Data Processing Agreement
Auftragsverarbeitungsvertrag pursuant to Art. 28 GDPR
Version 1.0 · Effective: 28.07.2026
Parties
Controller ("the Merchant")
The merchant operating the Shopify store on which the App is installed, as identified by the Shopify account under which the installation took place.
Processor ("we", "us")
Micha Saalmüller
Mittenwalder Straße 32
10961 Berlin, Germany
privacy@michasaalmueller.com
1. Subject matter and how this agreement is concluded
This agreement governs the processing of personal data that we carry out on behalf of the Merchant when the Merchant uses the Saal: Sales Agent Shopify app ("the App").
It forms part of our Terms of Service and takes effect when the Merchant installs the App. It applies for as long as the App remains installed. A separately signed copy is available on request at the address above.
Where this agreement conflicts with our Terms of Service in relation to the processing of personal data, this agreement prevails.
2. Roles of the parties
The Merchant is the controller and determines the purposes and means of the processing. We act solely as processor and process personal data only on the Merchant's documented instructions.
The Merchant is responsible for ensuring there is a valid legal basis for the processing, and in particular for obtaining and documenting any consent required from its own customers before a sales agent acts on their behalf. The App provides tooling to record such consent; it does not obtain consent on the Merchant's behalf and does not assess whether the consent obtained is legally sufficient.
3. Scope of the processing
The nature, purpose, duration, types of personal data and categories of data subjects are set out in Annex I.
4. Our obligations
We undertake to:
4.1 Process only on instructions. We process personal data only on the Merchant's documented instructions, including regarding transfers to third countries, unless required otherwise by Union or Member State law. The Merchant's instructions are given through the configuration of the App and through the use of its functions. If we consider an instruction to infringe data protection law, we will inform the Merchant without delay and may suspend execution of that instruction.
4.2 Ensure confidentiality. Persons authorised to process personal data are bound to confidentiality. Access is limited to the sole developer of the App.
4.3 Implement security measures. We implement the technical and organisational measures required under Art. 32 GDPR, as described in Annex II. We may update these measures provided the level of protection is not reduced.
4.4 Engage sub-processors only as agreed. See section 6.
4.5 Assist with data subject rights. Taking into account the nature of the processing, we assist the Merchant by appropriate technical and organisational measures in responding to requests from data subjects. Because we do not maintain our own store of customer data, such requests are ordinarily fulfilled by the Merchant directly in Shopify. If a data subject contacts us directly, we will not respond substantively but will forward the request to the Merchant without undue delay.
4.6 Assist with compliance obligations. We assist the Merchant in complying with Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to us.
4.7 Report personal data breaches. We notify the Merchant without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Merchant's data, and provide the information the Merchant needs to meet its own notification obligations.
4.8 Delete data at the end of the processing. See section 8.
4.9 Provide information and allow audits. See section 9.
5. Merchant's obligations
The Merchant:
- is responsible for the lawfulness of the processing and for the instructions it gives;
- is responsible for informing its own customers about the processing, including through its own privacy notice;
- is responsible for determining which of its customers are granted sales agent permissions, and for the scope of the access granted to them;
- must not enter special categories of personal data (Art. 9 GDPR) into fields provided by the App, in particular the free-text consent note.
6. Sub-processors
The Merchant grants general authorisation for the engagement of sub-processors. The sub-processors engaged at the time this version takes effect are listed in Annex III.
We will inform the Merchant of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the address associated with the Shopify account or by notice in the App. The Merchant may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Merchant may terminate by uninstalling the App.
We impose on each sub-processor the same data protection obligations as set out in this agreement, and remain fully liable to the Merchant for their performance.
7. International transfers
Personal data is stored in a Western European region within the European Union. Our hosting provider is established in the United States and access from outside the EEA cannot be entirely excluded, for example for support or maintenance. Such transfers are covered by appropriate safeguards under Art. 46 GDPR, including EU Standard Contractual Clauses agreed with the provider.
8. Deletion and return of data
We do not maintain our own copy of the Merchant's customer data. Consent records created through the App are written to the Merchant's own Shopify account and remain under the Merchant's control at all times; they are unaffected by termination of this agreement.
