SDDR Spain
Data Processing Addendum
Last updated: August 18, 2026
1. Parties and scope
This DPA forms part of the SDDR Spain Terms between the Shopify merchant (the “Merchant”) and Genius Nutrition S.R.L. (the “Provider”). It applies when the Provider processes personal data on the Merchant's behalf to provide the app.
Minimal hashed exclusion identifiers and deletion dates are retained solely to prevent reimport of deleted data. A delayed request removes affected earlier data without deleting a newer installation.
2. Roles and instructions
The Merchant acts as controller and the Provider as processor unless applicable law determines otherwise. The Provider processes data only on the Merchant's documented instructions, including the Terms, app configuration, and requests transmitted by Shopify, unless legally required otherwise.
3. Processing
- Subject
- Container-deposit configuration, cart operation, and report preparation.
- Duration
- While the app is installed and until required deletion following termination.
- Nature
- Receipt, validation, organization, storage, retrieval, export, and deletion.
- Data subjects
- Store customers or visitors linked to orders containing SDDR lines.
- Data
- Technical order and line identifiers, order name/number, date, product, financial status, fulfillment status, cancellation, refunded quantities, currency, and SDDR amounts. The order and refund webhooks request only these technical fields and the line attributes needed to identify SDDR components. Only the technical lifecycle index, SDDR attributes, and resulting deposit records are retained; buyer name, email, phone, address, and payment fields are neither requested nor retained.
4. Provider obligations
- Process only the minimum data for the described purposes and ensure authorized personnel are bound by confidentiality.
- Apply appropriate technical and organizational measures and review their effectiveness.
- Reasonably assist the Merchant with data-subject rights, security, incidents, and regulatory obligations related to the service.
- Notify the Merchant without undue delay after confirming a personal-data breach affecting the service.
- Delete or return data after the service ends, except where retention is legally required.
5. Security
Current measures include HTTPS/TLS, an encrypted private network between app and database, infrastructure storage encryption at rest, Shopify authentication and sessions, webhook HMAC verification, least privilege, logical per-store isolation, input validation, secret/dependency scanning, and backup or recovery controls managed according to the production configuration.
6. Subprocessors and transfers
The Merchant authorizes Railway Corporation for application and PostgreSQL hosting. Shopify provides the platform and APIs under its direct relationship with the Merchant. Railway may process data in the United States; its data-protection terms incorporate applicable transfer mechanisms. We will communicate material subprocessor changes through this page or the service.
7. Requests, deletion, and audit
The Provider processes Shopify's mandatory customers/data_request, customers/redact, and shop/redact webhooks. Reports and exports let the Merchant access retained data. On reasonable request, we will provide information needed to demonstrate compliance with this DPA while protecting the security and confidentiality of other customers.
8. Contact and precedence
Questions about this DPA should be sent to privacy@obsedia.ai. If there is a conflict concerning personal-data processing, this DPA prevails over the Terms.