← Return to DFA demo store
Dollflow

GDPR terms

Data Processing Addendum

Controller–processor terms for customer and staff information handled through Dollflow.Effective October 2, 2026
01

Scope and roles

This DPA forms part of the Terms between Great Big AB ("Dollflow" or "Processor") and the Shopify merchant ("Merchant" or "Controller"). The Merchant determines why and how customer and staff information is used. Dollflow processes it only to provide, secure, support, and maintain the service under documented instructions, unless law requires otherwise.

02

Processing details

Subject and duration. Appointment booking, administration, waitlists, recurring visits, memberships, notifications, self-service, optional payment-state synchronization, and optional calendar synchronization during the Merchant's use and applicable retention period.

Nature and purpose. Collecting, organizing, storing, retrieving, transmitting, updating, and deleting information needed to offer services, calculate availability, manage bookings, communicate, prevent conflicts, and maintain related commercial records.

Data subjects. Customers and prospective customers; Merchant owners, staff, contractors, and specialists.

Categories. Identity and contact details; shop, staff, service, appointment and availability data; messages and intake responses; waitlist and recurring preferences; membership, order, transaction, refund, and payment references; notification logs; optional Google account, calendar, token, busy-time, and event references; and technical security data.

Special-category data

The Merchant must not request health or other sensitive data unless it has a valid legal basis, required notices, suitable safeguards, and has independently determined that Dollflow is appropriate.

03

Processor obligations

Dollflow will process personal data only on documented instructions; ensure authorized persons are bound by confidentiality; implement appropriate safeguards; assist with rights, security obligations, impact assessments, and regulator consultations where applicable; and inform the Merchant if an instruction appears unlawful.

04

Security measures

Measures include encrypted transport, access controls, merchant-data separation, encrypted Google OAuth tokens, hashed single-use tokens, pseudonymous protected-data access logs, dependency maintenance, backup and recovery procedures, and tested deletion controls. Measures may evolve without materially reducing protection.

05

Subprocessors

The Merchant gives general authorization for providers on our Subprocessors page. Dollflow requires appropriate protection and remains responsible as required by law. We will update the list when a material provider is introduced. A Merchant may object on reasonable data-protection grounds; if unresolved, it may discontinue the affected feature or terminate the service.

06

International transfers

Where processing transfers personal data outside its protected jurisdiction, Dollflow will use a recognized mechanism when required, such as an adequacy decision or standard contractual clauses, and provide reasonable assessment information.

07

Data-subject requests

Dollflow will reasonably assist with verified access, correction, deletion, restriction, objection, and portability requests. It supports Shopify's mandatory customer data-request, customer-redaction, and shop-redaction webhooks. The Merchant remains responsible for verification and response.

08

Retention, return, and deletion

Dollflow follows its Retention Policy, including automatic anonymization of appointment personal data 24 months after the appointment and deletion of expired waitlist records. Earlier deletion is supported through Shopify privacy requests. After termination, data is deleted or anonymized through the applicable shop-redaction process unless law requires retention.

09

Incidents and compliance evidence

Dollflow will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting its data and provide available response information. On reasonable notice, Dollflow will provide information necessary to demonstrate compliance and cooperate with proportionate assessments required by law, subject to confidentiality and security.

10

Merchant obligations

The Merchant will process data lawfully; provide notices; obtain consent; configure Dollflow accordingly; keep data accurate; limit collection; and issue only lawful instructions. It is responsible for determining whether Dollflow is appropriate for its processing.

11

Precedence and contact

If this DPA conflicts with the Terms on personal-data processing, this DPA controls. Questions, requests, or notices may be sent to dollflowapp@gmail.com.