1. Definitions
- “Data Protection Laws” means, to the extent they apply to the processing: Regulation (EU) 2016/679 (the “GDPR”); the GDPR as it forms part of UK law and the UK Data Protection Act 2018 (the “UK GDPR”); the Swiss Federal Act on Data Protection (the “FADP”); and United States state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the “CCPA”).
- “Customer Personal Data” means personal data that WholeFrame processes on Customer’s behalf in providing the Service, including personal data of Customer’s own customers that WholeFrame receives from the platforms Customer connects.
- “Sub-processor” means a third party WholeFrame engages that processes Customer Personal Data.
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- “Standard Contractual Clauses” means the clauses approved by Commission Implementing Decision (EU) 2021/914.
- “Controller,” “processor,” “data subject,” “personal data” and “processing” have the meanings given in the GDPR. “Business,” “service provider,” “sell” and “share” have the meanings given in the CCPA. Other capitalized terms have the meanings given in the Agreement.
2. Roles and scope
2.1 Customer is the controller of Customer Personal Data, or a processor acting for its own controller. WholeFrame is a processor, and a service provider under the CCPA.
2.2 This DPA does not apply to personal data for which WholeFrame is itself the controller: the account details of Customer’s users, early-access requests, and information about visitors to WholeFrame’s website. The Privacy Policy governs that data.
2.3 The subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of data subjects, are described in Annex I.
3. Processing on Customer’s instructions
3.1 WholeFrame processes Customer Personal Data only on Customer’s documented instructions, including with regard to international transfers, unless the law requires otherwise, in which case WholeFrame will inform Customer of that requirement first unless the law prohibits it. The Agreement, this DPA and Customer’s use and configuration of the Service, such as connecting a platform, requesting an export or requesting deletion, are Customer’s complete instructions.
3.2 WholeFrame will inform Customer promptly if, in its opinion, an instruction infringes Data Protection Laws.
3.3 WholeFrame will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than providing the Service to Customer, or outside the direct business relationship between WholeFrame and Customer; combine it with personal data WholeFrame receives from or on behalf of anyone else, except as the CCPA permits a service provider to do; or use it to develop, train or improve any product, service or model other than the Service provided to Customer. WholeFrame certifies that it understands and will comply with these restrictions, and will notify Customer if it can no longer meet its obligations under Data Protection Laws. On such notice, Customer may take reasonable steps to stop and remedy unauthorized processing.
3.4 Customer is responsible for having a lawful basis for the processing it instructs, for giving any notices its customers are owed, and for having the rights it needs to connect its platforms to the Service.
4. Confidentiality
WholeFrame ensures that the people it authorizes to process Customer Personal Data are bound by an obligation of confidentiality and that access is limited to those who need it to provide the Service.
5. Security
WholeFrame implements the technical and organizational measures described in Annex II, which are designed to provide a level of security appropriate to the risk. WholeFrame may update those measures, provided the overall level of security is not materially reduced.
6. Sub-processors
6.1 Customer gives WholeFrame general written authorization to engage Sub-processors. The Sub-processors engaged today are listed in Annex III.
6.2 WholeFrame will update Annex III and email Customer’s account administrators at least 30 days before a new Sub-processor begins processing Customer Personal Data. Customer may object on reasonable data protection grounds within those 30 days. The parties will then discuss the objection in good faith, and if they cannot resolve it, Customer may terminate the affected part of the Service without penalty.
6.3 WholeFrame imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains liable to Customer for each Sub-processor’s performance of them.
6.4 The platforms Customer connects to the Service, such as Shopify or an affiliate platform, are Customer’s own providers and are not Sub-processors. WholeFrame exchanges data with them only on Customer’s instruction.
7. Data subject requests
7.1 Taking into account the nature of the processing, WholeFrame assists Customer by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights.
7.2 For a store connected through Shopify, WholeFrame acts on the privacy requests Shopify forwards. On an erasure request, WholeFrame erases or redacts the data subject’s identifying information across the records described in Annex I. On an access request, WholeFrame makes a machine-readable export of those records available to Customer in the Service, under Settings, Data requests. Customer can also export the records held for any customer directly, by that customer’s Shopify ID. Every export is recorded in WholeFrame’s audit trail.
7.3 If a data subject contacts WholeFrame directly, WholeFrame will not respond to the substance of the request without Customer’s instruction, unless the law requires it, and will forward the request to Customer without undue delay.
8. Security Incidents
8.1 WholeFrame will notify Customer without undue delay after becoming aware of a Security Incident.
8.2 The notice will describe, as far as known, the nature of the Security Incident, the categories and approximate number of data subjects and records concerned, its likely consequences, and the measures taken or proposed. Information that is not available at first will be provided in phases, without further undue delay.
8.3 WholeFrame will assist Customer in meeting its own notification obligations, and will not notify a supervisory authority or data subject on Customer’s behalf unless Customer instructs it to or the law requires it. A notice under this section is not an admission of fault.
