Data Processing Addendum
Effective
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Nextsense Solution FZC LLC ("Processor", "PixlBridge") and the Customer ("Controller") and applies whenever PixlBridge processes personal data on the Customer's behalf. It is written to satisfy Article 28 GDPR, the UK GDPR and, where applicable, the CPRA service-provider requirements. A signed copy is available on request from privacy@pixlbridge.com.
1. Roles
The Customer is the controller of shopper data (clicks on tracked links, storefront events, order data, hashed identifiers). PixlBridge is the processor and processes that data only on the Customer's documented instructions, which consist of the Terms, this DPA and the settings the Customer configures in the Service (connected accounts, enabled events, send delay, event toggles). PixlBridge is an independent controller of Customer account data as described in the Privacy Policy.
2. Details of processing
| Item | Description |
|---|---|
| Subject matter | Conversion tracking and attribution for the Customer's Meta advertising that leads to purchases on Amazon or in the Customer's Shopify store. |
| Duration | The term of the Customer's subscription plus the deletion periods in section 8. |
| Nature and purpose | Collection of click and event data; hashing of identifiers; matching purchases to clicks; transmission of conversion events to Meta's Conversions API; aggregated reporting. |
| Data subjects | Visitors who click the Customer's ads; visitors and customers of the Customer's Shopify store. |
| Categories of data | Online identifiers (fbclid-derived click id, _fbp browser id, IP address, user agent, device and browser type); commerce data (order id, value, currency, product identifiers, quantities); SHA-256 hashes of email, phone, first and last name, city, state, postal code, country and customer id. No special categories. |
| Retention | Click data 13 months; hashed Shopify events 90 days after sending; report aggregates for the term; see section 8. |
3. Processor obligations
- Process personal data only on documented instructions, including with regard to international transfers, unless required by law (in which case we inform the Customer unless prohibited).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures in section 5.
- Engage sub-processors only under section 4.
- Assist the Customer with data subject requests (section 6) and with Articles 32 to 36 GDPR obligations, taking into account the nature of processing.
- Delete or return personal data at the end of the service (section 8).
- Make available information necessary to demonstrate compliance and allow audits (section 7).
- Inform the Customer if an instruction, in our opinion, infringes data protection law.
4. Sub-processors
The Customer gives general authorisation to the sub-processors below. We will notify the Customer by email at least 30 days before adding or replacing a sub-processor; the Customer may object on reasonable data-protection grounds, in which case the parties will discuss in good faith and the Customer may terminate the affected service if no resolution is found.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Meta Platforms Ireland Ltd / Meta Platforms, Inc. | Conversions API and Marketing API | EU / US | SCCs; Data Privacy Framework |
| Amazon.com, Inc. and affiliates (Amazon Ads) | Attribution tags and reports | US / EU | SCCs; Data Privacy Framework |
| Shopify Inc. and affiliates | App platform, webhooks, web pixel | Canada / US | Adequacy (Canada); SCCs |
| Stripe, Inc. / Stripe Payments Europe Ltd | Subscription billing (Customer account data only) | US / EU | SCCs; Data Privacy Framework |
| Resend, Inc. | Transactional email (Customer account data only) | US | SCCs |
| Contabo GmbH | Servers, database, backups | Germany (European Union) | Standard Contractual Clauses where required |
| Cloudflare, Inc. (optional) | Edge redirects and DNS for go.pixlbridge.com | Global | SCCs; Data Privacy Framework |
Note that Meta, Amazon and Shopify also act as independent controllers or as the Customer's own processors under the agreements the Customer has with them; transmission of events to Meta is performed on the Customer's instruction as the advertiser.
5. Security measures
- Encryption in transit (TLS 1.2+) and at rest; provider tokens encrypted with AES-256-GCM with the key held outside the database.
- Pseudonymisation: shopper identifiers are SHA-256 hashed at ingest; raw values are not stored.
- Logical tenant isolation: every query is scoped to a workspace by a database access layer; verified by automated cross-tenant tests.
- Access control: role-based access, database-verified on each request; platform-operator access time-limited and audit logged; no shared credentials.
- Integrity: signature verification of all inbound webhooks; single-use OAuth state; idempotent processing.
- Availability: daily encrypted backups with off-site copies; documented restore procedure.
- Secure development: threat model, security review with regression tests, dependency auditing, generic error responses, rate limiting.
Further detail: pixlbridge.com/security.
6. Data subject requests
We do not respond directly to data subjects about Customer Data except to refer them to the Customer. We honour Shopify's customers/data_request and customers/redact webhooks automatically and provide export or erasure for other requests within 10 business days of the Customer's instruction.
7. Audits
On request no more than once per year (or after a security incident), we provide our security documentation, the current sub-processor list and a summary of test results. Where this is insufficient, the Customer may conduct or mandate an audit on 30 days' notice, during business hours, under confidentiality, at the Customer's cost, without disrupting other tenants.
8. Deletion and return
The Customer may export reports at any time (CSV) and delete a store, a connection or the whole workspace from the application. On workspace deletion or termination we delete Customer Data from live systems within 30 days and from backups within 14 days, unless retention is required by law. Uninstalling the Shopify app clears the store token immediately; shop/redact deletes the store's remaining data.
9. Personal data breach
We notify the Customer without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting Customer Data, with the information reasonably available to allow the Customer to meet its own notification duties.
10. International transfers
Where Customer Data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the EU Standard Contractual Clauses (Module 2 controller-to-processor, Module 3 processor-to-processor with sub-processors) with the UK Addendum and Swiss amendments are incorporated by reference, with the Customer as data exporter and PixlBridge as importer.
11. California
To the extent the CPRA applies, PixlBridge is a service provider: it does not sell or share personal information, does not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Service, and will notify the Customer if it can no longer meet these obligations.
12. Contact
Nextsense Solution FZC LLC, CWS-2V-195841, 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates, the United Arab Emirates (Emirate of Ajman). privacy@pixlbridge.com.