This agreement forms part of the terms between NDA CRM ("the processor") and the merchant using the app ("the controller"). It applies automatically when the app is installed; no signature is required, though we will sign a copy on request.
The merchant determines why and how their customers' personal data is processed and is the controller. NDA CRM processes that data solely to provide the service and only on the merchant's documented instructions, which include the configuration chosen inside the app.
Processing lasts as long as the app is installed, plus the retention periods set out below. On uninstall, store access tokens are deleted immediately.
Data subjects: the merchant's customers and the people who place orders with them. Categories: name, phone number, email address, delivery and billing address, order contents and totals, parcel and tracking status, call notes and message history.
The merchant gives general authorisation for the sub-processors listed in our Privacy Policy. We impose the same data protection obligations on each of them. If we add or replace a sub-processor, we notify merchants by email at least 30 days in advance, and a merchant who objects on reasonable data protection grounds may terminate without penalty.
| Measure | How |
|---|---|
| Encryption in transit | TLS on every connection, to the app and to every supplier API |
| Encryption at rest | Platform-level encryption, plus AES-GCM encryption applied by us to all supplier credentials, with the master key held separately from the database |
| Backups | Managed and encrypted by the infrastructure provider |
| Tenant isolation | Every stored record is namespaced per workspace and the boundary is enforced server-side on each request |
| Test separation | Workspaces marked as test write under a separate namespace and never share storage with production data |
| Access control | Roles and departments enforced on the server; a request outside a user's departments is refused, not merely hidden |
| Authentication | Passwords hashed with PBKDF2; minimum ten characters, mixed character classes, common and breached passwords rejected |
| Access logging | Reads of personal data are recorded with user, route, time and IP; the log records the access, not the content |
| Retention | Automatic deletion once the periods in section 7 pass, with the result written to the audit log |
| Loss prevention | Credentials never leave the server in readable form; the app returns no supplier secret to the browser; exports are limited to the merchant's own workspace and are logged |
| Category | Kept for |
|---|---|
| Parcels and orders | 24 months |
| Call records and conversations | 12 months |
| Access log | 12 months |
| Audit log | 24 months |
| Privacy requests received from Shopify | 90 days |
Deletion runs automatically each day. A merchant may request earlier deletion at any time.
On reasonable notice and no more than once a year, we will answer a written security questionnaire and provide the documentation we hold. We have not yet completed an external certification such as SOC 2 or ISO 27001; when that changes, this section will say so with the date.
If we become aware of a personal data breach, we notify the affected merchants without undue delay and in any case within 72 hours, with the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken.
Data is processed on infrastructure located in the European Union. Where a merchant connects a supplier outside the EU — a messaging or courier provider of their choosing — that transfer is made on the merchant's instruction and under that provider's own terms.