Piaflo
Home Features Pricing Help Blog
EN
English Français
Install app
Piaflo
HomeFeaturesPricingHelpBlog Install app
EN FR
Legal

Data Processing Agreement (DPA)

Last updated: October 2, 2026

This Data Processing Agreement ("DPA") is part of the Terms of Service between the merchant using Piaflo - WhatsApp Flows ("Controller") and monweb.dev, operator of Piaflo ("Processor"). It applies to personal data the Processor processes on the Controller's behalf, in accordance with Article 28 of the EU General Data Protection Regulation (GDPR). It is accepted when the app is installed and remains in force as long as the Processor processes such data.

1. Subject, nature and purpose

  • Subject: providing the Piaflo service (WhatsApp notifications, automated flows, campaigns and shared inbox for the Controller's Shopify store).
  • Nature: collection from Shopify and WhatsApp, storage, structuring, consultation, transmission (message sending), erasure.
  • Purpose: only to provide the Service as configured by the Controller.
  • Duration: the term of the Service, plus the retention periods in the Privacy Policy, until deletion.

2. Data subjects and categories of data

  • Data subjects: the Controller's customers, prospective customers and storefront visitors who interact with WhatsApp messages or the opt-in widget.
  • Data: names, phone numbers, email addresses, address fields, order and checkout details, WhatsApp messages and media, delivery statuses, consent records.
  • No special categories of data are intended to be processed.

3. Processor obligations

The Processor:

  1. processes personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's configuration of the app, unless required by law (in which case it informs the Controller first, unless prohibited);
  2. ensures that persons authorized to process the data are bound by confidentiality;
  3. implements the technical and organizational measures in Annex 1;
  4. engages sub-processors only as set out in section 4;
  5. assists the Controller, taking into account the nature of the processing, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection), including through Shopify's privacy webhooks;
  6. assists the Controller with security, breach notification, data protection impact assessments and prior consultations;
  7. notifies the Controller of a personal data breach without undue delay and within 48 hours of becoming aware of it, with the information required by Article 33(3) GDPR;
  8. at the end of the Service, deletes all personal data (within 48 hours of Shopify's shop/redact request) unless storage is required by law; backups expire within 14 days;
  9. makes available the information necessary to demonstrate compliance and allows for audits, at the Controller's cost, with reasonable notice, at most once per year, without access to other merchants' data.

4. Sub-processors

The Controller authorizes the sub-processors listed in the Privacy Policy (Hetzner, Zernio, Meta, Shopify, Cloudflare, Crisp). The Processor imposes data protection obligations on them equivalent to this DPA and remains liable for them. The Processor informs the Controller of any intended addition or replacement at least 30 days in advance (in the app or by email); the Controller may object on reasonable grounds and terminate the Service if no solution is found.

5. International transfers

Where data is transferred outside the European Economic Area, the Processor ensures appropriate safeguards (EU Standard Contractual Clauses, EU-US Data Privacy Framework or an adequacy decision).

6. Controller obligations

The Controller ensures a lawful basis for the processing (in particular the consent required for marketing messages), informs data subjects, and gives only lawful instructions.

7. Liability and precedence

Liability follows the Terms of Service. In case of conflict on data protection matters, this DPA prevails.

Annex 1 — Technical and organizational measures

  • Encryption in transit (TLS) and at rest (AES-256-GCM application-level encryption of personal fields, message contents, media and backups).
  • Hosting in the EU (Hetzner, Germany); isolated containers; key-based administrative access with two-factor authentication on provider accounts.
  • Access control: least privilege, access to personal data restricted to authorized personnel, access log of personal data views kept 12 months.
  • Daily encrypted backups (14 days) with tested restore; data loss prevention measures; separation of test and production data.
  • Retention limits with automatic deletion; opt-out suppression list stored as one-way hashes.
  • Signed webhooks, input validation, dependency updates, automated tests before release.
  • Written security incident response policy, reviewed yearly.
Piaflo

WhatsApp flows for Shopify stores. Recover checkouts, confirm cash on delivery orders and keep customers posted, with Meta fees at cost.

WhatsApp is a trademark of WhatsApp LLC. Piaflo is an independent Shopify app and is not affiliated with or endorsed by Meta or WhatsApp.

Product

  • Features
  • Pricing
  • FAQ
  • Install on Shopify

Resources

  • Connect your WhatsApp number
  • Blog
  • Contact support

Legal

  • Privacy policy
  • Terms of service
  • Data processing agreement
  • Security
© 2026 Piaflo. All rights reserved.