9. Deletion and return
9.1 Customer can delete data during the term. Disconnecting Shopify in the Service disconnects every Shopify store in Customer’s organization. If Customer also chooses to delete the imported data now, WholeFrame erases the personal data of those stores’ customers immediately and permanently deletes the stores’ remaining records 30 days later.
9.2 If Customer does not choose immediate deletion, disconnecting does not delete data at once. Once a Shopify store has stayed disconnected for 90 consecutive days, whether because the app was uninstalled from it or because Customer disconnected Shopify in the Service, WholeFrame erases the personal data of that store’s customers, and permanently deletes the store’s remaining records 30 days after that.
9.3 Affiliate-program records are held for Customer’s organization and filed under one of Customer’s connected stores. Deleting a store deletes the affiliate records filed under it. An individual’s erasure under section 7.2 reaches their affiliate records across all of Customer’s stores.
9.4 When the Agreement ends, WholeFrame will delete Customer Personal Data within 30 days of Customer’s request, unless the law requires WholeFrame to keep it. If Customer asks before the Agreement ends, WholeFrame will first provide a copy in a machine-readable format. Requests go to support@wholeframe.io.
9.5 Customer Personal Data in an encrypted backup taken before a deletion is not removed from that backup, and remains until the backup expires 28 days after it was taken. Backups are restored only for disaster recovery and for testing that restoration works.
10. Information and audits
10.1 WholeFrame will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, by Customer or an auditor Customer mandates.
10.2 WholeFrame may meet section 10.1 by providing its security documentation, the descriptions in Annex II and written answers to reasonable security questionnaires. Customer may request an inspection no more than once in any twelve-month period, on 30 days’ notice, during business hours and subject to confidentiality, at Customer’s cost unless the inspection reveals material non-compliance by WholeFrame.
11. International transfers
11.1 WholeFrame processes and stores Customer Personal Data in the United States.
11.2 European Economic Area. Where Customer Personal Data subject to the GDPR is transferred to WholeFrame, the Standard Contractual Clauses are incorporated into this DPA as follows: Module Two applies where Customer is a controller, and Module Three where Customer is a processor; Customer is the data exporter and WholeFrame the data importer; the optional docking clause in Clause 7 applies; Option 2 of Clause 9(a) applies, with the notice period in section 6.2 of this DPA; the optional language in Clause 11 does not apply; the competent supervisory authority is determined under Clause 13(a); under Clause 17 (Option 1) the Clauses are governed by the law of Ireland; under Clause 18 disputes are resolved by the courts of Ireland; and Annexes I, II and III of the Clauses are completed by Annexes I, II and III of this DPA.
11.3 United Kingdom. Where Customer Personal Data subject to the UK GDPR is transferred to WholeFrame, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) is incorporated into this DPA. Its Table 1 is completed by Annex I, Table 2 by section 11.2, and Table 3 by Annexes I, II and III, and for Table 4 either party may end the Addendum as set out in its Section 19.
11.4 Switzerland. Where Customer Personal Data subject to the FADP is transferred to WholeFrame, the Standard Contractual Clauses apply as set out in section 11.2, with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; references to the GDPR include the FADP; and the term “Member State” does not prevent data subjects in Switzerland from bringing claims in their place of habitual residence.
11.5 If the Standard Contractual Clauses conflict with this DPA, the Clauses prevail.
12. Term, liability and precedence
12.1 This DPA lasts as long as WholeFrame processes Customer Personal Data.
12.2 Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws or the Standard Contractual Clauses do not allow it.
12.3 If this DPA conflicts with the Agreement in respect of the processing of Customer Personal Data, this DPA prevails.
12.4 WholeFrame may update this DPA by publishing a new version on this page. WholeFrame will email Customer’s account administrators at least 30 days before a change that materially reduces the protection of Customer Personal Data takes effect.
Annex I — Description of the processing
A. Parties
- Data exporter: Customer, with the name, address and contact details held in its WholeFrame account. Role: controller, or processor for its own controller. Activities: use of the Service. Acceptance of the Agreement constitutes its signature.
- Data importer: WHOLEFRAME LLC, 5 Bartlett Street, Newton, NH 03858, United States. Contact: support@wholeframe.io. Role: processor. Activities: providing the Service. Acceptance of the Agreement constitutes its signature.
B. Description of the transfer and processing
Categories of data subjects. Customer’s own customers: people who have placed an order with, or hold a customer record in, Customer’s connected store. Where Customer connects an affiliate platform, Customer’s affiliate partners.
Categories of personal data.
- From Shopify: the Shopify customer ID; order records, including order number, dates, status, totals, taxes, discounts, shipping charges, line items and refunds; order notes and refund notes, which are free text; customer account state, tags, number of orders and total spent; customers’ email addresses; the country and region of the billing address; email-marketing consent status; and each order’s landing page and campaign parameters, such as UTM values and advertising click identifiers. Of Shopify’s protected customer fields, WholeFrame’s Shopify app requests only email addresses; it does not request names, phone numbers or street addresses.
