Data Processing Agreement
GDPR Article 28 data-processing terms | Effective: August 12, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between ParticleSearch ("Processor") and the Shopify merchant who installs and uses the ParticleSearch application ("Controller"). It governs the processing of personal data by ParticleSearch on behalf of the Controller, in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws. This DPA is incorporated by reference into the ParticleSearch Terms of Service. By installing ParticleSearch, the Controller agrees to the terms of this DPA.
01. Definitions
In this DPA, the following terms have the meanings set out below. Capitalised terms not defined here have the meanings given in the GDPR.
Controller
The Shopify merchant who determines the purposes and means of processing personal data, i.e., you, the store owner.
Processor
ParticleSearch, which processes personal data on behalf of the Controller.
Personal Data
Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
Processing
Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, or deletion.
Sub-Processor
Any third party engaged by the Processor to process personal data on the Controller's behalf.
Data Subject
The natural person to whom personal data relates.
Supervisory Authority
The competent data protection authority in the relevant jurisdiction.
02. Roles and Responsibilities
2.1 Controller
The Controller (the Shopify merchant) is responsible for:
- Determining the lawful basis for processing personal data in connection with their Shopify store
- Ensuring that any personal data provided to ParticleSearch for processing is done lawfully
- Handling data subject requests from their customers (shoppers) relating to personal data
- Ensuring their own compliance with applicable data protection laws
2.2 Processor
ParticleSearch acts as a Processor when it processes data on the Controller's behalf. ParticleSearch is responsible for:
- Processing personal data in accordance with the Controller's documented instructions
- Maintaining appropriate technical and organisational security measures
- Providing reasonable assistance to the Controller in fulfilling its GDPR obligations
- Notifying the Controller of personal data breaches as required by applicable law
Important clarification: ParticleSearch indexes product catalogue data (product titles, prices, SKUs, images, variants, metafields). This data is generally not personal data. However, to the extent that any merchant-provided data contains personal data (for example, a product description referencing an individual), this DPA governs its processing.
Search queries, browser-session context, and optional attribution evidence may relate to end customers even though ParticleSearch does not request customer contact fields or payment-card details. Raw session and order identifiers are replaced with store-scoped pseudonymous values before persistence, and search requests are processed as they arrive.
03. Details of Processing
The following table sets out the details of processing carried out by ParticleSearch on behalf of the Controller.
| Category | Details |
|---|---|
| Subject matter | Search and discovery services, merchant analytics, and optional revenue attribution for Shopify stores |
| Duration | For the duration of the Controller's active ParticleSearch subscription, plus up to 30 days post-termination for deletion of product catalogue data. Aggregated, anonymised search analytics may be retained indefinitely. |
| Nature of processing | Collection, storage, indexing, retrieval, analysis, pseudonymisation, and deletion of catalogue, search-interaction, and optional attribution data |
| Purpose of processing | To provide the configured ParticleSearch services: synchronising the Controller's Shopify catalogue, serving search and discovery experiences, reporting merchant analytics, and, when enabled, attributing eligible completed orders |
| Types of data processed | Product titles, descriptions, prices, inventory levels, variant data (sizes, colours, SKUs), product images (URLs), metafield data, product tags, collection membership, search queries, search-result interactions, pseudonymous session identifiers, and, when enabled, limited pseudonymous order evidence as retrieved from Shopify or derived through ParticleSearch's data processing pipeline |
| Categories of data subjects | Merchant personnel and, where configured, end customers represented by pseudonymous search, browser-session, or attribution evidence. ParticleSearch does not request customer contact fields or payment-card details for these purposes |
| Special category data | The service is not intended to collect special category data as defined in Article 9 GDPR. Merchants should not configure catalogue fields for that purpose. Free-text queries may contain unexpected information and are handled using the minimisation, redaction, retention, and deletion measures described in this DPA and the Privacy Policy |
04. Processing Instructions
ParticleSearch processes personal data in accordance with the Controller's documented instructions, which include:
- Syncing the Controller's Shopify product catalogue to the ParticleSearch search index
- Processing webhook-led incremental updates when product data changes in the Controller's Shopify store
- Serving search results to customers visiting the Controller's store
- Deleting the Controller's data upon termination of the service
If ParticleSearch is required by applicable law to process personal data outside these instructions, ParticleSearch will inform the Controller when legally permitted to do so.
05. Confidentiality
ParticleSearch ensures that personnel authorized to process personal data are bound by confidentiality obligations. Access to personal data is limited to personnel who need it to perform the services. This obligation of confidentiality survives termination of this DPA and the underlying service agreement.
06. Security
6.1 Technical and Organisational Measures
ParticleSearch implements appropriate technical and organisational security measures, including:
- Encryption of data in transit using TLS 1.3
- Encryption of OAuth access tokens at rest
- Access controls limiting data access to authorised personnel
- Security monitoring and vulnerability management
- Anti-abuse rate limiting
- Infrastructure hosted on reputable cloud providers
6.2 Security Updates
ParticleSearch makes reasonable efforts to review and update security measures as technology and risks evolve.
