjects and personal data
5.1 Categories of data subjects
- Shoppers of the Merchant’s Shopify store.
- The Merchant’s personnel authorised to interact with the Services on behalf of the Merchant.
5.2 Categories of personal data
The categories of Personal Data processed are set out in section 3 of our Privacy Policy and summarised in Annex I. They include:
- Order and transaction data.
- Limited Shopper customer data (name, email or hashed email, phone, shipping and billing addresses, Shopify customer identifier).
- Product and size data.
- Behavioural and feature signals.
- Merchant and store data.
5.3 Special categories of data
Zizr does not require, request, or intentionally process special categories of data under Article 9 GDPR. Where such data are inadvertently provided (for example in free-text notes), Zizr will delete or minimise them.
6. Security of processing
6.1 Technical and organisational measures
Zizr shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required under Article 32 GDPR. These measures are described in detail in Annex II and include encryption in transit and at rest, access controls, pseudonymisation, vulnerability management, employee confidentiality, and incident response.
6.2 Security updates
Zizr reviews and updates its security measures periodically and may update Annex II in accordance with section 18.5 (Modifications). Updates will not materially reduce the level of security.
This fulfils the requirements of Article 28(3)(c) and Article 32 GDPR, and SCC Clause 8.6.
7. Confidentiality
Zizr shall ensure that all personnel authorised to process Customer Personal Data:
- Have committed themselves to confidentiality or are under appropriate statutory obligations of confidentiality.
- Receive appropriate data protection and security training.
- Are granted access only on a need-to-know basis, in accordance with the principle of least privilege.
Confidentiality obligations survive termination of employment or engagement and survive termination of this DPA.
This fulfils the requirements of Article 28(3)(b) GDPR and SCC Clause 8.3.
8. Subprocessors
8.1 General authorisation
The Merchant provides general written authorisation for Zizr to engage Subprocessors, subject to the requirements in this section. This implements Option 2 under SCC Clause 9(a).
8.2 Current subprocessors
The current list of Subprocessors, including their location and processing activities, is set out in Annex III and on the Zizr website at https://www.zizr.com/legal/subprocessors. Zizr keeps this list up to date.
8.3 Adding or replacing Subprocessors
Zizr shall notify the Merchant at least 15 days before adding or replacing any Subprocessor that processes Customer Personal Data. Notification will be provided via in-app notice or email to the merchant admin contact on file. Notification will include the name, location, and processing activities of the new Subprocessor.
8.4 Right to object
The Merchant may object within the notification period on reasonable grounds relating to data protection. If the objection cannot be resolved within a reasonable time, the Merchant may terminate the affected portion of the Services in accordance with section 17. Continued use of the Services after the notification period constitutes acceptance of the new Subprocessor.
8.5 Subprocessor obligations
Zizr shall:
- Conduct appropriate due diligence on each Subprocessor before engagement, prioritising vendors with recognised certifications (such as SOC 2, ISO 27001, ISO 27018).
- Enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those in this DPA.
- Remain fully liable to the Merchant for the acts and omissions of its Subprocessors to the same extent Zizr would be liable if performing the services directly, subject to the limitations of liability set out in the Main Agreement.
Where a Subprocessor processes Personal Data outside the EEA, the UK, or Switzerland, Zizr shall ensure that appropriate transfer mechanisms are in place in accordance with section 9.
This fulfils the requirements of Article 28(2) and 28(4) GDPR and SCC Clause 9.
9. International transfers
9.1 Primary processing location
Zizr’s primary processing location is within the European Economic Area (Microsoft Azure, France Central). Some Subprocessors process Personal Data outside the EEA, as identified in Annex III.
9.2 Transfer mechanism
For transfers of Customer Personal Data outside the EEA, the UK, or Switzerland to countries that have not been recognised as providing an adequate level of protection, Zizr relies on:
- The SCCs incorporated in Annex IV (Module Two: Controller to Processor, or Module Three: Processor to Subprocessor, as applicable).
