Larderia

Larderia Data Processing Agreement

Last updated: October 5, 2026

This agreement forms part of the Larderia Terms of Service and governs how we process your store's personal data on your behalf, as required by Article 28 of the General Data Protection Regulation (GDPR). The App Privacy Policy explains it in summary.

Parties

1. Subject matter

Larderia processes data on the Customer's behalf only to provide the service described in the Terms of Service: reading the store's catalog, inventory, locations and orders; calculating daily sales per variant and location; calculating demand forecasts, order dates, reorder points and suggested quantities; managing the Customer's suppliers; generating the reorder list, purchase orders (with their PDF and CSV) and dead stock reports; emailing to the supplier the purchase orders the Customer instructs; importing orders from a Stocky export; when the Customer confirms a receipt, recording the received goods in Shopify inventory and, if chosen, updating the unit cost; sending the Customer, if turned on, a periodic digest by email or Slack; measuring forecast accuracy; and keeping a log of the app's actions.

2. Duration

While the app is installed on the store and, afterwards, for the time needed to complete the deletion in section 11.

3. Nature, purpose and data processed

ItemDetails
PurposeDemand forecasting, reorder calculation, supplier management, purchase orders and their receipt into inventory, digests to the Customer, accuracy measurement, activity log and inventory reports
OperationsCollection through the Shopify API and webhooks, reduction of orders and fulfillments before storage, aggregation, calculation, storage, consultation, export and erasure; writing to Shopify limited to inventory (adjusting received quantities, activating the item at the location and, if the Customer chooses, the unit cost) when the Customer confirms a receipt; sending emails to suppliers when the Customer instructs it and digests to the email or Slack channel the Customer sets up
Store and catalog dataStore domain, name, currency and time zone; store contact email (only in the log of emails sent to suppliers); products and variants (title, SKU, barcode, vendor, price, unit cost and status); locations; stock per variant and location and observed stock-level history; forecasts, weekly forecast snapshots and calculated accuracy. In general not personal data
Data derived from orders (level 1 protected data)Read: order identifier, dates, cancellation, test order, location and line items (variant, quantity, current quantity and refunds with date and quantity). From each fulfillment, its identifier, the order identifier, status, location and lines (identifier, variant and quantity) are read. Stored: (a) each order's contribution (order identifier, variant, location, day and units); (b) fulfillment lines (order, fulfillment and line identifiers, variant, location, quantity, status and dates); and (c) daily sales aggregated per variant and location. The order identifier is pseudonymised data: it does not identify the customer by itself, but the Customer can link it to them in Shopify. The full order is not stored
End-customer data that is not storedName, email, phone, address and payment data. Larderia does not request access to Shopify's level 2 protected fields. Order, fulfillment and refund webhooks subscribe only to the necessary fields; any other field that arrives is discarded in memory before anything is stored
Supplier and purchase order data (entered by the Customer)Supplier name, email, currency, document language, free-text notes, reorder parameters and alternative names; purchase orders (supplier and supplier email, destination, lines, costs, notes, receipts) and the log of emails sent (recipient, copy, reply-to, subject, status and date). The email and notes may contain personal data of the supplier's contact person. The Customer is responsible for having obtained them lawfully
Digest settingsFrequency, time, language, destination email and Slack incoming webhook URL (encrypted); log of digests sent
Activity logType of action, date, action details (references and quantities) and author; with store sessions without a user, the author is always "app"
Session dataStore session identifier, Shopify access token and refresh token (encrypted) and granted permissions. The name and email of the person who opens the app are not stored
Technical dataStore identifiers, IP addresses and server logs, with limited retention
Data subjectsThe Customer's end customers (only through the pseudonymised order identifier); contact persons at the Customer's suppliers; staff of the Customer and its agency (only in technical logs; email support is outside this agreement, section 6.7)
Special categoriesNone expected. The Customer undertakes not to enter special categories of data (GDPR Art. 9) in supplier notes or the catalog for Larderia to process

4. The Customer's instructions

  1. The Customer's documented instructions are: this agreement, the Terms of Service, the settings the Customer chooses in the app (for example, its suppliers' details and parameters) and the actions it takes in it (for example, downloading a CSV, instructing a purchase order to be emailed to a supplier, confirming a receipt, which entails the inventory adjustment in Shopify, or turning on the email or Slack digest). The instructions in section 7 on international transfers are also instructions.
  2. Larderia will immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law (GDPR Art. 28(3), last paragraph).
  3. If Union or Member State law required Larderia to process data differently, it will inform the Customer beforehand, unless that law prohibits it on important grounds of public interest (GDPR Art. 28(3)(a)).

