Data Processing Agreement
Reamly — invoicing and document printing for Shopify.
Version 1.0 · 29 August 2026.
This Data Processing Agreement ("DPA") applies whenever Reamly processes personal data on behalf of a merchant. It forms part of, and is governed by, the Terms of Service.
You do not need to sign anything for this to apply. It takes effect automatically when you install Reamly, and it is written so that a merchant who needs a data processing agreement for their own compliance file already has one. If your auditor requires a countersigned copy, email privacy@bpers.com and we will sign and return it.
1. The parties, and who is what
| Controller | You — the merchant who installs Reamly on a Shopify store |
|---|---|
| Processor | Syed Shahzaib Hassan, a sole trader in Pakistan, trading as Reamly |
| Contact | privacy@bpers.com |
You determine why and how your customers' personal data is processed. We process it only to provide Reamly to you. Where this DPA and the Terms of Service disagree about personal data, this DPA wins.
Note that Shopify is your own processor, not our sub-processor. Your relationship with Shopify, and the data protection terms covering it, are between you and them. We receive order data through Shopify's API because you have authorised us to.
2. What we process, and why
| Subject matter | Generating invoices, packing slips and credit notes from your Shopify orders, storing them, and optionally emailing them to your customers. |
|---|---|
| Duration | For as long as Reamly is installed, plus the deletion periods in section 8. |
| Nature of the processing | Reading order data, rendering documents, storing them, and — only if you switch it on — sending them by email. |
| Purpose | To provide the service. Nothing else. We do not use your data to train models, to build profiles, or for our own analytics. |
| Categories of data subject | Your customers, and the staff of your business customers whose details appear on an invoice. |
| Types of personal data | Name; billing and shipping address; the items purchased and their prices; a VAT or tax registration number where you recorded one; and a masked email address in the form j***@example.com where a document was emailed. |
| Special category data | None. Reamly is not designed for it and must not be used to process it. |
| Data we never receive | Payment card numbers, bank details, government identifiers, passwords. All payment handling is Shopify's. |
3. Our obligations
- We process only on your documented instructions. Your instructions are this DPA, the Terms of Service, and the settings you choose in the app. If we are ever required by law to process your data otherwise, we will tell you first unless the law forbids it.
- We keep it confidential. Everyone with access is bound by confidentiality obligations.
- We keep access to a minimum. One person holds production credentials. There is no wider staff with standing access, because there is no wider staff.
- We will not sell your data, and we will not use it for our own purposes.
- We help you meet your own obligations under Articles 32 to 36 of the GDPR, taking into account the information available to us.
4. Security
The technical and organisational measures we actually operate are set out in Annex II. They are described there as they are, not as we would like them to be; where a control is not yet in place, our staff access policy says so, and it is available on request.
5. Sub-processors
You give us general authorisation to use the sub-processors listed in Annex III. Each is bound by written terms no less protective than this DPA.
If we add or replace one, we will tell you at least 30 days beforehand by email and in the app. If you object on reasonable data protection grounds within those 30 days, you may terminate and uninstall without penalty, and we will refund any unused prepaid period.
6. International transfers
All stored data resides in the European Union — see Annex III.
The single transfer outside the EU is administrative access by the processor, who is located in Pakistan, in order to operate and repair the service. Pakistan is not the subject of a European Commission adequacy decision.
For that transfer, the parties incorporate the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), which are deemed entered into and completed as follows:
| Clause 7 (docking) | Applies |
|---|---|
| Clause 9 (sub-processors) | Option 2, general written authorisation, with 30 days' notice as in section 5 |
| Clause 11 (redress) | The optional independent dispute resolution wording does not apply |
| Clause 17 (governing law) | The law of Germany |
| Clause 18 (forum) | The courts of Germany |
| Annex I, II, III | The Annexes below serve as the Annexes to the Clauses |
Where the transfer is subject to UK law, the Clauses apply as modified by the UK Information Commissioner's International Data Transfer Addendum (version B1.0), with Tables 1 to 4 completed by reference to this DPA and its Annexes, and neither party may end the Addendum under its Section 19.
