PopUplift Data Processing Agreement (DPA)
Data Processing Agreement pursuant to Art. 28 GDPR for the Shopify app PopUplift, version dated September 1, 2026
Art. 28 GDPR sets specific requirements for data processing on behalf of a controller. To meet these requirements, the parties enter into this data processing agreement in addition to the Terms of Service (https://popuplift.com/tos). It applies to all activities related to the main contract in which the processor, or persons engaged by the processor, process personal data (hereinafter "data") of the controller. The definitions of the GDPR apply.
Processor: Richard Wagentristl, Drorygasse 8/4/15, 1030 Vienna, Austria, email: r.wagentristl@gmail.com (hereinafter "Processor")
Controller: The merchant who installs the app PopUplift in their Shopify store and accepts this agreement during onboarding (hereinafter "Controller")
1. Subject matter of the contract and the Controller's right to issue instructions
The subject matter of this agreement is the Processor's services for the Controller in the area of displaying popups in the Controller's online store, collecting contact details and signups of shop visitors, creating and assigning discount codes and evaluating popup performance through the PopUplift solution. Reference is also made to Annex 1 of this agreement and to the Terms of Service. If the commissioned service changes, this agreement is to be adjusted and supplemented accordingly in Annex 1.
The Controller, as the responsible party, is solely responsible for assessing the lawfulness of the data processing under the GDPR. This includes in particular obtaining lawful consent from shop visitors for newsletter signups and for the use of cookies or comparable technologies in the Controller's store.
In providing the service, the Processor gains access to personal data and processes it exclusively on behalf of and according to the instructions of the Controller, unless the Processor is required by Union or Member State law to process it otherwise.
The Controller's instructions are set out in this agreement and in the configuration of popups, integrations and settings in the app. They can be changed, supplemented or replaced by the Controller through individual instructions in at least documented electronic form. If the Processor is required by Union or Member State law to carry out further processing, it will inform the Controller of these legal requirements before processing (Art. 28 (3) (a) GDPR).
If the Processor believes that an instruction from the Controller violates data protection law, it must inform the Controller without delay. The Processor is entitled to suspend the execution of the instruction until it is confirmed or modified by the Controller. The Processor may refuse to execute an obviously unlawful instruction without facing negative consequences. The Controller is responsible for issuing lawful instructions (Art. 28 (3) sentence 3 GDPR).
The term of this agreement corresponds to the term of the main contract, meaning the period during which the app is installed in the Controller's store, unless the following provisions give rise to further obligations or termination rights.
2. Technical and organizational measures
The Processor complies with the statutory data protection provisions. Information of the Controller is not passed on or disclosed to third parties without the Controller's express instruction. Documents and data are secured against unauthorized access taking into account the state of the art.
The Processor organizes its internal operations so as to meet the specific requirements of data protection and ensures that all necessary technical and organizational measures to protect the Controller's data pursuant to Art. 32 GDPR have been taken. Reference is made to Annex 2.
The Controller reviews the Processor's technical and organizational measures before processing begins and regularly thereafter. Changes to the agreed security measures may be made provided they do not fall below the contractually agreed level of protection.
3. Confidentiality
The Processor and any persons it engages are prohibited from processing personal data without authorization. The Processor obliges all persons entrusted with the processing and fulfilment of this agreement to maintain confidentiality. The confidentiality obligations continue to apply after termination of this agreement or of the relationship between the engaged person and the Processor.
4. Information obligations of the Processor
In the event of disruptions, suspected data protection violations or breaches of the Processor's contractual obligations, suspected security incidents or other irregularities in the processing of personal data by the Processor, by persons engaged by it or by third parties, the Processor will inform the Controller without delay in writing or in documented electronic form, insofar as they relate to this agreement. The same applies to audits of the Processor by the data protection supervisory authority insofar as they relate to this agreement.
The notification of a personal data breach to the Controller will contain, where possible, the following information:
a) a description of the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
b) a description of the likely consequences of the breach; and
c) a description of the measures taken or proposed by the Processor to address the breach and, where appropriate, measures to mitigate its possible adverse effects.
The Processor takes the necessary measures without delay to secure the data and to mitigate possible adverse consequences for the data subjects, informs the Controller and requests further instructions.
Should the Controller's data held by the Processor be endangered by seizure or confiscation, by insolvency or composition proceedings or by other events or measures of third parties, the Processor will inform the Controller without delay unless prohibited by court or official order. In this context the Processor will inform all competent bodies without delay that the decision-making authority over the data lies exclusively with the Controller as "controller" within the meaning of the GDPR.
The Processor supports the Controller, where possible, with appropriate technical and organizational measures in fulfilling its obligations under Art. 12 to 22 (Art. 28 (3) (e) GDPR) and Art. 32 to 36 GDPR (Art. 28 (3) (f) GDPR). This includes in particular the automated handling of the Shopify privacy webhooks customers/data_request, customers/redact and shop/redact.