5. Larderia's obligations (GDPR Art. 28(3))

Larderia undertakes to:

  1. Process the data only on the instructions in section 4, including with regard to international transfers (Art. 28(3)(a)).
  2. Ensure that persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality (Art. 28(3)(b)). Today the only person with access is the owner.
  3. Apply the security measures under GDPR Art. 32 described in Annex II (Art. 28(3)(c)).
  4. Engage sub-processors only under section 6 (Art. 28(3)(d)).
  5. Assist the Customer, by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights, including Shopify's customers/data_request and customers/redact webhooks (section 11.4; Art. 28(3)(e)). If Larderia receives a request about the Customer's data directly, it will pass it to the Customer without delay and will not answer it itself unless the Customer instructs it to.
  6. Assist the Customer in complying with GDPR Arts. 32 to 36 (security, breach notification, impact assessments and prior consultation), taking into account the nature of the processing and the information available to it (Art. 28(3)(f)).
  7. Delete the data when the service ends, under section 11 (Art. 28(3)(g)).
  8. Make available to the Customer all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, under section 10 (Art. 28(3)(h)).
  9. Keep a record of processing activities as processor (GDPR Art. 30(2) and LOPDGDD Art. 31).
  10. Not use the Customer's data for its own purposes: not sell it, not disclose it, not use it for advertising and not use it to train artificial intelligence models. Not make automated decisions about the Customer's end customers with it: forecasts concern inventory, not people. Larderia may only produce aggregated technical metrics about how the service runs (for example, the number of variants processed or of errors) that do not identify the store or any person.

6. Sub-processors

  1. The Customer gives general written authorisation (GDPR Art. 28(2)) to engage the sub-processors in Annex III.
  2. Larderia will inform the Customer, by email and in the app, of any addition or replacement of the sub-processors in Annex III at least 30 days in advance. The Customer may object on reasonable data protection grounds within that period. If no solution is found, the Customer may cancel the service and will receive a refund of the unused days of the paid period, under the Terms of Service.
  3. Each sub-processor in Annex III may in turn engage its own providers, with its own prior notice (Render, 10 days; Resend, 14 days). Their lists are public (Annex III). Larderia will review those notices and pass any relevant change on to the Customer as soon as it learns of it, with the same right to object.
  4. Larderia will impose on each sub-processor, by contract, the same data protection obligations as those in this agreement (Art. 28(4)), in particular sufficient guarantees to implement appropriate technical and organisational measures, and will remain fully liable to the Customer for those sub-processors' compliance.
  5. Shopify is not a sub-processor of Larderia. It is the Customer's platform, with which the Customer has its own contract; Larderia reads data from Shopify on the Customer's instructions.
  6. Not sub-processors are the recipients the Customer chooses: its suppliers, when it instructs a purchase order to be emailed to them; the email it enters to receive the digest; and Slack, when the Customer pastes an incoming webhook URL of its own workspace to receive the digest (which contains replenishment figures, product and supplier names and order references, never end-customer data).
  7. Email support is not part of this processing. Emails the Customer or its agency send to hello@enric.app, and our replies, are processed by Larderia as controller to handle the request, under the app Privacy Policy (sections 5 to 7): they are kept in the Zoho Mail mailbox and a copy is forwarded to a Gmail account of the owner. The Customer should therefore not include in them personal data of its end customers or of its suppliers' contact persons. Larderia does not need such data to provide support: if it has to see store data to resolve a request, it looks at it in the app, within this processing. If an email did include such data, Larderia will use it only to reply and, if the Customer asks, will delete it from both mailboxes.

7. Location and international transfers

  1. Location: database and app servers in Render's Frankfurt region (Germany, EU).
  2. Transfers by sub-processors: Render is a US company that, although the data is hosted in the EU, may have remote access for support or security; Resend sends from Ireland but keeps the content and sending logs in the United States. These transfers rely on: (a) the provider's certification under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), including its UK Extension and, where held, the Swiss framework; and (b) if that certification does not apply or ceases to exist, the standard contractual clauses of Implementing Decision (EU) 2021/914 included in each provider's data processing agreement, Module 3 (processor to processor). Each provider's specific safeguard is in Annex III.
  3. Customers outside the EEA: where the Customer is established outside the EEA, the return of data from Larderia (in the EU) to the Customer relies, to the extent necessary, on the standard contractual clauses, Module 4 (processor to controller), which are incorporated by reference. In case of conflict, the standard contractual clauses prevail.
  4. United Kingdom and Switzerland: for data subject to the UK GDPR, the ICO's International Data Transfer Addendum to the standard contractual clauses also applies; for data subject to the Swiss Federal Act on Data Protection, the standard contractual clauses with the adaptations that law requires.
  5. Larderia will not make other transfers outside the EEA without informing the Customer first and without the safeguards of Chapter V of the GDPR.

