Skip to content
DocumentationSupportSecurityService status
SK EN
TOREVO
Products Shopify solutions Integrations Projects About
Discuss a project
Primary navigation
Products Shopify solutions Integrations Projects About
Slovenčina English
DocumentationSupportSecurityService status
Discuss a project
Legal
PrivacyTermsDPASubprocessors
Contact
Torevo Legal

Data processing addendum

This DPA is a binding part of the contract for a Shopify app or other Torevo service in which we process personal data under the customer’s instructions.

Last updated: 29 July 2026

1. Parties and acceptance

The processor is mespi s.r.o., registered office Východná 4, 949 01 Nitra, Slovenská republika, company ID 52004040 (“Torevo”). The controller is the merchant identified by its Shopify store, subscription or order (“Customer”). This DPA takes effect when version 2026-07-29 is accepted in the app or when an agreement incorporating it is signed. The person accepting confirms authority to act for the Customer.

2. Subject matter, purpose and duration

Processing is required to operate the installed Shopify app, enabled module or agreed integration. Its purpose is to securely receive, check, transfer, reconcile, display, export or delete data for a function used by the Customer. Processing continues for the contract term and the subsequent retention periods stated in the Privacy Policy.

3. Nature of processing

Operations may include collection from Shopify, validation, normalisation, transient use, encrypted storage, transfer to a connected provider, retrieval of state or PDF, audit, backup, export, anonymisation and deletion. Torevo does not determine the accounting or commercial purpose of Customer Data.

4. Data and data subjects

Data may include store and administrator identifiers, orders, transactions, billing and company data, customer or recipient name, address, email and telephone, provider identifiers, document state, encrypted PDFs and technical, security and audit records. Data subjects may include the Customer’s customers, recipients, staff, representatives and contacts. Special-category data is not intended for processing.

5. Customer instructions

Documented instructions consist of the contract, app settings, supported actions taken by an authorised user and requests sent through a secure channel. Torevo processes data only on those instructions unless EU or Member State law requires otherwise. It will inform the Customer of that legal requirement in advance unless law prohibits this. Torevo will flag an instruction that, based on available information, infringes data-protection law and may suspend it.

6. Duties and confidentiality

Torevo ensures that data is processed only by authorised persons bound by confidentiality and only as needed for operations, support, security or a legal duty. It does not sell data, use it for its own advertising or use it to train general-purpose artificial-intelligence models.

7. Technical and organisational measures

Measures include encryption in transit, encryption of stored secrets and documents, store isolation, permission controls, multi-factor authentication for privileged accounts, secure secret management, audit records without unnecessary personal data, production/test separation, monitoring, recovery, limited backup retention, vulnerability management and incident response. Measures may evolve technically but must not reduce the appropriate level of protection.

8. Data-subject rights and assistance

Taking account of the nature of processing, Torevo provides reasonable assistance with access, correction, erasure, restriction, objection and portability. A request received directly from a data subject is forwarded to the Customer without undue delay unless Torevo can handle it as controller of its own data. The Customer remains responsible for the instruction and communication with the data subject.

9. Security incidents

After confirming a personal-data breach, Torevo informs the Customer without undue delay and provides available details about the nature of the incident, affected categories, likely consequences, measures taken and a contact point. Details may be supplied in phases. Notice does not by itself constitute an admission of fault.

10. Assessments, consultation and audit

Torevo supplies reasonable information needed to demonstrate compliance with Article 28 GDPR and, using available information, assists with security, breach notification, impact assessment and prior consultation. The Customer first uses documentation and independent evidence. An audit is reasonably pre-notified, avoids compromising other customers and is paid by the Customer unless it identifies a material Torevo breach.

11. Subprocessors

The Customer grants general authorisation for the subprocessors listed on the Subprocessors page. Torevo imposes data-protection obligations corresponding to this DPA and remains responsible for their performance to the extent required by GDPR. A planned material change is notified through an appropriate channel. The Customer may raise a reasoned data-protection objection before the change. If no solution is agreed, the affected service may be terminated.

12. Customer-selected external platforms

Shopify, KROS, Packeta or another provider whose account the Customer connects and to which it instructs data to be sent is not necessarily a Torevo subprocessor. Its role follows its own terms, the Customer’s instructions and the specific data flow. Torevo transfers only data required for the requested operation.

13. International transfers

Where a subprocessor transfers data outside the EEA without an adequacy decision, the applicable EU Standard Contractual Clauses module, a valid Data Privacy Framework certification or another lawful mechanism is used with supplementary measures appropriate to the risk. The current mechanism is described in the relevant provider’s contractual documentation.

14. Return, deletion and backups

After service termination, Torevo provides an available export at the Customer’s choice and deletes or anonymises the data except where law or a legal claim requires retention. Backups remain isolated from routine use and expire no later than the published retention cycle.

15. Precedence and liability

For personal-data processing, this DPA prevails over conflicting general terms. Other liability and governing-law matters follow the Terms of Service or a separate written agreement. GDPR obligations that cannot be limited remain unaffected.

16. Contact and signed copy

Electronic acceptance in the app records the store, user, time and document versions. If the Customer needs a separately signed copy or security annex, contact torevo@torevo.tech with the Shopify store and contracting entity, without passwords or API keys.

TOREVO

Torevo builds Shopify apps, integrations and e-commerce systems for day-to-day commerce operations.

Slovenčina · English

Products

KROS InvoicingTorevo ShippingTorevo • Packeta SKTorevo • ZasilkovnaLocalisations

Shopify solutions

Custom appsIntegrationsAutomationStorefront and UXTechnical audit

Resources and support

DocumentationSupportSecurityService statusChangelog

Torevo

AboutProjectsContactLegal

© 2026 Torevo. All rights reserved.