On uninstallation of the App:
- shop session data and access tokens are deleted;
- shop data is deleted on receipt of Shopify's
shop/redactwebhook, sent 48 hours after uninstallation; - operational logs expire automatically within approximately 3 days.
Records that we are required to retain under statutory obligations, in particular commercial and tax law, are retained for the required period and processed only for that purpose.
9. Information and audit rights
We provide the Merchant with all information necessary to demonstrate compliance with Art. 28 GDPR on request.
Given that the App is operated by a single developer, audits are ordinarily satisfied by the provision of documentation, this agreement and Annex II. Where the Merchant demonstrates a specific need going beyond this, an audit may be carried out remotely, once per calendar year, with 30 days' written notice and at the Merchant's expense, without disrupting the operation of the service. This limitation does not apply following a personal data breach affecting the Merchant.
10. Liability
Liability is governed by Art. 82 GDPR and the liability provisions of our Terms of Service.
11. Term, governing law and jurisdiction
This agreement takes effect on installation of the App and ends when the App is uninstalled and the deletion obligations under section 8 have been fulfilled.
This agreement is governed by the law of the Federal Republic of Germany. Where the Merchant is a business, the place of jurisdiction is Berlin.
Should individual provisions be invalid, the validity of the remainder is unaffected.
Annex I — Description of the processing
Nature and purpose
Enabling authorised sales agents of the Merchant to place orders on behalf of the Merchant's customers, in the Merchant's storefront, using the customer's own catalogue, pricing and delivery locations; and recording the consent under which they do so.
Duration
For as long as the App is installed.
Categories of data subjects
- Customers of the Merchant on whose behalf orders are placed
- Customers of the Merchant designated as sales agents
- Contact persons of the Merchant's business customers (companies and company locations)
Types of personal data
- Customer identifier, display name, email address
- Customer tags used to determine access permissions
- Company and company location assignments (Shopify Plus B2B)
- Order data received through the
orders/createwebhook - Consent records: date, free-text note, identifier of the responsible sales agent
- Technical log data: shop domain, customer identifier, order identifier and, in some error cases, an email address
Special categories of personal data
None. The Merchant is required not to enter such data into free-text fields.
Where the data is held
Customer data is read from Shopify's APIs, processed in memory and not persisted by us. Consent records are stored in the Merchant's Shopify account. Only shop session data, access tokens and subscription status are stored in our database.
Annex II — Technical and organisational measures (Art. 32 GDPR)
Confidentiality
- Access control (physical): no own server infrastructure; hosting is provided by a certified data centre operator.
- Access control (system): administrative access is limited to the sole developer, secured by unique credentials, a password manager and two-factor authentication on all relevant accounts.
- Access control (data): the App accesses Shopify data only through scoped API tokens, limited to the permissions requested at installation. Access to customer data is additionally restricted per sales agent through Merchant-configured rules.
- Separation: development and production environments and databases are strictly separated. No live Merchant or customer data is used in development or testing.
Integrity
- Transmission control: all data is transmitted over TLS. Incoming webhooks are verified by HMAC signature.
- Input control: actions taken by sales agents are recorded with a timestamp and the identifier of the responsible agent, providing traceability of who acted for whom.
Availability and resilience
- Data is stored on managed infrastructure with automated backup and point-in-time recovery.
- Backups are encrypted at rest by the provider.
- Reconciliation routines detect and correct failed order attribution.
Data minimisation and storage limitation
- Only the data fields required for the App's function are requested and processed.
- Customer data is not persisted in our own database.
- Operational logs expire automatically within approximately 3 days.
- Shop data is deleted on uninstallation, in accordance with Shopify's mandatory privacy webhooks.
Procedures for review and evaluation
- Incident response procedure with defined notification paths, including notification of the competent supervisory authority within 72 hours where required.
- Implementation of Shopify's mandatory privacy webhooks:
customers/data_request,customers/redact,shop/redact. - Review of these measures on material changes to the App.
Annex III — Approved sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA | Application hosting, database, operational logging | Database in Western Europe (EU); provider established in the USA |
Billing is administered by Shopify. We do not receive or process payment card data.
Shopify Inc. is the platform on which the App operates and is the source and destination of the processed data. Shopify is not a sub-processor of ours; the Merchant's relationship with Shopify is governed by the Merchant's own agreements with Shopify.
This agreement is also available in German.