Mufatech Clearance / Data Processing Addendum
Data Processing Addendum
Last updated 10 October 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the merchant that installs the Mufatech Clearance app ("Merchant", "you") and Mufatech ("we"). It applies to personal data we process on your behalf when you use Mufatech Clearance. By installing and using the app you accept this DPA.
1. Roles
For personal data in your store's data that the app reads, you are the controller and we are your processor. We process it only to provide the app to you, on your documented instructions, which are this DPA, the app's settings you choose, and the campaigns and other actions you confirm in the app.
2. What we process, and why
| Purpose | Finding slow and unsold stock and why it is not selling; planning, previewing, applying and restoring the price changes and other actions you confirm; the price history used for price reduction rules; and the reports on what your campaigns did. |
|---|---|
| Data we read from Shopify | Products and variants with prices, compare-at prices and cost per item; stock levels and locations; orders with their line items, discounts, refunds, totals, dates and currency; markets and their price lists; whether products are published on the online store. |
| Data we write to Shopify | Only what you confirm: variant prices and compare-at prices, market price list and B2B catalog prices, publishing products on the online store or taking them off it (hibernation), automatic discounts (gift from stuck stock, discount code guard), collections the app sets up for you and collection sort order during a visibility test, product tags for ad labels, a draft order for a B2B lot when you allow it, and app metafields that mark clearance items and items not to reorder. |
| Data we keep | Your settings and campaigns; a record of every price the app wrote and when; a daily price and stock history per variant; and, for the price-drop wish list, the number of shoppers waiting at each price for each variant. |
| Data we do not read | Customer names, email addresses, postal addresses, phone numbers and customer IDs. The app does not read who placed an order. The wish list stores counts only: the shopper's contact details, if they give them, go to your own customer accounts or email tool, never to us. |
| Personal data involved | Order records can relate to a buyer even without their identity (for example an order total and date). We treat them as personal data. |
| Your own data | Your store's domain and the settings you choose. For staff who open the app, Shopify's user ID only, never a name or an email address. |
| Duration | While the app is installed, then until deletion under section 7. The daily price history is kept for up to 400 days while the app is installed. |
We do not sell personal data, share it for advertising, use it to train models, or combine it with data from other merchants' stores.
3. Our obligations
We will:
- process the data only on your instructions, and tell you if we believe an instruction breaks data protection law;
- make sure everyone who can access the data is bound to confidentiality;
- apply the security measures in section 4;
- help you, as far as the app allows, to answer requests from people exercising their rights. Shopify forwards these to us through its mandatory privacy webhooks, and we act on them;
- help you with data protection impact assessments and consultations with authorities where they concern the app, on request;
- make available the information needed to show we meet this DPA, on request.
4. Security measures
- In transit: all connections use TLS (Shopify, our servers and backups).
- At rest: the database and working data sit on an encrypted disk (LUKS2, AES-XTS 512). Shopify access tokens are additionally encrypted in the database (AES-256-GCM). Backups are stored encrypted at rest.
- Access: only named Mufatech staff can reach the servers and the operations panel, through Cloudflare Access and SSH keys. The public web ports accept traffic only from Cloudflare.
- Minimisation: the app asks Shopify only for the access its features need, uses its access to publications and discounts only for the features that need it, and never requests customer identity fields.
- Safe writes: every price the app writes is recorded before and after, so it can be checked and restored.
- Backups: daily database backups, kept for 14 days.
- Monitoring: job and error logs without customer data or tokens.
5. Subprocessors
You authorise these subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting (database, app, jobs) | Germany (EU) |
| Cloudflare, Inc. | Network, access control, backup storage (R2) | Global network; United States company |
We will give at least 30 days' notice on this page before adding or replacing a subprocessor. If you object on reasonable data protection grounds, you may stop using the app. We bind every subprocessor to data protection terms no less protective than this DPA, and remain responsible for them.
6. Transfers outside the EEA and the UK
Your store's data is stored in Germany. Where it is accessed or processed outside the EEA or the UK, by us or by a subprocessor (for example Cloudflare in the United States), the transfer is covered by the European Commission's Standard Contractual Clauses (Module 2, controller to processor, and Module 3 onward to subprocessors), with the UK International Data Transfer Addendum for UK data, or by the EU–US Data Privacy Framework where the recipient is certified. Those clauses are incorporated into this DPA by reference.
7. Deletion
When you uninstall the app, Shopify asks us 48 hours later to erase your store's data, and we delete what Clearance holds about your store from the live systems then: settings, campaigns, the record of price writes, the price and stock history and the wish list counts. If Store Diagnosis, another Mufatech app, is still installed on your store, the product, stock and order data both apps read is kept for it and erased under its own terms when it is uninstalled. Copies in database backups are not edited; they expire and are destroyed within 14 days. You can ask us to delete your data earlier at [email protected].
8. Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any case within 48 hours, at your store's contact email, with what we know and the steps we are taking. We will keep you informed as we learn more.
9. Audits
We will answer reasonable written questions about our compliance with this DPA. Where that is not enough to show compliance, you may request an audit on 30 days' notice, at your cost, once a year, under confidentiality, in a way that does not expose other merchants' data.
10. Liability, precedence and changes
This DPA forms part of the Mufatech Clearance Terms of Service, and each party's liability under it is subject to the limits in those terms. If this DPA conflicts with those terms on data protection, this DPA prevails. We may update this DPA to reflect changes in the law or the app; material changes are announced on this page and in the app at least 30 days ahead.
Contact
Data protection questions: [email protected]