C Capyo
nl
Installeren op Shopify

Data Processing Agreement

Last updated: 2026-09-23

These are the processor terms required by Article 28(3) GDPR. They form part of the Terms of Service and take effect when you install the app — you do not need to sign or return anything. If your organisation requires a countersigned copy, email gimbernat13@gmail.com and we will provide one.

1. The parties

Controller: you, the merchant that installed the app.
Processor: Capyo, operated by an individual developer.

This split covers the data listed in section 3. For Capyo's own account, plan, billing and support correspondence with you, Capyo is an independent controller rather than your processor; the Privacy Policy, section 1, describes that side.

Operator legal name and address: see the Privacy Policy.

Shopify is a separate processor for you, under Shopify's own data processing addendum, which governs the Shopify-to-merchant relationship and is unaffected by this document. Store data we process reaches us through Shopify; a product image whose alt text is being written is sent to OpenAI, and a free-tool lead is held by Cloudflare, as described in section 8.

2. Subject matter, duration, nature and purpose

3. Types of personal data

Most of what the app stores is store configuration, page-set and scan data, findings, fix states, alt-text job data and generated documents rather than personal data about an identifiable person. Where personal data is processed, it is one of these kinds:

Excluded by design: customer name, email address, postal address, phone number or customer id; order, checkout and payment data; shopper IP addresses, user agents or per-shopper widget usage; the full HTML of your pages or your theme code; screenshots; and merchant AI-provider keys — the app asks you for none. The OpenAI key is the operator's.

4. Categories of data subjects

The merchant and the merchant's staff and collaborators who use the app. Your storefront visitors do not appear in the app at all: the storefront embed is anonymous, the widget keeps a shopper's adjustments in that browser's localStorage only, and the app holds no shopper identifier. The free public check processes a URL and, only if you submit an email to unlock a result, an email hash and the checked domain — that is covered by the Privacy Policy, section 6.

5. Your instructions

We process personal data only on your documented instructions. Installing the app, building and editing the page set, enabling a fix, generating and accepting alt text, creating a report and publishing or unpublishing the statement are those instructions; the Privacy Policy describes their scope. Sending a product image to OpenAI is carried out to write the alt text you asked for, with the operator's key. Further or different instructions can be sent to gimbernat13@gmail.com; if one would require disproportionate effort or a change to the service, we will say so rather than silently not do it.

If EU or member-state law obliges us to process beyond your instructions, we will tell you before doing so, unless that law forbids telling you. If we believe an instruction infringes the GDPR, we will inform you.

6. Confidentiality

Access is limited to the operator, who is bound by a duty of confidentiality that survives the end of this agreement. There are no other staff. Should that change, anyone given access will be bound by an equivalent written obligation before receiving it.

7. Security measures (Art. 32)

We claim no formal security standard (no ISO 27001, no SOC 2) and do not claim application-level encryption at rest beyond what the hosting providers apply to their own storage.

8. Sub-processors and the providers

You give general authorisation for the sub-processors below.

Sub-processorCompany countryPurposeWhere the servers are
Shopify International Ltd Ireland Platform, source of all store data, billing, and the Files API the accepted alt text is written through Per Shopify's own DPA
OpenAI United States Writes alt text: receives a product image and the app's prompt and returns a generated string. Product images only — no merchant personal data and no customer personal data Per OpenAI's own terms
Cloudflare, Inc. United States Runs the free "Barrierefreiheit Check" Worker and the KV lead store (email hash and checked domain, 12-month retention) — the free tool only, never the installed app's merchant data Cloudflare global network
Hostinger International Ltd Cyprus Application hosting (virtual server) Boston, Massachusetts, United States
netcup GmbH Germany Database hosting (PostgreSQL) Manassas, Virginia, United States
GitHub, Inc. United States Hosting of this public website only; no app data reaches it GitHub Pages infrastructure

OpenAI receives a product image and the app's prompt because you asked the app to write alt text; the app always calls it with the operator's own key, never with an account or credential of yours. Every provider lives behind one adapter, and a provider that is not configured is never called. We remain fully liable to you for the performance of the sub-processors listed above that we do engage directly.

Changes. Before a new sub-processor starts processing, a listed one is replaced, or a hosting location moves, we update this table with a new date at the top of the page. You may object on reasonable data-protection grounds by writing to gimbernat13@gmail.com; if we cannot accommodate the objection, you may uninstall the app and stop paying, with a pro-rata refund of any prepaid period through Shopify.

9. International transfers (GDPR Chapter V)

Merchant data processed through the app is stored on servers located in the United States: the application server in Boston, Massachusetts and the PostgreSQL database in Manassas, Virginia. The companies operating them are European (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing takes place outside the EEA.

Those transfers rely on the Standard Contractual Clauses included in the providers' data processing terms, together with the providers' technical and organisational security commitments and the measures in section 7. The product images sent to OpenAI, and the free-tool lead held by Cloudflare, likewise involve processing in the United States.

The app stores no end-customer personal data, so nothing about your shoppers crosses a border. The transferred data is the store configuration, page set, scan and finding data, fix states, alt-text job data, reports, statement fields and access token described in section 3, plus the product images described there.

Hosting locations may change, including a move to an EU region. Any such change is announced on this page before it takes effect, under the notice rule in section 8. Shopify's own transfers are governed by its DPA and transfer mechanisms.

10. Assistance to you

11. Deletion at the end of the agreement

Sessions and queued jobs are deleted immediately on the app/uninstalled webhook, the statement URL returns 404 within one request, and scheduled jobs for your shop are cancelled. All remaining data about your shop is deleted when Shopify sends the shop/redact webhook, 48 hours after uninstall, which deletes every row for the shop in every table, or earlier if you ask us in writing. A reinstall inside those 48 hours cancels the scheduled deletion and keeps the page set, fixes, reports and statement. Scans, scan pages, findings and usage events age out on the retention in the Privacy Policy, section 9. Alt text already written to your product media stays in your own Shopify data. Database backups are taken daily and rotated after 14 days, so a deleted row can remain inside a backup until that rotation passes; backups are used only for disaster recovery and are never used to restore a deleted shop's data on request.

12. Audit

On written request we provide the information needed to demonstrate compliance with Article 28 — the current sub-processor list, the security measures in section 7, the data model, and answers to a reasonable security questionnaire — once per twelve months, or more often after a breach affecting your data or where a supervisory authority requires it. Because the service is small and single-tenant per shop, we do not host on-site audits; where a controller's law requires an inspection, we will agree a proportionate remote alternative in good faith.

13. Order of precedence

Where this document conflicts with the Terms of Service on a matter of personal-data processing, this document wins. The GDPR wins over both.

14. Contact

gimbernat13@gmail.com. See also the Privacy Policy and the Terms of Service.