Legal information

ComplyDock Terms of Service

These Terms govern business access to and use of the ComplyDock Shopify application, supplier portal, website, and related services.

Last updated10 August 2026
Effective from10 August 2026

Service operator

From 10 August 2026

Efstathios Tsanidis
Sole proprietor (Einzelunternehmer), trading as TsanDev
Luhnenstraße 7
30559 Hannover
Germany
Email: tsan-dev@outlook.com

In these Terms, “TsanDev”, “ComplyDock”, “we”, “us”, and “our” refer to Efstathios Tsanidis, trading as TsanDev.

1. Scope and contract parties

These Terms apply to Shopify merchants that install, access, subscribe to, or use ComplyDock (Merchants); people authorised by a Merchant to use ComplyDock through the Merchant’s Shopify account (Authorised Users); and suppliers, manufacturers, responsible persons, and other invited people who use a secure ComplyDock request link (Supplier Users).

The Merchant is TsanDev’s contractual customer. Authorised Users act for the Merchant. Supplier Users receive limited access only to respond to a specific request. Shopify is not a party to the contract between TsanDev and the Merchant.

2. Business use only

ComplyDock is offered exclusively for business and professional purposes. A Merchant must be an entrepreneur within the meaning of section 14 of the German Civil Code (Unternehmer gemäß § 14 BGB), a legal entity under public law, or a special fund under public law. Consumers may not subscribe to or use ComplyDock as customers.

A person accepting these Terms for a company or organisation confirms that the person:

  • Is at least 18 years old.
  • Has authority to bind that organisation.
  • Uses the Service in connection with commercial or independent professional activity.

Supplier Users must be authorised to provide the requested information for the relevant supplier, manufacturer, responsible person, or other represented organisation.

3. Acceptance and contract formation

A Merchant accepts these Terms when they are presented or made available before installation, plan selection, or use and the Merchant then installs ComplyDock, activates access, selects a plan, or continues to use the Service.

For a free plan, the contract begins when ComplyDock access is activated for the Merchant’s store. For a paid plan, the paid subscription begins when the Merchant approves the plan through Shopify and Shopify confirms the subscription. The plan, price, currency, billing interval, and any trial displayed and confirmed by Shopify form part of the contract.

Before submitting through the supplier portal, a Supplier User is shown links to these Terms and the Privacy Policy and must confirm that they have read the supplier terms and are authorised to provide the information. By submitting after that confirmation, the Supplier User agrees to the provisions of these Terms that apply to Supplier Users. This does not create a paid subscription for the Supplier User. Anyone who does not agree or lacks the required authority must not submit information.

4. Description of the Service

ComplyDock is an information-management tool for Shopify merchants. Depending on the selected plan and current functionality, the Service may allow a Merchant to:

  • Synchronise selected Shopify product information.
  • Create supplier records and assign products to suppliers.
  • Send account-free, expiring, and revocable supplier requests.
  • Collect manufacturer, responsible-person, warning, safety, instruction, custom-answer, and supporting-document information.
  • Review, approve, reject, or return submitted information.
  • Keep original supplier submissions separate from later Merchant revisions.
  • Track missing, approved, expiring, and expired information.
  • Maintain source, review, publication, and audit records.
  • Publish Merchant-approved information through a Shopify theme app extension or Shopify-controlled product data.

Features and limits vary by plan.

5. No legal advice, certification, or compliance guarantee

ComplyDock organises information. It does not:

  • Determine which laws, standards, or regulatory requirements apply.
  • Provide legal, regulatory, product-safety, tax, or professional advice.
  • Test, inspect, certify, approve, or register products.
  • Verify the truth, authenticity, or legal sufficiency of information or documents supplied by Merchants or Supplier Users.
  • Guarantee that a product, document, workflow, storefront, or Merchant complies with applicable law.
  • Replace advice from qualified lawyers, testing laboratories, conformity-assessment bodies, authorities, or other professionals.

Profiles, required-field lists, completeness indicators, expiry reminders, warnings, readiness percentages, and status labels are organisational tools only. They are not legal conclusions or certifications.

The Merchant remains solely responsible for determining applicable requirements, obtaining professional advice where necessary, reviewing all information, and deciding whether a product may be offered, advertised, imported, distributed, or sold.

6. Shopify account and permissions

The Merchant must maintain an active Shopify store and provide the Shopify permissions required for the Service. The Merchant is responsible for:

  • The security of its Shopify account.
  • Deciding which users may access the app.
  • Actions performed through authorised Shopify sessions.
  • Keeping Shopify account, billing, and contact information current.
  • Reviewing requested permission changes.