5. Control rights of the Controller
The Processor undertakes to provide the Controller, upon verbal, written or electronic request and within a reasonable period, with all information and evidence required to carry out a review of the Processor's technical and organizational measures.
Inspections by the Controller or its authorized auditors, who must not be in a competitive relationship with the Processor, may be carried out during normal business hours with 14 days' notice. The Controller conducts inspections only to the extent necessary and disrupts the Processor's operations only in a proportionate manner. The Processor may charge a fee for supporting an inspection. The fee is agreed individually.
6. Use of sub-processors
Personal data may only be processed in third countries in compliance with Art. 44 to 49 GDPR. The contractually agreed services or the partial services described below are performed with the involvement of the sub-processors listed in Annex 3. All sub-processors already engaged and approved by the Controller at the time of conclusion of this agreement are listed in Annex 3. The Controller grants general authorization to engage further sub-processors for the processing of Controller data. The Processor is obliged to inform the Controller of the engagement or replacement of sub-processors, whereby information in text form is sufficient. The Processor concludes comparable data processing agreements with all sub-processors. The Processor informs the Controller in writing at least 14 days in advance of any intended changes to this list by adding or replacing sub-processors, giving the Controller sufficient time to object before the sub-processor concerned is engaged (right to object pursuant to Art. 28 (2) sentence 2 GDPR). The right to object expires if the Controller has not objected in writing within 14 days of receipt of the notification. In the event of an objection, both parties have the right to terminate the main contract and this agreement with immediate effect by uninstalling the app.
A sub-processor relationship within the meaning of these provisions does not exist if the Processor engages third parties for services that are to be regarded as purely ancillary. These include, for example, postal, transport and shipping services, cleaning services, telecommunications services without a specific connection to services provided by the Processor for the Controller, and security services. Maintenance and testing services constitute sub-processor relationships requiring approval if they are provided for IT systems that are also used in connection with the provision of services for the Controller.
Services that the Controller operates or has commissioned itself and with which PopUplift exchanges data on the Controller's instruction are not sub-processors within the meaning of this agreement. This applies in particular to Shopify (Shopify International Limited or Shopify Inc.) as the Controller's store platform and to Klaviyo (Klaviyo, Inc.) as the email marketing system connected by the Controller. The data processing agreements between the Controller and the respective provider apply to these services.
7. Liability
The Controller and the Processor are liable towards data subjects in accordance with Art. 82 GDPR.
8. Termination of the main contract
After termination of the main contract (uninstallation of the app) or at any time upon the Controller's request, the Processor will return all documents, data and data carriers provided to it or, at the Controller's request and unless there is a statutory obligation to retain the personal data, delete them. This also applies to any backups held by the Processor. After uninstallation of the app, all store data is deleted automatically upon receipt of the Shopify webhook shop/redact, which is triggered 48 hours after uninstallation. The Processor keeps documented proof of the proper deletion of any remaining data.
The Processor is obliged to treat the data it has become aware of in connection with the main contract as confidential even after the end of the main contract. This agreement remains valid beyond the end of the main contract for as long as the Processor holds personal data provided by or collected for the Controller.
9. Final provisions
The parties agree that the Processor cannot assert any right of retention with respect to the data to be processed and the associated data carriers.
Amendments and supplements to this agreement must be made in writing or in documented electronic form.
Should individual provisions of this agreement be or become wholly or partially invalid or unenforceable, this does not affect the validity of the remaining provisions and the statutory provisions of Art. 28 GDPR apply.
This agreement is governed by Austrian law. The exclusive place of jurisdiction is Vienna, Austria.
The English version of this agreement is the original and authoritative version. Translations are provided for information only and are not legally binding.
Annexes:
Annex 1: Description of data subjects and data categories
Annex 2: Technical and organizational measures of the Processor
Annex 3: Sub-processors
Annex 1: Description of data subjects and data categories
Subject matter, nature and purpose of processing PopUplift is a Shopify app for displaying personalized popups in the Controller's online store. A script embedded in the store delivers popups (e.g. email quiz, spin to win, scratch card), records signups of shop visitors, creates discount codes via the Shopify API and transmits signup data to the Klaviyo account connected by the Controller. Purposes of processing: display and personalization of popups based on visitor behavior, collection of email addresses and opt-ins for the Controller's newsletter, creation and assignment of discount codes, synchronization of signups, quiz answers and segments to Klaviyo, measurement of opt-in rate and attribution of revenue to popups (revenue attribution), optimization of popup delivery using AI based on aggregated interaction data. Type of personal data Pseudonymous visitor ID, event data (popup impression, interaction, dismissal, signup), technical data (page URL, device type, browser, scroll depth, time on page), email address, opt-in status (single/double opt-in), quiz answers, assigned discount codes and redemption timestamp, order data from Shopify for revenue attribution (order number, order value, timestamp). Are special categories of personal data processed? No. The Controller is obliged to configure popups so that no special categories of personal data within the meaning of Art. 9 GDPR are requested. Categories of data subjects Visitors of the Controller's online store, newsletter subscribers of the Controller, customers of the Controller Retention period Event data: 180 days. Data of anonymous visitors without signup: 90 days. Signup data: duration of the app installation, deletion on the Controller's instruction or after uninstallation.
