Trust & legal
Data Processing Agreement
Last updated 2026-07-20
This Data Processing Agreement ("DPA") forms part of the BlendBadger Terms of Service between Andes Trade EOOD, D-R Hristo Momchilov 1, Elena 5070, Bulgaria, VAT BG203691176 ("BlendBadger", the "Processor") and the customer accepting the Terms (the "Customer", the "Controller"). It applies whenever BlendBadger processes personal data on the Customer's behalf and implements Article 28(3) of Regulation (EU) 2016/679 ("GDPR"). No signature is required — the DPA is incorporated into the Terms by reference; on request to [email protected] we will countersign a copy.
1. Subject matter and roles
For personal data contained in the store, order and advertising data the Customer connects to BlendBadger — including data Shopify classifies as Protected Customer Data — the Customer is the controller and BlendBadger is the processor. (For the Customer's own account data — name, email, billing details — BlendBadger is an independent controller as described in the Privacy Policy; that processing is outside this DPA.)
2. Details of processing (Art. 28(3), first sentence)
| Subject matter & nature | Ingestion, normalization, pseudonymization (one-way hashing of customer identifiers at ingestion), storage and analytical processing of e-commerce and advertising data to compute profit and efficacy analytics. |
| Purpose | Providing the BlendBadger service to the Customer, as described in the Terms — and no other purpose. |
| Duration | The term of the Customer's account, plus the deletion windows in section 8. |
| Types of personal data | Pseudonymized (SHA-256 hashed) customer identifiers; coarse order geography (country, province/state, postal code); order and transaction metadata; third-party personal data appearing on invoices the Customer uploads. Raw customer names, emails, phone numbers and street addresses are never stored. |
| Categories of data subjects | The Customer's own customers (buyers), and suppliers named on uploaded expense documents. |
3. Documented instructions (Art. 28(3)(a))
BlendBadger processes personal data only on the Customer's documented instructions — constituted by the Terms, this DPA, the Customer's configuration of the service (which platforms are connected, which features are enabled) and any further written instructions — including with regard to transfers to third countries, unless required to process by EU or member-state law; in that case BlendBadger informs the Customer of the legal requirement before processing, unless the law prohibits it. BlendBadger will immediately inform the Customer if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality (Art. 28(3)(b))
BlendBadger ensures that every person authorized to process the personal data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality. Access is restricted to personnel who need it for their role, per the least-privilege model in our Privacy Policy and information-security policy.
5. Security (Art. 28(3)(c), Art. 32)
BlendBadger implements the technical and organizational measures appropriate to the risk, including: TLS 1.2+ for all data in transit; encryption at rest; sealed-box (libsodium) encryption for platform access tokens; pseudonymization of customer identifiers at ingestion with raw values discarded; EU-hosted infrastructure with network segmentation, firewalling, intrusion prevention and malware scanning; role-based access control with MFA for administrative access; audit logging; and a tested backup and restore procedure (14 daily + 8 weekly encrypted backups, maximum age 56 days). Details are in the security documentation summarized in the Privacy Policy.
6. Sub-processors (Art. 28(2), 28(3)(d), 28(4))
The Customer grants a general written authorization for the sub-processors listed in Privacy Policy section 4. BlendBadger will notify account holders at least 14 days before adding or replacing a sub-processor; the Customer may object on reasonable data-protection grounds before the change takes effect, and may terminate the affected service if the objection cannot be resolved. BlendBadger imposes on every sub-processor, by contract, data-protection obligations no less protective than this DPA, and remains fully liable to the Customer for the sub-processor's performance.
7. Assistance (Art. 28(3)(e) and (f))
-
Data-subject requests: taking into account the nature of the
processing, BlendBadger assists the Customer with appropriate technical and
organizational measures in fulfilling the Customer's obligation to respond to
data-subject requests under GDPR Chapter III — including automated honoring of
Shopify's
customers/data_requestandcustomers/redactwebhooks, in-app export and deletion, and support at [email protected]. Requests received directly from data subjects are forwarded to the Customer without undue delay. - Security, breach notification and DPIAs: BlendBadger assists the Customer in ensuring compliance with Articles 32–36. BlendBadger notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information required by Art. 33(3) as it becomes available, and provides reasonable assistance with data protection impact assessments and prior consultations.
8. Deletion and return (Art. 28(3)(g))
On termination of the service — or earlier, when the Customer disconnects a platform connection — BlendBadger deletes the associated personal data within 30 days, per the retention table in Privacy Policy section 5; encrypted backups roll off within 56 days. Before deletion, the Customer can export its data in machine-readable formats at any time (the "return" route). BlendBadger retains only what EU or Bulgarian law requires (billing and accounting records) and deletes it when the statutory period ends.
9. Audits (Art. 28(3)(h))
BlendBadger makes available to the Customer all information necessary to demonstrate compliance with Article 28 — including the security documentation referenced above — and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits require 30 days' written notice, occur at most once per 12 months (except after a personal data breach or at a supervisory authority's direction), respect the confidentiality of other customers' data, and are at the Customer's expense.
10. International transfers
Processing occurs on EU-hosted infrastructure. Where a sub-processor outside the EEA is engaged, transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where available, the EU-US Data Privacy Framework, as listed per sub-processor in Privacy Policy section 4.
11. Liability, precedence and law
Liability under this DPA is subject to the limitations in the Terms, except where GDPR mandates otherwise. If this DPA conflicts with the Terms, this DPA prevails for data-protection matters. This DPA is governed by the law specified in the Terms; mandatory provisions of the GDPR and Bulgarian data-protection law are unaffected.
Questions
Email [email protected]. See also our Privacy policy, Terms of service and Data deletion pages.