If Shopify access is removed, permissions are reduced, the store is frozen, or Shopify changes or discontinues relevant functionality, some or all of ComplyDock may become unavailable. Each Shopify store requires its own installation and, unless expressly agreed otherwise, its own plan or subscription.

7. Merchant responsibilities

The Merchant must:

  • Provide accurate account and business information.
  • Contact only suppliers or people it is lawfully entitled to contact.
  • Use supplier email addresses and other personal data lawfully.
  • Request only information reasonably relevant to its compliance workflow.
  • Review supplier submissions before approval or publication and verify information where appropriate.
  • Correct or remove information that is inaccurate, outdated, unlawful, or misleading.
  • Ensure that information published on the storefront may lawfully be made public.
  • Maintain appropriate internal access controls and export records needed for its own retention duties.
  • Comply with applicable product, ecommerce, advertising, intellectual-property, confidentiality, and data-protection laws.

The Merchant is responsible for decisions made using the Service and for all information published to its storefront.

8. Supplier requests and secure links

Secure supplier links are request-specific, expiring, revocable, and intended only for authorised recipients. The Merchant must not use ComplyDock to send unlawful, deceptive, abusive, or unsolicited bulk messages.

A Supplier User must:

  • Keep the secure request link confidential and use it only for the intended request.
  • Submit only information the Supplier User is authorised to provide and that is accurate to the Supplier User’s knowledge.
  • Avoid unnecessary personal data and confidential information the requesting Merchant is not authorised to receive.
  • Contact the Merchant if the link was received by mistake.

TsanDev may expire, revoke, replace, throttle, or block a link where reasonably necessary for security, abuse prevention, plan enforcement, or operation of the Service.

9. Merchant and Supplier Content

Content means information, text, answers, supplier records, product data, warnings, instructions, files, documents, images, comments, and other material submitted to or generated through the Service by or for a Merchant. As between the parties, the Merchant or relevant Content owner retains ownership of its Content.

The Merchant grants TsanDev a non-exclusive, worldwide, royalty-free licence, for the contract and applicable retention period, to host, store, reproduce, structure, validate, transmit, display, modify solely for technical formatting, and otherwise process Content only as necessary to:

  • Provide and secure the Service and follow the Merchant’s instructions.
  • Send requests and transactional communications.
  • Support review, provenance, publication, and audit functions.
  • Transmit approved information to Shopify and publish information selected by the Merchant.
  • Provide support and comply with law.

TsanDev may permit contracted service providers to process Content only as necessary to provide their services. The Merchant represents that it has the rights, permissions, notices, and legal bases required for Content submitted to ComplyDock and for its instructions to TsanDev.

10. Storefront publication

Supplier submissions are not intended to be published automatically. The Merchant must approve information and separately initiate or enable publication before eligible information is displayed through ComplyDock’s storefront integration. Supporting documents in the private document area are not automatically published.

When the Merchant publishes information:

  • The information may become publicly accessible.
  • Shopify and the Merchant’s storefront infrastructure may store or cache it.
  • Search engines, customers, and third parties may view, copy, or retain it.
  • TsanDev cannot control copies created outside the Service.

The Merchant must verify information before publication and is responsible for obtaining permission required to publish names, addresses, contact details, or other Content.

11. Acceptable use

A user must not use the Service to:

  • Break any law or infringe another person’s rights.
  • Upload malware, malicious code, corrupted files, deceptive content, or unlawful, defamatory, threatening, discriminatory, or infringing material.
  • Send spam, phishing messages, misleading requests, or knowingly false information.
  • Impersonate another person or organisation.
  • Obtain unauthorised access or probe, scan, attack, overload, or disrupt the Service.
  • Circumvent authentication, secure-link controls, rate limits, plan limits, or usage restrictions.
  • Share secure request links with unauthorised people.
  • Scrape or extract Service data through unauthorised automated means.
  • Reverse engineer, decompile, or attempt to discover source code except where mandatory law expressly permits it.
  • Resell, sublicense, rent, or provide the Service as a standalone third-party service without written permission.
  • Systematically extract non-public functionality or data to build or train a competing product.
  • Upload special-category personal data, government identification documents, or unrelated sensitive personal data unless expressly supported and legally necessary.

TsanDev may reject or remove files and Content that violate these Terms or create a security, legal, or operational risk.

