Data Processing Agreement

Draft. 19 details in [brackets] still need to be filled in before this document takes effect.

Effective date: [DATE]
Last updated: [DATE]

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between [LEGAL ENTITY NAME] ("REASONBACK", "Processor") and the Brand using the Service ("Brand", "Controller"). It applies automatically when the Brand accepts the Terms.

1. Definitions

  • Applicable Data Protection Law: all laws on personal data that apply to the processing, including Egypt's Personal Data Protection Law No. 151 of 2020 and its executive regulations and, where applicable, the EU General Data Protection Regulation (GDPR).
  • Personal Data: any information about an identified or identifiable person that REASONBACK processes for the Brand under the Terms.
  • Sub-processor: a third party engaged by REASONBACK to process Personal Data.
  • Security Incident: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

Other terms have the meaning given in Applicable Data Protection Law.

2. Roles and scope

2.1 The Brand is the controller and REASONBACK is the processor of the Personal Data described in Annex 1.

2.2 For data about the Brand's own team members used to run their accounts, billing and security, REASONBACK acts as an independent controller under its Privacy Policy.

3. The Brand's instructions

3.1 REASONBACK will process Personal Data only on the Brand's documented instructions. The Terms, this DPA, and the Brand's configuration and use of the Service (for example connecting Shopify or Bosta, or approving a return) are the Brand's complete instructions.

3.2 REASONBACK will tell the Brand if it believes an instruction breaks Applicable Data Protection Law, unless the law prohibits this.

3.3 The Brand confirms that it has a lawful basis for the processing, has given its customers the required notices, and that its instructions comply with the law.

4. Confidentiality

REASONBACK will ensure that everyone authorised to process Personal Data is bound by confidentiality. REASONBACK staff access Brand accounts only to provide support, in a read-only view that expires after one hour, and every access is recorded in an audit log.

5. Security

REASONBACK will implement and maintain the technical and organisational measures in Annex 2. REASONBACK may update these measures, provided the overall level of protection is not reduced.

6. Sub-processors

6.1 The Brand gives general authorisation for REASONBACK to use the Sub-processors listed in Annex 3.

6.2 REASONBACK will give at least [30] days' notice of any new Sub-processor by [email to the Brand owner / updating the list at URL, with email notification]. The Brand may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Brand may end the Terms and receive a refund of prepaid fees for the unused period.

6.3 REASONBACK will impose data protection obligations on each Sub-processor that are at least as protective as this DPA, and remains responsible for their performance.

6.4 Shopify, Bosta and other services the Brand chooses to connect are not Sub-processors. They are the Brand's own providers, and data is exchanged with them on the Brand's instruction.

7. International transfers

Personal Data is stored primarily in the European Union (Frankfurt, Germany). Where Personal Data is transferred across borders, REASONBACK will do so only in line with Applicable Data Protection Law, using appropriate safeguards (such as standard contractual clauses) and obtaining any licences or approvals required.

8. Requests from individuals

8.1 REASONBACK provides tools to help the Brand respond to requests from individuals:

  • Access requests received through Shopify appear in the dashboard with a 30-day countdown, and the Brand can download a file of all data held about that customer.
  • Erasure requests received through Shopify are carried out automatically.

8.2 For requests that do not come through Shopify, REASONBACK will help the Brand within [10] working days of a written request to [privacy@DOMAIN].

8.3 If REASONBACK receives a request directly from an individual, it will forward it to the Brand and will not respond itself unless the Brand instructs it or the law requires.

9. Security Incidents

9.1 REASONBACK will notify the Brand without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting the Brand's Personal Data.

9.2 The notice will describe, as far as known: what happened, the categories and approximate number of people and records affected, the likely consequences, and the steps taken or proposed. REASONBACK will provide further information as it becomes available.

9.3 REASONBACK will take reasonable steps to contain the incident and will help the Brand meet its own obligations to notify authorities and individuals.

10. Assistance

Taking into account the nature of the processing, REASONBACK will reasonably help the Brand with data protection impact assessments and consultations with authorities relating to the Service.

11. Deletion and return of data

11.1 Customer erasure: REASONBACK erases the customer's name, phone number, email, address, notes, photos (the files themselves), refund numbers, transfer references, proof files, and message recipients. A record of the return (items, dates, amounts, governorate) is kept without those identifiers for the Brand's stock and financial records. Internal team comments are the Brand's own notes and are not erased automatically. The Brand is responsible for not writing personal data in them.

11.2 When the Brand leaves: Access keys to the store are deleted immediately on uninstall. About 48 hours later, when Shopify sends its erasure request, all customer personal data is erased in the same way. On request, REASONBACK will delete the Brand's remaining account data within [30] days.

11.3 Backups: erased data is removed from backups as they are overwritten, within [X] days.

11.4 Before leaving, the Brand may download its records. REASONBACK may keep data where the law requires it, protected by this DPA for as long as it is kept.

12. Audits

12.1 On written request, REASONBACK will provide information reasonably necessary to show compliance with this DPA, including a summary of its security measures.

12.2 If that information is not enough, or if an authority requires it, the Brand may carry out an audit no more than once every 12 months, with at least [30] days' notice, during business hours, at its own cost, and under confidentiality, in a way that does not expose other Brands' data.

13. Liability and term

13.1 Each party's liability under this DPA is subject to the limitations in the Terms, except where the law does not allow this.

13.2 This DPA lasts as long as REASONBACK processes Personal Data for the Brand.

13.3 If this DPA conflicts with the Terms on data protection, this DPA prevails.


Annex 1: Details of processing

Annex 2: Security measures

1. Encryption: HTTPS for all data in transit. Database and file storage encrypted at rest. Shopify and Bosta keys encrypted with AES-256 using a key held outside the database.
2. Access control: identity, Brand and role checked on the server for every request. Database closed to direct browser access. Each Brand's data separated by Brand.
3. Roles: permissions limited by role (owner, admin, manager, finance, [others]). Only authorised roles can send refunds, connect integrations, change refund destinations, or manage team members.
4. Authentication: passwords stored only as hashes by the authentication provider. Sign-in by email link available. Two-step sign-in mandatory for REASONBACK staff [and available / required for Brand owners, admins and finance].
5. Private files: customer photos and refund proofs are never on public addresses. Access is through links that expire after one hour. Uploads are checked to be real images, resized, and stripped of location metadata.
6. Portal protection: customers must give both the order number and the phone or email on the order. Repeated failed attempts are slowed down.
7. Integrity of incoming notifications: Shopify signatures and Bosta secrets are verified before any notification is processed. Notification contents are not logged.
8. Logging: a timeline of every change to a return request. A separate audit log of all REASONBACK staff access, which contains no customer personal data.
9. Data minimisation and retention: no card or bank account numbers collected. Automatic deletion of operational logs (30, 60 and 90 days) and anonymous visit counts (about 13 months).
10. Backups and recovery: managed backups by the database provider, retained for [X] days.
11. Incident response: a documented process for assessing, containing and reporting Security Incidents.

Annex 3: Sub-processors