Data Processing Addendum

1. Roles

For personal data about your store's customers and visitors that Krevya processes on your behalf in providing the service ("Customer Personal Data"), you are the controller and Krevya is the processor. Data Krevya processes to run your own account and the service is covered by the Privacy Policy, not by this Addendum.

2. Subject matter and duration

The subject matter of the processing is providing the service described in the Terms: receiving sign-ups collected by your store's popups and passing them to your Shopify store, sending your email flows, and summarising your store's sales at product level. Processing lasts for the term of your subscription and until deletion or return under section 10 is complete.

3. Categories of data and data subjects

  • Data subjects: people who sign up through your store's popups, recipients of your email flows and, if you grant Shopify's order-reading permission, your store's customers.
  • Categories of data: email address, which popup and page a sign-up came from, a salted hash of the IP address for rate limiting (never the address itself), the matching Shopify customer id, and email delivery and unsubscribe records; from order data, only product-level sales totals.
  • No special categories of personal data are intended to be processed, and you should not send any to Krevya.

4. Documented instructions

Krevya processes Customer Personal Data only on your documented instructions. The Terms, this Addendum and the settings you choose in the service are your instructions. Krevya will tell you if it believes an instruction infringes applicable data protection law. If the law requires Krevya to process otherwise, it will tell you before processing unless the law forbids it.

5. Confidentiality

Krevya ensures that everyone authorised to access Customer Personal Data is under a contractual or statutory duty of confidentiality, and limits access to the people who need it to provide the service.

6. Security measures

Krevya takes technical and organisational measures appropriate to the risk and reviews them over time. The list below summarises those in place today.

  • Encryption in transit (HTTPS) and the encryption at rest provided by the hosting provider.
  • Access limited by workspace membership; a separate session and two-step verification for administrative access.
  • Salted hashes kept instead of IP addresses, and rate limiting.
  • Logging, error reporting and monitoring for unusual activity.

7. Sub-processors

The sub-processors Krevya uses are listed in section 5 of the Privacy Policy (krevya.com/legal/privacy). Of these, Cloudflare (hosting, database and storage) and Resend (email delivery) process Customer Personal Data. By accepting this Addendum you give general authorisation for them. Krevya will update the list and tell you before adding a new sub-processor, and you may object on reasonable grounds. Krevya imposes data protection obligations on its sub-processors that are in substance no less protective than this Addendum, and remains responsible to you for their performance.

8. Help with data subject requests

Taking into account the nature of the processing, Krevya helps you answer requests from data subjects exercising their rights, through appropriate technical and organisational measures. If Krevya receives a request directly, it will pass it to you where the law allows and will not answer it without your instruction.

9. Breach notification and other assistance

Krevya will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and share the information it has to help you meet your own notification duties. Krevya will also give reasonable help, with the information available to it, with data protection impact assessments and prior consultations with supervisory authorities.

10. Deletion or return

When the service ends, Krevya will, at your choice, delete Customer Personal Data or return it to you and delete existing copies, unless the law requires it to be kept. You can make that choice by writing to support.

11. Audits and cooperation

On request, Krevya will make available the information needed to show it complies with this Addendum, and will cooperate with audits and inspections by you or an auditor you mandate, on reasonable notice and subject to confidentiality. Krevya will also cooperate with requests from supervisory authorities.

12. International transfers

Krevya is a US company and processes Customer Personal Data in the US and in the countries where its sub-processors' infrastructure is. Where a transfer is made from the EEA, or from anywhere else whose law requires it, to a country without an adequacy decision, the Standard Contractual Clauses adopted by European Commission Decision 2021/914 are incorporated into this Addendum by reference, as Module 2 (controller to processor) or Module 3 (processor to processor) as applicable, with you as data exporter and Krevya as data importer. If they conflict with this Addendum, the Standard Contractual Clauses prevail. Where processing of personal data relating to individuals in Türkiye involves an international transfer within the meaning of Article 9 of Law No. 6698, Krevya applies the transfer mechanism required by applicable law.

13. Your obligations

You are responsible for having a lawful basis and giving notice for collecting Customer Personal Data and having Krevya process it, and for obtaining consent where it is required.

Email: support@krevya.com. Postal address: 30 N Gould St Ste 58362, Sheridan, WY 82801, USA. Phone: +90 539 735 98 53.