This Data Processing Agreement (“DPA”) is entered into between:
This DPA forms an integral part of the Service agreement between Synctrack and the Client (the “Agreement”) and governs the processing of personal data by Synctrack on behalf of the Client in accordance with Article 28 of the General Data Protection Regulation (GDPR) and other Applicable Data Protection Law.
By installing an Synctrack application from the Shopify App Store, Wix App Store; You accept this DPA which forms part of Your agreement with Synctrack for the provision of the Services (“Services”).
The following terms shall have the meanings set forth below:
1.1 GDPR Definitions. Terms defined in Regulation (EU) 2016/679 (“GDPR”) have the same meaning in this DPA, including but not limited to:
“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, “Supervisory Authority”.
1.2 Additional Definitions.
2.1 Appointment as Processor. The Controller appoints Synctrack as a Processor to process Personal Data on the Controller’s behalf in connection with the Services. This appointment is made in accordance with Article 28(1) GDPR.
2.2 Authorization to Process. Synctrack is authorized to process Personal Data only:
This fulfills the requirements of Article 28(3)(a) GDPR.
3.1 Documented Instructions. Synctrack shall process Personal Data only on documented instructions from the Controller, which include:
Note: The Controller is responsible for configuring privacy and consent settings appropriately before collecting End User data. Synctrack processes data according to these configured settings. This fulfills the requirements of Article 28(3)(a) GDPR.
3.2 Notification. Synctrack will notify Controllers of significant Service issues that may impact data collection. However, brief interruptions or minor technical issues may be resolved without notification if they do not materially impact the Service. If Synctrack:
Synctrack shall:
Service Limitations: The Controller acknowledges that: technical issues may occasionally affect data collection and processing; some data loss may occur during Service interruptions or technical issues; Synctrack will use commercially reasonable efforts to minimize any data loss; and real-time data collection depends on multiple factors including third-party platforms and browser technologies.
3.3 Controller Obligations. The Controller shall:
4.1 Subject Matter. The subject matter of the processing is the provision of the Services through the Synctrack applications, which operate on the Shopify platform.
4.2 Purpose of Processing. Personal Data shall be processed exclusively for the following purposes:
This fulfills the requirements of Article 28(3) GDPR.
4.3 Nature of Processing. Processing operations may include, depending on the applicable Synctrack application:
4.4 Duration of Processing. Processing shall continue for the duration of the Controller’s active Synctrack subscription. Data is deleted or returned upon termination as per Section 10 of this DPA. This information is required by Article 28(3) GDPR.
5.1 Categories of Data Subjects.
This information is required by Article 28(3) GDPR.
5.2 Categories of Personal Data. The specific categories depend on the Synctrack application used and the Controller’s configuration, and may include:
From Store Visitors (End Users):
From Clients (Merchants):
This fulfills the requirements of Article 28(3) GDPR.
5.3 Special Categories of Data. No special categories of data under Article 9 GDPR are intentionally collected or processed.
6.1 Technical and Organizational Measures. Synctrack shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Technical Measures Currently Implemented:
Note: The Cloud Provider provides built-in redundancy and data durability, and Synctrack maintains backup and recovery procedures for personal data, including encrypted backups and documented restoration processes.
Organizational Measures:
This fulfills the requirements of Article 28(3)(c) and Article 32 GDPR.
6.2 Security Updates. Synctrack shall regularly review and update security measures to maintain appropriate protection levels.
6.3 Data Storage. Synctrack may store certain data in the user’s browser, including existing or custom cookie values, URL parameters, and other information provided by the user, using browser-based technologies such as Cookies, Local Storage, or Session Storage. These processes are essential for maintaining data integrity, supporting necessary backend operations, and delivering core, additional, and enhanced functionalities.
7.1 Personnel Confidentiality. Synctrack ensures that:
This fulfills the requirements of Article 28(3)(b) GDPR.
7.2 Ongoing Obligations. Confidentiality obligations survive termination of employment or engagement.
8.1 General Authorization. The Controller provides general written authorization for Synctrack to engage Subprocessors, subject to the requirements in this section.
8.2 Current Subprocessors. The Controller acknowledges that Synctrack engages multiple Sub-processors to provide the Services, including but not limited to our Cloud Provider as our primary infrastructure provider for cloud hosting and data storage. The complete and current list of all Sub-processors, including their specific processing activities and locations, is maintained by Synctrack and made available to the Controller upon request and in accordance with Section 8.3.
8.3 Adding or Replacing Subprocessors.
This fulfills the requirements of Article 28(2) GDPR.
8.4 Right to Object.
This fulfills the requirements of Article 28(2) GDPR.
8.5 Subprocessor Obligations. Synctrack shall:
This fulfills the requirements of Article 28(4) GDPR.
