Store Diagnosis / Data Processing Addendum
Data Processing Addendum
Last updated 26 September 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the merchant that installs the Store Diagnosis app ("Merchant", "you") and Mufatech ("we"). It applies to personal data we process on your behalf when you use Store Diagnosis. By installing and using the app you accept this DPA.
1. Roles
For personal data in your store's data that the app reads, you are the controller and we are your processor. We process it only to provide the app to you, on your documented instructions, which are this DPA, the app's settings you choose, and the actions you take in the app.
2. What we process, and why
| Purpose | Producing your store's report: stock not selling, best-sellers running out, discounts and refunds that cost margin, and profit by product; and the optional weekly email to you. |
|---|---|
| Data we read from Shopify | Products and variants with prices and cost per item; stock levels and locations; orders with their line items, discounts, refunds, totals, dates and currency. |
| Data we do not read | Customer names, email addresses, postal addresses, phone numbers and customer IDs. The app does not read who placed an order. |
| Personal data involved | Order records can relate to a buyer even without their identity (for example an order total and date). We treat them as personal data. |
| Your own data | Your store's contact email (for the weekly email and, only if you tick the box, product news from Mufatech). |
| Duration | While the app is installed, then until deletion under section 7. |
We do not sell personal data, share it for advertising, use it to train models, or combine it with data from other merchants' stores.
3. Our obligations
We will:
- process the data only on your instructions, and tell you if we believe an instruction breaks data protection law;
- make sure everyone who can access the data is bound to confidentiality;
- apply the security measures in section 4;
- help you, as far as the app allows, to answer requests from people exercising their rights. Shopify forwards these to us through its mandatory privacy webhooks, and we act on them;
- help you with data protection impact assessments and consultations with authorities where they concern the app, on request;
- make available the information needed to show we meet this DPA, on request.
4. Security measures
- In transit: all connections use TLS (Shopify, our servers, email and backups).
- At rest: the database and working data sit on an encrypted disk (LUKS2, AES-XTS 512). Shopify access tokens are additionally encrypted in the database (AES-256-GCM). Backups are stored encrypted at rest.
- Access: only named Mufatech staff can reach the servers and the operations panel, through Cloudflare Access and SSH keys. The public web ports accept traffic only from Cloudflare.
- Minimisation: the app asks Shopify for read-only access, and never requests customer identity fields.
- Backups: daily database backups, kept for 14 days.
- Monitoring: job and error logs without customer data or tokens.
5. Subprocessors
You authorise these subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting (database, app, jobs) | Germany (EU) |
| Cloudflare, Inc. | Network, access control, backup storage (R2) | Global network; United States company |
| Postmark (ActiveCampaign, LLC) | Sending the weekly email to you | United States |
We will give at least 30 days' notice on this page before adding or replacing a subprocessor. If you object on reasonable data protection grounds, you may stop using the app. We bind every subprocessor to data protection terms no less protective than this DPA, and remain responsible for them.
6. Transfers outside the EEA and the UK
Your store's data is stored in Germany. Where it is accessed or processed outside the EEA or the UK, by us or by a subprocessor (for example Cloudflare or Postmark in the United States), the transfer is covered by the European Commission's Standard Contractual Clauses (Module 2, controller to processor, and Module 3 onward to subprocessors), with the UK International Data Transfer Addendum for UK data, or by the EU–US Data Privacy Framework where the recipient is certified. Those clauses are incorporated into this DPA by reference.
7. Deletion
When you uninstall the app, Shopify asks us 48 hours later to erase your store's data, and we delete everything held about your store from the live systems then. Copies in database backups are not edited; they expire and are destroyed within 14 days. You can ask us to delete your data earlier at [email protected].
8. Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any case within 48 hours, at your store's contact email, with what we know and the steps we are taking. We will keep you informed as we learn more.
9. Audits
We will answer reasonable written questions about our compliance with this DPA. Where that is not enough to show compliance, you may request an audit on 30 days' notice, at your cost, once a year, under confidentiality, in a way that does not expose other merchants' data.
10. Liability, precedence and changes
This DPA forms part of the Store Diagnosis Terms of Service, and each party's liability under it is subject to the limits in those terms. If this DPA conflicts with those terms on data protection, this DPA prevails. We may update this DPA to reflect changes in the law or the app; material changes are announced on this page and in the app at least 30 days ahead.
Contact
Data protection questions: [email protected]