Data Processing Addendum
Last updated: August 19, 2026
This Data Processing Addendum ("DPA") forms part of the TinyBackup Terms of Service (the "Agreement") between TK DIGITAL LTD, trading as TinyBackup, a company registered in England with company number 09164546 and registered office at 93 Fernside Road, Poole, Dorset, BH15 2JQ, United Kingdom ("TinyBackup", "we", "us"), and the person or entity that installs, accesses, or uses the Service ("Customer").
This DPA applies where TinyBackup processes Customer Personal Data on behalf of Customer and is intended to comply with the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and other applicable data protection laws.
Contract hierarchy. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls to the extent of that conflict. Where the SCCs apply, the SCCs control over this DPA to the extent of any conflict. All other commercial terms remain unchanged.
1. Definitions and scope
- "Customer Personal Data" means personal data processed by TinyBackup on behalf of Customer through the Service.
- "Data Protection Laws" means applicable laws governing the processing of personal data, including the GDPR (Regulation (EU) 2016/679), the UK GDPR and the UK Data Protection Act 2018, and, where applicable, the Swiss Federal Act on Data Protection.
- "SCCs" means the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data on systems managed or controlled by TinyBackup.
- "Sub-processor" means a third party engaged by TinyBackup to process Customer Personal Data to help provide the Service. Sub-processors exclude TinyBackup's own employees and contractors.
- "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner's Office under s.119A of the UK Data Protection Act 2018.
"Controller", "processor", "data subject", and "processing" have the meanings given in the GDPR. Capitalized terms not defined here have the meaning given in the Agreement.
2. Roles and documented instructions
2.1 Customer is the controller of Customer Personal Data and TinyBackup is the processor, except where Customer itself acts as a processor for another controller, in which case TinyBackup acts as Customer's sub-processor.
2.2 TinyBackup will process Customer Personal Data only on Customer's documented instructions, consisting of the Agreement, this DPA, Customer's configuration and use of the Service, and other written instructions accepted by TinyBackup, unless processing is required by applicable law. TinyBackup will not use Customer Personal Data for its own purposes, including marketing, profiling, advertising, or training of machine-learning models.
2.3 If TinyBackup believes an instruction infringes applicable Data Protection Laws, TinyBackup will inform Customer unless prohibited by law.
2.4 Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for ensuring it has a lawful basis and all necessary notices, rights, and authorizations for the processing instructed under this DPA. Where Customer acts as a processor for a third-party controller, Customer warrants that its instructions and its authorization of Sub-processors under this DPA have been authorized by that controller, and Customer serves as TinyBackup's sole point of contact.
3. Confidentiality and personnel
TinyBackup will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where necessary for their duties.
4. Security
4.1 TinyBackup will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Schedule 2 and on our security page.
4.2 Security measures may evolve with technical progress, provided that the overall level of protection is not materially reduced.
5. Security incidents
5.1 If TinyBackup becomes aware of a Security Incident, TinyBackup will notify Customer without undue delay and, where feasible, within 72 hours of becoming aware, and will provide information reasonably available to TinyBackup that Customer may need to meet applicable breach-notification obligations under Articles 33 and 34 of the GDPR.
5.2 TinyBackup will take reasonable steps to contain, investigate, and mitigate the effects of the incident. A notification under this section is not an admission of fault or liability.
6. Sub-processors
6.1 Customer gives TinyBackup general written authorization to engage Sub-processors to provide the Service, subject to this section. The Sub-processors currently engaged by TinyBackup and authorized by Customer are listed in Schedule 3, with the current list also published in our Help Center.
6.2 TinyBackup will impose written data-protection obligations on each Sub-processor that provide a level of protection appropriate to the processing and consistent with TinyBackup's obligations under this DPA. TinyBackup remains responsible to Customer for the performance of its Sub-processors to the extent required by applicable Data Protection Laws.
6.3 TinyBackup will inform Customer of intended additions or replacements of Sub-processors by updating the published list before the new Sub-processor begins processing Customer Personal Data.
