This Agreement applies between the merchant ("Controller") and North Digital Axis LLC ("Processor") and governs the processing of personal data through NDA Signal. It is accepted by the merchant within the app and forms part of the terms of use.
The Processor processes personal data of the Controller's customers solely to deliver conversion events to advertising platforms configured by the Controller. Processing lasts as long as the app is installed, and ends with the deletion described in section 7.
Collection of order and browsing data, normalisation, irreversible hashing, and transmission of hashed matching parameters to the advertising platforms chosen by the Controller.
Customers and visitors of the Controller's store. Categories of data are listed in the Privacy Policy, section 2.
The Processor processes personal data only on the Controller's documented instructions, which are given through the app's configuration. The Processor will inform the Controller if an instruction appears to infringe applicable data protection law.
Personnel authorised to process personal data are bound by confidentiality and are granted access only to the extent required for their duties.
The Processor uses Cloudflare, Inc. for compute, database and storage. The Controller authorises this sub-processor. The Controller will be notified of any intended change with reasonable notice and may object.
Advertising platforms configured by the Controller act as independent controllers or as the Controller's own processors under their own terms; they are not sub-processors of NDA Signal.
The Processor assists the Controller in responding to data subject requests through Shopify's compliance webhooks, which are handled automatically, and in meeting obligations relating to security, breach notification and impact assessments.
The Processor will notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach, providing the information needed for the Controller to meet its own notification duties.
On uninstallation, all personal data relating to the Controller is deleted within 48 hours. On an individual deletion request received through Shopify's compliance webhooks, the relevant data is deleted on receipt.
The Processor makes available the information necessary to demonstrate compliance with this Agreement and allows for audits by the Controller or an auditor mandated by the Controller, on reasonable notice.
Where personal data is transferred outside the European Economic Area, the transfer is made under the European Commission's Standard Contractual Clauses or another valid transfer mechanism.