Data Processing Agreement
The terms under which TrueSlot processes personal data on a merchant's behalf.
Last updated: July 29, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Web Designly Ltd (“Processor”, “we”) and the merchant installing TrueSlot (“Controller”, “you”). It applies automatically from the moment you install the App and takes precedence over the Terms of Service on matters of personal data.
1. Roles
You are the Controller of the personal data of your customers. We are a Processor acting only on your documented instructions. Installing and configuring the App constitutes those instructions. Shopify is a separate processor whose own terms govern the store data it holds.
2. Subject matter and duration
We process personal data solely to provide delivery and pickup scheduling for your store, for as long as the App remains installed. Processing ends when you uninstall.
3. Categories of data subjects and personal data
Data subjects are your customers who place an order with a scheduled delivery or pickup. The categories of personal data are limited to:
- Customer first and last name
- Customer email address
- Delivery postal code (read at checkout only, when postal code validation is enabled; never stored)
- Order identifier and the delivery date, time slot, method, and location booked
We do not process phone numbers, payment data, full street addresses, or any special categories of personal data.
4. Purposes of processing
| Purpose | Personal data used |
|---|---|
| Record and display each order’s schedule to you | Name, order identifier, delivery details |
| Send order confirmation and reminder emails | Name, email |
| Validate a delivery address against your service area | Postal code |
| Write delivery details onto the order for fulfillment | Order identifier, delivery details |
We will not process personal data for any other purpose, and we do not sell personal data, share it for cross-context behavioural advertising, or use it to train machine learning models.
5. Our obligations
We will:
- Process personal data only on your documented instructions, unless required otherwise by law, in which case we will notify you first unless that notice is itself prohibited.
- Ensure that personnel authorised to process personal data are bound by confidentiality.
- Implement the technical and organisational measures described in Section 7.
- Assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your obligations for security, breach notification, and data protection impact assessments.
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
6. Sub-processors
You grant us general authorisation to engage the sub-processors below. Each is bound by data protection terms no less protective than this DPA. We will give at least 30 days’ notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds, in which case you may terminate by uninstalling the App.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, and transactional email delivery | Global edge network |
| Shopify Inc. | The platform the App runs on and the source of all order data | Global |
7. Security measures
We maintain the following measures, reviewed at least annually:
- Encryption. All data is encrypted in transit with TLS 1.3 and at rest by the storage platform. Backups are encrypted with the same controls as the primary datastore.
- Access control. Access to production systems and to personal data is limited to personnel who need it to operate the service, granted on a least-privilege basis and revoked when no longer required.
- Authentication. All administrative accounts require strong, unique passwords stored in a password manager, with multi-factor authentication enforced.
- Access logging. Every read, write, and erasure of protected customer data is written to an append-only audit log recording the store, the actor, the purpose, the fields touched, and the record count. Field values are never logged.
- Environment separation. Test and development environments use separate databases and synthetic data. Production personal data is never copied into a test environment.
- Data loss prevention. Point-in-time recovery is retained for the production database, restores are exercised periodically, and personal data leaves the production environment only through the App’s own documented interfaces.
- Incident response. We maintain a written incident response procedure covering detection, containment, assessment, notification, and post-incident review.
8. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed.
9. Data subject requests
Deletion and access requests you receive through Shopify reach us automatically through Shopify’s compliance webhooks. On a customer redaction request we erase that customer’s name and email from our records within 30 days. If a data subject contacts us directly, we will refer them to you rather than respond on your behalf.
10. Retention and deletion
We apply the following retention periods, enforced automatically:
- Customer name and email are erased 90 days after the delivery date.
- Booking records, which contain no personal data after that point, are deleted 365 days after the delivery date.
- All data for a store is deleted when the store uninstalls the App and Shopify sends the corresponding redaction request.
11. International transfers
Data may be processed in any region in which our sub-processors operate. Where personal data originating in the EEA, UK, or Switzerland is transferred outside those regions, the transfer relies on the European Commission’s Standard Contractual Clauses as incorporated into our sub-processors’ terms, together with the UK Addendum where applicable.
12. Audits
On reasonable written request, no more than once in any 12-month period, we will provide the documentation reasonably necessary to demonstrate compliance with this DPA. Where a sub-processor’s independent audit report covers the relevant controls, providing that report satisfies this obligation.
13. Contact
Data protection enquiries: legal@trueslot.app