8. Security

Larderia applies the measures in Annex II and reviews them at least once a year and whenever the service changes. A measure is considered in place only when it is deployed in production and checked. Encryption at rest and in transit is also a Shopify requirement for access to protected data.

9. Security breaches

  1. Larderia will notify the Customer of any breach of the security of its personal data without undue delay (GDPR Art. 33(2)) and, as a target, within 48 hours of becoming aware of it, at the store's contact email and in the app.
  2. The notification will include, to the extent known (and in phases if not everything is known at once): the nature of the breach, the categories and approximate number of data subjects and records concerned, Larderia's contact, the likely consequences and the measures taken or proposed (GDPR Art. 33(3)).
  3. Notifying the supervisory authority (within 72 hours of the Customer becoming aware, Art. 33(1)) and, where applicable, the data subjects (Art. 34) is the Customer's responsibility as controller; Larderia will assist it with the information available to it.
  4. As Shopify's developer terms require, Larderia will also notify Shopify of any actual or suspected breach affecting merchant data within 24 hours at most, and will cooperate with its investigation.

10. Audits

  1. Larderia will provide, at the Customer's request, the information needed to demonstrate compliance: this agreement, the up-to-date description of the measures in Annex II, answers to reasonable security questionnaires and the reports or certifications of its sub-processors that it holds.
  2. If that information is not enough, or if a supervisory authority requires it, the Customer may carry out an audit or inspection, itself or through an independent auditor bound by confidentiality, with at least 30 days' notice, during business hours, without access to other customers' data and at most once a year, unless there has been a security breach or an authority requires it. The Customer bears the cost.

11. Retention, end of service and deletion

  1. Full order: not stored. Order, fulfillment and refund webhooks arrive trimmed and are reduced in memory to the data in section 3 before anything is stored; the reduced webhook is cleared once processed and, in any case, after 24 hours (automatic hourly clean-up). The initial history import is streamed and never written to disk.
  2. During the service: (a) each order's contribution and the fulfillment lines are deleted after 120 days; (b) the stock-level history, after 25 months; (c) forecast snapshots, the activity log and the log of digests sent, after 400 days; (d) the log of each Shopify webhook (without content), 30 days after processing, except for privacy webhooks (section 11.5); (e) daily sales, catalog, inventory, suppliers, purchase orders with their receipts and email log, forecasts, calculated accuracy, logo and digest settings, while the app is installed. The Slack URL is deleted as soon as the Customer removes it in Settings.
  3. After uninstall: the session and tokens are deleted as soon as Shopify reports the uninstall. Shopify sends the shop/redact webhook about 48 hours later; on receiving it, Larderia deletes all that store's data and, if it never arrives, does so automatically 22 days after uninstall. Technical backups are overwritten on rotation within 7 days of the deletion at most and, until then, are used only for disaster recovery (if they were restored, the store's data would be deleted again). So, in every case, the store's data is gone from the database and its backups within 30 days of uninstall at most, as Shopify's developer terms require. Copies of emails already sent that Resend keeps are deleted within its own period (Annex III).
  4. Notices about end customers: on receiving customers/redact, Larderia deletes the contribution and fulfillment lines of the orders Shopify lists; aggregated daily sales, which identify no one, are kept. On receiving customers/data_request, Larderia automatically gathers the stored contribution and fulfillment lines of the listed orders and emails them, with a machine-readable attached file, to the Customer's store contact email, as it is the Customer who answers the data subject; if there is no data, the email says so. Both actions are done when the webhook is processed, within the 30-day period set by Shopify. The content of these webhooks is not stored, only the record of receipt and the counts.
  5. Record: Larderia keeps only the store's *.myshopify.com domain, the uninstall date and the log of privacy webhooks (without their content), to be able to demonstrate compliance (GDPR Art. 5(2)).
  6. The Customer chooses deletion (rather than return) of the data when the service ends (Art. 28(3)(g)), since it can export what it needs beforehand (for example, its orders' CSV or PDF) and its catalog, inventory and orders remain in its Shopify store. No data will be kept unless Union or Member State law requires it.

