Data processing addendum
This DPA is a binding part of the contract for a Shopify app or other Torevo service in which we process personal data under the customer’s instructions.
Last updated: 29 July 20261. Parties and acceptance
The processor is mespi s.r.o., registered office Východná 4, 949 01 Nitra, Slovenská republika, company ID 52004040 (“Torevo”). The controller is the merchant identified by its Shopify store, subscription or order (“Customer”). This DPA takes effect when version 2026-07-29 is accepted in the app or when an agreement incorporating it is signed. The person accepting confirms authority to act for the Customer.
2. Subject matter, purpose and duration
Processing is required to operate the installed Shopify app, enabled module or agreed integration. Its purpose is to securely receive, check, transfer, reconcile, display, export or delete data for a function used by the Customer. Processing continues for the contract term and the subsequent retention periods stated in the Privacy Policy.
3. Nature of processing
Operations may include collection from Shopify, validation, normalisation, transient use, encrypted storage, transfer to a connected provider, retrieval of state or PDF, audit, backup, export, anonymisation and deletion. Torevo does not determine the accounting or commercial purpose of Customer Data.
4. Data and data subjects
Data may include store and administrator identifiers, orders, transactions, billing and company data, customer or recipient name, address, email and telephone, provider identifiers, document state, encrypted PDFs and technical, security and audit records. Data subjects may include the Customer’s customers, recipients, staff, representatives and contacts. Special-category data is not intended for processing.
5. Customer instructions
Documented instructions consist of the contract, app settings, supported actions taken by an authorised user and requests sent through a secure channel. Torevo processes data only on those instructions unless EU or Member State law requires otherwise. It will inform the Customer of that legal requirement in advance unless law prohibits this. Torevo will flag an instruction that, based on available information, infringes data-protection law and may suspend it.
6. Duties and confidentiality
Torevo ensures that data is processed only by authorised persons bound by confidentiality and only as needed for operations, support, security or a legal duty. It does not sell data, use it for its own advertising or use it to train general-purpose artificial-intelligence models.
7. Technical and organisational measures
Measures include encryption in transit, encryption of stored secrets and documents, store isolation, permission controls, multi-factor authentication for privileged accounts, secure secret management, audit records without unnecessary personal data, production/test separation, monitoring, recovery, limited backup retention, vulnerability management and incident response. Measures may evolve technically but must not reduce the appropriate level of protection.
8. Data-subject rights and assistance
Taking account of the nature of processing, Torevo provides reasonable assistance with access, correction, erasure, restriction, objection and portability. A request received directly from a data subject is forwarded to the Customer without undue delay unless Torevo can handle it as controller of its own data. The Customer remains responsible for the instruction and communication with the data subject.
9. Security incidents
After confirming a personal-data breach, Torevo informs the Customer without undue delay and provides available details about the nature of the incident, affected categories, likely consequences, measures taken and a contact point. Details may be supplied in phases. Notice does not by itself constitute an admission of fault.
10. Assessments, consultation and audit
Torevo supplies reasonable information needed to demonstrate compliance with Article 28 GDPR and, using available information, assists with security, breach notification, impact assessment and prior consultation. The Customer first uses documentation and independent evidence. An audit is reasonably pre-notified, avoids compromising other customers and is paid by the Customer unless it identifies a material Torevo breach.
11. Subprocessors
The Customer grants general authorisation for the subprocessors listed on the Subprocessors page. Torevo imposes data-protection obligations corresponding to this DPA and remains responsible for their performance to the extent required by GDPR. A planned material change is notified through an appropriate channel. The Customer may raise a reasoned data-protection objection before the change. If no solution is agreed, the affected service may be terminated.
12. Customer-selected external platforms
Shopify, KROS, Packeta or another provider whose account the Customer connects and to which it instructs data to be sent is not necessarily a Torevo subprocessor. Its role follows its own terms, the Customer’s instructions and the specific data flow. Torevo transfers only data required for the requested operation.
13. International transfers
Where a subprocessor transfers data outside the EEA without an adequacy decision, the applicable EU Standard Contractual Clauses module, a valid Data Privacy Framework certification or another lawful mechanism is used with supplementary measures appropriate to the risk. The current mechanism is described in the relevant provider’s contractual documentation.
14. Return, deletion and backups
After service termination, Torevo provides an available export at the Customer’s choice and deletes or anonymises the data except where law or a legal claim requires retention. Backups remain isolated from routine use and expire no later than the published retention cycle.
15. Precedence and liability
For personal-data processing, this DPA prevails over conflicting general terms. Other liability and governing-law matters follow the Terms of Service or a separate written agreement. GDPR obligations that cannot be limited remain unaffected.
16. Contact and signed copy
Electronic acceptance in the app records the store, user, time and document versions. If the Customer needs a separately signed copy or security annex, contact torevo@torevo.tech with the Shopify store and contracting entity, without passwords or API keys.