Data Processing Agreement
Version 2026-09-23 · Fixed annex to the Terms of Service
1. Parties and scope
Data controller: the customer that accepts the Terms of Service. Data processor: KDI ApS, Danish company registration number (CVR) 46525892, Thors Allé 1, 4673 Rødvig Stevns, Denmark.
This agreement governs the personal data the processor processes on the controller's behalf when providing Recortex, as described in Annex A, in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 (GDPR). How the processor handles personal data as controller — accounts, sign-in, its own correspondence — is described in the Privacy Policy and is not covered here.
2. Instructions
The processor processes the personal data only on documented instructions from the controller: this agreement, the Terms of Service, Annex C, and the controller's own choices in Recortex (which systems it connects, which accounts it selects, what it writes in its Playbook). The processor informs the controller immediately if, in its opinion, an instruction infringes the GDPR or other data protection law.
3. Confidentiality
Only persons who need access to provide Recortex have access to the personal data, and they are bound by confidentiality.
4. Security
The processor implements the technical and organisational measures in Annex C, appropriate to the risk (GDPR Article 32).
5. Sub-processors
The controller gives general authorisation for the sub-processors in Annex B. The processor notifies the controller by email at least 30 days before adding or replacing a sub-processor. The controller may object within that period; if the parties cannot agree, the controller may end the agreement before the change takes effect. The processor imposes the same data protection obligations on each sub-processor by contract and remains responsible to the controller for them.
6. Transfers to third countries
Personal data is transferred outside the EU/EEA only as set out in Annex B, on the basis of the EU Standard Contractual Clauses in the relevant sub-processor's data processing agreement.
7. Assistance
Taking into account the nature of the processing, the processor assists the controller with requests from data subjects (GDPR Articles 12–23) and with its obligations under Articles 32–36, including by passing on without delay any request it receives directly.
8. Personal data breaches
The processor notifies the controller without undue delay after becoming aware of a personal data breach, with the information the controller needs to meet its own obligations (GDPR Article 33(3)), and keeps the controller informed as more becomes known.
9. Deletion at the end of the agreement
When the agreement ends, the processor deletes all personal data processed for the controller within 30 days, unless law requires it to be kept. The controller may ask for its data to be returned before then. Deleted data can remain in the hosting provider's daily backups for up to 7 days.
During the agreement, figures computed from connected systems are kept for 24 months and then deleted, and a Shopify store's data is deleted within 30 days after Recortex is uninstalled in Shopify †. A connection error, an expired access or a disconnected system does not end the agreement.
10. Audit and information
The processor makes available the information necessary to demonstrate compliance with this agreement. The controller, or an auditor it appoints who is bound by confidentiality, may carry out an inspection with reasonable notice, at the controller's cost, no more than once a year unless a breach gives reason to.
11. Term, liability and law
This agreement applies for as long as the processor processes personal data for the controller. Liability follows the Terms of Service. Danish law applies, and disputes are settled by the Danish courts.
Annex A. The processing
† Shopify, Meta and e-conomic cannot be connected yet. The processing below that concerns them applies from the day each becomes available.
Purpose. To show the controller whether its marketing pays for itself and to propose actions, from figures read from the systems it connects and from what it writes in its Playbook.
Nature. Reading (read-only) from connected systems, summing into daily and monthly figures, storing those figures, computing findings and proposed actions, displaying them to the controller's users, and — for recommendations built on Shopify figures — having their wording phrased by a sub-processor (Annex B). No automated decisions about individual people, no profiling, no sale of data, no training of AI models.
| Data subjects | Personal data | Kept |
|---|---|---|
| The controller's own customers (via Shopify orders) | Per order: amounts, quantities, discounts, refunds, tax rates, currency, dates and the order id. No names, email addresses, phone numbers, addresses or product details are requested. | Only totals per day. Individual orders and order ids are handled in memory while reading and not stored. |
| The controller's staff (via e-conomic, when available) | The name and email address of the signed-in e-conomic user, and booking texts, which can name people — returned by e-conomic without being requested. | Not stored: read while handling a request. Only monthly totals of the accounts the controller selects are kept. |
| People the controller's users mention in the Playbook | Whatever free text the controller's users write. The controller is asked not to enter personal data about others. | Until the controller changes it, and at the latest until the agreement ends (+30 days). |
Meta ad data is account-level (spend and the purchase value Meta attributes to its own ads, per day) and contains no personal data; it is not yet available.
Duration. For the term of the Terms of Service, and until deletion under section 9.
Annex B. Sub-processors
| Sub-processor | What for | Where |
|---|---|---|
| SupabaseSupabase, Inc. | Database, encrypted credential store, sign-in and sign-in emails, background processing | Data stored in Frankfurt, Germany (EU) |
| VercelVercel Inc. | Website and application hosting | Application functions in Frankfurt, Germany (EU); requests pass through Vercel's global network |
| AnthropicAnthropic Ireland, Limited or Anthropic, PBC (according to Anthropic's Commercial Terms) | Plain-language wording of recommendations built on Shopify figures, from those figures and the customer's Playbook answers. No data from Meta or e-conomic. | Stored in the United States; may be processed in the United States, Europe, Asia and Australia (EU Standard Contractual Clauses) |
Annex C. Instructions and security measures
† Shopify, Meta and e-conomic cannot be connected yet. The measures marked † concern those connections and apply from the day each becomes available.
- Read-only access to connected systems; nothing is ever written to them. †
- Data minimisation: only the fields listed in Annex A are requested; figures are stored as daily or monthly totals. †
- Data from Meta and e-conomic is never sent to an AI service. † Text sent to the AI sub-processor is checked for identifier patterns (email addresses, identification numbers, account and token formats) and not sent if one is found.
- Encryption in transit (TLS) everywhere; database storage encrypted at rest by the hosting provider.
- Access credentials for connected systems are stored in a separate encrypted store readable only by the service itself, and are deleted at once on disconnect or uninstall. †
- Each customer's data is isolated from every other customer's by the database's own row-level security, not only by the application.
- No access credential is written to the processor's own logs or error records, and none travels in a web address. †
- The 24-month period in section 9 is enforced by a scheduled job; deletion at the end of the agreement is carried out by the processor within the 30 days.