Data Processing Agreement
Last updated: 2026-09-22
These are the processor terms required by Article 28(3) GDPR. They form part of the Terms of Service and take effect when you install the app — you do not need to sign or return anything. If your organisation requires a countersigned copy, email gimbernat13@gmail.com and we will provide one.
1. The parties
Controller: you, the merchant that installed the app.
Processor: Capyo, operated by an individual developer.
This split covers the data listed in section 3. For Capyo's own account, plan, billing and support correspondence with you, Capyo is an independent controller rather than your processor; the Privacy Policy, section 1, describes that side.
Operator legal name and address: see the Privacy Policy.
Shopify is a separate processor for you, under Shopify's own data processing addendum, which governs the Shopify-to-merchant relationship and is unaffected by this document. Store data we process reaches us through Shopify; product images and mode prompts are sent to the image providers described in section 8 when a run generates photos.
2. Subject matter, duration, nature and purpose
- Subject matter: providing the Capyo: AI Product Photos Bulk Shopify app — bulk selections and runs, the three generation modes, the four-output preview, uploading outputs to your Files, publishing them as product media, the credit ledger, and the snapshot and undo history.
- Duration: from installation until the app is uninstalled and the deletion in section 11 completes.
- Nature of processing: collection from Shopify's Admin API and Files API, storage, structured retrieval, transmission of the source image and mode instruction to the image provider for the mode, uploading the generated image to your Files, publishing new media to your products when asked, and erasure.
- Purpose: solely to deliver the app to you and keep it secure. Never for our own marketing, never for profiling, never for training models, never for sale.
3. Types of personal data
Most of what the app stores is store configuration, run and snapshot data, and credit-history data rather than personal data about an identifiable person. Where personal data is processed, it is one of these kinds:
- Business-contact and account data about you and your staff: the shop's
.myshopify.comdomain, store name, the Shopify OAuth access token, plan and locale, install and uninstall timestamps, and the session fields Shopify supplies — staff user id, first and last name, email address, locale, account-owner/collaborator flags, and token expiry and refresh data. - Shop configuration and run data: the selections and product ids you froze into runs, the modes and presets you chose, any custom scene prompt you wrote, the publish options you set, the generated file and media ids, and the snapshot ids that make a run undoable. This describes your catalog and your runs, not your customers.
- Product images sent to providers: the featured images of the products in a run, and the mode instruction (or your custom prompt), are transmitted to the provider for that mode so it can generate the output. The app does not store image bytes itself.
- Operational error traces: the identifiers a job needs (shop domain, run id, error text) in the container's rotating log buffer. No IP address or user agent is written to the database, and the web server keeps no access logs.
Excluded by design: customer name, email address, postal address, phone number or customer id; order, checkout and payment data; your theme code; IP addresses and user agents; and merchant AI-provider keys — the app asks you for none. The provider keys are the operator's, not yours.
4. Categories of data subjects
The merchant and the merchant's staff and collaborators who use the app. Your storefront visitors do not appear at all: the app has no storefront component, no web pixel and no shopper-facing code. The synthetic model presets are not data subjects; they do not depict real people.
5. Your instructions
We process personal data only on your documented instructions. Installing the app, creating a run with a selection, a mode and a preset or custom prompt, confirming the preview, and publishing or undoing outputs are those instructions; the Privacy Policy describes their scope. Sending a product image and mode instruction to an image provider is carried out to generate the output you asked for, with the operator's provider keys. Further or different instructions can be sent to gimbernat13@gmail.com; if one would require disproportionate effort or a change to the service, we will say so rather than silently not do it.
If EU or member-state law obliges us to process beyond your instructions, we will tell you before doing so, unless that law forbids telling you. If we believe an instruction infringes the GDPR, we will inform you.
6. Confidentiality
Access is limited to the operator, who is bound by a duty of confidentiality that survives the end of this agreement. There are no other staff. Should that change, anyone given access will be bound by an equivalent written obligation before receiving it.
7. Security measures (Art. 32)
- TLS on every connection to the app and to this website; no plaintext endpoint exists.
- The database is closed to the public internet: it accepts PostgreSQL connections only from the application server's IP address, over an encrypted connection with password authentication.
- Shopify access tokens are stored only in that database and are never logged or displayed.
- Administrative access to server and database is limited to the operator, over SSH with key authentication.
- Shopify webhooks are verified by HMAC signature before any action is taken.
- Minimum scopes:
read_products,write_products,write_files. Noread_orders, noread_customersand no protected customer data. - Provider credentials (Gemini and fal.ai keys) are held as server environment secrets, belong to the operator, and are never requested from or shown to merchants.
