Data Processing Agreement

Reamly — invoicing and document printing for Shopify.
Version 1.0 · 29 August 2026.

This Data Processing Agreement ("DPA") applies whenever Reamly processes personal data on behalf of a merchant. It forms part of, and is governed by, the Terms of Service.

You do not need to sign anything for this to apply. It takes effect automatically when you install Reamly, and it is written so that a merchant who needs a data processing agreement for their own compliance file already has one. If your auditor requires a countersigned copy, email privacy@bpers.com and we will sign and return it.

1. The parties, and who is what

ControllerYou — the merchant who installs Reamly on a Shopify store
ProcessorSyed Shahzaib Hassan, a sole trader in Pakistan, trading as Reamly
Contactprivacy@bpers.com

You determine why and how your customers' personal data is processed. We process it only to provide Reamly to you. Where this DPA and the Terms of Service disagree about personal data, this DPA wins.

Note that Shopify is your own processor, not our sub-processor. Your relationship with Shopify, and the data protection terms covering it, are between you and them. We receive order data through Shopify's API because you have authorised us to.

2. What we process, and why

Subject matterGenerating invoices, packing slips and credit notes from your Shopify orders, storing them, and optionally emailing them to your customers.
DurationFor as long as Reamly is installed, plus the deletion periods in section 8.
Nature of the processingReading order data, rendering documents, storing them, and — only if you switch it on — sending them by email.
PurposeTo provide the service. Nothing else. We do not use your data to train models, to build profiles, or for our own analytics.
Categories of data subjectYour customers, and the staff of your business customers whose details appear on an invoice.
Types of personal dataName; billing and shipping address; the items purchased and their prices; a VAT or tax registration number where you recorded one; and a masked email address in the form j***@example.com where a document was emailed.
Special category dataNone. Reamly is not designed for it and must not be used to process it.
Data we never receivePayment card numbers, bank details, government identifiers, passwords. All payment handling is Shopify's.

3. Our obligations

4. Security

The technical and organisational measures we actually operate are set out in Annex II. They are described there as they are, not as we would like them to be; where a control is not yet in place, our staff access policy says so, and it is available on request.

5. Sub-processors

You give us general authorisation to use the sub-processors listed in Annex III. Each is bound by written terms no less protective than this DPA.

If we add or replace one, we will tell you at least 30 days beforehand by email and in the app. If you object on reasonable data protection grounds within those 30 days, you may terminate and uninstall without penalty, and we will refund any unused prepaid period.

6. International transfers

All stored data resides in the European Union — see Annex III.

The single transfer outside the EU is administrative access by the processor, who is located in Pakistan, in order to operate and repair the service. Pakistan is not the subject of a European Commission adequacy decision.

For that transfer, the parties incorporate the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), which are deemed entered into and completed as follows:

Clause 7 (docking)Applies
Clause 9 (sub-processors)Option 2, general written authorisation, with 30 days' notice as in section 5
Clause 11 (redress)The optional independent dispute resolution wording does not apply
Clause 17 (governing law)The law of Germany
Clause 18 (forum)The courts of Germany
Annex I, II, IIIThe Annexes below serve as the Annexes to the Clauses

Where the transfer is subject to UK law, the Clauses apply as modified by the UK Information Commissioner's International Data Transfer Addendum (version B1.0), with Tables 1 to 4 completed by reference to this DPA and its Annexes, and neither party may end the Addendum under its Section 19.

Note that the choice of German law here governs the Clauses only. It does not change the governing law of the Terms of Service.

7. Assisting you with data subject requests

If a data subject contacts us directly, we will not respond on your behalf. We will tell them to contact you, and tell you that we have.

Because Reamly is a Shopify app, the fastest route is already built in. Shopify sends us three mandatory requests, and we implement all three:

customers/data_requestWe return what we hold about that customer
customers/redactWe erase that customer's data
shop/redactWe erase everything for your store

You can also simply email us and ask. We do not charge for this.

8. Breaches, deletion, and audits

Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the nature of the breach, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. Where we do not have all of that at first, we will send what we have and follow up. Notification is not an admission of fault.

Deletion and return

Audits

We will make available the information needed to demonstrate compliance with Article 28 of the GDPR, and will contribute to audits, including inspections, conducted by you or an auditor you appoint. In the first instance we will answer a written security questionnaire and provide our staff access policy. An on-site inspection may be requested once in any twelve months, on 30 days' notice, at your cost, subject to reasonable confidentiality terms.

9. Liability and term

This DPA takes effect when you install Reamly and ends when the Terms of Service end and the deletion obligations above are complete. Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR or the Standard Contractual Clauses do not permit that limitation.


Annex I — Description of the transfer

Data exporter: the merchant, as identified by the Shopify store domain on which Reamly is installed. Role: controller.
Data importer: Syed Shahzaib Hassan, trading as Reamly, Pakistan. Role: processor. Contact: privacy@bpers.com.

Categories of data subject, categories of personal data, and the nature, purpose and duration of processing are as set out in section 2 above.

Frequency of the transfer: continuous, for the duration of the installation.
Competent supervisory authority (Clause 13): that of the EU member state in which the merchant is established; where the merchant is not established in the EU, that of the member state in which its Article 27 representative is established.

Annex II — Technical and organisational measures

Measures we do not yet operate are listed, dated and owned in our staff access policy, which we will send on request. We would rather disclose a gap than claim a control we do not run.

Annex III — Sub-processors

Sub-processorPurposeLocation of data
NeonDatabaseFrankfurt, Germany (EU)
Cloudflare (R2)Storage of generated documentsEU jurisdiction
Fly.ioApplication hostingFrankfurt, Germany (EU)
ResendEmail delivery — only where the merchant enables automatic sendingIreland (EU) — region eu-west-1

Shopify is not listed because it is your own processor, not ours. See section 1.