1. Purpose and how this DPA applies
This DPA sets out the terms that apply when we process personal data on your behalf as a processor, in connection with the Argumentum app’s dispute-documentation features, so that both parties meet their obligations under applicable data protection law — including the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, and, where applicable, other data protection laws that apply to your use of the App.
2. Definitions
“Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” “Sub-processor,” and “Personal Data Breach” have the meanings given in the GDPR, regardless of whether GDPR itself applies to a particular instance of processing. “SCCs” means the Standard Contractual Clauses described in Section 9. “Your Data” has the meaning given in our Terms of Service, Section 6.
3. Roles of the parties
As described in our Privacy Policy, Section 5: with respect to personal data about your customers that we process to provide the App’s dispute-documentation features, you are the Controller and we are the Processor. We process that personal data only on your documented instructions — which consist of the Terms of Service, this DPA, and your configuration and use of the App’s features (for example, the access scopes you grant during installation, and any communication-log notes or settings you choose to enter) — unless we’re required to do otherwise by law that applies to us, in which case we’ll inform you before processing, unless that law prohibits us from doing so.
4. Details of processing (Annex I)
| Element | Description |
|---|---|
| Subject matter | Provision of the Argumentum app’s dispute-documentation features |
| Duration | For as long as Argumentum remains installed on your Shopify store, plus the retention period described in our Privacy Policy, Section 7 |
| Nature and purpose of processing | Capturing, organizing, and presenting order, fulfillment, and dispute information into evidence packets and a readiness dashboard, as described in our Privacy Policy, Sections 3 and 4 |
| Categories of data subjects | Your store’s customers whose orders or disputes are processed through the App; and, where your staff interact with the App directly, your own personnel |
| Categories of personal data | The categories listed in our Privacy Policy, Section 3 — customer name, email, and phone number; billing and shipping addresses; order, fulfillment, and dispute details; purchase IP address; and any personal data a member of your staff includes in a communication-log note or an uploaded attachment (Standard and Pro plans). We do not process any special category of data (as defined by GDPR Article 9) as part of providing the App, unless you choose to include it in free-text notes or attachments you enter or upload yourself. |
5. Processor obligations
- We process personal data only on your documented instructions (Section 3), including with regard to international transfers, unless required to do otherwise by applicable law.
- We ensure that personnel authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
- We implement the technical and organizational security measures described in Section 7.
- We do not engage a sub-processor without the general authorization described in Section 6.
- We assist you in responding to data subject requests and in meeting your own obligations around data protection impact assessments and breach notification, as described in Section 8.
- At the end of the provision of services, we return or delete personal data as described in Section 11.
- We make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in Section 10.
6. Sub-processors (Annex III)
You authorize us, generally, to engage the sub-processors listed in our Privacy Policy, Section 6 (currently Neon, Cloudflare, Postmark, ipwho.is, and Shopify’s Partner API / App Events API — see that section for what each is used for and what information is involved), each engaged solely to help us operate the App and bound by data protection obligations no less protective than this DPA.
If we add or replace a sub-processor, we’ll update our Privacy Policy, Section 6 and, where the change is material, notify you as described in our Privacy Policy, Section 13. If you reasonably object to a new sub-processor on data protection grounds, your remedy is to uninstall the App, as described in our Terms of Service, Section 10 — we aren’t able to offer a smaller-scale opt-out for an individual sub-processor the App’s core features depend on.
Stripe is not among the sub-processors described above. If you independently connect your own Stripe account to the App and use its optional direct-submission feature, you — not us — are directing that specific transmission of personal data to a processor (or, with respect to its own use of the data once received, potentially an independent controller) that you have chosen and that has its own direct relationship and data protection terms with you. We act as your instructed conduit for each such transmission, not as the party engaging Stripe as our sub-processor. See our Privacy Policy, Section 6 for what this feature transmits and when.
