Data Processing Agreement

Last updated: 2026-09-18
Processor: INTROY LTD (company no. 16708956)
Suite 9839, 5 Brayford Square, London, United Kingdom, E1 0SG
Contact: ismailgokhanaru@gmail.com

This agreement applies between INTROY LTD (“we”, the processor) and the merchant who installs Codship (“you”, the controller). It takes effect when you install the app and lasts as long as it stays installed. A Turkish version is also available.

1. Who is who

You are the controller. The personal data belongs to your customers; you decide why it is collected. We only process it to run the app for you.

We are the processor. We act on your documented instructions. Installing the app, configuring it and using its features are those instructions. We do not use your customers’ data for our own purposes.

This matters in a breach: the notification to a supervisory authority is yours to make. Our duty is to tell you fast enough that you can make it in time (section 7).

2. What we process

CategoryData
Data subjectsYour customers and visitors who submit the order form
Personal dataName, phone number, delivery address, optional email, order contents and totals, order outcome, IP address, user agent
Special categoriesNone. We do not process special category data.
PurposeCreating and delivering cash-on-delivery orders, calculating fees, verifying phone numbers, detecting fraudulent orders
DurationWhile the app is installed, plus the retention periods in section 6

3. Our obligations

4. Security measures

We state plainly what we do not yet have, rather than implying we do: automated encrypted backups are not in place yet. Until they are, a data loss event has no restore path. This is disclosed here because you are entitled to know it before you rely on us.

5. Sub-processors

You agree to the following sub-processors:

WhoWhat forWhere
Railway Corp.Hosting and databaseAmsterdam, Netherlands (EU)
Shopify Inc.The platform your store runs onPer your Shopify agreement
Your own SMS providerSending verification codes, only if you connect oneChosen by you

We will tell you before adding or replacing a sub-processor, and you may object by uninstalling the app.

6. Retention and deletion

7. Breach notification

If we become aware of a personal data breach, we notify you without undue delay and within 72 hours, with what happened, which data and how many records are affected, what we have done, and what you may need to do.

Your own 72-hour clock towards the supervisory authority starts when we tell you. Telling you late would put you in breach, which is why this is the one deadline we treat as absolute.

8. Your customers’ rights

Requests can reach us directly through our data request form, or through you. Either way we act on them and keep you informed. We do not charge you for this assistance.

9. Audits

On reasonable notice, and no more than once a year unless an incident warrants it, we will answer written questions about how we process your customers’ data and provide the records we hold about it.

10. International transfers

Data is stored in the European Union. If that ever changes, we will tell you before it happens and put a lawful transfer mechanism in place.

11. End of the agreement

When you uninstall the app, we delete your store’s personal data. Hashed entries you contributed to the shared fraud network stay, because they carry no identity and removing them would erase other merchants’ signal; the underlying phone numbers were never in the network to begin with.


Türkçe sürüm · Privacy policy