This Data Processing Addendum (“DPA”) forms part of the agreement between the merchant (“Controller”) and Avocado Blvd LLC, trading as Outside Projects, operator of Syncwright (“Processor”), and applies whenever Syncwright processes personal information on the merchant's behalf. Where terms are defined in the EU or UK GDPR, they carry the same meaning here.
Roles of the parties
The merchant is the Controller of its customers' personal information and Sync Right is the Processor, acting on the Controller's documented instructions. Each party is responsible for complying with the data protection laws that apply to it in that role.
Scope and subject matter
The subject matter of the processing is the synchronization of product, inventory, order, and customer data between the Controller's Lightspeed Retail R-Series account and its Shopify store. Processing lasts for as long as Syncwright is installed on the Controller's store, plus the short windows required to complete deletion after uninstall.
Details of processing
| Item | Detail |
|---|---|
| Categories of data subjects | The Controller's customers (shoppers whose orders or records are synced). |
| Types of personal data | Name, email address, phone number, and shipping and billing address. |
| Special categories | None. Syncwright does not process special-category data, payment card data, government identification, or credentials. |
| Nature and purpose | Matching customer records across the two systems, creating the sale and customer record in Lightspeed, and recording merchant-facing sync error logs. |
| Duration | For the term of the installation. Customer personal data is processed in flight and not stored at rest. |
Processing on instructions
Syncwright processes personal data only on the Controller's documented instructions, which include the settings and approvals configured in the app and these Terms, unless required otherwise by law (in which case we will inform the Controller where permitted). Syncwright will not use the Controller's customer personal data for marketing, advertising, resale, analytics, profiling, or any other secondary purpose. Personnel authorized to process the data are bound by confidentiality.
Subprocessors
The Controller authorizes Syncwright to engage subprocessors to provide the service. Our current subprocessors are Cloudflare (hosting and storage), Shopify and Lightspeed (the source platforms), Resend (transactional email to merchants), and, for the optional image-enrichment feature, SerpAPI and Claid (product images only). The full list, with purpose and location, is on our Subprocessors page. We impose data protection obligations on our subprocessors that are consistent with this DPA, and we remain responsible for their performance. We will give notice of a new or replacement subprocessor and, if the Controller reasonably objects on data protection grounds, the parties will work in good faith to resolve it.
Security measures
Syncwright maintains technical and organizational measures appropriate to the risk, including:
- Encryption of personal data in transit (TLS) and encryption at rest (Cloudflare D1);
- Connection credentials (OAuth tokens) stored as secrets and never written to logs;
- Data minimization: only the fields needed are read, and customer personal data is not stored at rest;
- Multi-factor authentication required for production infrastructure access;
- Access logging through Cloudflare Workers Observability;
- A written incident-response policy covering containment, notification, secret rotation, and post-incident review;
- Crypto-shredding of a store's stored credentials on uninstall.
Our full Security overview describes these measures in more detail.
Data-subject requests
Taking into account the nature of the processing, Syncwright will assist the Controller by
appropriate technical and organizational measures, insofar as possible, to respond to requests from
data subjects to exercise their rights. In practice, Syncwright honors Shopify's compliance
webhooks: customers/data_request is acknowledged (there is no customer personal data
stored at rest to export), customers/redact deletes the tenant-scoped sync metadata for
that customer, and shop/redact deletes all of the store's data. Each request is HMAC
verified and completed within 30 days.
Breach notification
Syncwright will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide the information the Controller reasonably needs to meet its own notification obligations. Our incident-response policy covers breach containment, merchant notification consistent with applicable law, rotation of affected secrets, and a post-incident review.
Deletion and return
Because customer personal data is processed in flight and not stored at rest, there is no standing
store of customer PII to return. On termination of the service, and on receipt of a
shop/redact request, Syncwright deletes all of the Controller's tenant data, including
stored sync metadata and connection credentials, unless retention is required by law.
Audit
Syncwright will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, on reasonable prior notice and subject to confidentiality, conducted no more than once per year unless required by a supervisory authority.
International transfers
Syncwright and its subprocessors operate internationally, including in the United States. Where personal data is transferred out of the EEA or the UK, the transfer is made under an appropriate safeguard, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this DPA by reference where they apply.
Contact
To raise a data protection matter or request a signed copy of this DPA, contact jonathan@outsideprojects.com or help@syncwright.io.