PayPal support is planned but not yet available. We have built the capability described above for a merchant’s own connected PayPal account, including responding to more than one round of evidence PayPal may request on the same dispute, but it is switched off pending PayPal’s own approval of Tenpenny Software as an integration partner — an external process outside our control, with no guaranteed timeline. No merchant can currently connect a PayPal account through the App, and until that changes, this DPA’s treatment of Stripe above does not yet apply to PayPal in practice. We will update this DPA before the feature becomes available to any merchant.
7. Security measures (Annex II)
We implement the technical and organizational security measures described in our Privacy Policy, Section 8, including encryption of stored access credentials, cryptographic verification of inbound webhooks, private (non-public) storage of exported evidence files with short-lived access links, encrypted transmission, per-store data isolation, and secret-based authentication with rate limiting on administrative endpoints — see that section for the current, complete list, which we keep up to date there rather than duplicating a second, driftable copy here.
8. Assistance with data subject requests and breaches
Taking into account the nature of processing, we assist you, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under applicable data protection law. Where such a request reaches us through Shopify’s own compliance webhooks, we act on it directly, as described in our Privacy Policy, Section 9; a request that reaches you directly is yours to fulfill, and we’ll provide reasonable assistance if you contact us using the details in Section 14.
If we become aware of a Personal Data Breach affecting personal data we process on your behalf, we will notify you without undue delay after becoming aware of it, and provide the information reasonably available to us to help you meet your own breach-notification obligations, consistent with our Privacy Policy, Section 8.
9. International transfers; Standard Contractual Clauses
As described in our Privacy Policy, Section 11, providing the App may involve transferring personal data to the United States and to other countries where our sub-processors operate. Where a transfer of personal data originating in the European Economic Area, the United Kingdom, or Switzerland to us (or a sub-processor) requires appropriate safeguards under applicable data protection law, the Standard Contractual Clauses issued by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021 (Module Two: Controller to Processor) are incorporated into this DPA by reference and apply to that transfer, completed using the information in Sections 4, 6, and 7 of this DPA (in place of separate annexes) and with the Clause 13/17/18 options and competent supervisory authority determined by where you and your customers are located. For transfers subject to UK data protection law, the UK’s International Data Transfer Addendum to the SCCs is incorporated on the same basis. In the event of a conflict between this DPA and the SCCs (as completed above), the SCCs control to the extent required by applicable law.
10. Audits and information rights
On reasonable written request, no more than once in any 12-month period (except following a genuine Personal Data Breach affecting your data, or where required by a supervisory authority), we will make available the information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to an audit, including an inspection, conducted by you or an auditor you mandate, subject to reasonable advance notice, confidentiality, and scheduling that avoids disrupting the App’s operation for other merchants.
11. Return or deletion of data
When you uninstall the App, we erase your store’s data as described in our Privacy Policy, Section 7. If you need a copy of your data before uninstalling, you can request one using the details in Section 14, or use the in-app dashboards and PDF export while the App remains installed.
12. Liability and term
This DPA remains in effect for as long as our Terms of Service remain in effect. Each party’s liability arising out of or in connection with this DPA, including the SCCs incorporated under Section 9, is subject to the limitations set out in our Terms of Service, Section 12, except to the extent applicable data protection law (including Clause 12 of the SCCs) prohibits limiting liability for a party’s own violation of that law, in which case that law’s own liability terms apply instead.
13. Requesting a countersigned copy
This DPA applies automatically and doesn’t require a separate signature to take effect. If your organization’s own compliance process requires a countersigned copy — for example, with your entity name and address completed on the SCCs’ own signature page — email us at the address in Section 14 and we’ll provide one.
14. Contact us
If you have questions about this DPA or need a countersigned copy, contact us at:
Tenpenny Software
PO Box 672
Zillah, WA 98953
United States
admin@tenpennysoftware.com
This DPA supplements our Privacy Policy and Terms of Service — it doesn’t replace either one.