- For transfers from the UK: the UK International Data Transfer Addendum to the SCCs.
- For transfers from Switzerland: the SCCs as adapted for Switzerland.
- Where available, additional adequacy frameworks such as the EU-U.S. Data Privacy Framework, for Subprocessors that participate in such frameworks.
9.3 SCC implementation
The Parties adopt Module Two (Controller to Processor) of the SCCs in Annex IV, with the following selections:
- Clause 7 (Docking clause): Included.
- Clause 9 (Use of Subprocessors): Option 2, General written authorisation.
- Clause 11 (Redress): Optional independent body language not included.
- Clause 17 (Governing law): Option 1, the law of Ireland.
- Clause 18 (Choice of forum and jurisdiction): Courts of Ireland.
Norwegian law (and Oslo tingrett as competent court) governs this DPA generally, but the SCCs themselves are governed by Irish law as required by Clause 17 of the SCCs, because Norway is in the EEA but not an EU Member State.
9.4 Supplementary measures
In addition to the SCCs, Zizr applies supplementary safeguards:
- Pseudonymisation through hashing of identifiers where feasible.
- Encryption in transit and at rest.
- Geographic restriction of processing to known regions identified in Annex III.
- Personnel access controls, training, and confidentiality agreements.
- Documented Transfer Impact Assessments maintained in Zizr’s internal records.
10. Data retention and deletion
10.1 Return or deletion upon termination
Upon termination or expiry of the Services, Zizr shall, at the Merchant’s choice:
- Return all Customer Personal Data processed on behalf of the Merchant in a commonly used machine-readable format, or
- Delete or anonymise such data, unless retention is required by applicable law.
Where the Merchant uninstalls the Zizr app on Shopify, Zizr treats this as a deletion instruction and complies with Shopify’s shop/redact webhook, deleting or anonymising shop-scoped Customer Personal Data within 30 days, unless retention is required by applicable law.
This fulfils the requirements of Article 28(3)(g) GDPR and SCC Clause 8.5.
10.2 Deletion during active service
The Merchant may request deletion of specific Customer Personal Data at any time through the Zizr admin, by triggering Shopify’s customers/redact webhook, or by written request to privacy@zizr.com. Zizr shall complete deletion within 30 days of receipt, unless retention is required by applicable law or unless the deletion is technically infeasible, in which case Zizr shall promptly inform the Merchant.
10.3 Retention exceptions
Notwithstanding the above, Zizr may retain Customer Personal Data:
- As required by applicable law, including Norwegian accounting legislation (bokføringsloven, minimum five years for accounting records).
- In standard backups, subject to the confidentiality and security obligations of this DPA, until the backup is rotated out in the ordinary course of business.
- In aggregated or de-identified form from which re-identification is not reasonably possible.
11. Assistance with data subject rights
11.1 Obligation to assist
Taking into account the nature of the processing, Zizr shall provide reasonable assistance to the Merchant in fulfilling its obligations to respond to data subject requests regarding:
- Access to Personal Data (Article 15 GDPR).
- Rectification (Article 16 GDPR).
- Erasure (Article 17 GDPR).
- Restriction of processing (Article 18 GDPR).
- Data portability (Article 20 GDPR).
- Objection to processing (Article 21 GDPR).
- Rights related to automated decision-making, where applicable (Article 22 GDPR).
This fulfils the requirements of Article 28(3)(e) GDPR and SCC Clause 8.4.
11.2 Direct requests to Zizr
If Zizr receives a request directly from a Shopper relating to Customer Personal Data processed on behalf of the Merchant, Zizr shall promptly forward the request to the Merchant and shall not respond directly unless instructed in writing by the Merchant or required by applicable law.
11.3 Shopify webhook integration
Zizr’s primary mechanism for handling Shopper rights requests is via Shopify’s privacy webhooks (customers/data_request, customers/redact, shop/redact), as required by Shopify’s platform requirements. Zizr operates to a 30-day response timeline for these webhooks, or faster where required by law.
