TrueVAT Invoicing data processing agreement
Effective: 17 September 2026
This DPA forms part of the agreement between the Shopify merchant (controller) and the operator of TrueVAT Invoicing (processor) when the merchant installs or uses the app.
Instructions and purpose
The processor handles personal data only on the merchant’s documented instructions to create, retain and deliver VAT invoices and credit notes, operate the review queue, and satisfy Shopify privacy requests. No sale, advertising, profiling or unrelated use is permitted.
Data and people
Data subjects are buyers and merchant users. Data is limited to buyer identity and contact fields, supplied VAT information, order/refund financial data, document and delivery records, and authenticated access audit entries. Phone and payment-card data are excluded.
Processor commitments
- Apply appropriate technical and organisational security measures, confidentiality restrictions, encryption, access logging and encrypted backups.
- Assist with data-subject requests through Shopify’s mandatory privacy webhooks.
- Notify the merchant without undue delay after confirming a personal-data breach and provide information reasonably needed for the merchant’s obligations.
- Delete or return data at termination as described in the privacy policy, subject to legal retention duties and Shopify’s shop-redaction process.
- Ensure any subprocessor is bound by materially equivalent data-protection duties and remain responsible for its performance.
- Provide information reasonably necessary to demonstrate compliance and cooperate with proportionate audits.
International transfers
Where a restricted international transfer occurs, the parties will rely on an applicable lawful transfer mechanism, including the EU Standard Contractual Clauses or UK Addendum where required.
Security and retention controls are described at truevat.app/security.