Data Processing Addendum

Version 1.1 · Effective date: 25 July 2026

This Data Processing Addendum ("DPA") applies between the merchant using NORTHMAST ("Controller") and Satisfy & I B.V. ("Processor"), and forms part of the Merchant Terms of Service. It applies to the extent that we process personal data on the merchant's behalf under the GDPR or equivalent applicable data protection law.

NORTHMAST was formerly developed under the working name Clearboard Analytics. It is the same application, provided by the same legal entity, and this document replaces the corresponding document published under that working name.

Processor details: Satisfy & I B.V., Kloosterpark 12, 5554 GP Valkenswaard, The Netherlands. Chamber of Commerce number: 94013195. VAT identification number: NL866603839B01. E-mail: info@satisfyi.nl.

Roles

  • For order data relating to the merchant's customers, the merchant is the controller and we act solely as processor.
  • For merchant and staff account data, support correspondence, security records and our own legal and administrative records, we act as an independent controller. That processing is described in the Privacy Policy and falls outside this DPA.

Subject matter and duration

The subject matter is the provision of profit and cost analytics for the merchant's Shopify store. Processing continues for as long as the app is installed for that store, and ends in accordance with the deletion section below.

Nature and purpose of processing

We retrieve order, refund and product cost data from Shopify, store it, and compute revenue, cost, margin and profit figures from it, together with advertising cost data where the merchant has connected an advertising platform. Processing operations comprise collection, storage, structuring, consultation, use for the computations described, and erasure.

Types of personal data

Order-level financial data as listed in the Privacy Policy: order and line item identifiers, dates, quantities, currencies, prices, discounts, taxes, shipping amounts, refunds and refund components. Where Shopify sends a privacy webhook, the numeric Shopify customer identifier and the order identifiers contained in that webhook.

NORTHMAST does not request and does not store the customer name, customer e-mail address, customer telephone number, billing address, shipping address of your customers. None of these fields are queried from Shopify, none are stored in our database, and none appear in any export the app generates.

The app is not designed for, and is not intended to process, special categories of personal data within the meaning of Article 9 GDPR — such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or data concerning a person's sex life or sexual orientation. The app queries no field of that kind. Merchants must not knowingly supply such data to the app, including through free-text configuration fields, without a separate written agreement with us first.

Categories of data subjects

Customers of the merchant's Shopify store.

Rights and obligations of the controller

The merchant determines the purposes and means of the processing of their customers' order data and is responsible for the lawfulness of that processing. In particular the merchant is responsible for having a valid legal basis, for providing their customers with the information data protection law requires, for the accuracy of the source data, and for ensuring that their instructions to us are lawful.

The merchant has the right to give instructions within the scope of this DPA, to receive the information needed to demonstrate our compliance, to have their data deleted or returned on termination, and to object to a new subprocessor as described below.

Documented instructions

We process personal data only on the merchant's documented instructions. The Merchant Terms of Service, this DPA, and the merchant's configuration and use of the app constitute those instructions. We do not process the data for our own purposes, do not sell it, and do not use it for advertising. If we believe an instruction infringes applicable data protection law, we will inform the merchant. Where applicable law requires us to process personal data beyond those instructions, we will inform the merchant of that legal requirement before processing, unless the law prohibits that notification.

Confidentiality

Personnel authorised to process personal data are bound by an obligation of confidentiality, and access is limited to those who need it to operate and support the service. That obligation survives the end of their engagement.

Technical and organisational measures

We implement the measures described in the Security section of the Privacy Policy, including per-store scoping of every database read and write, encryption of advertising platform tokens at rest using AES-256-GCM, HMAC verification of incoming Shopify webhooks, single-use hashed OAuth state values, and logging designed to exclude tokens, payloads and personal data. Data in transit is protected by TLS as provided by our hosting and database providers. We may update these measures over time, provided the level of protection is not reduced.

Subprocessors

The merchant gives general authorisation for us to engage the subprocessors listed in the Privacy Policy.

Before we add or replace a subprocessor for processing carried out on the merchant's behalf, we will update the list in the Privacy Policy and give the merchant advance notice by e-mail to the address associated with their store, so that the merchant has a genuine opportunity to object first. A merchant who objects on reasonable data protection grounds may notify us at info@satisfyi.nl; we will then discuss the objection in good faith and, if we cannot offer a reasonable alternative, the merchant may terminate by uninstalling the app, which triggers the deletion process below.