12. Personal data breach notification
12.1 Notification timeline
Zizr shall notify the Merchant without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will be delivered via email to the merchant admin contact on file and, where possible, via in-app notice.
12.2 Notification content
The initial notification shall include, to the extent known at the time:
- A description of the breach, including the type of incident, categories of data subjects affected, and estimated number of records.
- The likely consequences of the breach.
- Measures taken or planned to address the breach and to mitigate possible harm.
- Contact information for follow-up.
Zizr shall update the Merchant as further information becomes available.
12.3 Cooperation
Zizr shall cooperate with the Merchant in fulfilling any regulatory notification duties under Articles 33 and 34 GDPR, document all breaches regardless of notification requirements, and implement measures to prevent recurrence.
12.4 Exclusions
Zizr is not required to notify the Merchant of routine security events that do not compromise Personal Data, including but not limited to failed login attempts, port scans, attempted but unsuccessful intrusions, and internal testing or security exercises.
The detailed Incident Response Procedure is set out in Annex V.
This fulfils the requirements of Article 28(3)(f) and Article 33 GDPR, and SCC Clause 8.6.
13. Audit and inspection rights
13.1 Audit rights
The Merchant has the right to audit Zizr’s compliance with this DPA, as required under Article 28(3)(h) GDPR and SCC Clause 8.9. Zizr shall provide all information reasonably necessary to demonstrate compliance.
13.2 Audit procedure
Audits shall:
- Be limited to once per calendar year, unless a Personal Data Breach has occurred or unless required more frequently by a Supervisory Authority.
- Be conducted with at least 30 days’ written notice to privacy@zizr.com, during normal business hours.
- Be performed in a manner that does not unreasonably disrupt Zizr’s operations.
- Be subject to confidentiality obligations between the Parties.
- Be limited in scope to matters reasonably required to assess Zizr’s compliance with this DPA.
13.3 Audit reports as a substitute
Zizr may fulfil the Merchant’s audit rights by providing, upon written request, its then-current third-party audit reports (such as ISO 27001, SOC 2 Type II, or equivalent) where available, and additional information necessary to demonstrate compliance with Article 28 GDPR. The Merchant may exercise on-site audit rights only where such reports do not provide sufficient information to verify compliance, or where required by a Supervisory Authority.
14. Compliance assistance
Taking into account the nature of the processing and the information available to Zizr, Zizr shall assist the Merchant, upon request, in:
- Implementing appropriate technical and organisational security measures (Article 32 GDPR).
- Notifying Supervisory Authorities and Data Subjects in the event of a Personal Data Breach (Articles 33 and 34 GDPR).
- Conducting Data Protection Impact Assessments (Article 35 GDPR).
- Consulting Supervisory Authorities prior to processing where required (Article 36 GDPR).
Assistance under this section is provided at no additional charge for reasonable requests. For assistance that requires significant Zizr resources (more than 8 person-hours per request), Zizr may charge a reasonable fee at its then-current professional services rate, subject to advance notice and approval by the Merchant.
This fulfils the requirements of Article 28(3)(f) GDPR and SCC Clauses 8.6, 8.7, 10(b), and 10(c).
15. Prohibited uses
Zizr shall not:
- Use Customer Personal Data for its own purposes outside the scope of this DPA, except as expressly set out in section 2.2 (independent controller activities).
- “Sell” or “share” Customer Personal Data, as those terms are defined under CCPA/CPRA or analogous U.S. state privacy laws.
- Use Customer Personal Data for cross-context behavioural advertising, except where the Merchant has expressly configured such processing and has obtained the required consents and opt-out mechanisms.
- Combine Customer Personal Data from the Merchant with Personal Data from other sources in a way that violates Applicable Data Protection Laws.
16. Liability
Liability under this DPA is subject to the limitations of liability set out in the Main Agreement. Nothing in this DPA limits either Party’s liability under Articles 82 and 83 GDPR or under the SCCs, where applicable mandatory law does not permit limitation.