6.4 If Customer has a reasonable, good-faith objection to a new Sub-processor on data-protection grounds, Customer may notify TinyBackup in writing within 10 days after the change is posted, and the parties will work together in good faith to address the objection. If the parties cannot reasonably resolve the objection, Customer may terminate the affected part of the Service without penalty for future unused service periods, where continued provision of that part of the Service reasonably requires the objected-to Sub-processor.
7. International transfers
7.1 TinyBackup stores backup data in secure infrastructure located in Frankfurt, Germany. Other limited processing by authorized Sub-processors may occur in other locations where necessary to provide the Service, as described in Schedule 3.
7.2 If Customer Personal Data is transferred from the EEA to a country that does not benefit from an applicable adequacy decision, the parties agree to comply with the SCCs, which are incorporated into and form part of this DPA. TinyBackup is the data importer and Customer is the data exporter.
7.3 Where Customer is a controller, Module Two of the SCCs applies; where Customer is itself a processor, Module Three applies. In each case: (a) the optional docking clause in Clause 7 does not apply; (b) in Clause 9, Option 2 (general written authorization) applies, with notice given in accordance with Section 6.3; (c) the optional redress mechanism in Clause 11 does not apply; (d) in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland; and (e) in Clause 18(b), the courts of Ireland are selected. Annex I is completed with the information in Schedule 1 and the parties' details in the Agreement and Customer's account; Annex II is completed with Schedule 2; Annex III is completed with Schedule 3.
7.4 For transfers subject to UK Data Protection Laws, the SCCs apply as amended by the UK Addendum, which is deemed executed and incorporated into this DPA. Tables 1 to 3 of the UK Addendum are deemed completed with the information in the SCC Annexes, and in Table 4 "neither party" is selected.
7.5 For transfers subject to Swiss data protection law, the SCCs apply with the adaptations required by that law, including references to the competent Swiss supervisory authority and courts.
8. Data subject requests and regulatory assistance
8.1 Taking into account the nature of the processing, TinyBackup will provide reasonable assistance to Customer, through appropriate technical and organisational measures where possible, to enable Customer to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection).
8.2 If TinyBackup receives a request directly from a data subject concerning Customer Personal Data, TinyBackup will direct the requester to Customer or notify Customer, unless applicable law requires TinyBackup to respond directly. When Shopify delivers a customer or order redaction request for Customer's store, TinyBackup removes the affected records from stored backups automatically.
8.3 Taking into account the nature of the processing and the information available to TinyBackup, TinyBackup will reasonably assist Customer with obligations relating to security of processing, breach notifications, data protection impact assessments, and prior consultation with supervisory authorities, to the extent required by applicable Data Protection Laws.
9. Return and deletion
9.1 During the Service term, Customer can retrieve Customer Personal Data through the Service's restore and export functionality.
9.2 When Customer uninstalls the app, all backup data and stored store data are automatically and permanently deleted from TinyBackup's systems 14 days after uninstallation. The 14-day window exists so that a reinstall within that period does not lose Customer's backup history. Customer may request earlier deletion by contacting [email protected].
9.3 Records of the Customer account, subscription, and billing history that do not include store backup data may be retained as required for legitimate business purposes and legal compliance.
9.4 TinyBackup will provide reasonable confirmation of deletion upon Customer's written request.
10. Audit and compliance information
10.1 TinyBackup will make available information reasonably necessary to demonstrate compliance with Article 28 obligations applicable to its processing under this DPA, including responses to reasonable security and compliance questionnaires.
10.2 Customer may first satisfy its audit needs through documentation, security information, and questionnaires. If those materials are insufficient, Customer may conduct, or appoint an independent auditor to conduct, an audit relevant to Customer Personal Data, subject to reasonable confidentiality, security, scheduling, and non-interference requirements.
10.3 Unless required by a supervisory authority or reasonably necessary following a material Security Incident affecting Customer Personal Data, audits are limited to once per 12-month period, on at least 30 days' prior written notice, during normal business hours, and at Customer's expense.
11. Liability
The liability provisions and limitations in the Agreement apply to this DPA to the fullest extent permitted by applicable law. Nothing in this DPA limits rights of data subjects or liabilities that cannot lawfully be limited under applicable Data Protection Laws.
