Última atualização: 2026-08-31
O texto em inglês que se segue é a versão vinculativa deste acordo; esta nota é uma cortesia.
This Data Processing Agreement (“DPA”) supplements the Combora Terms of Service wherever applicable data protection law (in particular the EU General Data Protection Regulation, “GDPR”) requires a documented agreement between us regarding the processing of personal data. Where this DPA applies, you (the merchant) act as Controller and we (Combora) act as Processor, processing personal data only as described below.
Our Privacy Policy already discloses that Combora does not collect or process any shopper personal data — no IP addresses, names, emails, or browsing identifiers. The personal data actually processed under this DPA is limited to: (a) your own store's account and contact information, already described in the Privacy Policy (shop domain, access session, plan and configuration); and (b) any personal data — such as a name, email address or message content — that you or your staff voluntarily submit through the in-app support chat.
We process personal data covered by this DPA only to operate the Service and provide support, and only on your documented instructions — the Terms of Service and your ordinary use of the Service — unless we are required to do otherwise by EU or Member State law, in which case we will inform you of that legal requirement before processing, unless the law prohibits this.
We ensure that anyone authorized to process personal data covered by this DPA is bound by an appropriate duty of confidentiality.
We apply appropriate technical and organizational measures to protect personal data, including encryption of data in transit, access controls limited to what operating the Service requires, and the retention and deletion schedules already described in the Privacy Policy (e.g. the 30-day purge of technical error logs and the 90-day purge of closed support conversations).
We use the following sub-processors to operate the Service: Vercel (hosting), Supabase (database), Resend (email delivery for support chat transcripts), and Shopify itself (the source platform). You give us general authorization to use these sub-processors. If we add or replace a sub-processor in a way that materially changes this list, we will note it on this page and, where reasonably possible, notify you through the app or by email in advance.
Vercel and Resend are US-based providers. Where personal data covered by this DPA is transferred to them, that transfer relies on the safeguards available under EU data protection law at the time — such as the providers' EU-U.S. Data Privacy Framework certification and/or Standard Contractual Clauses. We will provide details of the applicable safeguard on reasonable written request.
We implement Shopify's mandatory privacy webhooks: a customer data request returns nothing to return, because we hold no shopper personal data, and a shop redaction erases your store's records from our systems within 48 hours. For personal data covered by clause 2(b), we will assist you in responding to a data subject request on reasonable request.
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process under this DPA.
On termination — uninstalling the app — personal data covered by this DPA is deleted per the Terms of Service (within 48 hours of Shopify's shop-redaction webhook), unless EU or Member State law requires that we keep it.
We will make available the information reasonably necessary to demonstrate compliance with this DPA. Given the scale of our operation, this is provided as relevant documentation on reasonable written request rather than as an on-site audit; we will discuss a different arrangement in good faith if you have a specific, documented compliance requirement that this does not satisfy.
12.1 This DPA is subject to the limitation of liability and the governing law and jurisdiction clauses of the Terms of Service. 12.2 If this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails to the extent required by applicable data protection law. 12.3 If a clause is held invalid, the rest remains in force. 12.4 We may update this DPA for the same reasons and in the same way as the Terms of Service. 12.5 The English text of this DPA is the only binding version; translations of this page, where offered, are a courtesy.
Dúvidas sobre este acordo? Escreva para support@combora.app.