17. Term and termination
17.1 Term
This DPA takes effect upon installation of the Zizr app and acceptance of the Main Agreement, and continues for the duration of the Services.
17.2 Termination
Termination of this DPA shall be governed by the termination provisions of the Main Agreement. Upon termination, the data deletion obligations in section 10 apply.
17.3 Survival
The following obligations survive termination: data deletion (section 10), confidentiality (section 7), liability (section 16), governing law (section 19), and any other provisions that by their nature should survive.
18. Miscellaneous
18.1 Notices
Notices under this DPA shall be sent to:
- For Zizr: privacy@zizr.com.
- For the Merchant: the merchant admin email on file in the Shopify admin, or such other address as the Merchant has notified to Zizr in writing.
18.2 Entire agreement
This DPA, together with the Main Agreement and its Annexes, constitutes the entire agreement between the Parties with respect to the processing of Customer Personal Data and supersedes any prior data processing terms.
18.3 Severability
If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid provision shall be replaced by a valid provision that most closely reflects the original intent.
18.4 No third-party beneficiaries
Except as expressly provided for Data Subjects under the SCCs, this DPA does not create any rights for third parties.
18.5 Modifications
Zizr may amend this DPA from time to time. Material changes that adversely affect the Merchant’s rights will be communicated via in-app notice or email at least 15 days before they take effect. Non-material changes (such as clarifications, typo corrections, or updates to the subprocessor list in Annex III) may be made without advance notice. Continued use of the Services after a material change takes effect constitutes acceptance.
19. Governing law and jurisdiction
This DPA is governed by Norwegian law. The Parties submit to the exclusive jurisdiction of Oslo tingrett for any dispute arising out of or in connection with this DPA, subject to mandatory consumer or data protection law that confers jurisdiction elsewhere.
The SCCs incorporated in Annex IV are governed by Irish law and subject to the courts of Ireland, as required by Clause 17 of the SCCs.
Annex I: Description of the processing
A. Parties
Data Exporter (Controller): The Merchant who has installed the Zizr app and accepted this DPA.
Data Importer (Processor):
Zizr AS
Dronningens gate 38, 7011 Trondheim, Norway
Organisation number: 922 796 556
Privacy contact: privacy@zizr.com
Privacy Lead: Petter Hellevik, CEO
B. Description of processing
-
Categories of data subjects. Shoppers of the Merchant’s Shopify store and the Merchant’s authorised personnel.
-
Categories of Personal Data. As set out in section 3 of the Zizr Privacy Policy, including order and transaction data, limited Shopper customer data (name, email or hashed email, phone, shipping and billing addresses, Shopify customer identifier), product and size data, behavioural and feature signals, and merchant and store data.
-
Sensitive data (special categories). None intentionally processed.
-
Nature and purpose of processing. Provision of the Zizr Services, including size recommendations, FitBack, returns analytics, product data normalisation, and related features as enabled by the Merchant.
-
Duration. For the duration of the Merchant’s active subscription, plus the retention periods in section 10.
-
Frequency. Continuous, in real time during Service provision.
-
Transfers to third countries. As identified in Annex III. SCCs are incorporated in Annex IV.
C. Competent supervisory authority
Datatilsynet (the Norwegian Data Protection Authority), datatilsynet.no, Postboks 458 Sentrum, 0105 Oslo, Norway.
Annex II: Technical and organisational measures
Zizr implements the following technical and organisational measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and Services, in accordance with Article 32 GDPR.
1. Access control and authentication
- Role-based access control (RBAC) for internal systems and databases.
- Unique user accounts for all team members. Shared logins prohibited.
- Multi-factor authentication enforced for administrative access.
- Access rights reviewed periodically and revoked promptly upon role change or offboarding.
- Principle of least privilege enforced across all systems.
2. Data encryption
- All data in transit is protected using TLS 1.2 or higher.