9.1 Data Location. Personal Data is processed and stored on infrastructure operated by Synctrack’s Sub-processors, primarily on servers hosted with our Cloud Provider (Leaseweb Canada Inc in Montreal, Canada). Additional Sub-processors may process data in other locations as required to provide the Services.
9.2 Safeguards. Where Personal Data is processed in a country other than the Controller’s country of origin, Synctrack protects the data through:
9.3 Frequency and Volume. Processing and any cross-border data flows occur continuously during Service provision as end-user interactions are tracked and processed.
9.4 Standard Contractual Clauses (SCCs). Where the provision of the Services involves a transfer of Personal Data from the European Economic Area (EEA) to a country that has not been recognised as ensuring an adequate level of protection – including transfers to Synctrack in Vietnam and to Synctrack’s Sub-processors – then:
In the absence of such an adequacy decision, the transfer shall be governed by the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCCs”), including any amending or replacing instrument. The EU SCCs are incorporated into and form an integral part of this DPA by reference.
If an adequacy decision of the European Commission or of the relevant competent authority applies to that transfer, that decision shall constitute the legal basis for the transfer;
10.1 Deletion or Return Upon Termination. Upon termination or expiry of the Services, Synctrack shall, at the choice of the Controller:
Synctrack shall inform the Controller if it is legally obligated to retain any personal data after the termination of processing activities. This fulfills the requirements of Article 28(3)(g) GDPR.
10.2 Deletion on Request During Active Service. During the term of Service, the Controller may request the deletion of personal data at any time through the Services or by written instruction. Synctrack shall delete such data without undue delay, unless retention is required by applicable law. If immediate deletion is not technically feasible, Synctrack shall inform the Controller of the reason and the expected timeline. This fulfills the requirements of Article 28(3)(f) GDPR.
10.3 Deletion Timing and Method. Unless otherwise agreed in writing, Synctrack shall delete personal data:
10.4 Data Export During Service. To exercise data access rights, Controllers can use the account or data settings available within the Services or contact [email protected].
10.5 Retention Periods. In accordance with the Terms of Service Section 11.4.2, Synctrack retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected and processed. Specifically:
Clients may request deletion of their data at any time via the Services. All data retention is subject to legal obligations, dispute resolution needs, enforcement of agreements, security requirements, or legitimate business interests (including backups, audit logs, and fraud prevention).
10.6 Shopify Compliance Webhooks. As a Shopify application, Synctrack implements and honors Shopify’s mandatory privacy webhooks. Upon receiving the relevant webhook from Shopify, Synctrack will:
These mechanisms operate in addition to, and are consistent with, the deletion and data subject rights provisions set out in Sections 10 and 11 of this DPA.
11.1 Assistance Obligation. Synctrack shall provide reasonable assistance to the Controller in fulfilling its obligations to respond to data subject requests regarding:
This fulfills the requirements of Article 28(3)(e) GDPR.
11.2 Procedure for Requests.
11.3 Technical Assistance. Synctrack provides tools and technical measures to enable the Controller to respond to data subject requests in a timely and legally compliant manner.
12.1 Notification Timeline. Synctrack shall notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach. The notification will be delivered via email. This fulfills the requirements of Article 28(3)(f) and Article 33 of the GDPR.
12.2 Initial Notification Content. The initial breach notification shall include, to the extent known:
This fulfills the requirements of Article 33(3) GDPR.
12.3 Ongoing Cooperation. Synctrack shall:
This fulfills the requirements of Article 28(3)(f) GDPR.
12.4 Exclusions. Synctrack is not required to notify the Controller of:
13.1 Audit Rights. The Controller has the right to conduct audits or inspections of Synctrack’s data processing activities and relevant systems, as required under Article 28(3)(h) GDPR.
13.2 Audit Procedures. Synctrack shall satisfy the Controller’s audit rights primarily by making available documentation describing its security measures, summary information, and relevant third-party audit reports or certifications (such as SOC 2, ISO 27001, or equivalent), where available. A direct audit or on-site inspection may be conducted only where: (a) required by a competent supervisory authority; (b) following a confirmed Personal Data Breach affecting the Controller’s Personal Data; or (c) the documentation and reports made available above are insufficient to demonstrate compliance. Any such audit shall be:
This fulfills the requirements of Article 28(3)(h) GDPR.
13.3 Documentation. Synctrack shall maintain appropriate records of processing activities and make them available to the Controller or competent supervisory authority upon request. This fulfills the requirements of Article 28(3)(h) GDPR.
14.1 General Assistance. Taking into account the nature of the processing, Synctrack shall assist the Controller, upon request, in ensuring compliance with:
This assistance shall be provided in accordance with Article 28(3)(f) GDPR.
14.2 Information Provision. Synctrack shall provide all information necessary to demonstrate compliance with Article 28 GDPR obligations. This fulfills the requirements of Article 28(3)(h) GDPR.
