Skip to content
Momentburst
How it worksMomentsPricingJoin the beta

OUR DOCUMENTS

Data processing agreement

DRAFT FOR LEGAL REVIEW

Not effective or agreed. Operator details and production arrangements must be completed and reviewed before merchant use.

Version: 2026-10-03 draft. Not executed or effective. This proposed schedule accompanies the future merchant terms. Controller: [merchant identity/contact]. Processor: Teddy Cane, trading as Momentburst; contact mehceh3690@gmail.com; [business/service address and legal form to be confirmed]. [Confirm applicable UK/EU law, party roles and any international-transfer addendum.]

Processing schedule

Subject: operating football-triggered promotions and measuring attributed orders in the merchant’s Shopify shop. Nature: receiving minimal order fields, matching discounts to runs, storing and summarising results, operating integration jobs, and responding to verified requests. Duration: the service relationship plus the agreed deletion/return schedule, subject to documented legal retention.

Data subjects: merchant users and customers whose qualifying orders are attributed. Data: shop/contact configuration, order IDs/numbers, totals, currency/timestamps, promotion records and operational identifiers. Shopify session and Klaviyo credentials enable authorised processing. Customer names, delivery addresses, phone numbers and customer email addresses are not persisted for attribution; Klaviyo recipients remain in the merchant’s account. No special-category data is required or intended. The merchant must not insert unnecessary sensitive data into rule/template text.

Proposed processor commitments

1. Process only on documented merchant instructions, including permitted transfer instructions; flag an instruction believed unlawful and identify any legally required processing where disclosure is permitted. 2. Restrict staff access to authorised, confidentiality-bound personnel. Use proportionate access controls, secure transmission and the agreed security schedule. 3. Obtain the agreed written subprocessor authorisation, disclose changes with an objection process, and impose equivalent protection obligations. Remain responsible for subprocessor performance as required by the applicable agreement and law. 4. Assist the controller with applicable individual-rights requests, security obligations, breach response, impact assessments and regulator consultation using information available to the processor. 5. Notify the controller of a personal-data breach without undue delay after awareness, with available facts and staged updates. [Agree operational contacts, escalation and any contractual deadline; do not invent an unimplemented SLA.] 6. At termination, return or delete personal data at the controller’s choice unless law requires retention. Specify protected backup handling and a deletion confirmation process. 7. Provide compliance information and facilitate proportionate audits/inspections under agreed arrangements. Explain any instruction considered incompatible with applicable law.

Review these commitments against the ICO controller–processor contract guidance. The language is proposed contract content, not a representation that every operational control is deployed.

Security and retention schedule — current facts and open controls

Implemented development controls include authenticated admin requests, HMAC-verified Shopify webhooks and app proxy, per-shop firing locks, audience restrictions for test email, AES-256-GCM encryption of Klaviyo credentials, sanitised application logging and dependency checks. Shopify session credentials remain database-held; whole-database and backup encryption must be verified for production. External phone alerting/uptime monitoring is currently deferred.

Daily cleanup at 03:30 Europe/London clears latest raw fixture snapshots after 14 days and audit entries after 180 days. Durable minimal retry receipts prevent duplicates after audit expiry. Shop-specific rows and queued jobs are removed on Shopify shop redaction. Customer-order erasure also updates attributed totals and prevents replay resurrection. On-demand request exports contain only retained data; acknowledgement is not proof of delivery to the requesting person.

[Approve periods and deletion/return procedures for all other order/run data, local recordings, logs, subprocessors and backups; specify access reviews, incident exercises, restore tests and encryption-key management. Confirm justified retention rather than treating a paid plan’s display-history limit as a deletion policy.]

Subprocessors and transfers — complete before execution

ServiceCurrent role / dataAppointment and region status
ShopifyMerchant platform, authentication, discounts, billing and order sourceDetermine contractual roles under the merchant and operator agreements
Klaviyo, when connectedMerchant’s marketing platform; campaign/template/audience operationsDetermine role and relevant DPA/transfer terms; recipients remain in merchant account
Production hosting/databaseProposed app compute/storageNot selected, no appointment or region verified
Sentry, if enabledSanitised operational error telemetryVerify actual configuration, contract, fields and region before listing as appointed
API-FootballMatch-data supplierNo customer data intentionally transmitted; review provider licence separately

[Complete actual subprocessor entities, locations, purposes, notification/objection mechanism and required transfer safeguards.] Signature/acceptance: [controller authorised person, date, version] / [processor authorised person, date, version]. No signature or merchant acceptance has been captured by this draft.

MomentburstSales on cue.Not affiliated with any club, league or governing body.© 2026 Momentburst · Terms and DPA are drafts for legal review.
PrivacyTermsData processingContact