12. Plans, features, and usage limits

ComplyDock currently offers public Free, Lite, Starter, and Growth plans. Current features, limits, prices, billing intervals, and availability are displayed on Shopify’s hosted plan-selection page and, where applicable, inside the app. Shopify’s confirmation page is authoritative for the selected plan, price, currency, billing interval, and any trial.

Plan limits may apply to products, suppliers, active requests, supplier document uploads, Merchant revisions, custom compliance profiles, request cooldowns, or other functionality shown on the plan-selection page. Unlimited means no fixed numerical plan limit is displayed for that feature; it does not permit abusive, unlawful, technically unreasonable, or excessive use that threatens the Service or other users.

13. Downgrades and over-limit accounts

If a downgrade or plan change leaves the Merchant above the new plan’s limits, the Merchant may be required to choose which products, suppliers, or active requests remain in the active workspace. Depending on the affected records:

  • Products or suppliers not selected may leave the active workspace or be archived.
  • Product-supplier assignments may be removed.
  • Affected active requests may be revoked and related secure links may stop working.
  • Audit or source records may remain for traceability, security, or legal reasons.
  • Access to parts of the Service may be restricted until the adjustment is completed.

The Merchant should export or review important data before downgrading.

14. Fees, billing, renewal, and taxes

Paid plans are billed through Shopify App Pricing. Shopify hosts plan selection and charge confirmation and handles invoicing and applicable billing adjustments.

Unless Shopify’s confirmation states otherwise:

  • Paid plans use fixed recurring charges.
  • Monthly plans renew on Shopify’s applicable recurring billing cycle.
  • Yearly plans are charged in full for the annual billing period.
  • Subscriptions renew automatically until cancelled or replaced.
  • No free trial applies unless Shopify expressly displays one before confirmation.
  • Prices use the currency displayed by Shopify, and applicable taxes may be added or handled through Shopify’s billing system.

The Merchant authorises Shopify to place approved ComplyDock charges on its Shopify invoice and is responsible for maintaining a valid Shopify billing account and paying charges when due.

15. Plan changes, cancellation, and refunds

The Merchant can change or cancel a paid plan using options made available through Shopify and may uninstall ComplyDock. Shopify controls the effective date of subscription changes and any proration, credit, deferral, or billing adjustment made through its billing system.

Except where mandatory law requires otherwise, Shopify applies an adjustment, or TsanDev agrees in writing, fees already charged are non-refundable and no refund or credit is owed for a partially used billing period. Uninstalling, cancelling, not using the Service, or not completing onboarding does not itself create a refund right. A scheduled cancellation may leave paid-plan access active until the end of the period shown by Shopify.

A billing dispute should be reported promptly to TsanDev with the store name and relevant Shopify invoice information. Users must not send passwords, access tokens, or payment-card details.

16. Price and plan changes

TsanDev may introduce, remove, or change plans, prices, limits, or included features prospectively. A paid-price change will be presented or notified through Shopify where Shopify confirmation is required and will not take effect contrary to that confirmation or applicable law.

Where reasonably possible, TsanDev will give advance notice of a material reduction to a paid plan’s core functionality. A Merchant that does not accept a prospective material change may cancel before it takes effect.

17. Service availability and changes

TsanDev will use reasonable efforts to operate the Service reliably and securely. The Service is internet-based and depends on Shopify and other infrastructure providers. Unless a separate written service-level agreement expressly says otherwise, TsanDev does not promise uninterrupted, error-free, or permanently available operation.

The Service may be unavailable because of maintenance, security updates, infrastructure or network failures, Shopify changes, third-party failures, bugs, deployment errors, capacity constraints, or events outside reasonable control.

TsanDev may modify, replace, or discontinue functionality where reasonably necessary for security, law, platform compatibility, technical development, or product improvement. Material discontinuation of the entire paid Service without Merchant breach will be notified in advance where reasonably possible.

18. Support

Standard support is provided by email. Unless separately agreed in writing, no guaranteed response or resolution time applies, and support is provided during reasonable business availability.

Support does not include legal advice, product certification, supplier verification, custom development, or management of the Merchant’s Shopify store. Users must not email passwords, secure supplier links, private documents, or unnecessary sensitive personal data.

19. Data protection

The ComplyDock Privacy Policy describes how personal data is processed. For Merchant-controlled personal data, the Merchant generally acts as controller and TsanDev generally acts as processor.

