Skip to content
Hand-E Solutions, to the home page

Data Processing Agreement

Agreement pursuant to Art. 28 GDPR for the Shopify apps Hand-E AI Discounts and Hand-E Checkout Rules.
Version 1.6, As of: October 7, 2026
This English version is a convenience translation. Only the German version is legally binding; in case of any discrepancy, the German version prevails.

1. Parties and conclusion of the agreement

The Controller is the merchant who installs the app in their Shopify store.

The Processor is:

Max Handrik
Hand-E Solutions
c/o flexdienst - #22000
Kurt-Schumacher-Straße 74
67663 Kaiserslautern
Germany
info@hand-e.de

This agreement is concluded when the merchant expressly accepts it on the first launch of the app. The store, the time and the version are logged in the process. It is valid in text form pursuant to Art. 28(9) GDPR; no signature is required for this.

If this agreement changes, the new version is presented to the merchant for acceptance again on the next launch of the app.

It ends as soon as the merchant uninstalls the app. The deletion obligations under Section 10 continue to apply beyond that.

2. Subject matter and purpose

Hand-E AI Discounts creates discounts in the merchant's store and evaluates how often they were redeemed. For this purpose, the app processes, on behalf of the merchant, a narrowly limited portion of the merchant's order data.

Hand-E Checkout Rules decides, based on the merchant's rules, which payment and shipping methods appear in the checkout, what they are called and in which order they are listed, and whether an order is held back with a notice. This evaluation runs at Shopify and lasts only as long as the respective checkout request; in doing so, it processes the information listed in Section 3. No storage takes place in the process.

No processing for the Processor's own purposes takes place. The data is not sold and is not used for advertising.

3. Type of data

Only the following is processed:

DataPurpose
Store domain Assigning all data to the correct store
Order identifier (technical ID), time of the order So that the same order is not counted twice
Currency, order total, discount amount granted, name of the discount campaign The evaluation in the dashboard
Optional contact address for follow-up questions when reporting an error Responding to a malfunction reported by the merchant

Names, addresses, email addresses, phone numbers or payment data of end customers are not processed. The app does not request the corresponding permissions from Shopify. The ordered items are not transferred either.

The complete list of all eight data sets is in the Privacy Policy, Section 4.

Additionally for Hand-E Checkout Rules

This app processes the following information exclusively during the evaluation in the checkout and without storing it:

DataPurpose
Cart total, number of items, currency Rules that depend on the cart value
Delivery country Rules that are meant to apply only in certain countries
Login status, number of previous orders, amount spent so far Rules such as "Pay by invoice only from the second order onward"
Whether customer tags specified by the merchant are present Rules for certain customer groups, such as business customers
Items in the cart: product tags, title, collection Rules for certain goods, such as bulky goods or dangerous goods
Offered shipping methods with name and price Hiding, renaming or sorting shipping methods

Here, too, name, address, postal code, email address and phone number are not queried. The information listed does not leave Shopify; the sole result of the evaluation is the information which payment and shipping methods are displayed, renamed or reordered, and whether the notice stored by the merchant appears and the order is held back.

4. Categories of data subjects

  • Customers of the merchant whose order contained a discount from the app
  • Visitors to the store who open the checkout while a rule of Hand-E Checkout Rules is active
  • The merchant and their staff, insofar as they operate the app

5. Instructions

The Processor processes the data exclusively on documented instructions from the Controller. This agreement, together with the privacy policy, constitutes the instruction within the meaning of Art. 28(3)(a) GDPR; it is given by installing and using the app.

The merchant sends further or different instructions to info@hand-e.de. If the Processor considers an instruction to be unlawful, it shall inform the Controller of this without undue delay and may suspend its execution.

6. Obligations and rights of the Controller

The Controller is responsible for the lawfulness of the processing and for safeguarding the rights of the data subjects. In particular, it ensures that

  • there is a legal basis for the processing and that its own information obligations under Art. 13 and 14 GDPR towards its customers are fulfilled,
  • it does not enter any personal data into the input fields of the AI features,
  • it issues instructions in text form and informs the Processor without undue delay if it detects a violation of data protection regulations.

The Controller is entitled to verify compliance with this agreement in accordance with Section 12.

7. Confidentiality

Only the owner has access to the data. No other persons are engaged. If persons are brought in in the future, the Processor shall first commit them in writing to confidentiality and instruct them on data protection.

