This Data Processing Addendum (“DPA”) forms part of the agreement between thunder-team
(“Yeli,” “we,” “us”) and the merchant using the Yeli app (“Merchant,” “you”)
and applies whenever Yeli processes personal data on the Merchant’s behalf in the course of providing the Yeli app
(the “Service”).
1. Definitions
“Data Protection Laws” means all data protection and privacy laws applicable to the processing of personal data under this DPA, including, where applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).
“Controller,” “Processor,” “Data Subject,” “Personal Data,” and “Processing” have the meanings given in the GDPR, and equivalent terms under other Data Protection Laws are read accordingly.
“Merchant Data” means personal data of the Merchant’s customers (Reviewers) that Yeli processes on the Merchant’s behalf in connection with the Service, as further described in Annex 1.
“Sub-processor” means any third party engaged by Yeli to process Merchant Data.
2. Roles of the Parties
The Merchant is the Controller of Merchant Data. Yeli is the Processor, processing Merchant Data only on the Merchant’s documented instructions, which are given by the Merchant’s configuration and use of the Service (e.g., enabling review requests, moderation settings, or incentive discounts) and by this DPA.
3. Yeli’s Obligations as Processor
Yeli shall:
Process Merchant Data only on the Merchant’s documented instructions, unless required to do otherwise by law (in which case Yeli will inform the Merchant before processing, unless legally prohibited from doing so).
Ensure personnel authorized to process Merchant Data are subject to a duty of confidentiality.
Implement appropriate technical and organizational security measures, as described in Section 6.
Not engage a new Sub-processor without giving the Merchant prior notice of the change (Section 5), and remain fully liable for a Sub-processor’s performance of its data protection obligations.
Taking into account the nature of the processing, assist the Merchant (by appropriate technical and organizational measures, insofar as possible) in responding to requests from Data Subjects exercising their rights under Data Protection Laws — Yeli’s automated handling of Shopify’s customers/data_request and customers/redact webhooks is part of this assistance.
Assist the Merchant in ensuring compliance with obligations relating to the security of processing, breach notification, and data protection impact assessments, taking into account the information available to Yeli.
At the Merchant’s choice, delete or return all Merchant Data at the end of the provision of the Service, except where Yeli is required to retain copies by law — in practice, Yeli’s shop/redact handling (Section 7) erases Merchant Data automatically once Shopify confirms the app has been uninstalled and not reinstalled within its 48-hour grace window.
Make available to the Merchant information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor mandated by the Merchant, subject to reasonable notice and confidentiality.
4. Merchant’s Obligations
The Merchant shall ensure it has a lawful basis for the Merchant Data it submits to or generates through the Service, and that its instructions to Yeli (including its configuration of the Service) comply with Data Protection Laws.
5. Sub-processors
The Merchant provides general authorization to Yeli’s use of the Sub-processors listed below. Yeli will update this list and notify Merchants (e.g., by email or an in-app notice) before adding a new Sub-processor, giving the Merchant a reasonable opportunity to object on reasonable data protection grounds.
Sub-processor
Purpose
Location
Neon
Database hosting
United States
Fly.io
Application/API hosting
United States
Cloudflare
Storage/delivery of review media (photos, video)
Global CDN
Resend
Transactional email delivery
United States
OpenAI
Automated analysis of review text
United States
6. Security Measures
Yeli maintains technical and organizational measures appropriate to the risk, including:
Encrypted connections (TLS) between application services and the database.
Encryption at rest and for backups, provided by our database infrastructure.
Production access restricted to authorized personnel, secured with strong, unique credentials.
An internal security incident response process covering detection, containment, and notification.
7. Personal Data Breach Notification
Yeli will notify the Merchant without undue delay, and where feasible no later than 72 hours, after becoming aware of a personal data breach affecting Merchant Data, providing the information reasonably available to enable the Merchant to meet its own notification obligations under Data Protection Laws.
8. Data Subject Requests and Erasure
Yeli automatically fulfills Shopify’s mandatory compliance webhooks on the Merchant’s behalf:
customers/data_request — Yeli compiles everything it holds for that customer (their reviews, including any they’ve since deleted themselves, and their review-request email history) and sends it directly to the Merchant’s admin contact, so the Merchant can deliver it to their customer within their own response window.
customers/redact — the identified Reviewer’s reviews are unpublished, their media permanently deleted, and their name/email/Shopify customer id anonymized.
shop/redact — fired by Shopify roughly 48 hours after the Merchant uninstalls the app (only if the Merchant has not reinstalled); all Reviewer identities for that store are anonymized, all review media is permanently deleted, and all email-request history is anonymized.
9. International Transfers
Where Yeli transfers Merchant Data outside the UK/EEA (including to the Sub-processors in Section 5), Yeli will ensure an appropriate transfer mechanism is in place as required by Data Protection Laws.
10. Liability, Term, and Governing Law
This DPA remains in effect for as long as Yeli processes Merchant Data under the Service. This DPA, and any dispute arising out of or in connection with it, shall be governed by and construed in accordance with the laws of the People’s Republic of Bangladesh, without regard to its conflict of law principles, and the courts of Bangladesh shall have exclusive jurisdiction to settle any such dispute. Liability under this DPA is subject to the limitations of liability in the Merchant’s underlying agreement with Yeli (Terms of Service).
Annex 1 — Details of Processing
Subject matter: provision of the Yeli reviews app.
Duration: for the term of the Merchant’s use of the Service, plus the erasure window described in Section 8.
Nature and purpose: collecting, verifying, moderating, and displaying product reviews; sending review-request communications; administering review-based incentives.
Categories of Data Subjects: the Merchant’s customers who submit, vote on, or are asked to submit, a product review.
Categories of Personal Data: name, email address, review content (rating, title, body text, photos/videos), order id/number used for purchase verification, shipping country (only when the Merchant enables region-based email timing), and Shopify customer id.