Data Processing Agreement (DPA)
Last updated: October 2, 2026
This Data Processing Agreement ("DPA") is part of the Terms of Service between the merchant using Piaflo - WhatsApp Flows ("Controller") and monweb.dev, operator of Piaflo ("Processor"). It applies to personal data the Processor processes on the Controller's behalf, in accordance with Article 28 of the EU General Data Protection Regulation (GDPR). It is accepted when the app is installed and remains in force as long as the Processor processes such data.
1. Subject, nature and purpose
- Subject: providing the Piaflo service (WhatsApp notifications, automated flows, campaigns and shared inbox for the Controller's Shopify store).
- Nature: collection from Shopify and WhatsApp, storage, structuring, consultation, transmission (message sending), erasure.
- Purpose: only to provide the Service as configured by the Controller.
- Duration: the term of the Service, plus the retention periods in the Privacy Policy, until deletion.
2. Data subjects and categories of data
- Data subjects: the Controller's customers, prospective customers and storefront visitors who interact with WhatsApp messages or the opt-in widget.
- Data: names, phone numbers, email addresses, address fields, order and checkout details, WhatsApp messages and media, delivery statuses, consent records.
- No special categories of data are intended to be processed.
3. Processor obligations
The Processor:
- processes personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's configuration of the app, unless required by law (in which case it informs the Controller first, unless prohibited);
- ensures that persons authorized to process the data are bound by confidentiality;
- implements the technical and organizational measures in Annex 1;
- engages sub-processors only as set out in section 4;
- assists the Controller, taking into account the nature of the processing, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection), including through Shopify's privacy webhooks;
- assists the Controller with security, breach notification, data protection impact assessments and prior consultations;
- notifies the Controller of a personal data breach without undue delay and within 48 hours of becoming aware of it, with the information required by Article 33(3) GDPR;
- at the end of the Service, deletes all personal data (within 48 hours of Shopify's
shop/redactrequest) unless storage is required by law; backups expire within 14 days; - makes available the information necessary to demonstrate compliance and allows for audits, at the Controller's cost, with reasonable notice, at most once per year, without access to other merchants' data.
4. Sub-processors
The Controller authorizes the sub-processors listed in the Privacy Policy (Hetzner, Zernio, Meta, Shopify, Cloudflare, Crisp). The Processor imposes data protection obligations on them equivalent to this DPA and remains liable for them. The Processor informs the Controller of any intended addition or replacement at least 30 days in advance (in the app or by email); the Controller may object on reasonable grounds and terminate the Service if no solution is found.
5. International transfers
Where data is transferred outside the European Economic Area, the Processor ensures appropriate safeguards (EU Standard Contractual Clauses, EU-US Data Privacy Framework or an adequacy decision).
6. Controller obligations
The Controller ensures a lawful basis for the processing (in particular the consent required for marketing messages), informs data subjects, and gives only lawful instructions.
7. Liability and precedence
Liability follows the Terms of Service. In case of conflict on data protection matters, this DPA prevails.
Annex 1 — Technical and organizational measures
- Encryption in transit (TLS) and at rest (AES-256-GCM application-level encryption of personal fields, message contents, media and backups).
- Hosting in the EU (Hetzner, Germany); isolated containers; key-based administrative access with two-factor authentication on provider accounts.
- Access control: least privilege, access to personal data restricted to authorized personnel, access log of personal data views kept 12 months.
- Daily encrypted backups (14 days) with tested restore; data loss prevention measures; separation of test and production data.
- Retention limits with automatic deletion; opt-out suppression list stored as one-way hashes.
- Signed webhooks, input validation, dependency updates, automated tests before release.
- Written security incident response policy, reviewed yearly.