8. Technical and organisational measures (Art. 32 GDPR)

  • Encryption in transit. All connections to the app and to the Shopify interface run exclusively over TLS (HTTPS).
  • Encryption at rest. The database is hosted at Railway; the underlying storage media are encrypted.
  • Access control. The app can only be reached from within the Shopify admin and authenticates every request via a session token issued by Shopify. There are no separate user accounts and no passwords.
  • Tenant separation. Every record carries the store domain; every query is restricted to it.
  • Data minimisation. An order without a discount from the app is not stored at all. The permissions are limited to five (write discounts, read products, read orders, write files for images in the widgets, which are stored in the store's files at Shopify, and read rollouts, so that a discount that applies only to part of the customer base is not advertised to everyone; nothing from this is stored).
  • Storage limitation. Entries of the discount evaluation are automatically deleted after 90 days (see Section 10).
  • Recoverability. The database is backed up by the operator Railway.

9. Sub-processors

The Controller grants general authorisation to engage the following sub-processors (Art. 28(2) GDPR):

Shopify is not listed here. The platform on which the app runs is based on the Controller's own contract with Shopify; it is not a sub-processor engaged by the Processor.

ServiceService providedRegistered office / processing
Railway Corp. Operation of the app and the database USA; servers in the EU (region EU-West)
Anthropic, PBC Language models for the support chat and the discount assistant USA
ALL-INKL.COM - Neue Medien Münnich Website and email reception Germany

No order or customer data is transmitted to Anthropic. What is transmitted is the text entered by the merchant, the history of the respective conversation, and the names and identifiers of the products and collections searched.

The Processor imposes on each sub-processor, by contract, the same data protection obligations as are set out in this agreement (Art. 28(4) GDPR). If a sub-processor fails to fulfil its obligations, the Processor is liable to the Controller for that sub-processor's conduct.

Changes and additions. The Processor informs the Controller at least 30 days in advance by email to the address stored in the Shopify account and by a notice in the app. The currently valid list is in the Privacy Policy, Section 7.

Objection. The Controller may object to a change within this period for an important reason relating to data protection law by email to info@hand-e.de. If the reason cannot be resolved, the Controller may terminate this agreement with immediate effect by uninstalling the app; the deletion obligations of this agreement then apply unchanged.

10. Deletion and return

  • After 90 days, entries of the discount evaluation are automatically deleted. The dashboard shows at most the last 60 days; older data is no longer needed (Art. 5(1)(e) GDPR).
  • After uninstallation, all of the store's data is deleted from all data sets as soon as Shopify sends the deletion request 48 hours after uninstallation. Implemented via the Shopify webhook shop/redact. The session with the access token is already deleted at uninstallation.
  • Upon a deletion request by a data subject, the entries relating to the specified orders are deleted. Implemented via the webhook customers/redact.

The Controller has the choice between deletion and return (Art. 28(3)(g) GDPR). As a rule, deletion is sufficient: all processed data originates from the Controller's store and remains fully available there. If the Controller requests a return, the Processor provides the data stored for its store before deletion in a common, machine-readable format. Such a request must be sent to info@hand-e.de before uninstallation, since deletion takes place automatically 48 hours after uninstallation.

11. Assistance to the Controller

  • Data subject rights (Art. 12 to 23 GDPR). The app implements the data protection interfaces required by Shopify (customers/data_request, customers/redact, shop/redact). In response to an access request, the Processor states that no identifying customer data is stored and transmits the evaluation entries available for the specified orders (order identifier, time, amounts), so that the Controller can fulfil its obligation to provide information.
  • Notification of breaches (Art. 33 and 34 GDPR). The Processor notifies the Controller of any personal data breach that has come to its attention without undue delay, and at the latest within 48 hours after becoming aware of it.
  • Data protection impact assessment (Art. 35 and 36 GDPR). The Processor assists the Controller within the scope of the information available to it.

12. Evidence and inspections

Upon request, the Processor makes available to the Controller all information necessary to demonstrate compliance with this agreement (Art. 28(3)(h) GDPR). Requests to info@hand-e.de.

On-site inspections are possible with reasonable advance notice and during normal business hours.

13. Transfers to third countries

Processing generally takes place in the European Union. For the language models of Anthropic, PBC (USA), a transfer to the USA takes place on the basis of the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. Railway Corp. has its registered office in the USA but operates this app's database in the EU-West region; the EU Standard Contractual Clauses likewise apply to processing by Railway Corp. in the USA.

14. Final provisions

In the event of conflicts between this agreement and other arrangements between the parties, this agreement takes precedence in matters of data protection.

Should any provision be invalid, the validity of the remaining provisions shall remain unaffected.

German law applies.

Further information

Terms and Conditions · Privacy Policy · Legal Notice