Where Article 28 GDPR applies, the Data Processing Agreement in Appendix 1 forms part of the contract and governs TsanDev's processing of Merchant Personal Data as processor. It is concluded electronically together with these Terms. The Merchant must provide lawful instructions and comply with its controller obligations, including giving required privacy information to Supplier Users and other affected people.

20. Data retention, export, and deletion

The Merchant can use available export functions to download certain product and compliance data and should export information it is legally or operationally required to retain before uninstalling or terminating the Service.

Following the first recorded uninstallation, ComplyDock data and private uploaded documents receive a deletion deadline currently configured for 30 days after uninstall. Provider failures may require deletion retries after that deadline. A valid Shopify shop-redact request accelerates the deadline. Security incidents, disputes, legal claims, statutory retention duties, and temporary backup cycles may require limited information to be retained as described in the Privacy Policy.

Information transferred to Shopify or made public through the Merchant’s storefront may also be held by Shopify, the Merchant, search engines, customers, or other third parties. The Merchant is responsible for checking and removing information held in its Shopify environment where necessary.

21. Security responsibilities

TsanDev uses technical and organisational measures intended to protect the Service, but no system is completely secure. Merchants and Supplier Users must:

  • Protect devices, accounts, email inboxes, and secure request links.
  • Use access only through authorised sessions.
  • Notify TsanDev promptly of suspected unauthorised access, compromised links, or security incidents.
  • Avoid transmitting secrets or sensitive data through support email.
  • Keep copies of information needed for business continuity or legal retention.

TsanDev may temporarily restrict access while investigating a security issue.

22. Confidentiality

Each party must protect non-public business, technical, commercial, and compliance information received from the other party and use it only for the contract. This duty does not apply to information the receiving party can demonstrate:

  • Was already lawfully known without confidentiality restrictions.
  • Becomes public without breach of these Terms.
  • Is received lawfully from a third party without a confidentiality duty.
  • Is independently developed without using the confidential information.
  • Must be disclosed by law, court order, or a competent authority.

Where legally permitted, the receiving party will give reasonable notice before compelled disclosure. These obligations continue after termination for as long as the information remains confidential.

23. Intellectual property

TsanDev and its licensors retain all rights in ComplyDock software and source code; app design, interfaces, workflows, documentation, and branding; the ComplyDock and TsanDev names, logos, and marks; and technical improvements, updates, and derivatives.

Subject to these Terms and payment of applicable fees, TsanDev grants the Merchant a limited, non-exclusive, non-transferable, non-sublicensable right to use the Service for the Merchant’s internal business operations during the contract. No ownership rights are transferred to the Merchant.

24. Feedback

If a user voluntarily provides suggestions or feedback, TsanDev may use it without payment or obligation, provided TsanDev does not publicly identify the user or disclose the user’s confidential information without permission.

25. Third-party services

The Service depends on or interacts with third-party services, including Shopify and providers used for hosting, databases, storage, transactional email, contact-form abuse prevention, and infrastructure. Third-party services may have their own terms and privacy notices.

TsanDev is not responsible for independent third-party products, decisions, accounts, or content. This does not limit TsanDev’s responsibility for selecting and managing processors where data-protection law makes TsanDev responsible.

26. Suspension

TsanDev may suspend or restrict access where reasonably necessary to:

  • Address a security threat or suspected compromise.
  • Prevent unlawful activity, fraud, spam, abuse, or harm.
  • Enforce plan limits or address overdue payment or an inactive Shopify subscription.
  • Protect another user or third party.
  • Respond to Shopify, a court, or a competent authority.
  • Investigate a material breach of these Terms.

Where appropriate and legally permitted, TsanDev will notify the Merchant and provide a reasonable opportunity to remedy the issue. Immediate suspension may occur where delay would create material risk.

27. Term and termination

The contract continues until terminated. The Merchant may terminate by cancelling through Shopify and uninstalling ComplyDock. The effective termination and billing date are determined by the Shopify subscription status and applicable billing confirmation.

TsanDev may terminate immediately for a material breach that cannot be remedied; after reasonable notice and an opportunity to cure a remediable material breach; immediately where required by law or necessary for serious security, fraud, or abuse risk; or on reasonable advance notice if TsanDev discontinues the Service. Either party’s right to terminate for good cause remains unaffected.

Supplier access ends when the relevant request expires, is completed or revoked, or the Merchant’s access ends.

28. Consequences of termination

When the contract or relevant access ends:

  • The right to use the Service ends.
  • Secure supplier links may be revoked or expire.
  • Storefront app blocks may stop displaying ComplyDock information.
  • The Merchant should export required data before termination.
  • Data is handled according to the Privacy Policy and section 20.

