This is a working draft prepared by Vibel for customer and internal review. It has not yet been reviewed by qualified legal counsel and should not be treated as a final, lawyer-approved agreement. If you need a signed copy for procurement, contact us at the address below and we will work through it with you.
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Vibel Terms of Service (the “Main Agreement”) between the merchant using Vibel (“Customer,” “you”) and HAVA EXPORT B.V., trading as Vibel (“Vibel,” “we”), a company registered in the Netherlands [registered address to complete] [Chamber of Commerce (KVK) number to complete]. It applies whenever Vibel processes personal data on Customer's behalf as described in Article 28 of the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR.
1. Parties and roles
For personal data that Customer's own store and customers generate (order, customer, and store data read from Shopify and any tool Customer chooses to connect), Customer is the data controller and Vibel is the data processor, processing that data only to provide the Service and only on Customer's instructions as set out in this DPA. For Customer's own account and billing data, Vibel is an independent controller, as explained in the
Privacy Policy.
2. Subject matter and duration
The subject matter of this DPA is Vibel's processing of personal data in order to provide the operations and analytics platform described in the Main Agreement. Processing lasts for the term of the Main Agreement. On termination, Vibel deletes or returns Customer's data as described in Section 12 below.
3. Nature and purpose of processing
Vibel reads data from Shopify and from any additional source Customer chooses to connect (see Section 6), normalizes it, and uses it to compute analytics, run the watcher engine that flags issues needing attention, generate drafted actions and reports, and respond to support requests. Processing is limited to what these features need. Vibel does not use Customer's data for its own marketing, does not sell it, and does not use it to train third-party AI models.
4. Types of personal data and categories of data subjects
Types of personal data:order and customer records read from Shopify (name, email, address, order history), account data about Customer's own users (name, email), performance and reporting data from any connected marketing, analytics, support, or accounting tool, mailbox content read over IMAP if Customer connects an inbox (sender, recipient, subject, and body of messages in the folders Customer authorizes), and usage and diagnostic data generated by using the Service.
Categories of data subjects:Customer's end customers (people who place orders on Customer's store), Customer's own personnel who use Vibel, and, where Customer connects a mailbox, the senders and recipients of email in that mailbox.
5. Controller instructions
Vibel processes personal data only on Customer's documented instructions, which consist of: the Main Agreement, this DPA, Customer's configuration of the Service (which sources to connect, which features to enable), and any additional written instruction Customer gives us. If Vibel believes an instruction would infringe GDPR or another applicable data protection law, we will tell Customer before carrying it out.
6. Confidentiality of personnel
Vibel ensures that anyone authorized to process personal data under this DPA, whether an employee or contractor, is bound by an obligation of confidentiality, contractual or statutory, and is only given access to the personal data needed for their role.
7. Security measures
Vibel applies the following technical and organizational measures, described in full on our
Security page:
Encryption in transit: all traffic between the browser, Vibel, and every connected platform uses TLS.
Secrets isolation: OAuth tokens, refresh tokens, and API keys are stored in Supabase Vault, an encrypted secrets store, and are referenced elsewhere only by an opaque id. They are never stored in application database tables, never sent to the browser, and never logged.
Tenant isolation:every table is protected by Postgres row-level security scoped to the owning brand, so one customer's data cannot be read through another customer's account.
Read-only mailbox access: when Customer connects a mailbox over IMAP, Vibel uses a connector that only connects, lists folders, and fetches messages. It never issues a delete, move, flag-change, or append command against the mailbox.
Access control and audit logging:production data access is restricted to authorized personnel for support, security, and legal compliance purposes only. Mutating actions taken through the Service's command layer are recorded in an append-only audit log.
Least privilege: Vibel requests only read-only, or the narrowest available, scopes from every connected platform.
8. Sub-processors
Customer gives Vibel general authorization to engage sub-processors to help provide the Service. The current list, with each sub-processor's purpose and the region it processes data in, is published at
getvibel.com/subprocessors. Vibel imposes data protection obligations on each sub-processor that are equivalent to those in this DPA, and remains responsible to Customer for a sub-processor's performance of those obligations. Vibel will give notice before adding a new sub-processor, as described on that page, so Customer can object on reasonable data protection grounds.
9. International transfers
Some sub-processors process data in the United States. Where Vibel transfers personal data originating in the EEA or UK to a country without an adequacy decision, it relies on the EU Standard Contractual Clauses (or the UK International Data Transfer Addendum, as applicable) that the relevant sub-processor has in place, or another valid transfer mechanism under GDPR Chapter V.
10. Assistance with data subject rights
Because Customer is the controller for its store and customer data, requests from Customer's own customers (access, correction, deletion, objection) should go through Customer. Vibel supports this in two ways: as a Shopify app, Vibel implements Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact), described in the
Privacy Policy; and Vibel will otherwise give Customer reasonable assistance, taking into account the nature of the processing, in responding to a request Customer receives, at Customer's cost if the request requires material engineering work.
11. Personal data breach notification
If Vibel becomes aware of a personal data breach affecting Customer's data, we will notify Customer without undue delay, and in any case within 72 hours where GDPR requires it, describing the nature of the incident, the data and data subjects likely affected, and the steps taken or planned. Our incident response process is described on the
Security page.
12. Deletion and return of data on termination
On termination of the Main Agreement, or earlier on Customer's request, Vibel deletes Customer's personal data from production systems on the schedule described in the
Privacy Policy and
Data Deletion page, currently: 48 hours after uninstall (Shopify's shop/redact webhook), or immediately on account deletion, unless Vibel is required by law to retain specific records. Customer can request an export of its own account data before deletion by contacting us.
13. Audit and information rights
Vibel will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including the Security and Sub-processors pages referenced above. On reasonable written notice, and no more than once per year unless required by a supervisory authority or following a breach, Vibel will answer a reasonable written audit questionnaire or, where that is not sufficient, allow Customer or its appointed auditor to carry out an on-site or remote audit during business hours, subject to confidentiality and not disrupting Vibel's operations or other customers.
14. Liability
Liability under this DPA follows the limitation of liability set out in the
Terms of Service. Nothing in this DPA limits liability that cannot be limited by applicable law.
15. Governing law
This DPA is governed by the laws of the Netherlands, matching the governing law of the Main Agreement.
Contact
Questions about this DPA, or to request a signed copy: post@stephancolen.nl.