12. Agencies

  1. When an agency installs or manages Larderia on a merchant's store, it is deemed to act on behalf and with the authorisation of the merchant, who is the Customer and the controller. The agency warrants that it has that authorisation and has informed the merchant of this agreement.
  2. If the agency is itself the merchant's processor, Larderia acts as the agency's sub-processor, and the agency is responsible for having obtained the merchant's authorisation to engage Larderia (GDPR Art. 28(2) and 28(4)) and for passing on the information in this agreement.

13. CCPA/CPRA and other laws

See Annex IV. In case of conflict between this agreement and a stricter applicable data protection law, the rule most protective of data subjects applies.

14. Liability

Liability between the parties under this agreement is governed by the limitation of liability section of the Terms of Service. That limitation does not affect data subjects' rights against either party (GDPR Art. 82) and does not apply in case of wilful misconduct or gross negligence.

15. Order of precedence, governing law and jurisdiction

  1. Order of precedence: (1) standard contractual clauses, where they apply; (2) this agreement; (3) the Terms of Service.
  2. This agreement is governed by Spanish law and the GDPR. The competent courts are those set by the jurisdiction section of the Terms of Service, without prejudice to data subjects' rights to complain to their supervisory authority or go to their courts.

Annex I · Details of the processing

Annex II · Technical and organisational measures

They are considered in place only when deployed and checked in production.

Annex III · Sub-processors

Checked on October 5, 2026 in the official register at dataprivacyframework.gov and in the data processing agreements published by each provider.

Sub-processorServiceData locationTransfer safeguards
Render Services, Inc. (San Francisco, US)App servers, scheduled jobs and managed PostgreSQL databaseFrankfurt (Germany, EU)Certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US framework; its data processing addendum (render.com/dpa, version of 19/12/2024, accepted with its terms) includes the EU standard contractual clauses (Decision 2021/914) for when the framework does not apply. Its sub-processors: render.com/trust (10 days' notice)
Plus Five Five, Inc. ("Resend", San Francisco, US)Sending the emails the Customer instructs: purchase orders to its suppliers, digests to its email and replies to customers' data requestsSent from Ireland (EU); the content and sending logs are stored in the USCertified under the EU-US Data Privacy Framework and its UK Extension; its data processing addendum (resend.com/legal/dpa, version of 31/12/2025) includes the EU standard contractual clauses (Modules 1 to 3), the UK addendum and the Swiss adaptations. 14 days' notice of new sub-processors. It keeps the content and logs of each email for 30 days after sending, and its backups for 7 more days

Not sub-processors (section 6): Shopify (the Customer's platform), the Customer's suppliers as recipients of its orders, the digest's destination email and Slack when the Customer connects it to its own workspace. Nor are the providers of the hello@enric.app support mailbox (Zoho Mail and the Gmail copy), because email support is outside this processing (section 6.7).

Annex IV · CCPA/CPRA (California) and other laws

  1. CCPA/CPRA. To the extent the Customer is a "business" under the California Consumer Privacy Act, as amended by the CPRA, Larderia acts as its "service provider" for the "personal information" processed under this agreement. The limited and specified business purposes are those in section 1. Larderia undertakes to: (a) not sell or share that information; (b) not retain, use or disclose it for any purpose other than those business purposes, including any commercial purpose of its own; (c) not retain, use or disclose it outside the direct business relationship with the Customer; (d) not combine it with personal information received from third parties or collected on its own behalf, except as the law allows; (e) comply with the obligations the CCPA imposes on service providers and provide the same level of privacy protection it requires; (f) allow the Customer to take reasonable and appropriate steps to check that it uses the information consistently with the Customer's obligations (section 10); (g) notify the Customer if it can no longer meet these obligations; and (h) allow the Customer, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorised use. Larderia certifies that it understands these restrictions and will comply with them (Cal. Civ. Code § 1798.100(d) and § 1798.140(ag)).
  2. Brazil (LGPD). Larderia acts as "operador" and the Customer as "controlador"; Larderia processes the data on the Customer's instructions.
  3. Canada (PIPEDA) and Australia (Privacy Act 1988). Through this agreement, Larderia provides a level of protection comparable to that required by the law applicable to the Customer, who remains responsible for the information it transfers.
  4. United Kingdom. References to the GDPR include the UK GDPR and the Data Protection Act 2018 where applicable.

Other Larderia documents: Larderia App Privacy Policy · Larderia Terms of Service