Clauses intended by their nature to survive remain effective, including confidentiality, intellectual property, payment obligations, liability, governing law, and dispute provisions. Termination does not remove payment obligations arising before its effective date.

29. Warranties and defects

TsanDev will provide the Service with reasonable professional care and use reasonable efforts to keep core functionality materially consistent with its current description. TsanDev does not warrant that:

  • Every error will be corrected immediately.
  • The Service will meet every individual business or legal requirement.
  • Supplier Content will be accurate or complete or that documents will be authentic or legally sufficient.
  • Use will prevent enforcement action, product incidents, recalls, losses, or disputes.
  • Third-party services will remain available or unchanged.

Mandatory statutory defect rights remain unaffected. To the extent section 536a(1), first alternative, BGB applies, strict liability for defects already existing when the contract was formed is excluded, except where TsanDev fraudulently concealed the defect or expressly guaranteed the relevant quality.

30. Liability

TsanDev has unlimited liability for intent and gross negligence; culpable injury to life, body, or health; liability under the German Product Liability Act; an express guarantee; and other cases where liability cannot legally be limited.

For slight negligence, TsanDev is liable only for breach of an essential contractual obligation whose fulfilment makes proper performance possible and on whose fulfilment the Merchant may regularly rely. Liability is then limited to damage foreseeable and typical for this type of contract when it was formed. In all other cases, liability for slight negligence is excluded.

Subject to those rules, liability for data loss is limited to reasonable restoration costs that would have arisen if the Merchant had made appropriate exports and backups according to the data’s importance. These limitations also apply to TsanDev’s employees, representatives, agents, and service providers where claims are made directly against them.

These Terms do not shift responsibility to TsanDev for the Merchant’s product, legal, publication, supplier-selection, or business decisions.

31. Third-party claims

The Merchant must reimburse and indemnify TsanDev against reasonable third-party claims, losses, and necessary defence costs arising from Merchant Content that infringes third-party rights; the Merchant’s unlawful collection, use, or publication of information; products offered, imported, distributed, advertised, or sold by the Merchant; supplier requests sent without lawful authority; or the Merchant’s material breach of these Terms.

This obligation applies only to the extent the claim was caused by circumstances for which the Merchant is responsible. TsanDev will notify the Merchant without undue delay and will not make an admission or settlement materially affecting the Merchant without reasonable consultation, unless legally required.

32. Force majeure

Neither party is responsible for delay or failure caused by an event outside reasonable control, including natural disasters, war, civil unrest, labour disputes, epidemics, government action, widespread internet or energy failure, cyberattacks not reasonably preventable, or major third-party infrastructure failure.

The affected party must use reasonable efforts to reduce the impact and resume performance. Payment obligations for services already provided are not excused by this section.

33. Changes to these Terms

TsanDev may update these Terms for legal, regulatory, security, technical, Shopify-platform, or service-development reasons. Material changes will be announced through the app, by email, or through another reasonable channel before taking effect where practicable.

If a material change substantially disadvantages the Merchant, the Merchant may terminate before its effective date. Where applicable law requires express consent, the change will not bind the Merchant without that consent. Changes urgently required for law or security may take effect sooner where legally permitted.

34. Notices

TsanDev may send contractual and service notices to the email associated with the Merchant’s Shopify account, through Shopify Admin, or inside ComplyDock. The Merchant must keep its contact information current. Notices to TsanDev may be sent using the contact details in section 38 unless these Terms specify another method.

35. Assignment and subcontractors

The Merchant may not transfer the contract without TsanDev’s prior written consent, which will not be unreasonably withheld where the transfer is part of a legitimate business succession and does not increase risk.

TsanDev may transfer the contract as part of a sale, reorganisation, or transfer of ComplyDock or TsanDev’s relevant business, provided the Merchant is notified and the transfer does not materially reduce the Merchant’s contractual rights. TsanDev may use subcontractors while remaining responsible to the extent required by law and the contract.

36. Governing law and jurisdiction

These Terms and the contractual relationship are governed by the laws of the Federal Republic of Germany, excluding conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods.

If the Merchant is a merchant (Kaufmann), a legal entity under public law, a special fund under public law, or has no general place of jurisdiction in Germany, the exclusive place of jurisdiction for disputes connected with the contract is Hannover, Germany, to the extent legally permitted. TsanDev may also bring a claim at the Merchant’s general place of jurisdiction where legally permitted.

