Upfront Invoice

Data Processing Agreement

Version 1.0 · Effective 5 August 2026

1. Parties and roles

This DPA is between the Merchant (the Shopify store installing the App) and Woratas Nirasratom, sole proprietor (Samut Sakhon, Thailand) (“Provider”, “we”), operator of Upfront Invoice.

Installing the App constitutes acceptance of this DPA. It prevails over any other terms between the parties with respect to the processing of personal data.

2. Scope of processing

We process personal data only on the Merchant’s documented instructions. Installing and configuring the App constitutes those instructions. We will tell the Merchant if we believe an instruction breaches applicable data-protection law.

Full details are in Annex A.

3. Our obligations as processor

  1. Instructions only — no processing for our own purposes. We never sell or rent personal data, use it for marketing, or use it to train AI models.
  2. Confidentiality — everyone with access is bound by confidentiality.
  3. Security — we maintain the technical and organisational measures in Annex B.
  4. Subprocessors — general authorisation is granted for the subprocessors listed in Annex C. We impose equivalent obligations on each and remain liable for their performance. We give the Merchant prior notice of any addition or replacement so they may object.
  5. Data subject requests — we assist the Merchant in responding, and act on Shopify’s customers/data_request, customers/redact and shop/redact webhooks.
  6. Breach — we notify the Merchant without undue delay after becoming aware of a personal data breach, with the information they need for their own notification duties.
  7. Assistance — we reasonably assist with DPIAs and prior consultations.
  8. Data minimisation by design — customer personal data is never written to our database and never stored as a file; it exists only in memory for the duration of a single render. On termination or uninstall we delete the Merchant’s shop record and all attached invoice records within 48 hours, unless law requires retention.
  9. Information & audit — we make available the information needed to demonstrate compliance and allow audits, which may be satisfied by documentation and written responses given the size of our operation.

4. International transfers

For merchants in the EU/UK, rendering and storage take place in Frankfurt, Germany and invoice email is sent from Ireland. Our subprocessors are incorporated outside the EEA/UK, so their support and administrative access may constitute a transfer; each is engaged under Standard Contractual Clauses or another lawful mechanism through their own data processing agreements (Annex C).

5. Term, liability, governing law

This DPA applies for as long as the App is installed.

Governing law: the laws of the Kingdom of Thailand, with the courts of Thailand having jurisdiction — this does not deprive the Merchant or any data subject of the protection of mandatory provisions of the law that applies to them, including the GDPR and UK GDPR.

Our aggregate liability under this DPA is limited to the fees paid by the Merchant for the App in the twelve months preceding the claim, except where such a limitation is not permitted by applicable law.


Annex A — Details of processing

ItemDetail
Subject matterGenerating and delivering invoices, credit notes and packing slips
DurationWhile the App is installed (+ up to 48h for deletion of stored records)
Nature & purposeAutomated retrieval of order data, rendering to PDF in memory, emailing to the buyer
Categories of data subjectsThe Merchant’s customers (buyers); Merchant staff users
Categories of personal dataName; billing and shipping address; email; order contents, amounts, tax lines, currency, dates
Stored by the ProviderInvoice number, sequence, Shopify order ID, issue date, template version, shop domain, the Merchant’s own template settings, and an access log of which order was rendered and when
Never stored by the ProviderCustomer name, address, email; the generated PDF
Explicitly excludedCustomer phone number (not requested); payment card data; special-category data

Annex B — Technical and organisational measures (Art. 32)

Encryption in transit (TLS) and at rest, including encrypted backups · least-privilege access with strong passwords and 2FA · access logging for every read of protected customer data · separation of test and production data · data-loss-prevention controls (no public database exposure, no bulk personal-data export endpoint) · documented incident response · data minimisation (phone field never requested; customer data never persisted).

Annex C — Subprocessors

SubprocessorPurposeCustomer dataLocationTheir terms
Shopify Inc. (Canada)App platform; source of order dataController-side platformGlobalshopify.com/legal/dpa
Fly.io, Inc. (USA)Application hosting; PDF renderingIn memory only, during a renderFrankfurt, Germanyfly.io/legal/dpa
Neon, LLC (USA — a Databricks company)Invoice record and settings storageNoneFrankfurt, Germany (AWS eu-central-1)neon.com DPA · subprocessors
Resend, Inc. (USA)Invoice email deliveryRecipient address and attached PDF, in transitIreland (AWS eu-west-1)resend.com/legal/dpa