Note that the choice of German law here governs the Clauses only. It does not change the governing law of the Terms of Service.
7. Assisting you with data subject requests
If a data subject contacts us directly, we will not respond on your behalf. We will tell them to contact you, and tell you that we have.
Because Reamly is a Shopify app, the fastest route is already built in. Shopify sends us three mandatory requests, and we implement all three:
customers/data_request | We return what we hold about that customer |
|---|---|
customers/redact | We erase that customer's data |
shop/redact | We erase everything for your store |
You can also simply email us and ask. We do not charge for this.
8. Breaches, deletion, and audits
Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the nature of the breach, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. Where we do not have all of that at first, we will send what we have and follow up. Notification is not an admission of fault.
Deletion and return
- Generated PDF files are deleted automatically 90 days after they are created. The underlying record is kept so a document can be regenerated, because invoices must be reproducible.
- On uninstall, Shopify sends
shop/redact48 hours later, and we delete your data on receiving it. - You may ask us to delete or return your data at any time, and we will do so within 30 days, except where we are legally required to keep something.
Audits
We will make available the information needed to demonstrate compliance with Article 28 of the GDPR, and will contribute to audits, including inspections, conducted by you or an auditor you appoint. In the first instance we will answer a written security questionnaire and provide our staff access policy. An on-site inspection may be requested once in any twelve months, on 30 days' notice, at your cost, subject to reasonable confidentiality terms.
9. Liability and term
This DPA takes effect when you install Reamly and ends when the Terms of Service end and the deletion obligations above are complete. Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR or the Standard Contractual Clauses do not permit that limitation.
Annex I — Description of the transfer
Data exporter: the merchant, as identified by the Shopify store domain
on which Reamly is installed. Role: controller.
Data importer: Syed Shahzaib Hassan, trading as Reamly, Pakistan. Role:
processor. Contact: privacy@bpers.com.
Categories of data subject, categories of personal data, and the nature, purpose and duration of processing are as set out in section 2 above.
Frequency of the transfer: continuous, for the duration of the
installation.
Competent supervisory authority (Clause 13): that of the EU member state
in which the merchant is established; where the merchant is not established in the EU, that
of the member state in which its Article 27 representative is established.
Annex II — Technical and organisational measures
- Encryption in transit. The database connection requires TLS with channel binding. Object storage is HTTPS only. The application enforces HTTPS.
- Encryption at rest. Provided by the infrastructure platforms for both the database and its backups, and for stored files.
- Access control. One person holds production credentials, stored in a password manager and in the host's secret store, and nowhere else. They are not in the source repository and not in any backup.
- Least privilege. The credential the running application uses for file storage can read and write objects but cannot alter storage configuration — so a leaked application credential cannot disable the 90-day deletion rule.
- Separation of environments. The application refuses to start against the production database outside production. This is enforced in code, not by convention, and is tested.
- Data minimisation in logs. No name, address, email or order payload is ever written to a log. Logs carry identifiers and status codes only. This is enforced by an automated check that runs on every change to the source code.
- Minimisation in storage. Email addresses are stored only in a fixed-width masked form, so neither the address nor its length is retained.
- Deletion by default. Generated files are purged after 90 days by a scheduled job and by an independent storage lifecycle rule, so neither depends on the other.
- Pseudonymisation. Not applicable — an invoice must legibly carry the customer's real name and address to be valid.
- Testing. The security-relevant behaviours above are covered by an automated test suite that runs on every change.
Measures we do not yet operate are listed, dated and owned in our staff access policy, which we will send on request. We would rather disclose a gap than claim a control we do not run.
Annex III — Sub-processors
| Sub-processor | Purpose | Location of data |
|---|---|---|
| Neon | Database | Frankfurt, Germany (EU) |
| Cloudflare (R2) | Storage of generated documents | EU jurisdiction |
| Fly.io | Application hosting | Frankfurt, Germany (EU) |
| Resend | Email delivery — only where the merchant enables automatic sending | Ireland (EU) — region eu-west-1 |
Shopify is not listed because it is your own processor, not ours. See section 1.