37. General provisions

These Terms, Shopify's plan confirmation, and the Data Processing Agreement in Appendix 1 form the contractual framework. If documents conflict, Shopify's confirmation controls the confirmed plan, price, currency, billing interval, and billing-effective date; Appendix 1 controls processor-specific data-protection matters; and the main Terms control other use of the Service.

Failure to enforce a provision is not a waiver. If a provision is invalid or unenforceable, the remaining provisions remain effective and the applicable statutory rule takes its place. The parties will cooperate on a valid provision that most closely reflects the lawful commercial purpose where appropriate.

The contract language is English. A translation may be provided for convenience. Where legally permitted, the English version controls in the event of inconsistency. No person other than the contractual parties acquires rights under these Terms unless expressly stated.

38. Contact

Questions about these Terms may be sent to:

Efstathios Tsanidis
Sole proprietor (Einzelunternehmer), trading as TsanDev
Luhnenstraße 7
30559 Hannover
Germany
Email: tsan-dev@outlook.com

Contractual appendix

Appendix 1 — Data Processing Agreement (Article 28 GDPR)

This Appendix is an integral and binding part of the Terms wherever TsanDev processes Merchant Personal Data on the Merchant's behalf.

1. Parties, application, and duration

This Data Processing Agreement (DPA) forms Appendix 1 to the ComplyDock Terms of Service. It applies where the Merchant acts as controller and Efstathios Tsanidis, sole proprietor trading as TsanDev, acts as processor for personal data processed through the Merchant's ComplyDock workspace (Merchant Personal Data). Terms such as controller, processor, personal data, processing, data subject, personal data breach, and supervisory authority have the meanings given by the GDPR.

The Merchant is identified by the Shopify store and organisation information connected to its ComplyDock installation. TsanDev's identity and contact details appear at the beginning of these Terms. This DPA is concluded in electronic form when the Merchant accepts the Terms and starts when the service contract begins. It remains effective for as long as TsanDev processes Merchant Personal Data, including an applicable deletion or restricted-retention period after termination.

This DPA does not govern processing for which TsanDev determines its own purposes as controller, such as necessary account administration, security, legal compliance, and direct support records. That processing is described in the ComplyDock Privacy Policy.

2. Subject matter, instructions, and purpose limitation

The subject matter, nature, purposes, duration, data categories, and data subjects are set out in Schedule 1. The Merchant instructs TsanDev to process Merchant Personal Data only as necessary to provide, secure, support, and terminate ComplyDock according to these Terms, the Merchant's configuration and actions in the Service, and additional lawful written instructions agreed by TsanDev.

TsanDev will process Merchant Personal Data only on documented instructions from the Merchant, including instructions concerning transfers, unless Union or Member State law requires processing. Where legally permitted, TsanDev will inform the Merchant before processing required by law. TsanDev will promptly inform the Merchant if, in TsanDev's opinion, an instruction infringes applicable data-protection law and may suspend the affected processing while the parties clarify the instruction.

TsanDev will not sell Merchant Personal Data, use it for third-party behavioural advertising, or use Merchant supplier, document, submission, or compliance content to train public artificial-intelligence models.

3. Merchant obligations and confidentiality

The Merchant is responsible for the lawfulness, fairness, accuracy, and proportionality of its instructions and Merchant Personal Data. In particular, the Merchant must have a valid legal basis, provide required notices, respect data-subject rights, limit access to authorised people, request only relevant information, and avoid submitting special-category data or unrelated sensitive data that ComplyDock does not expressly support.

TsanDev will ensure that each person authorised to process Merchant Personal Data is bound by confidentiality or an appropriate statutory duty and receives access only as necessary for that person's role. Confidentiality obligations continue after access or this DPA ends.

4. Security and personal data breaches

Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and risks to data subjects, TsanDev will maintain the technical and organisational measures in Schedule 2 and may update them where the overall level of protection is not materially reduced.

TsanDev will notify the Merchant without undue delay after becoming aware of a confirmed personal data breach affecting Merchant Personal Data. As information becomes available, the notice will describe the nature of the breach, affected data and people where reasonably possible, likely consequences, mitigation or remediation measures, and an appropriate contact point. Notification does not constitute an admission of fault or liability.

The Merchant remains responsible for determining whether notification to a supervisory authority or communication to data subjects is required. TsanDev will provide reasonable assistance with those duties, taking into account the nature of processing and information available to TsanDev.

