NORTHMAST

Data Processing Addendum

Version 1.2 · Effective date: 8 September 2026

This Data Processing Addendum ("DPA") applies between the merchant using NORTHMAST ("Controller") and Satisfy & I B.V. ("Processor"), and forms part of the Merchant Terms of Service. It applies to the extent that we process personal data on the merchant's behalf under the GDPR or equivalent applicable data protection law.

NORTHMAST was formerly developed under the working name Clearboard Analytics. It is the same application, provided by the same legal entity, and this document replaces the corresponding document published under that working name.

Processor details: Satisfy & I B.V., Kloosterpark 12, 5554 GP Valkenswaard, The Netherlands. Chamber of Commerce number: 94013195. VAT identification number: NL866603839B01. E-mail: info@northmast.app.

Roles

  • For order data relating to the merchant's customers, for the supplier records the merchant enters, and for the contents of any file the merchant uploads as a stock count attachment, the merchant is the controller and we act solely as processor.
  • For merchant and staff account data — including the business details a merchant records for use on their own documents — as well as support correspondence, security records and our own legal and administrative records, we act as an independent controller. That processing is described in the Privacy Policy and falls outside this DPA.

Subject matter and duration

The subject matter is the provision of the app for the merchant's Shopify store: profit and cost reporting together with the inventory, replenishment, product and cost, purchasing, receiving, supplier return and stock count administration that supports it. Processing continues for as long as the app is installed for that store, and ends in accordance with the deletion section below.

Nature and purpose of processing

We retrieve order, refund, product, cost and inventory data from Shopify, store it, and compute revenue, cost, margin and profit figures from it, together with advertising cost data where the merchant has connected an advertising platform.

On the merchant's instruction we also maintain the operational records they build up in the app — products and their cost history, stock positions and inventory value, replenishment proposals, suppliers and the purchasing conditions agreed with them, warehouses, purchase orders, receipts, supplier returns, stock counts and recorded operating costs — and produce the purchase documents the merchant generates from them.

Reporting, analysis and planning only read from Shopify. The app writes back in one narrow place: when you deliberately carry out an action that changes stock or cost — processing a stock count, posting or correcting a receipt, posting a supplier return, or changing a unit cost — it updates the corresponding inventory quantity or cost per item in your Shopify store. Nothing happens automatically and nothing happens in the background: each of those writes follows an action you took. The app holds no permission to create or change your orders, your customers, your products or your product prices, and issues no request of that kind anywhere.

Processing operations comprise collection, retrieval, storage, organisation and structuring, consultation, use for the computations and the administration described, disclosure by transmission back to Shopify where the merchant carries out an action that requires it, restriction where a privacy request requires it, and erasure.

Types of personal data

Order-level financial data as listed in the Privacy Policy: order and line item identifiers, dates, quantities, currencies, prices, discounts, taxes, shipping amounts, the destination country code of the order, refunds and refund components. Shipping method metadata for the delivery option chosen at checkout. Payment and refund transaction metadata: the payment gateway, transaction type and status, test flag, amounts, currencies, transaction dates and transaction references. Shopify-provided transaction fee information where Shopify makes it available. Where Shopify sends a privacy webhook, the numeric Shopify customer identifier and the order identifiers contained in that webhook.

You can record the suppliers you buy from. A supplier record holds the company name and your own reference code for it, and optionally the name of a contact person, an e-mail address, a telephone number, an address and your own notes. Where you fill those fields in, they are personal data about that contact person — someone who is neither our customer nor yours — and you decide what to enter. We do not obtain supplier details from any other source, do not enrich or verify them, and do not use them for anything except showing them to you and placing them on the purchase documents you generate. A supplier's details are deleted with the supplier, and with your store when Shopify sends a shop/redact request.

A file you attach to a stock count is your own document, and we do not know what is in it. A scan or photograph of a counted sheet may contain personal data — the name or the handwriting of whoever counted, for example — because you chose to upload it. The app stores the file and shows it back to you; it does not open, read, index, analyse or extract anything from the contents, and nothing in the file is used in any calculation.

NORTHMAST does not request and does not store the customer name, customer e-mail address, customer telephone number, street address and house number, address line 2, postal or ZIP code, city, geolocation coordinates of your customers. None of these fields are queried from Shopify, none are stored in our database, and none appear in any export the app generates. We request no billing address at all.

From an order's shipping address we request exactly one field: the destination country code, a two-letter country code such as NL, BE or US. NORTHMAST may process and store that country code together with the order, to support the merchant's financial calculations — in particular the merchant-configured shipping-cost rules that can differ per destination country. Detailed shipping-address information such as street, house number, postal code, city or geolocation is not required for that calculation and is not requested. The country code is never used for profiling, marketing, personalisation or advertising, and is not shown per individual customer. It is stored on the order record and follows that record's lifecycle: it is deleted with the order, including when Shopify sends a customers/redact or shop/redact request.