- From an affiliate platform, where connected: the referred customer’s email address, the affiliate partner’s name and email address, referral and commission records, and the referral data the platform returns.
- From advertising platforms, where connected: campaign, ad and spend metrics, which are aggregated and generally do not identify individuals.
Sensitive data. None is sought or used. Order and refund notes are free text entered by Customer’s staff or customers and could contain anything they typed.
Frequency of the transfer. Continuous, for as long as a platform stays connected.
Nature of the processing. Collection through the connected platforms’ interfaces and notifications, storage, organization, analysis, display to Customer’s users, export at Customer’s request, and erasure.
Purpose. To provide Customer with analytics, reporting and profitability measurement for its business, to act on Customer’s privacy requests, and to keep the Service secure.
Retention. For the term of the Agreement, subject to section 9. In addition: the contents of each notification Shopify sends are cleared 30 days after it is processed; a disconnected store’s customer personal data is erased after 90 consecutive days and its remaining records deleted 30 days later; and encrypted backups expire 28 days after they are taken.
Transfers to Sub-processors. Hosting and storage, as described in Annex III, for the term of the Agreement.
C. Competent supervisory authority
The supervisory authority determined under Clause 13(a) of the Standard Contractual Clauses. For the UK GDPR, the UK Information Commissioner. For the FADP, the Swiss Federal Data Protection and Information Commissioner.
Annex II — Technical and organizational measures
Encryption
- All traffic between browsers, connected platforms and WholeFrame’s servers is encrypted with TLS.
- Customers’ names, phone numbers and street addresses, the customer email addresses received from Shopify, on customer profiles and on orders, and every access credential a connected platform issues, are encrypted with AES-256-GCM before they are stored, with a fresh random initialization vector for each value.
- The database runs on storage volumes that the hosting provider encrypts at rest, as are their snapshots. Fields not listed in the previous point, including the rest of each order record and the email addresses received from affiliate platforms, are protected by that volume encryption but are not encrypted separately by the application.
- Nightly backups are encrypted before they are uploaded, are never written to disk unencrypted, use a key that is never stored alongside them, and are kept in a different region from the database.
Access control
- Users sign in with an email address and password. Passwords must be at least 12 characters, are checked against a list of common and breached passwords, and are stored only as a bcrypt hash. Access tokens expire after 24 hours, and refresh tokens rotate on every use and can be revoked.
- Every request for an organization’s data checks both the user’s role and the user’s membership of that organization. An automated test fails the build if any route omits the check.
- Access credentials for connected platforms are never returned through the API.
- Access to production systems is limited to the WholeFrame staff who operate the Service.
- Multi-factor authentication is not currently available for WholeFrame accounts.
Logging and monitoring
- An append-only audit trail records sign-ins, administrative actions and every export of an individual’s personal data, including who exported it, when, from which store and for which customer ID, and the number of records, never the exported values. Audit records are deleted after 365 days, except a record of a change to a user’s sign-in email, which is kept while that user’s account exists; the network address and user-agent in each are removed after 90 days.
- Server logs stay on the server that wrote them and are not copied to a separate log store; they are deleted when that server process is replaced or overwritten once they reach a fixed size. Log lines about a store installation or a customer privacy request can name the email address or Shopify customer ID involved.
- Notifications from Shopify are verified by their signature before they are processed.
- Requests are rate-limited per organization.
Data minimization and retention
- Of Shopify’s protected customer fields, WholeFrame’s Shopify app requests only email addresses, which it needs to answer privacy requests and to match marketing to orders. It does not request names, phone numbers or street addresses.
- The retention periods in section 9 and Annex I are applied by an automated nightly job.
Availability and recovery
- The application runs as several instances.
- The database is backed up every night. An automated test restores the latest backup every week into a separate database and checks it against the counts recorded at backup time.
Separation, change control and incident response
- Production data is not used for software development or automated testing, which use generated sample data.
- Every change is made through a pull request and must pass the full automated test suite before it can be merged.
- WholeFrame maintains a written security incident response policy covering severity, containment, evidence and notification.
- WholeFrame does not currently hold a third-party security certification such as SOC 2 or ISO 27001.
Annex III — Sub-processors
- DigitalOcean, LLC. Application hosting, database storage, encrypted backup storage and container registry. Location: United States (New York).
- Vercel Inc. Hosting of the WholeFrame web application and website, and cookieless aggregate page-view analytics. Location: United States, with global content delivery.
- GitHub, Inc. Source code hosting and the deployment pipeline. It does not receive Customer Personal Data in normal operation. Location: United States.
The platforms Customer connects, such as Shopify and UpPromote, are not Sub-processors; see section 6.4.