07. Sub-Processors
ParticleSearch engages third-party sub-processors to provide the Service. A current list of sub-processors is maintained at particlesearch.com/subprocessors, including:
- Typesense: Search indexing engine
- Database and hosting providers
- Payment processing (via Shopify billing system)
ParticleSearch will make reasonable efforts to notify Controllers before engaging new sub-processors that process product catalogue data. ParticleSearch may engage new sub-processors immediately when required for service operation, security, or to prevent service disruption.
Controllers may object to new sub-processors by contacting support@particlesearch.com within 14 days of notification. If the objection cannot be resolved, the Controller may terminate without penalty.
ParticleSearch selects sub-processors that maintain appropriate security and data protection standards. ParticleSearch's liability for sub-processor actions is subject to the limitations set out in Section 14 of this DPA and the Terms of Service.
8. Assistance with Data Subject Rights
ParticleSearch will provide reasonable assistance to help Controllers respond to data subject requests, including rights to access, rectification, erasure, restriction, portability, and objection. In practice, ParticleSearch processes product catalogue data, which is generally not personal data relating to individual shoppers. If ParticleSearch receives a data subject request relating to data processed on behalf of the Controller, it will promptly forward the request to the Controller. ParticleSearch will not respond directly to data subject requests without the Controller's authorisation, except where required by law.
9. Personal Data Breaches
In the event of a personal data breach affecting data processed under this DPA, ParticleSearch will notify the Controller without undue delay after becoming aware of the breach, provide sufficient information to enable the Controller to assess the breach, and cooperate in investigating and remediating the breach. The Controller is responsible for determining whether to notify the relevant Supervisory Authority and affected data subjects.
10. Data Protection Impact Assessments
ParticleSearch will provide reasonable assistance to Controllers carrying out Data Protection Impact Assessments (DPIAs) when required. The Controller determines whether a DPIA is required by considering the nature, scope, context, purposes, and risks of its configured processing. ParticleSearch will provide relevant technical information about the service upon request.
11. Deletion of Data
Upon termination or expiry of the service agreement, ParticleSearch will immediately revoke all Shopify OAuth access tokens and delete all product catalogue data from the search index within 30 days. Associated personal data in application logs will be deleted or anonymised under the applicable retention schedule, subject to security, legal, and backup exceptions. ParticleSearch will provide written confirmation of deletion upon request. ParticleSearch may retain anonymised, aggregated data for service improvement. This data cannot be used to reconstruct the Controller's product catalogue.
12. Audits and Inspections
ParticleSearch will make available information necessary to demonstrate compliance with this DPA upon reasonable request. The Controller may request an audit of ParticleSearch's data processing activities with at least 30 days' written notice. ParticleSearch may fulfill audit requests by providing security certifications, audit reports, or other documentation demonstrating compliance.
13. International Data Transfers
Where processing involves transfers of personal data to countries outside the European Economic Area (EEA), ParticleSearch relies on appropriate transfer mechanisms, which may include Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework (where applicable), or other mechanisms recognised under applicable law. ParticleSearch will provide information about transfer mechanisms for sub-processors upon request.
14. Liability
Each party's liability under this DPA is subject to the limitations set out in the ParticleSearch Terms of Service, to the maximum extent permitted by law. Where both parties are responsible for GDPR violations, liability will be apportioned according to each party's degree of responsibility.
15. Duration and Termination
This DPA remains in force while ParticleSearch processes personal data on behalf of the Controller. This DPA terminates automatically when the Controller uninstalls ParticleSearch or the Terms of Service are terminated. Sections 5 (Confidentiality), 11 (Deletion), and 14 (Liability) survive termination.
16. General
Precedence: For data protection matters, this DPA takes precedence
over conflicting Terms of Service provisions.
Entire Agreement: This DPA, the Terms of Service, and Privacy
Policy constitute the entire agreement regarding data processing.
Amendments: ParticleSearch may amend this DPA with 30 days' notice. However,
changes may be made immediately if required for security, legal compliance, or to prevent
abuse, with notification as soon as reasonably practicable.
Schedule, Security Measures
Security StandardsParticleSearch implements the following security measures:
Encryption in Transit
TLS for data transmitted over public networks
Encryption at Rest
OAuth tokens and sensitive data encrypted at rest
Access Controls
Role-based access restrictions
Data Minimisation
Only data categories necessary for the configured capabilities are processed
Audit Logging
System access and processing activities logged
Vulnerability Management
Regular security monitoring
Sub-Processor Controls
Sub-processors selected based on security standards
Incident Response
Process for detecting and responding to breaches
Data Deletion
Processes for deleting data within 30 days of termination
17. Contact
For queries relating to this DPA or data protection compliance:
Email: support@particlesearch.com
Website: particlesearch.com/privacy-policy
ParticleSearch will respond to data protection queries within 5 business days.
Acceptance
For merchants who install via Shopify, acceptance of the Terms of Service constitutes acceptance of this DPA.
For Enterprise merchants requiring a countersigned DPA, contact support@particlesearch.com.