- Data at rest is encrypted using AES-256 or equivalent in Azure infrastructure.
- Access to cryptographic keys is restricted, monitored, and logged.
3. Infrastructure and hosting security
- Primary infrastructure on Microsoft Azure (France Central), which holds certifications including ISO 27001 and SOC 2.
- Regular infrastructure updates and vulnerability patching.
- Security updates deployed following vendor advisories or internal risk assessments.
- Network segmentation and firewall protection.
4. Data processing security
- Personal identifiers (such as email addresses) are hashed where feasible before further processing or before transmission to third parties.
- Data minimisation applied by default. Only data necessary for the stated purpose is collected.
- Pseudonymisation used where feasible.
5. Organisational security
- All personnel bound by confidentiality agreements and access control policies.
- Personnel receive onboarding and recurring data protection and security training.
- Access to Customer Personal Data limited to authorised personnel on a need-to-know basis.
- Background checks performed for personnel with access to production systems, where permitted by law.
6. Incident detection and response
- Logging and monitoring via Datadog.
- Documented Incident Response Procedure (Annex V).
- Personal data breaches notified to the Merchant in accordance with section 12 of the DPA.
- Post-incident reviews and root cause analyses documented to prevent recurrence.
7. Data segregation and minimisation
- Only data necessary for the Services is collected and processed.
- Merchant-specific data is logically segregated within multi-tenant systems.
- Test and production data are kept strictly separate, in line with Shopify’s protected customer data Level 2 requirements.
8. Payment security
- All payment processing is handled via Shopify Billing API. Zizr does not process, store, or access payment card information.
9. Backup and recovery
- Azure infrastructure provides redundancy and durability for stored data.
- Backups are encrypted at rest, in line with Shopify’s Level 2 requirements.
- Documented backup and recovery procedures specifically for Customer Personal Data, with periodic restore testing.
10. Vulnerability management
- Regular vulnerability scanning and dependency monitoring.
- Coordinated disclosure process for externally reported vulnerabilities (privacy@zizr.com).
11. Subprocessor oversight
- All Subprocessors undergo a security assessment prior to engagement.
- Preference for Subprocessors with recognised certifications (SOC 2, ISO 27001, ISO 27018, or equivalent).
- Subprocessor contracts impose obligations no less protective than this DPA.
Annex III: List of subprocessors
The following Subprocessors are engaged as of the effective date of this DPA. The current list is maintained at https://www.zizr.com/legal/subprocessors and updated in accordance with section 8 of this DPA.
| Subprocessor | Legal entity | Location of processing | Purpose | Transfer mechanism |
|---|---|---|---|---|
| Microsoft Azure | Microsoft Ireland Operations Ltd | France (France Central) | Cloud infrastructure, data storage, Azure OpenAI Service | EEA, no transfer |
| Cloudflare | Cloudflare, Inc. | Frankfurt, Germany | Network delivery, DDoS protection, web application firewall | EEA, no transfer |
| Datadog | Datadog, Inc. | Frankfurt, Germany | Logging, monitoring, error tracking | EEA, no transfer |
| ClickHouse (planned) | ClickHouse, Inc. | Frankfurt, Germany | Analytics database | EEA, no transfer |
| Postmark | ActiveCampaign LLC | United States | Transactional email | SCCs Module 3, supplementary measures |
| HubSpot | HubSpot, Inc. | United States | Support, CRM, merchant communications | SCCs Module 3, supplementary measures |
| Google Cloud / Vertex AI | Google LLC | United States | Large language model processing for product parsing | SCCs Module 3, supplementary measures |
OpenAI inference is performed via Azure OpenAI Service within the Microsoft Azure tenant and does not constitute a separate transfer to OpenAI Inc.
Annex IV: Standard Contractual Clauses
The Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this DPA by reference, with the following selections:
- Module selected: Module Two (Controller to Processor). Module Three (Processor to Subprocessor) applies between Zizr and any non-EEA Subprocessor.