Before a subprocessor processes personal data on behalf of merchants under this DPA, we will ensure that appropriate written data protection terms required by applicable law are in place. We remain responsible for the performance of our subprocessors to the extent required by applicable law.

Assistance with data subject requests

Taking into account the nature of the processing, we assist the merchant by appropriate technical and organisational measures in fulfilling their obligation to respond to requests to exercise data subject rights.

The app implements Shopify's mandatory privacy webhooks. A customers/data_request produces an export of exactly the data we hold for the requested orders, which the merchant can retrieve in the app. A customers/redact deletes the relevant order data and blocks its re-import. Where a request cannot be handled through those flows, we will provide reasonable assistance, taking into account the nature of the processing and the information available to us.

Assistance with security, breaches and impact assessments

Taking into account the nature of the processing and the information available to us, we assist the merchant in complying with their obligations regarding the security of processing, the notification of a personal data breach to a supervisory authority and to affected data subjects, and — where the merchant is required to carry one out — a data protection impact assessment and any prior consultation with a supervisory authority.

That assistance consists of the information reasonably available to us about the processing we perform: the data categories we hold, our retention limits, the measures described above, and what we can establish about an incident. We do not assess the merchant's own processing for them.

Personal data breaches

We will notify the merchant without undue delay after becoming aware of a personal data breach affecting personal data processed on their behalf, and will provide the information reasonably available to us so that the merchant can meet their own notification obligations. That information covers, as far as we can establish it, the nature of the breach, the categories and approximate volume of data concerned, the likely consequences and the measures taken or proposed.

Deletion and return

Detailed order data — orders, order line items, refunds, refund line items and refund transactions, together with the related refund duties, order adjustments and refund shipping lines — is retained for a maximum of 24 calendar months, measured from the Shopify order creation date. Records past that limit are deleted automatically by a daily retention job, and orders older than the limit can no longer be imported or re-created.

When the app is uninstalled, the Shopify session records for that store — which hold the staff account details and access tokens — are deleted immediately. The remaining store data is kept only until Shopify's shop/redact request arrives, so that Shopify's mandatory compliance flow can be completed correctly, and is deleted at that point.

When Shopify sends a shop/redact request, all stored data for that store is deleted, including orders, line items, refunds and refund components, ad spend, settings, shipping rates, synchronisation logs, privacy request records and any advertising platform connection.

When Shopify sends a customers/redact request, the affected order data is deleted immediately and a minimal technical marker is kept for as long as the app remains installed for that store. That marker exists for one purpose only: to stop a later synchronisation from re-importing the deleted order. It contains the store key, a fixed topic, the order identifier and a status — no name, e-mail address, telephone number, address, customer identifier, amount or payload fragment.

A merchant who needs a copy of their data before termination can export it from the app while it is still installed. After the deletion described above we retain no copy, except where applicable law requires us to keep something for a defined period, in which case we keep only what that law requires and continue to protect it under this DPA.

Audits and information

We will make available to the merchant the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by the merchant or an auditor they mandate. Audits are limited to once per year unless a supervisory authority requires otherwise or a personal data breach has occurred, must be requested with reasonable notice, must not unreasonably disrupt our operations, and are subject to confidentiality.

International transfers

Our primary database is hosted in a European Supabase project region. We have concluded a Data Processing Addendum with Supabase which incorporates the EU Standard Contractual Clauses where these are required for a transfer. We do not claim that all processing by Supabase takes place exclusively within the European Economic Area; supporting activities such as operations and support may take place elsewhere, and the Standard Contractual Clauses are the safeguard relied on for that.

We do not claim a specific transfer mechanism or certification for any subprocessor beyond what is stated above. A merchant who needs the current transfer details for a particular subprocessor can request them at info@satisfyi.nl.

Order of precedence

In the event of a conflict between this DPA and the Merchant Terms of Service in relation to the processing of personal data on the merchant's behalf, this DPA prevails.

Changes to this DPA

Each document carries its own version number and effective date. A material change results in a new version number and a new effective date shown at the top of the page. Minor corrections that do not change your rights or our obligations — such as a typographical fix — do not.

Contact

Satisfy & I B.V., Kloosterpark 12, 5554 GP Valkenswaard, The Netherlands. Chamber of Commerce number: 94013195. VAT identification number: NL866603839B01. E-mail: info@satisfyi.nl.