5. Data-subject requests and regulatory assistance

Taking into account the nature of processing, TsanDev will provide reasonable technical and organisational assistance to help the Merchant respond to requests exercising data-subject rights. If TsanDev receives a request concerning Merchant Personal Data, TsanDev will direct the requester to the Merchant or notify the Merchant where appropriate, unless law prohibits doing so. TsanDev will not independently respond on the Merchant's behalf without instruction or a legal obligation.

TsanDev will provide reasonable assistance with the Merchant's obligations concerning security, breach assessment, data-protection impact assessments, and prior consultation with a supervisory authority, taking into account the nature of processing and the information available to TsanDev. Assistance that requires unusual or substantial work may be subject to reasonable agreed charges unless it is required because TsanDev breached this DPA.

6. Subprocessors

The Merchant gives general written authorisation for TsanDev to use the subprocessors listed in Schedule 3 to process Merchant Personal Data for the stated functions. TsanDev will impose data-protection obligations on each subprocessor that provide materially equivalent protection appropriate to the services performed and will remain responsible for subprocessor performance to the extent required by applicable law.

TsanDev will inform the Merchant of an intended addition or replacement of a subprocessor before the change takes effect, using email, an in-app notice, or another durable contractual notice. The Merchant may object before the stated effective date on reasonable and documented data-protection grounds. The parties will work in good faith to resolve the objection. If no reasonable solution is available, TsanDev may refrain from using the affected subprocessor or the Merchant may terminate the affected Service before the change takes effect.

Schedule 3 identifies providers engaged by TsanDev for Merchant-controlled processing. It does not list services contracted directly by the Merchant or recipients acting as independent controllers for their own purposes.

7. International transfers

TsanDev will not transfer Merchant Personal Data to a country outside the European Economic Area unless the transfer complies with applicable data-protection law. Where required, TsanDev or the relevant subprocessor will rely on an adequacy decision, the European Commission Standard Contractual Clauses, a valid Data Privacy Framework certification, or another legally recognised safeguard, together with supplementary measures where appropriate.

On reasonable request, TsanDev will make available information about the transfer mechanism applicable to Merchant Personal Data, subject to confidentiality and security restrictions. If a transfer mechanism becomes invalid, TsanDev will work to implement a lawful alternative or stop the affected transfer where required.

8. Return, deletion, and retention

During an active installation, the Merchant can use available exports to retrieve eligible product and compliance information. The Merchant should complete exports and communicate any lawful return instruction before uninstalling. Unless the Merchant lawfully instructs otherwise before termination, deletion is the default choice when processing services end.

After the first recorded uninstall, ComplyDock sessions and access credentials are removed promptly and Merchant Personal Data and private files receive a deletion deadline currently configured for 30 days after uninstall. A valid Shopify shop-redact request accelerates that deadline. Provider failures may require retrying a deletion after the deadline. Limited information may remain where Union or Member State law requires storage, or temporarily in restricted backups and provider replicas until the applicable cycle expires. Retained information will not be used for ordinary Service purposes.

At the Merchant's reasonable request, TsanDev will confirm completion of the applicable production-data deletion after the purge workflow has completed, subject to lawful retention and restricted residual copies described above.

9. Compliance information and audits

TsanDev will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. The Merchant should first use current contractual, security, architecture, provider, test, and audit information made available by TsanDev. Where that information is insufficient, TsanDev will allow and contribute to a proportionate audit by the Merchant or an independent auditor bound by confidentiality.

Audits must normally be requested with reasonable advance notice, occur during reasonable business availability, avoid access to another merchant's data or security-sensitive information, and not unreasonably disrupt the Service. Unless a confirmed breach, supervisory authority, or credible evidence of material non-compliance justifies more, an on-site audit may be limited to once in any twelve-month period. The Merchant bears its audit costs unless the audit establishes a material breach of this DPA by TsanDev.

TsanDev will cooperate with a competent supervisory authority as required by applicable law.

10. Priority, liability, and end of the DPA

If this DPA conflicts with the main Terms on processor-specific data-protection matters, this DPA prevails. The liability provisions in the main Terms apply to this DPA except where mandatory data-protection law requires otherwise. Nothing in this DPA limits rights of data subjects or powers of supervisory authorities.

This DPA ends only after TsanDev has stopped processing Merchant Personal Data and completed required deletion or return, except for provisions and restricted retention that must continue by their nature or by law.

