Docket data processing addendum
This Data Processing Addendum ("DPA") forms part of the Docket terms of service between the Shopify merchant (the "Merchant") and Piya Traders ("Docket") whenever Docket processes personal data for that Merchant.
Roles and instructions
The Merchant decides why and how customer data is used and is the data controller or business. Docket handles that data on the Merchant's behalf as the processor or service provider. Docket processes personal data only to provide, secure, support, and comply with law for the services documented in the terms, privacy policy, Shopify configuration, and the Merchant's in-app instructions.
Processing details
Docket receives data from Shopify, organizes it, formats it into documents, stores it privately, sends it when requested, allows approved customer downloads, supports troubleshooting, and deletes or replaces identifying details when required. The people covered are the Merchant's customers, prospective customers represented in draft orders, authorized customer-account users, and relevant merchant staff. The privacy policy lists the data categories. They do not include buyer phone fields or payment-card data.
Confidentiality and security
Docket limits access to people and services that need it, protects internal access with strong sign-in security, records access without placing full Shopify identifiers in the log, separates test and production data, encrypts data while sent and stored, uses private storage and links that expire, maintains backups under provider security controls, and follows documented security-incident and data-loss procedures.
Subprocessors
The authorized subprocessors are Shopify (platform and authentication), Railway (application hosting), Supabase (database and private storage), Resend (transactional delivery), and Sentry when configured (error monitoring). Docket remains responsible for directing subprocessors consistently with this DPA and will provide notice before a material new category of subprocessor is used.
Requests, incidents, and assistance
Docket assists the Merchant with customer access and deletion requests through Shopify's required privacy notifications and will complete applicable actions within 30 days. Docket will notify affected Merchants without undue delay after confirming a personal-data breach where notification is required, provide reasonably available incident information, and cooperate with lawful regulatory or data-protection-impact requests.
Return and deletion
Docket applies the retention schedule in the privacy policy. On termination, Docket stops pending merchant work and deletes or anonymizes data within the stated periods, unless a narrowly applicable legal obligation requires retention. Any numbering information kept after deletion uses a protected replacement for the original order identifier, and access remains restricted.
International transfers and audit information
Docket selects EU regions for its application, database, and storage. Where data crosses jurisdictions, Docket relies on the applicable contractual and transfer safeguards offered by its providers. On reasonable request, Docket will provide the Merchant with information necessary to demonstrate compliance, subject to confidentiality and security limits.
Contact
Data protection contact: omdeeppiyanp@gmail.com.