We use the shipping and payment metadata described above to calculate and explain your order economics — which costs belong to which order, and what remains as profit — and to support the shipping-cost and transaction-cost settings you configure yourself. It is not used for customer profiling, advertising, personalisation, segmentation or any form of scoring.

NORTHMAST never receives or stores payment credentials. We do not request card numbers — not even masked or truncated ones — card security codes, cardholder names, bank account or bank login details, payment account passwords, or any other payment authentication secret. What we process is transaction economics: which gateway processed a payment, what type and status the transaction had, how much it was and in which currency. That is not the payment instrument itself. We also do not process payout, settlement or bank reconciliation data, and we hold no payout history.

The app is not designed for, and is not intended to process, special categories of personal data within the meaning of Article 9 GDPR — such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or data concerning a person's sex life or sexual orientation. The app queries no field of that kind. Merchants must not knowingly supply such data to the app, including through free-text configuration fields, without a separate written agreement with us first.

Categories of data subjects

The processing under this DPA concerns the categories of data subject listed below. The merchant's own staff are not among them: the app's session and account data about them is processing for which we are an independent controller, described in the Privacy Policy and outside this DPA.

  • Customers of the merchant's Shopify store, in respect of the order data described above.
  • The contact people at the merchant's suppliers, where the merchant records a contact name, e-mail address, telephone number or address for a supplier.
  • Any individual whose personal data the merchant happens to include in a file uploaded as a stock count attachment. We do not read those files, so we cannot know in advance whether a given file contains such data; the merchant decides what to upload.

Rights and obligations of the controller

The merchant determines the purposes and means of the processing of their customers' order data and is responsible for the lawfulness of that processing. In particular the merchant is responsible for having a valid legal basis, for providing their customers with the information data protection law requires, for the accuracy of the source data, and for ensuring that their instructions to us are lawful.

The merchant has the right to give instructions within the scope of this DPA, to receive the information needed to demonstrate our compliance, to have their data deleted or returned on termination, and to object to a new subprocessor as described below.

Documented instructions

We process personal data only on the merchant's documented instructions. The Merchant Terms of Service, this DPA, and the merchant's configuration and use of the app constitute those instructions. We do not process the data for our own purposes, do not sell it, and do not use it for advertising. If we believe an instruction infringes applicable data protection law, we will inform the merchant. Where applicable law requires us to process personal data beyond those instructions, we will inform the merchant of that legal requirement before processing, unless the law prohibits that notification.

Confidentiality

Personnel authorised to process personal data are bound by an obligation of confidentiality, and access is limited to those who need it to operate and support the service. That obligation survives the end of their engagement.

Technical and organisational measures

We implement the measures described in the Security section of the Privacy Policy, including per-store scoping of every database read and write, encryption of advertising platform tokens at rest using AES-256-GCM, HMAC verification of incoming Shopify webhooks, single-use hashed OAuth state values, and logging designed to exclude tokens, payloads and personal data. Data in transit is protected by TLS as provided by our hosting and database providers. We may update these measures over time, provided the level of protection is not reduced.

Subprocessors

The merchant gives general authorisation for us to engage the subprocessors listed in the Privacy Policy.

Before we add or replace a subprocessor for processing carried out on the merchant's behalf, we will update the list in the Privacy Policy and give the merchant advance notice by e-mail to the address associated with their store, so that the merchant has a genuine opportunity to object first. A merchant who objects on reasonable data protection grounds may notify us at info@northmast.app; we will then discuss the objection in good faith and, if we cannot offer a reasonable alternative, the merchant may terminate by uninstalling the app, which triggers the deletion process below.

Before a subprocessor processes personal data on behalf of merchants under this DPA, we will ensure that appropriate written data protection terms required by applicable law are in place. We remain responsible for the performance of our subprocessors to the extent required by applicable law.

Assistance with data subject requests

Taking into account the nature of the processing, we assist the merchant by appropriate technical and organisational measures in fulfilling their obligation to respond to requests to exercise data subject rights.

The app implements Shopify's mandatory privacy webhooks. A customers/data_request produces an export of exactly the data we hold for the requested orders, which the merchant can retrieve in the app. A customers/redact deletes the relevant order data and blocks its re-import. Where a request cannot be handled through those flows, we will provide reasonable assistance, taking into account the nature of the processing and the information available to us.

Assistance with security, breaches and impact assessments

Taking into account the nature of the processing and the information available to us, we assist the merchant in complying with their obligations regarding the security of processing, the notification of a personal data breach to a supervisory authority and to affected data subjects, and — where the merchant is required to carry one out — a data protection impact assessment and any prior consultation with a supervisory authority.