Schedule 1 — Details of processing

Subject matter and purpose

Providing the Merchant with ComplyDock's supplier-information, document, review, provenance, publication, notification, export, and deletion workflows for the Merchant's Shopify products.

Nature of processing

Collection, receipt, recording, organisation, structuring, storage, retrieval, consultation, file-format validation, transmission, comparison, review, approval, correction, publication at the Merchant's direction, export, restriction, revocation, and deletion.

Duration and frequency

Processing occurs as needed during the Merchant's use of ComplyDock and continues through the applicable return, deletion, retry, and restricted-backup period described in this DPA. Frequency depends on the Merchant's and invited Supplier Users' use of the Service.

Categories of data subjects

  • Merchant personnel and Authorised Users.
  • Supplier, manufacturer, importer, distributor, authorised-representative, and responsible-person contacts.
  • Supplier Users invited to respond to secure requests.
  • Individuals identified in compliance answers or supporting documents where relevant to the Merchant's workflow.

Categories of personal data

  • Names, business contact details, role, organisation, and authorisation information.
  • Shopify store, installation, user, product, variant, SKU, barcode, and configuration identifiers where linked to a person or sole trader.
  • Supplier assignments, request messages, deadlines, secure-link access events, submissions, comments, review decisions, and audit history.
  • Manufacturer and responsible-person information, warnings, instructions, custom answers, dates, and provenance information.
  • Uploaded supporting files and their filenames, document types, issue dates, expiry dates, format-validation results, and review status.
  • IP address and related browser, device, security, delivery, and technical-event information necessary to operate and protect the workflow.

Sensitive data

ComplyDock is not designed for special-category personal data, government identification, criminal-offence data, payment-card data, or unrelated sensitive personal data. The Merchant must not submit such data unless processing is legally necessary, expressly supported by ComplyDock, and separately agreed in writing with appropriate safeguards.

Schedule 2 — Technical and organisational measures

  • Governance and confidentiality: documented product boundaries, restricted operational access, confidentiality obligations, provider separation, and review of security-relevant changes.
  • Authentication and authorisation: Shopify session authentication for merchants, least-privilege application access, environment-separated secrets, and tenant-scoped service operations using the trusted Shopify shop context.
  • Tenant isolation: merchant-owned database queries are scoped by internal shop identifier, with ownership checks applied to products, suppliers, requests, submissions, documents, reviews, publications, and destructive operations.
  • Transport protection: HTTPS/TLS for the website, embedded app, supplier portal, provider APIs, and webhooks.
  • Supplier-link security: high-entropy request tokens, storage of only SHA-256 token hashes, request and product scoping, expiry, revocation, replacement, and rate limiting. Plaintext tokens are not logged or persisted by ComplyDock.
  • Document safeguards: private object storage, tenant-derived randomised storage keys, file-size and extension limits, content-signature validation, merchant review, and deletion of rejected file content. Content-signature validation is not antivirus scanning.
  • Integrity and traceability: database constraints and transactions for sensitive workflows, idempotency and webhook validation where applicable, source and version records, and tenant-scoped audit events.
  • Availability and recovery: managed hosting, database, and object-storage resilience and recovery controls, production builds and automated tests, monitored failures, and retry handling for deletion operations.
  • Data minimisation and publication control: limited Shopify scopes and product fields, no intended collection of Shopify customer, order, checkout, or payment-card data, private-by-default documents, and explicit Merchant approval and publication before eligible information reaches the storefront integration.
  • Retention and disposal: prompt session removal after uninstall, a configured shop-data deletion deadline, privacy-webhook handling, retryable private-object deletion before database purge, and restricted treatment of residual provider backups.
  • Security operations: validation of external inputs, dependency and application testing, error handling that avoids secrets, audit and security-event records, and incident assessment and response procedures.

Schedule 3 — Authorised subprocessors

The following subprocessors may process Merchant Personal Data for the stated limited functions. Provider locations include the configured service region and locations used by the provider or its authorised subprocessors. International transfers are governed by section 7 above and the applicable provider agreement.

  • Vercel Inc. — application hosting, serverless execution, content delivery, technical logging, and private object storage through Vercel Blob.
  • Neon, Inc. — managed PostgreSQL database infrastructure, configured for the Frankfurt region.
  • Resend — transactional supplier and service email delivery, including recipient, message, delivery, bounce, and error information.

Cloudflare Turnstile and the support mailbox are used for TsanDev-controlled public contact and abuse-prevention processing described in the Privacy Policy; they are not used to store the Merchant's supplier submissions or private compliance documents.