15.1 Restrictions on Processing. Synctrack shall not:
Where the Controller and its End Users are subject to US Privacy Laws, the additional terms set out in Section 16 (CCPA / US State Privacy Terms) shall apply.
15.2 Aggregated and Anonymized Data. Notwithstanding Section 15.1, Synctrack may create and derive anonymized and/or aggregated data that does not identify the Controller or any natural person from its processing in connection with the Services, and may use such anonymized and/or aggregated data to operate, secure, develop, and improve the Services and for Synctrack’s other legitimate business purposes. Synctrack shall implement reasonable measures to ensure such data cannot be re-identified and shall not attempt to re-identify it.
16.1 Application. This Section applies where the Controller is a “Business” and the End Users are “Consumers” subject to the California Consumer Privacy Act (CCPA) or other US Privacy Laws. In the event of a conflict between this Section and the rest of this DPA with respect to processing governed by US Privacy Laws, this Section controls for those matters.
16.2 Roles of the Parties. For the purposes of US Privacy Laws, the Controller is the “Business” and Synctrack is the “Service Provider” (and, where applicable under other state laws, a “Processor”) that processes Personal Information on behalf of, and at the direction of, the Business.
16.3 Limitations on Processing. Synctrack shall process Personal Information only for the limited and specified business purposes of providing the Services as described in this DPA and the Agreement, and shall not:
16.4 Certification. Synctrack certifies that it understands the restrictions set out in Section 16.3 and will comply with them.
16.5 Consumer Rights. Synctrack shall provide reasonable assistance to the Controller in responding to verifiable Consumer requests to exercise their rights under US Privacy Laws, including the rights to know/access, delete, correct, opt out of sale/sharing, and limit the use of sensitive personal information. The assistance mechanisms described in Section 11 of this DPA apply equally to such requests.
16.6 Notice of Inability to Comply. Synctrack shall notify the Controller without undue delay if it determines that it can no longer meet its obligations under US Privacy Laws. Upon such notice, the Controller may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information.
16.7 Right to Monitor. The Controller has the right to take reasonable and appropriate steps to ensure that Synctrack uses Personal Information in a manner consistent with the Controller’s obligations under US Privacy Laws, consistent with the audit rights set out in Section 13 of this DPA.
16.8 Deidentified Data. Where Synctrack processes deidentified data, it shall maintain and use such data in accordance with the CCPA’s requirements for deidentified information and shall not attempt to reidentify the data, except as permitted by law.
17.1 Statutory Liability. Each Party shall be liable for the damages it causes through an infringement of this DPA or Applicable Data Protection Laws. Nothing in this DPA limits either party’s liability under Articles 82 and 83 GDPR.
17.2 Responsibility Allocation.
This allocation reflects Article 82 GDPR.
17.3 Limitation of Liability. Subject to Section 17.1, each party’s and its affiliates’ total aggregate liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), or any other theory of liability, shall be subject to the exclusions and limitations of liability set out in the Agreement (Terms of Service). Any claim brought against Synctrack or its affiliates under or in connection with this DPA shall be brought solely by the Controller entity that is a party to the Agreement.
18.1 Term. This DPA:
18.2 Survival. The following sections survive termination:
18.3 Termination. Termination of this DPA shall be governed by the termination provisions in the Terms of Service (Section 11). Specifically:
Upon termination, data deletion obligations in Section 10 of this DPA shall apply.
19.1 Governing Law. This DPA shall be governed by the laws of Vietnam, without regard to its conflict of law principles.
19.2 Jurisdiction. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the competent courts of Vietnam.
19.3 Modification. Synctrack will provide 30 days advance notice for any material changes to this DPA via email or dashboard notification. Non-material changes (such as clarifications, typo corrections, or formatting updates) may be made without advance notice. Material changes require Your acceptance through continued use of the Services after the notice period. If You do not agree to the modified DPA, You must discontinue use of the Services before the effective date of the changes.
19.4 Links to Other Websites. Our Service may contain links to third-party websites or Services that are not owned or controlled by Synctrack. Synctrack has no control over, and assumes no responsibility for, the content, privacy policies, or practices of any third party websites or Services.
19.5 Order of Precedence. For matters related to data protection and privacy, the following order of precedence shall apply:
This order of precedence applies only to data protection matters. For all other matters, the order of precedence in Section 14.13 of the Terms of Service shall apply.
Công ty Cổ phần Phần mềm Cyber (Cyber Software Joint Stock Company)
No. 3, Alley 175/55 Lac Long Quan, Tay Ho Ward, Hanoi City, Vietnam
Business Registration No. / Tax Code (MST): 0109598571
Email: [email protected]
By installing an Synctrack application, You acknowledge that You have read, understood, and agree to be bound by this Data Processing Agreement.