This Data Processing Agreement (“DPA”) is between the merchant using Popify (“Controller”) and Importify Ltd, Hagana 40/34, Givatayim, Israel 5348813, provider of the Popify service (“Processor”). It forms part of the terms under which the Controller uses Popify (the “Service”) and applies for as long as the Processor processes personal data for the Controller.
1. Scope and roles
- Terms such as “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the meanings given in Regulation (EU) 2016/679 (“GDPR”).
- “Customer Personal Data” means the personal data of the Controller’s store visitors and customers that the Processor processes to provide the Service, as described in Annex 1.
- The Controller is the controller of Customer Personal Data and the Processor is its processor.
- Account, billing and contact data of the Controller itself is not covered by this DPA. The Processor handles it as a controller under the Popify privacy policy.
2. Processor obligations
The Processor shall:
- process Customer Personal Data only on the Controller’s documented instructions, including for transfers outside the EEA, unless the law requires otherwise, in which case it will inform the Controller first where the law allows. Installing and configuring the Service is the Controller’s instruction;
- tell the Controller if it believes an instruction infringes data protection law;
- ensure that everyone authorised to process Customer Personal Data is bound by confidentiality;
- apply the security measures in Annex 2;
- help the Controller, as far as reasonably possible, to respond to requests from individuals exercising their rights, and forward to the Controller any such request it receives directly;
- help the Controller meet its obligations on security, breach notification and data protection impact assessments, taking into account the information available to the Processor;
- not sell Customer Personal Data or use it for its own purposes.
3. Controller obligations
- The Controller is responsible for having a lawful basis for the processing and for informing its own visitors and customers, including about the cookies and browser storage the Service uses, that details of recent orders and reviews are shown in popups on its store, and that the Service loads fonts and script libraries from third-party networks in the visitor’s browser.
- The Controller decides what its popups display and which forms and push notifications it uses. It is responsible for that content and for any consent needed to collect contact details or to send messages.
- The Service is not designed for special categories of personal data (GDPR Article 9), and the Controller will not use it to process them.
4. Subprocessors
- The Controller authorises the Processor to use the subprocessors listed in Annex 3.
- The Processor will inform the Controller by email before adding or replacing a subprocessor. The Controller may object within 14 days. If the objection cannot be resolved, the Controller may stop using the Service.
- The Processor binds each subprocessor to data protection obligations equivalent to this DPA and remains responsible for its performance.
5. International transfers
- The Processor is established in Israel, which the European Commission recognises as providing adequate protection (Decision 2011/61/EU).
- Customer Personal Data is hosted in the United States by the subprocessors in Annex 3. These transfers rely on the subprocessor’s certification under the EU-US Data Privacy Framework or on the European Commission’s Standard Contractual Clauses.
6. Personal data breaches
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will share the information the Controller needs to meet its own obligations.
7. Information and audits
The Processor will make available the information needed to show compliance with this DPA. The Controller, or an independent auditor bound by confidentiality, may audit that compliance once a year on 30 days’ written notice, at the Controller’s cost and without unreasonably disrupting the Processor’s business.
8. Return and deletion
After the Controller stops using the Service, the Processor will delete or return Customer Personal Data, at the Controller’s choice, within 30 days of the Controller’s written request to support@popify.app, unless the law requires it to be kept.
9. General
- If this DPA conflicts with the terms that govern the Service, this DPA prevails on data protection matters.
- Liability under this DPA is subject to the limits in the terms that govern the Service, except where the law does not allow liability to be limited.
This DPA applies to every merchant using Popify without the need for a signature. A copy signed by Importify Ltd is available on request from support@popify.app.
Annex 1: Details of the processing
| Item | Description |
|---|---|
| Purpose | Showing popups and notifications on the Controller’s store (recent orders, add to cart activity, visitor counts, reviews, offers), collecting the contact details visitors submit in popup forms, sending web push notifications where the Controller uses them, and reporting results to the Controller. |
| Duration | While Popify is installed on the Controller’s store, and until deletion under section 8. |
| Individuals | Visitors and customers of the Controller’s store, people who submit a popup form, and reviewers. |
| Personal data | A visitor identifier kept in cookies and browser storage, the pages on which popups are shown, IP address and browser type. Order data received from the store platform, which can include the customer’s name, contact details and address, the products ordered and the amounts. Add to cart events with IP address and approximate location. Name, email address and phone number entered in a popup form. Web push subscription details and cart contents. Reviewer name, location, rating and review text received from the Controller’s reviews app. |
| Special categories | None. |
Annex 2: Security measures
- All connections to the Service use HTTPS.
- Access to the server and the database is limited to two named administrators, over encrypted connections (SSH).
- The server and database are backed up regularly by the hosting provider.
- Payment card data is handled by the billing providers and never reaches Popify.
Annex 3: Subprocessors
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Cloudways Ltd | Managed hosting | All Customer Personal Data | Malta |
| DigitalOcean LLC | Cloud servers | All Customer Personal Data | United States (New York region) |
| Cloudflare, Inc. | Network security and delivery | Requests to the Service, including IP address | United States, global network |
| AC PM LLC (Postmark) | Emails that tell the Controller about a new popup form submission | Email address submitted in the form, page and device type | United States |
Shopify, Wix and WooCommerce are the Controller’s own store platforms and are not subprocessors of Popify. The same applies to the email marketing platforms, reviews apps and image hosting accounts the Controller connects to Popify. Web push notifications are delivered through the push service of the visitor’s own browser.