12. Duration and termination
This DPA begins when Customer first uses the Service and continues while TinyBackup processes Customer Personal Data on behalf of Customer. Provisions that by their nature must survive termination, including confidentiality, deletion, audit, and liability provisions, survive as necessary to give them effect.
13. Acceptance
By installing or using the TinyBackup application, Customer acknowledges and agrees to this DPA. This DPA is concluded in electronic form; under Article 28(9) of the GDPR no signature is required for it to be effective.
Schedule 1 - Details of processing
- Subject matter: Automated backup, version history, change tracking, storage, and restoration of data from Customer's Shopify store.
- Duration: The Service term plus the 14-day post-uninstallation deletion period described in Section 9.
- Nature of processing: Collection from Shopify APIs and webhooks; recording; organization; storage; retrieval; consultation; comparison; transmission to and from Shopify for backup and restore; support-related access where needed; deletion.
- Purpose: To provide automatic backups, incremental updates, historical versions, restore functionality, service reliability, security, troubleshooting, and customer support.
- Data subjects: Customer's shoppers and customers; store owner, staff, and contributors; business contacts; and other individuals whose personal data is contained in Shopify store data backed up through the Service.
- Categories of personal data: Names; email addresses; phone numbers; postal addresses; customer and company identifiers; order and fulfillment information; store-owner and staff information; online identifiers and technical metadata where exposed by Shopify; store content and metadata that may contain personal data.
- Special categories: The Service is not designed for special-category data. Customer is responsible for determining whether its Shopify data contains special-category data and for ensuring the instructed processing is lawful.
- Frequency: Continuous or recurring processing while the Service is installed and enabled, including scheduled backups and event-driven incremental backups.
Schedule 2 - Technical and organisational measures
- Encryption in transit: communication between Shopify and TinyBackup is protected using TLS.
- Encryption at rest: backup data is protected using encryption at rest.
- Hosting location: backup data is stored in secure infrastructure located in Frankfurt, Germany.
- Access control: purpose-based and role-based access controls limit access to persons who require it for authorized duties.
- Authentication: multi-factor authentication is used for relevant administrative access.
- Monitoring and review: systems are subject to monitoring and security review processes designed to identify operational and security issues. Error monitoring is scrubbed so that request contents and personal data are not transmitted.
- Network and system protection: backup data is protected through network and system isolation measures appropriate to the Service.
- Recovery: the Service maintains historical backup versions and recovery functions designed to restore supported Shopify store data.
- Data minimization: TinyBackup requests only the Shopify permissions needed to provide backup and recovery functions.
- Confidentiality: authorized personnel and relevant service providers are subject to confidentiality and data-protection obligations.
Further detail: tinybackup.io/security.
Schedule 3 - Sub-processors
The following Sub-processors process Customer Personal Data to help provide the Service:
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| DigitalOcean, LLC (USA) | Cloud infrastructure: application hosting, databases, and encrypted backup storage | Frankfurt, Germany |
| Google Cloud EMEA Ltd (Ireland) | Webhook event pipeline | Frankfurt, Germany |
All Sub-processors process Customer Personal Data in Frankfurt, Germany. Shopify is the platform through which Customer's store operates and is not a Sub-processor of TinyBackup. Service providers that process only TinyBackup's own customer-relationship data (such as transactional email to store owners and support chat) act under TinyBackup's controller role and are disclosed in the Privacy Policy. Error monitoring is configured so that request contents, user data, and email addresses never leave TinyBackup's systems, and therefore involves no processing of Customer Personal Data.
The current list, with any pending changes, is published in our Help Center. Should a future Sub-processor process Customer Personal Data outside the EEA, transfers will be safeguarded by the SCCs and, where certified, the EU-US Data Privacy Framework, with the advance notice described in Section 6.
Questions and contact
Please connect with us for clarifications or more information at [email protected]. Postal address: TK DIGITAL LTD, 93 Fernside Road, Poole, Dorset, BH15 2JQ, United Kingdom.