Skip to main content

GDPR Compliance & Data Security

Information on where customer files are stored, how we handle data security, and how to obtain a signed Data Processing Agreement (DPA).

Updated yesterday

For merchants operating in the EU/EEA, complying with the General Data Protection Regulation (GDPR) is critical. Below are the details regarding our data handling practices and security infrastructure.

1. Data Storage Location

To ensure compliance with data locality preferences, all files uploaded through the Upload Center are stored in the Google Cloud Platform (GCP) data center located in Frankfurt, Germany (europe-west3).

2. Data Processing Agreement (DPA)

We offer a standard Data Processing Agreement.

  • Review: You can access our standard DPA and Privacy Policy directly on our website.

  • Signed Copy: If you require a countersigned DPA for your records, please contact us at [email protected] . We will provide a version signed by our Director.

  • Digital Verification: Our signed agreements are often provided in .asice format (digitally signed via the Estonian government's DigiDoc standard) alongside a PDF, ensuring official verification of the signature's authenticity.

Roles under GDPR:

  • Processor: Quaflow OU (App Provider)

  • Controller: You (The Merchant)

Security Measures

We implement strict security protocols to protect customer data:

  • Encryption: Files are transferred using secure protocols (HTTPS) and are stored encrypted at rest using AES encryption on high-security cloud infrastructure.

  • Access Control: Access to file storage is strictly limited to authorized administrators who use hardware-based security keys (FIDO) for authentication.

  • Automatic Deletion: To minimize data retention risks, uploaded files are automatically and permanently deleted 30 days after the upload date. We do not maintain backups of files after they are deleted

4. Shopify Integration & Data Access

The app is fully integrated with Shopify. Uploaded files are legally associated with the specific order line item. You can access these files directly from the Order Details page in your Shopify Admin to fulfill the order

Did this answer your question?