STOQ
Home
Features
All featuresBack in stockPreorders
PricingFeaturesBlogOur storyCase StudiesContact us
Try for Free

DPA

This Data Processing Addendum ("Addendum") amends the agreement between Customer and Artos Software Inc. ("Artos" or "STOQ"), a Delaware C-Corp located at 1111B S Governors Ave STE 3617, Dover, DE 19904, USA, in connection with Customer's use of STOQ (https://apps.shopify.com/back-in-stock-restock-alerts).

‍

Definitions

  1. "Business," "Controller," "Processor," and related terms carry the meanings given in applicable Data Protection Legislation.
  2. "Data Subject" means an identified or identifiable natural person whose Personal Information is Processed.
  3. "Data Subject Request" means the exercise of rights under Data Protection Legislation with respect to Personal Information.
  4. "Data Protection Legislation" means (i) the GDPR, (ii) the California Consumer Privacy Act (as amended), (iii) any other data protection laws applicable to the Processing of Personal Information under this Addendum, (iv) applicable data breach notification statutes, and (v) all other applicable laws relating to the Processing of Personal Information.
  5. "EEA" means the European Economic Area.
  6. "GDPR" means EU Regulation 2016/679, the UK GDPR, and their implementing legislation.
  7. "Personal Information" means data constituting personal data under applicable Data Protection Legislation that Artos Processes on Customer's behalf in connection with the Service.
  8. "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information.
  9. "Relevant Body" means the applicable oversight authority in the UK or EEA, as relevant.
  10. "Restricted Country" means a territory outside the UK/EEA without an applicable adequacy decision.
  11. "Restricted Data Transfer" means a disclosure of Personal Information to a jurisdiction lacking an adequacy decision.
  12. "Security Measures" means the technical and organizational safeguards described in Appendix 2.
  13. "Standard Contractual Clauses" or "SCCs" means the clauses approved under EU Commission Implementing Decision (EU) 2021/914, and the equivalent UK mechanism, as applicable.
  14. "Subprocessors" means the parties listed at https://stoqapp.com/subprocessors.
  15. "Supervisory Authority" means the relevant data protection authority in the applicable jurisdiction.
  16. "UK" means the United Kingdom of Great Britain and Northern Ireland.

‍

Data Protection

‍

1. Roles and Responsibilities

Customer provides Personal Information to Artos in connection with STOQ. Customer will be the Controller and Artos will be the Processor for purposes of the GDPR, and Customer will be the Business and Artos will be the Service Provider for purposes of the CCPA.

‍

2. Artos's Processing Obligations

When Processing Personal Information on Customer's behalf, Artos will:

2.1 Process Personal Information as a Processor for the purpose of providing STOQ, in accordance with Customer's documented instructions, and is prohibited from retaining, using, or disclosing Personal Information for any purpose other than performing the Services, unless otherwise expressly permitted by applicable Data Protection Legislation.

2.2 Not sell Personal Information, and not share Customer Data for purposes of cross-context behavioral advertising.

2.3 Not combine Personal Information received from Customer with information from other sources, except as authorized by Data Protection Legislation.

2.4 Take reasonable measures to ensure that any de-identified data cannot be re-associated with an individual or household.

2.5 Notify Customer if Artos determines that an instruction from Customer conflicts with Data Protection Legislation.

2.6 Promptly notify Customer of any inquiry Artos receives from a Supervisory Authority relating to the Processing of Customer's Personal Information.

2.7 Provide reasonable assistance, upon Customer's written request, with data protection impact assessments and related regulatory consultations, to the extent Artos reasonably considers such assistance is required of it under Data Protection Legislation.

2.8 Provide reasonable assistance, as necessary and technically feasible, to help Customer fulfill Data Subject Request obligations.

2.9 Direct any Data Subject who contacts Artos directly to submit their request to Customer; Customer is solely responsible for responding to such requests.

2.10 Implement appropriate technical and organizational measures (Appendix 2) and provide attestations or certifications regarding those measures upon reasonable request.

2.11 Comply with applicable Data Protection Legislation and ensure its personnel and service providers do the same.

2.12 Notify Customer promptly upon becoming aware of any confirmed Personal Data Breach impacting Customer Data. Customer remains solely responsible for any breach notifications owed to Data Subjects or regulators.

2.13 Ensure that personnel with access to Personal Information are subject to confidentiality obligations.

2.14 Upon termination of the Agreement, cease Processing and delete all Personal Information — including Signup data and Customer account and store-level data — within 48 hours, consistent with Shopify's mandatory data-redaction process for uninstalled apps, subject to Artos retaining copies as required by applicable law. Aggregated, anonymized usage data that cannot be associated with an individual or Customer store is not Personal Information and may be retained thereafter.

‍

3. Customer's Obligations

3.1 Customer will ensure it has the necessary rights and authority to provide Personal Information to Artos for Processing under this Addendum.

3.2 Customer will comply with its own obligations under applicable Data Protection Legislation.

3.3 Customer will not act in a way that causes Artos to breach its obligations under Data Protection Legislation.

3.4 Customer will inform Artos promptly of any inquiry or request it receives that is relevant to Artos's obligations under this Addendum.

