Agreement version 2026-07-22

Data Processing Agreement.

These controller-processor terms govern customer personal data handled by Emberex Review Carousel on a Shopify merchant's instructions. Acceptance is recorded with the shop, time, version and a keyed pseudonymous administrator reference.

Parties and instructions

The Shopify merchant is the controller and Emberex is the processor for customer data handled through the service. The merchant instructs Emberex to import, verify, moderate, publish, secure, retain and delete review data as configured in the app and described in the Privacy Policy.

Processing details

  • Subject: review import, submission, verification, moderation and display.
  • Duration: while the merchant uses the service, subject to the published retention schedule.
  • People: merchant staff, reviewers and verified Shopify customers.
  • Data: review content, public attribution, product and order-verification references, merchant-enabled storefront-submission email, and security and audit metadata.

Emberex obligations

  • Process customer data only on documented merchant instructions or as required by law.
  • Ensure anyone authorised to process the data is bound by confidentiality obligations.
  • Apply data minimisation, encryption, private networking, environment separation, access control, audit logging, backup and tested deletion controls.
  • Assist with customer rights requests through Shopify compliance webhooks and merchant support.
  • Notify the merchant without undue delay after confirming a personal-data breach affecting that merchant.
  • Delete shop-owned data following uninstall, redaction or the retention schedule.

Subprocessors

The merchant authorises Railway to host application, database, log and encrypted backup data, and Shopify to provide the platform and authenticated API context. Etsy participates only when the merchant separately authorises an Etsy source. Emberex remains responsible for requiring appropriate data-protection commitments from subprocessors.

International transfers

Where a provider processes data outside the United Kingdom, Emberex relies on the provider's applicable contractual and legal transfer safeguards. Details are available from the relevant provider's trust or privacy documentation.

Security incidents and audit information

Emberex maintains documented detection, containment, evidence, recovery, notification and post-incident procedures. On reasonable request, Emberex will provide information needed to demonstrate these obligations without exposing another merchant's data or weakening service security.

Return, deletion and conflict

The merchant can export supported review data before uninstalling. After termination, Emberex deletes shop-owned data under the published lifecycle and backup-retention process unless law requires retention. If this agreement conflicts with the general product terms on personal data processing, this agreement controls.