- Clause 7 (Docking clause): Included.
- Clause 9 (Subprocessors): Option 2, General written authorisation, with 15 days’ notice.
- Clause 11 (Redress): Optional language for independent dispute resolution body is not selected.
- Clause 17 (Governing law): Option 1, Irish law.
- Clause 18 (Choice of forum and jurisdiction): Courts of Ireland.
The information required in the Annexes to the SCCs (description of the transfer, technical and organisational measures, list of Subprocessors) is provided in Annexes I, II, and III of this DPA.
For transfers from the United Kingdom, the UK International Data Transfer Addendum issued by the UK Information Commissioner’s Office is incorporated and supplements the SCCs.
For transfers from Switzerland, the SCCs are adapted to apply under Swiss data protection law, with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.
Annex V: Incident Response Procedure
This Annex sets out Zizr’s procedure for detecting, responding to, and notifying of Personal Data Breaches and other security incidents affecting Customer Personal Data.
1. Definitions
- Security Incident. Any event that may compromise the confidentiality, integrity, or availability of Zizr’s systems or Customer Personal Data.
- Personal Data Breach. A Security Incident that has, or is reasonably likely to have, resulted in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data, as defined in Article 4(12) GDPR.
2. Severity classification
| Level | Description | Examples |
|---|---|---|
| P1 Critical | Confirmed breach of Customer Personal Data with significant risk to Shoppers or Merchants | Confirmed unauthorised access to production database; large-scale data exfiltration |
| P2 High | Suspected breach or significant system compromise | Detected intrusion in production environment, root cause not yet confirmed |
| P3 Medium | Limited security event with potential to affect Customer Personal Data | Misconfigured access control discovered through audit; near-miss intrusion attempt |
| P4 Low | Routine security event with no apparent impact on Customer Personal Data | Blocked intrusion attempt, failed brute-force login |
3. Internal escalation
Upon detection of a Security Incident:
- The detecting team member reports the incident immediately to the Privacy Lead and the on-call engineering lead.
- The Privacy Lead classifies the severity and initiates the response.
- For P1 and P2 incidents, the CEO and the technical lead are notified within 1 hour of classification.
- For P1 incidents, an incident response team is convened within 4 hours.
4. Containment and mitigation
For P1 and P2 incidents, the response team takes immediate steps to:
- Contain the incident (for example by revoking credentials, isolating affected systems, rotating keys).
- Preserve evidence and logs.
- Identify the scope of affected data and data subjects.
- Implement mitigating measures to limit further impact.
5. Merchant notification
For P1 incidents that constitute a Personal Data Breach affecting Customer Personal Data, Zizr notifies affected Merchants:
- Without undue delay, and in any case within 72 hours after Zizr becomes aware of the breach.
- Via email to the merchant admin contact and, where possible, via in-app notice.
- With the content required under section 12.2 of the DPA.
For P2 incidents, Zizr notifies Merchants if and when it is determined that Customer Personal Data may have been affected.
6. Documentation
All Security Incidents are documented, including:
- Date and time of detection and classification.
- Description of the incident.
- Affected systems and data.
- Actions taken to contain, mitigate, and resolve.
- Notifications made (to whom, when, and what content).
- Root cause analysis (for P1, P2, and P3 incidents).
- Lessons learned and remediation steps.
Documentation is retained for a minimum of three years.
7. Post-incident review
For P1 and P2 incidents, a post-incident review is conducted within 30 days of resolution. The review identifies systemic improvements, updates to technical and organisational measures, and any updates required to this procedure.
8. Cooperation with Merchants and authorities
Zizr cooperates with Merchants and Supervisory Authorities in fulfilling notification and investigation obligations, as set out in section 14 of the DPA.
Document acceptance. By installing the Zizr app from the Shopify App Store and proceeding past the in-app acceptance screen, the Merchant acknowledges that it has read, understood, and agreed to be bound by this DPA, including all Annexes.