Data processing agreement
Effective date: 28 August 2026
This agreement sets out how MB Croppick, company code 308104331, registered office Krivių g. 5, LT-01204 Vilnius, Lithuania ("StatementClerk", "we", "us") processes personal data on behalf of the merchant that installs StatementClerk ("you"). It is the data processing agreement that Article 28 of the EU General Data Protection Regulation (GDPR) — and the UK GDPR, where that applies to you — requires between a controller and its processor. It forms part of the terms of service and should be read together with the privacy policy.
The short version
- You are the controller of your customers' data; we are your processor.
- It applies from the moment you install the app. There is nothing to sign.
- We process only what the app needs, only on your instructions — the app's settings and your use of it — and only through the sub-processors listed in the privacy policy, and we tell you 14 days before that list changes.
- If personal data is breached on our side, you hear from us within 72 hours.
- Uninstall, and everything is deleted.
1. Parties and roles
For the personal data described in section 3, you are the controller and StatementClerk is the processor. This agreement applies automatically when StatementClerk is installed on your Shopify store and needs no signature. If you install the app on behalf of a business you are authorised to act for, that business is the controller and this agreement binds it.
For your own account data — store domain, store name, your contact email, settings, plan and billing status — we are the controller, as the privacy policy explains; that data is outside this agreement.
2. Subject matter, duration, nature and purpose
- Subject matter: providing the StatementClerk app as described in the terms of service — computing account statements for your business (B2B) customers from your Shopify records, rendering them as PDFs and emails, and sending them on your schedule, together with optional before-due reminders.
- Duration: for as long as the app is installed on your store, plus the deletion period in section 7.
- Nature: reading records from Shopify, storing the ledger and statement data set out in the privacy policy, and sending email. Every figure is arithmetic over Shopify's own records; there is no profiling, no automated decision about any person, and no artificial-intelligence processing of any kind.
- Purpose: sending your customers statements of their account with you, in your name. Each email carries your store's name as the sender and your store's email address as the reply address, with a one-line "Sent with StatementClerk" note; the statement is your communication to your customer, not ours.
3. Personal data and data subjects
- Types of personal data: the names of your B2B companies and their locations (which can identify a person where the company is a sole trader); the email address of each company's billing contact, read from Shopify at the moment a statement or reminder is sent and not stored; any extra recipient email addresses you enter yourself in the app; and the ledger and statement data — order references, amounts, dates, what is outstanding — which describes a company's account with you and may relate to an identifiable person in the same sole-trader case.
- Categories of data subjects: your wholesale (B2B) customers and their staff — typically a bookkeeper or an accounts-payable contact.
- Nothing more: no special categories of data (health, beliefs and the like) are processed. The app does not store customer names, postal addresses, phone numbers or payment card details, and reads none of them from Shopify; apart from the billing contact's email address it reads only Shopify's internal identifiers for a contact.
4. Our obligations as processor
We will:
- Process only on your documented instructions. Installing the app, configuring it (schedule, recipients, templates, branding, review or automatic sending) and using it are your instructions; so is any written instruction you send to privacy@statementclerk.com. We do not process the data for any purpose of our own. If the law of the EU, of an EU member state or of the UK requires us to process it otherwise, we will tell you before doing so, unless that law forbids it.
- Tell you if an instruction would break the law. If we believe an instruction infringes the GDPR or other data-protection law, we will say so before acting on it.
- Keep it confidential. The only person with access to the data is the operator of MB Croppick, who is bound to confidentiality; there are no other staff or contractors with access.
- Keep it secure. We apply the measures described in the "Security" section of the privacy policy — encrypted Shopify tokens, TLS everywhere, verified webhook signatures, read-only Shopify permissions, PDFs served only through authenticated signed links, two-factor authentication and access limited to the operator on every account behind the service — and review them at least every six months.