- Image bytes are never written to the application database; only Shopify file and media ids are stored.
- The web server keeps no access logs; no IP address or user agent is written to the database.
We hold no ISO 27001 or SOC 2 certification and do not claim application-level encryption at rest beyond what the hosting providers apply to their own storage.
8. Sub-processors and the image providers
You give general authorisation for the sub-processors below.
| Sub-processor | Company country | Purpose | Where the servers are |
|---|---|---|---|
| Shopify International Ltd | Ireland | Platform, source of all store data, billing, and the Files API the generated images are uploaded to | Per Shopify's own DPA |
| United States | Gemini image generation for the scene and on-model modes: receives the product's source image and the mode instruction, returns the generated image | Per Google's own terms | |
| fal.ai | United States | Image-edit models and the dedicated background-removal model used by the clean-white mode: receives the product's source image and the mode instruction, returns the processed image | Per fal.ai's own terms |
| Hostinger International Ltd | Cyprus | Application hosting (virtual server) | Boston, Massachusetts, United States |
| netcup GmbH | Germany | Database hosting (PostgreSQL) | Manassas, Virginia, United States |
| GitHub, Inc. | United States | Hosting of this public website only; no app data reaches it | GitHub Pages infrastructure |
The image providers receive a product image and a mode instruction because you asked the app to generate an output in that mode; the app always calls them with the operator's own keys, never with an account or credential of yours. Every provider lives behind one adapter, and a provider that is not configured is never called. We remain fully liable to you for the performance of the sub-processors listed above that we do engage directly.
Changes. Before a new sub-processor starts processing, a listed one is replaced, or a hosting location moves, we update this table with a new date at the top of the page. You may object on reasonable data-protection grounds by writing to gimbernat13@gmail.com; if we cannot accommodate the objection, you may uninstall the app and stop paying, with a pro-rata refund of any prepaid period through Shopify.
9. International transfers (GDPR Chapter V)
Merchant data processed through the app is stored on servers located in the United States: the application server in Boston, Massachusetts and the PostgreSQL database in Manassas, Virginia. The companies operating them are European (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing takes place outside the EEA.
Those transfers rely on the Standard Contractual Clauses included in the providers' data processing terms, together with the providers' technical and organisational security commitments and the measures in section 7. The product images and mode prompts sent to Google and fal.ai likewise involve processing in the United States.
The app stores no end-customer personal data, so nothing about your shoppers crosses a border. The transferred data is the store configuration, runs and run items, credit ledger, snapshot ids and access token described in section 3, plus the product images and mode prompts described there.
Hosting locations may change, including a move to an EU region. Any such change is announced on this page before it takes effect, under the notice rule in section 8. Shopify's own transfers are governed by its DPA and transfer mechanisms.
10. Assistance to you
- Data-subject requests. If a data subject contacts us directly about data we process for you, we forward it and do not answer on your behalf. We help you respond, taking into account the nature of the processing and the information available to us.
- Security incidents. We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with what we know: what happened, which categories of data, likely consequences, and the measures taken.
- DPIAs and prior consultation. We provide the information you reasonably need for an assessment under Art. 35 or a consultation under Art. 36.
11. Deletion at the end of the agreement
Sessions and queued jobs are deleted immediately on the app/uninstalled webhook,
and scheduled jobs for your shop are cancelled. All remaining data about your shop is deleted
when Shopify sends the shop/redact webhook, 48 hours after uninstall, which
deletes every row for the shop in every table, or earlier if you ask us in writing. A reinstall
inside those 48 hours cancels the scheduled deletion. Database backups are taken daily and
rotated after 14 days, so a deleted row can remain inside a backup until that rotation passes;
backups are used only for disaster recovery and are never used to restore a deleted shop's data
on request. Generated images that were published live in your own Shopify Files and are
removed by the app's own undo or by you in Shopify; the operator keeps no separate copy.
12. Audit
On written request we provide the information needed to demonstrate compliance with Article 28 — the current sub-processor list, the security measures in section 7, the data model, and answers to a reasonable security questionnaire — once per twelve months, or more often after a breach affecting your data or where a supervisory authority requires it. Because the service is small and single-tenant per shop, we do not host on-site audits; where a controller's law requires an inspection, we will agree a proportionate remote alternative in good faith.
13. Order of precedence
Where this document conflicts with the Terms of Service on a matter of personal-data processing, this document wins. The GDPR wins over both.
14. Contact
gimbernat13@gmail.com. See also the Privacy Policy and the Terms of Service.