Annex 2: Technical and organizational measures (TOMs) of the Processor pursuant to Art. 32 GDPR, version dated September 1, 2026
PopUplift is operated on a cloud-first basis. The following technical and organizational measures are aligned with the state of the art, the nature, scope and risks of the processing and the security measures implemented by the cloud and platform providers used. Physical security measures for data centers are implemented exclusively by the cloud providers engaged.
1. Confidentiality
a. Physical access control
No own server rooms or data centers are operated
Physical access controls (e.g. access systems, video surveillance, security services, fire protection) are implemented by the data center and cloud providers engaged
Providers are selected on the basis of documented security measures and certifications
b. System access control
Personalized user accounts for all systems
Password policies (complexity, length)
Multi-factor authentication (MFA) for all critical systems (hosting, database, source code, domain and DNS)
Use of a password manager
Automatic screen locking
Access exclusively via approved cloud services
c. Data access control
Role-based and need-based access (strict need-to-know principle)
Merchants access only their own store's data via the Shopify admin authentication (App Bridge session)
Administrative rights limited to the necessary minimum
Logging of administrative activities
2. Integrity
a. Input and change control
Logging of creation, modification and deletion of personal data
Individual user identifiers (no shared accounts)
Protection and integrity of log files
Version control of all source code with full change history
b. Transfer control
Data transfers exclusively via encrypted connections (TLS/HTTPS) to approved cloud services; no physical data transport takes place
Use of approved interfaces only (Shopify API, Klaviyo API)
Webhook verification via HMAC signatures
3. Availability and resilience
Operation on highly available cloud infrastructure
Backup and recovery concepts within the cloud services used
Health checks and monitoring of the application
No own physical servers, UPS or air conditioning systems due to the cloud-first approach
4. Separation control
Logical tenant separation at application and database level (separation per store)
Separation of production, test and development environments
No use of real personal data in test systems
No physical separation on dedicated hardware (cloud architecture)
5. Pseudonymization and anonymization
Shop visitors are recorded exclusively via a pseudonymous visitor ID until signup
Personal data is deleted or anonymized once the purpose no longer applies (automated deletion periods: events 180 days, anonymous visitors 90 days)
Anonymization is applied where technically and operationally reasonable
6. Processor and sub-processor control
Sub-processors are engaged exclusively on a contractual basis
Data processing agreements (DPA) are concluded with all sub-processors
Providers are evaluated on the basis of their TOMs and certifications
7. Data protection and security management
Documented processes for handling data subject rights and for reporting data protection and security incidents
Automated handling of the Shopify privacy webhooks (customers/data_request, customers/redact, shop/redact)
Maintenance of a record of processing activities
8. Review and continuous improvement
Regular review of the TOMs
Event-driven review in the event of security incidents or changes to the processing
Continuous adaptation to new risks and technical developments
Annex 3: Approved sub-processors
Approved sub-processors pursuant to section 6 of this agreement:
Company Processing activity Processing location Supabase Pte. Ltd., 970 Toa Payoh North #07-04, Singapore 318992 Hosting of the Postgres database: popup configurations, visitor and event data, signup data, discount codes, aggregated metrics, background jobs Contracting entity in Singapore, database hosted on cloud infrastructure in the region selected by the Processor. Data Processing Addendum including EU Standard Contractual Clauses: https://supabase.com/legal/customer-resources/data-processing-addendum. Subprocessor list: https://supabase.com/legal/customer-resources/subprocessor-list Railway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USA Hosting of the app backend (API, admin app, widget delivery, background jobs) USA. Data Processing Agreement: https://railway.com/legal/dpa Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA DNS, CDN, DDoS protection, network security for popuplift.com and widget delivery. The IP address of the shop visitor is processed when the script is loaded USA. Data Processing Agreement: https://www.cloudflare.com/cloudflare-customer-dpa/ Cloudflare is certified under the EU-US Data Privacy Framework Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA Provision of AI technology (Claude API) for automatic popup creation and optimization of popup delivery. Aggregated interaction data and store content are processed, no email addresses USA. Data Processing Addendum including EU Standard Contractual Clauses (Module 2 and 3) OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland Provision of AI technology (OpenAI API) for automatic popup creation and optimization of popup delivery. Aggregated interaction data and store content are processed, no email addresses USA. Data Processing Addendum: https://openai.com/policies/data-processing-addendum including processor-to-processor Standard Contractual Clauses and complete subprocessor list: https://openai.com/policies/sub-processors/
Version dated: September 1, 2026