Data processing agreement
Last updated: 6 September 2026
This translation is provided for convenience only. Only the French version is legally binding.
Why this agreement exists
When a merchant connects their store to LIORA, they entrust us with personal data for which they are the controller: that of their own customers — names, delivery addresses, orders. We process it only in order to provide the service to them, on their instructions.
Article 28 of the GDPR requires that this relationship be framed by a written contract. This document serves as that contract. It is accepted by the customer at the moment they connect their store, and forms an integral part of the subscription contract.
It does NOT cover the merchant's own account data — their name, their email address, their subscription. For that data we are the controller, and it is our Privacy policy that applies.
Subject-matter, duration and nature of the processing
- Subject-matter — the provision of the LIORA service: synchronisation of the catalogue, stock levels, prices and orders of the customer's Shopify store.
- Duration — that of the subscription, plus the thirty-day retrieval period provided for by the Terms of sale.
- Nature — collection from the Shopify API, consultation, structuring, making available within the application, and writing back to the store when the customer asks for it.
- Purpose — to enable the customer to manage their business. No other.
- Data subjects — the customers of the merchant's store, and the people the merchant authorises to use the application.
- Categories of data — identity and contact details, delivery and billing addresses, order content and history. No sensitive data within the meaning of Article 9 is processed.
Our undertakings
- Acting on instructions — we process this data solely in order to provide the service, never on our own behalf, and never to train models.
- Confidentiality — the people with access to the data are bound by a duty of confidentiality and access it only for operational or support reasons.
- Security — encryption in transit and at rest, separation of data by business, access logging, hashed passwords. The detail is set out in our Security and incident response.
- Assistance — we help the customer respond to the requests to exercise data subject rights that they receive, and carry out their data protection impact assessments where these concern our processing.
- Alerting — we inform the customer without undue delay of any data breach affecting them, with what we know of it, so that they can meet their own seventy-two-hour deadline.
- Documentation — we make available to them whatever is needed to demonstrate compliance with these undertakings, and we submit to the audits they commission, on reasonable terms and without compromising the security of other customers.
Sub-processors
The customer authorises the use of the following providers, which act on our behalf in performing the service:
- Vercel Inc. — hosting of the site and execution of the processing, in the European Union (Paris).
- Neon Inc. — hosting of the database, in the European Union (Frankfurt).
- Stripe Payments Europe Ltd — collection of subscription payments. Has no access to store data; processes only account and payment data.
- Resend Inc. — delivery of the service's emails. Receives only the recipient's address and the content of the message.
- Scaleway SAS — hosting of the application, in France.
Any change to this list is announced at least thirty days in advance by email. A customer who objects to it on data protection grounds may terminate at no cost, and the unused part of their subscription is refunded to them.
Transfers outside the European Union
The data entrusted to us by merchants is hosted and processed in the European Union. Vercel Inc., Stripe and Resend are companies whose parent company is established in the United States: access from that country, for operational or support purposes, cannot be ruled out. Where that happens, it is framed by the European Commission's standard contractual clauses, together with the technical measures described above.
We would rather flag this reservation than claim a watertightness we could not demonstrate.
At the end of the contract
At the end of the contract, the customer chooses whether the data is returned or deleted. Failing an express choice, it remains retrievable for thirty days, and is then deleted from our active systems, including at our sub-processors.
Encrypted backups may keep a copy beyond that period, for the time it takes them to rotate. They are never consulted and are overwritten automatically.
For any question about this agreement, write to direction@liora-eu.com.