That assistance consists of the information reasonably available to us about the processing we perform: the data categories we hold, our retention limits, the measures described above, and what we can establish about an incident. We do not assess the merchant's own processing for them.

Personal data breaches

We will notify the merchant without undue delay after becoming aware of a personal data breach affecting personal data processed on their behalf, and will provide the information reasonably available to us so that the merchant can meet their own notification obligations. That information covers, as far as we can establish it, the nature of the breach, the categories and approximate volume of data concerned, the likely consequences and the measures taken or proposed.

Deletion and return

Detailed order data — orders, order line items, refunds, refund line items and refund transactions, together with the related refund duties, order adjustments, refund shipping lines, shipping method metadata, payment and refund transaction metadata and any Shopify-provided transaction fee information — is retained for a maximum of 24 calendar months, measured from the date the order was placed — the commercial order date Shopify records for the sale, not the date the order was imported into Shopify and not the date it was shipped. Records past that limit are deleted automatically by a daily retention job, and orders older than the limit can no longer be imported or re-created.

Advertising cost records (ad spend) and the related synchronisation provenance — which days were fetched for which advertising account, and which account was the reporting source in which period — are retained for a maximum of 24 calendar months, the same reporting horizon as detailed order data. Records past that limit are deleted or truncated automatically by the same daily retention job. Disconnecting an advertising platform stops future synchronisation but does not delete this history early; a shop/redact request always deletes it in full.

When the app is uninstalled, the Shopify session records for that store — which hold the staff account details and access tokens — are deleted immediately. The remaining store data is kept only until Shopify's shop/redact request arrives, so that Shopify's mandatory compliance flow can be completed correctly, and is deleted at that point.

When Shopify sends a shop/redact request, all stored data for that store is deleted, including orders, line items, refunds and refund components, ad spend, products and variants, cost prices and their history, inventory quantities and locations, warehouses, suppliers and their contact details, purchase orders, receipts, supplier returns, stock counts, recorded operating costs, your own business details, settings, shipping rates, synchronisation logs, privacy request records and any advertising platform connection. Files you uploaded — the attachments on your stock counts — are removed from private storage in the same request, and not only from our records of them.

When Shopify sends a customers/redact request, the affected order data is deleted immediately and a minimal technical marker is kept for as long as the app remains installed for that store. That marker exists for one purpose only: to stop a later synchronisation from re-importing the deleted order. It contains the store key, a fixed topic, the order identifier and a status — no name, e-mail address, telephone number, address, customer identifier, amount or payload fragment.

A merchant who needs a copy of their data before termination can export it from the app while it is still installed. After the deletion described above we retain no copy, except where applicable law requires us to keep something for a defined period, in which case we keep only what that law requires and continue to protect it under this DPA.

Audits and information

We will make available to the merchant the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by the merchant or an auditor they mandate. Audits are limited to once per year unless a supervisory authority requires otherwise or a personal data breach has occurred, must be requested with reasonable notice, must not unreasonably disrupt our operations, and are subject to confidentiality.

International transfers

Our primary database is hosted in a European Supabase project region. We have concluded a Data Processing Addendum with Supabase which incorporates the EU Standard Contractual Clauses where these are required for a transfer. We do not claim that all processing by Supabase takes place exclusively within the European Economic Area; supporting activities such as operations and support may take place elsewhere, and the Standard Contractual Clauses are the safeguard relied on for that.

We do not claim a specific transfer mechanism or certification for any subprocessor beyond what is stated above. A merchant who needs the current transfer details for a particular subprocessor can request them at info@northmast.app.

Order of precedence

In the event of a conflict between this DPA and the Merchant Terms of Service in relation to the processing of personal data on the merchant's behalf, this DPA prevails.

Changes to this DPA

Each document carries its own version number and effective date. A material change results in a new version number and a new effective date shown at the top of the page. Minor corrections that do not change your rights or our obligations — such as a typographical fix — do not.

Version 1.2 (8 September 2026) replaces version 1.1 (25 July 2026). Material change: this DPA described processing of order data alone, which was narrower than the processing we carry out for you. It now names the further categories of data subject — the contact people at your suppliers, and any individual whose details you happen to include in a file you upload as a stock count attachment — and the further categories of personal data that go with them. The nature and purpose of the processing now describes the whole service rather than analytics alone, the list of processing operations names disclosure back to Shopify on your instruction, and the description of our database provider records that the same provider holds the private storage your attachments live in. Nothing about our role, your instructions, our security measures, our subprocessors, retention or deletion has changed.

Contact

Satisfy & I B.V., Kloosterpark 12, 5554 GP Valkenswaard, The Netherlands. Chamber of Commerce number: 94013195. VAT identification number: NL866603839B01. E-mail: info@northmast.app.