‍

4. Subprocessors

Artos's use of any Subprocessor to Process Personal Information must comply with Data Protection Legislation and be governed by a written contract between Artos and the Subprocessor imposing data protection obligations no less protective than those in this Addendum.

If Artos adds a new Subprocessor, Artos will notify Customer by email to Customer's store contact address at least 14 days before the change takes effect, consistent with the notice process described at https://stoqapp.com/subprocessors. Customer may object to a new Subprocessor within that 14-day window by contacting support@stoqapp.com. If Customer objects and Artos is unable to provide the Service without the objected-to Subprocessor, Artos may increase applicable fees to accommodate Customer's requirements or, if the parties cannot reach agreement, either party may terminate the affected Service.

‍

5. Processing Location

Personal Information is Processed primarily in the United States, with certain Subprocessors located as described at https://stoqapp.com/subprocessors. Such Processing is carried out in compliance with applicable Data Protection Legislation.

‍

6. Restricted Data Transfers

Artos may transfer to, access, and Process Personal Information in a Restricted Country as necessary to provide the Service. Such transfers will comply with applicable Data Protection Legislation, and the parties will work together in good faith to resolve any compliance issue arising from a Restricted Data Transfer that is beyond Artos's reasonable control.

‍

7. Standard Contractual Clauses

For transfers subject to the GDPR or UK GDPR to a Restricted Country, the Standard Contractual Clauses are incorporated into this Addendum by reference, with Module Two (controller-to-processor) terms applying. The laws of Ireland govern the EU SCCs as incorporated here; the laws of England and Wales govern disputes under the UK IDTA as incorporated here.

‍

Miscellaneous

‍

1. Conflict Resolution

If there is any conflict or inconsistency between the Agreement and this Addendum, this Addendum will prevail with respect to the Processing of Personal Information.

‍

2. Amendment

Artos may amend this Addendum by providing 30 days' written notice (including by posting on stoqapp.com). Continued use of the Service after the notice period constitutes acceptance of the amendment. If Customer does not agree to an amendment, Customer may terminate the Service during the notice period.

‍

3. Severability

If any provision of this Addendum is found illegal or unenforceable, that provision will be severed and the remaining provisions will remain in full force and effect.

‍

4. Governing Law

This Addendum is governed by the laws of the State of Delaware and the laws of the United States of America applicable therein, without regard to conflict of law principles. The courts of the State of Delaware have exclusive jurisdiction over any dispute arising out of or in connection with this Addendum.

‍

Appendix 1 — Data Processing Details

‍

Artos's Activities and Purpose: Artos operates STOQ, a platform that facilitates preorders and sends back-in-stock alerts (with purchase links) to Customer's customers on Customer's behalf.

‍

Subject Matter and Duration: Processing occurs from Artos's initial receipt of Personal Information through termination of the Agreement, continuing for the duration of the term.

‍

Nature and Purpose of Processing: Processing consists of providing Customer's authorized users access to STOQ's preorder and back-in-stock alert platform, and enabling STOQ to collect and use Signup information to deliver preorder confirmations and back-in-stock notifications.

‍

Categories of Personal Information: Described at https://stoqapp.com/policy — primarily name, email address, and/or phone number of Signups, and store/account information Artos receives via Customer's Shopify connection.

‍

Categories of Data Subjects: Customer's customers ("Signups") whose Personal Information Artos collects or receives in the course of providing the Service as Processor.

‍

Appendix 2 — Security Measures

‍

Artos implements and maintains the following measures:

‍

1. Physical Access Control. Artos takes reasonable measures to prevent physical access by unauthorized persons to facilities where Personal Information is Processed. Artos's infrastructure providers implement safeguards including security personnel, alarm systems, access control systems, and video/CCTV surveillance.

‍

2. System Access Control. Artos takes reasonable measures to prevent unauthorized access to systems Processing Personal Information, including multi-factor authentication, change management processes, and system-level logging.

‍

3. Data Access Control. Artos takes reasonable measures to ensure Personal Information is accessed and managed only by authorized personnel, and to protect against Personal Information being read, modified, or removed without authorization.

‍

4. Transmission Control. Artos takes reasonable measures to prevent disclosure of Personal Information during transmission, including encryption over public networks.

‍

5. Data Availability Control. Artos takes reasonable measures to protect against accidental destruction or loss of Personal Information, including regular backups, restoration testing, replication of backups across multiple sites, and disaster recovery planning.

‍

6. Data Segregation Control. Artos takes reasonable measures to segregate Personal Information on a per-customer basis, using application-level controls for logical separation.

Artos may update these Security Measures from time to time, provided that any change does not materially decrease the overall security of the Service.

Convert demand into revenue for your Shopify store

Effortlessly capture demand, automate preorders, and recover lost revenue with STOQ’s powerful inventory optimization tools. Sell more, even when stock runs low.

Start for Free

Have a query? Reach out at

support@stoqapp.com
Product
FeaturesPricingHelp centre
Stoq
About usContact usBlogCase StudiesAffiliate ProgramReviews
COMPARE
vs Purple Dotvs WOD Preorder Nowvs Globovs Essent
DEVELOPERS
API docsChangelog
Socials
Twitter
LinkedIn
STOQ
STOQ
STOQ
STOQ
© All rights reserved. Artos Software Inc.
Privacy policyTerms of UseDPA