- Use only the listed sub-processors. The sub-processors we use, and what each processes, are listed in the privacy policy; you authorise those. Before any new sub-processor starts processing your data we update that list and notify you in the app or by email at least 14 days in advance. If you object, you may uninstall before the change takes effect, and the deletion in section 7 follows. Each sub-processor that handles the data covered by this agreement is bound by a written agreement imposing data-protection obligations at least as protective as this one, and we remain responsible to you for their performance. Email you send us is read in Gmail (see the privacy policy); please keep your customers' personal data out of email where you can — the app and Shopify's privacy webhooks are the channels built for it.
- Help you with data-subject requests — section 5.
- Help you with security, breaches and impact assessments — sections 5 and 6.
- Delete the data at the end — section 7.
- Show you that we comply — section 8.
You, as controller, are responsible for having a lawful basis to email statements to your customers, for the instructions you give us being lawful, and for telling your own customers what you do with their data where the law requires it.
5. Assistance with data-subject rights and your own obligations
Requests from the people who receive statements — access, correction, erasure, restriction, objection, portability — are yours to answer as the controller. We assist as follows:
- Shopify's mandatory privacy webhooks are the automated path. When a
customer asks your store for their data, Shopify sends us
customers/data_request; we record it, and since we hold no email address, name, postal address or phone number for any customer, the answer is usually that everything we have about the person is already visible to you in the app and in Shopify. When a customer asks for erasure, Shopify sendscustomers/redactand we remove our reference to that contact automatically. - For anything the webhooks do not cover, write to privacy@statementclerk.com; we will provide what we hold promptly and in any case in time for you to meet the one-month deadline the GDPR gives you.
- On request, and taking into account what we know as your processor, we will help you meet your obligations on security, breach notification, data-protection impact assessments and prior consultation with a supervisory authority.
6. Personal data breach
If we become aware of a personal data breach affecting data processed under this agreement, we will notify you without undue delay and no later than 72 hours after becoming aware, at your store's contact email. The notice describes what happened, which data and which customers are affected as far as we know, what we have done about it and what we recommend you do, and is updated as we learn more. Whether to notify your supervisory authority and your customers, where the law requires it, is your decision as controller; we give you what you need to make it.
7. Deletion at the end of the service
When you uninstall StatementClerk, our access to your store ends at once.
About 48 hours later Shopify sends the standard deletion signal
(shop/redact) and, on it, we delete every database record and every PDF
for your store — the ledger, the companies, the statements, the delivery
and audit logs, and any feedback you sent. Nothing is retained, except
where the law requires us to keep a copy, in which case we keep only that
copy, for only as long as required, and process it for no other purpose.
Statements already emailed remain with the people who received them. If you want your own copy of a statement, download its PDF from the app before you uninstall.
8. Information and audits
On request we make available the information needed to demonstrate that we meet the obligations in Article 28 of the GDPR: this agreement, the privacy policy, and the data-processing terms of our sub-processors. Where that is not enough, you — or an auditor you appoint who is not a competitor of ours and is bound to confidentiality — may audit our processing on at least 30 days' written notice, during business hours, at your own cost, no more than once in any 12-month period. The notice and frequency limits do not apply where a supervisory authority requires an audit or a personal data breach has occurred.
9. Where the data is processed and international transfers
The data is stored on Cloudflare's platform in Cloudflare's Eastern Europe region and is processed in transit by Cloudflare's global network, as with any Cloudflare-hosted service. In the running of the service, Cloudflare is the only sub-processor that handles the personal data covered by this agreement; its processing is covered by Cloudflare's data-processing addendum, which incorporates the EU standard contractual clauses for any transfer outside the EU/EEA. We do not transfer the data anywhere else, and we will not without a lawful transfer mechanism and the notice in section 4.
10. Term, precedence and law
This agreement applies for as long as the app is installed and until the deletion in section 7 is complete. Where it conflicts with the terms of service on a data-protection matter, this agreement prevails. It is governed by the law of the Republic of Lithuania, like the terms.
Changes to this agreement
If this agreement changes materially, we will note it here with a new effective date and flag it in the app.
Contact
privacy@statementclerk.com — or support@statementclerk.com for anything else.