Data Processing Agreement
Last updated: 2026-09-18
Processor: INTROY LTD (company no. 16708956)
Suite 9839, 5 Brayford Square, London, United Kingdom, E1 0SG
Contact: ismailgokhanaru@gmail.com
This agreement applies between INTROY LTD (“we”, the processor) and the merchant who installs Codship (“you”, the controller). It takes effect when you install the app and lasts as long as it stays installed. A Turkish version is also available.
1. Who is who
You are the controller. The personal data belongs to your customers; you decide why it is collected. We only process it to run the app for you.
We are the processor. We act on your documented instructions. Installing the app, configuring it and using its features are those instructions. We do not use your customers’ data for our own purposes.
This matters in a breach: the notification to a supervisory authority is yours to make. Our duty is to tell you fast enough that you can make it in time (section 7).
2. What we process
| Category | Data |
|---|---|
| Data subjects | Your customers and visitors who submit the order form |
| Personal data | Name, phone number, delivery address, optional email, order contents and totals, order outcome, IP address, user agent |
| Special categories | None. We do not process special category data. |
| Purpose | Creating and delivering cash-on-delivery orders, calculating fees, verifying phone numbers, detecting fraudulent orders |
| Duration | While the app is installed, plus the retention periods in section 6 |
3. Our obligations
- Process personal data only on your instructions.
- Keep it confidential, and bind anyone with access to the same duty.
- Apply the security measures in section 4.
- Help you answer your customers’ requests — access, correction, erasure, objection (section 8).
- Not sell the data, not use it for advertising, and not use it to train AI models.
- Delete it when you uninstall the app or when a retention period ends.
4. Security measures
- Encryption in transit (HTTPS enforced) and at rest
- Provider credentials you enter (SMS) are encrypted with AES-256-GCM before storage
- Staging and production data kept in separate environments
- Access to customers’ personal data is limited and logged
- Retention enforced automatically, not by hand
- A written security incident response policy, reviewed yearly
We state plainly what we do not yet have, rather than implying we do: automated encrypted backups are not in place yet. Until they are, a data loss event has no restore path. This is disclosed here because you are entitled to know it before you rely on us.
5. Sub-processors
You agree to the following sub-processors:
| Who | What for | Where |
|---|---|---|
| Railway Corp. | Hosting and database | Amsterdam, Netherlands (EU) |
| Shopify Inc. | The platform your store runs on | Per your Shopify agreement |
| Your own SMS provider | Sending verification codes, only if you connect one | Chosen by you |
We will tell you before adding or replacing a sub-processor, and you may object by uninstalling the app.
6. Retention and deletion
- IP address and user agent: erased after 90 days
- Order records: deleted after 24 months
- Access logs: deleted after 12 months
- Uninstalling the app: your store’s data is deleted, sooner than the periods above
- A Shopify customer redaction request deletes that person’s records, including their entry in the shared fraud network
7. Breach notification
If we become aware of a personal data breach, we notify you without undue delay and within 72 hours, with what happened, which data and how many records are affected, what we have done, and what you may need to do.
Your own 72-hour clock towards the supervisory authority starts when we tell you. Telling you late would put you in breach, which is why this is the one deadline we treat as absolute.
8. Your customers’ rights
Requests can reach us directly through our data request form, or through you. Either way we act on them and keep you informed. We do not charge you for this assistance.
9. Audits
On reasonable notice, and no more than once a year unless an incident warrants it, we will answer written questions about how we process your customers’ data and provide the records we hold about it.
10. International transfers
Data is stored in the European Union. If that ever changes, we will tell you before it happens and put a lawful transfer mechanism in place.
11. End of the agreement
When you uninstall the app, we delete your store’s personal data. Hashed entries you contributed to the shared fraud network stay, because they carry no identity and removing them would erase other merchants’ signal; the underlying phone numbers were never in the network to begin with.