findready

Data Processing Agreement

Effective date: 2026-07-23


1. Parties and binding effect

This Data Processing Agreement forms part of the agreement between the Shopify merchant using Findready, as controller, and Keoma Kindl, based in Austria, EU, as processor. By installing or continuing to use the app, the merchant instructs and authorizes the processing described here.

If this agreement conflicts with other service terms about processing personal data, this agreement controls.

2. Subject matter, duration and purpose

The processor provides on-demand order search and saved search definitions. Processing lasts while the app is installed and only as long afterward as needed to complete deletion, legal obligations or a documented merchant request.

The purpose is limited to finding Shopify orders by merchant-provided search terms and fields, opening matching orders, exporting merchant-requested results and repeating searches the merchant explicitly saves.

3. Data subjects and personal data

Data subjects are the merchant's customers, prospective customers, order recipients, store users and staff members whose information appears in an order or app account.

Data can include names, email addresses, phone numbers, shipping and billing addresses, customer and order identifiers, order content, notes, custom attributes, returns, refunds, tracking details and merchant-authored saved search text. The app does not request payment card data.

4. Documented instructions and confidentiality

The processor processes personal data only on the merchant's documented instructions, including instructions expressed through normal use of the app, unless European Union or Austrian law requires otherwise. The processor will inform the merchant before legally required processing unless the law prohibits notice.

Anyone authorized to process personal data is bound by confidentiality and receives access only when needed to operate, secure or support the service.

5. Security measures

The processor applies measures appropriate to the risk, including TLS in transit, encrypted managed storage and backups, AES-256-GCM encryption for Shopify session tokens, least-privilege named accounts, strong authentication, separated development and production data, access records, sanitized monitoring, short-lived order caching and an incident response process.

Orders and search results are not persisted. On-demand order data is held in process memory for no longer than five minutes and is removed automatically.

6. Sub-processors

The merchant gives general authorization for Shopify, Neon and Railway as sub-processors. They provide the commerce platform, EU-hosted managed PostgreSQL and EU-hosted application infrastructure. Each is bound by data protection obligations appropriate to its role.

The processor will publish material additions or replacements in the privacy policy before they take effect where reasonably possible. The merchant may object on reasonable data protection grounds by contacting support@keomakindl.at. If no reasonable alternative is available, either party may end use of the app.

7. Assistance to the merchant

Taking account of the nature of processing, the processor assists the merchant with requests to access, correct, erase, restrict, object to or export personal data. Shopify privacy webhooks handle customer data requests and deletion requests for app-held data.

The processor also provides reasonable assistance with security assessments, data protection impact assessments and consultations with supervisory authorities, considering the information available to it.

8. Personal data breaches

The processor will notify the merchant without undue delay after becoming aware of a personal data breach affecting merchant data. Notice will describe the known nature, likely consequences and containment or remediation measures, and will be updated as further information becomes available.

9. Return and deletion

On uninstall or written request, the processor deletes app-held merchant data unless applicable law requires retention. Shopify shop-redaction and customer-redaction webhooks delete the relevant records. The merchant can delete saved searches at any time and request earlier deletion at support@keomakindl.at.

Managed encrypted backups expire under the provider's retention schedule and are not restored for ordinary business use after a valid deletion request.

10. Information and audits

The processor will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. The merchant may request one audit per year with reasonable advance notice, subject to confidentiality, security and limits that protect other merchants. Additional audits are permitted after a substantiated incident or when required by a supervisory authority.

The processor will promptly inform the merchant if, in its opinion, an instruction infringes applicable data protection law.

11. International transfers and governing law

Findready's application and database infrastructure is configured in the European Union. If a sub-processor transfers personal data outside the European Economic Area, it must use a valid transfer mechanism such as an adequacy decision or the European Commission's Standard Contractual Clauses.

This agreement is governed by Austrian law and the GDPR. Questions and requests can be sent to support@keomakindl.at.