Data Processing Addendum
Merchant data processing terms
Effective date: August 25, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Blackwall Systems ("Blackwall") and a merchant or business customer ("Merchant") when Blackwall processes personal data on Merchant's behalf through a Blackwall product or service. It supplements the Terms of Service and Privacy Policy.
1. Roles and scope
For personal data submitted to or accessed by Blackwall solely to provide merchant-configured functionality, Merchant generally determines the purposes and means of processing and Blackwall acts as a processor or service provider to the extent required by applicable law. For Blackwall's own account, billing, security, fraud-prevention, legal, and business-administration activities, Blackwall may act as an independent controller or business as applicable.
2. Merchant instructions
Blackwall will process Merchant personal data only on documented instructions embodied in the applicable agreement, Merchant configuration, support request, or lawful platform instruction, except where law requires otherwise. Merchant is responsible for having an appropriate legal basis and providing required notices for the data it directs Blackwall to process.
3. Purpose limitation and minimization
Blackwall processes only the personal data reasonably necessary to provide enabled functionality. Depending on Merchant configuration, this may include customer name, email address, shipping or billing address, order information, conversation content, support communications, and technical identifiers. Blackwall does not sell Merchant customer personal data or use it for unrelated advertising.
4. Confidentiality and access control
Personnel and authorized service providers with access to Merchant personal data are required to handle it confidentially and only for legitimate business purposes. Blackwall applies least-privilege access principles, account-security controls, and access/audit logging appropriate to sensitive administrative functions.
5. Security measures
Blackwall maintains administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit, provider-managed encryption at rest where supported by the hosting platform, encryption of stored credentials, environment separation, access controls, logging, retention controls, and incident-response procedures. Additional information is available in the Security & Data Protection Policy.
6. Subprocessors
Blackwall may use subprocessors and infrastructure providers as reasonably necessary to provide the service. Current categories include:
- Cloudflare — hosting, network security, Workers/Pages execution, and database infrastructure.
- Shopify — Shopify platform, merchant/customer APIs, app distribution, and Shopify Billing for the Shopify edition.
- Stripe — billing and payment services for direct and applicable non-Shopify transactions.
- AI providers selected or configured by Merchant — model inference and related AI processing when Merchant enables those providers.
- Email or support delivery providers — when Merchant enables functionality that requires such delivery.
Blackwall requires service providers to process data under applicable contractual, security, and privacy obligations appropriate to the service they provide.
7. Data subject and privacy requests
Taking into account the nature of the processing, Blackwall will provide reasonable assistance to Merchant with access, deletion, correction, portability, or similar privacy requests where required. Shopify-related requests are also handled through Shopify's required privacy webhook process.
8. Retention and deletion
Blackwall follows defined retention and deletion practices designed to avoid retaining Merchant personal data longer than necessary. Merchant-configurable retention and deletion controls are honored where available. Details are published in the Data Retention & Deletion Policy.
9. Security incidents
Blackwall maintains procedures to identify, contain, investigate, remediate, document, and where required notify affected parties of security incidents involving personal data. See the Incident Response Policy.
10. International processing
Personal data may be processed in the United States and other locations where Blackwall's service providers operate. Where required, Blackwall or the applicable service provider uses legally recognized transfer mechanisms or contractual safeguards.
11. Return or deletion at termination
Following termination, uninstall, or a valid deletion request, Blackwall deletes or de-identifies Merchant personal data in accordance with platform obligations, configured retention, technical feasibility, and legal retention requirements. Limited records may be retained where necessary for security, fraud prevention, billing, tax, dispute, or legal obligations.
12. Contact
Questions about this DPA may be submitted through the Blackwall Systems contact form.
