Data Processing Agreement
Real User Monitoring (RUM) App for Shopify and Wix
Last updated: 30 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Use at https://makkpressapps.com/terms-and-conditions (the "Terms") between MakkPress Technologies Private Limited, 28/6, 3rd Floor, Double Storey Building, Ashok Nagar, Tilak Nagar, New Delhi, Delhi 110018, India ("MakkPress", "we", "us") and the merchant or business that installs or uses the RUM app (the "Customer", "you").
This DPA applies to the extent MakkPress processes Personal Data on your behalf that is subject to Data Protection Law. It is incorporated by reference into the Terms and no signature is required. If you require a countersigned copy for your records, contact support@makkpress.com.
In the event of a conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA prevails.
1. Definitions
- "Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and the Digital Personal Data Protection Act, 2023 of India ("DPDP Act").
- "Personal Data" means any information relating to an identified or identifiable natural person that MakkPress processes on your behalf under this DPA.
- "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in Data Protection Law. Under the CCPA, "Controller" includes "Business" and "Processor" includes "Service Provider". Under the DPDP Act, "Controller" includes "Data Fiduciary" and "Processor" includes "Data Processor".
- "Service" means the RUM app, its tracking script, collector, dashboards and related services provided by MakkPress through the Shopify App Store or Wix App Market.
- "Platform" means Shopify or Wix, as applicable, on which the Service is installed.
- "Sub-processor" means a third party engaged by MakkPress to process Personal Data on your behalf.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914.
- "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office.
2. Roles and responsibilities of the parties
2.1 For Personal Data relating to visitors of your store ("Customer Data"), you are the Controller and MakkPress is the Processor.
2.2 For Personal Data relating to your own account with MakkPress (the email address, store name, business name and phone number received from the Platform when you install the Service), MakkPress acts as an independent Controller for the purposes of providing and securing your account, sending one-time passcodes, responding to support requests, billing and legal compliance. That processing is governed by the Privacy Policy at https://makkpressapps.com/privacy-policy and not by this DPA.
2.3 The Platform is not a Sub-processor of MakkPress. Your relationship with the Platform is governed by your agreement with the Platform.
2.4 Third parties. MakkPress is not responsible for the processing of Personal Data by the Platform, by other apps, themes or scripts installed on your store, or by any third party you authorise to access the Service or your account.
2.5 Your responsibilities. You are responsible for: (a) having a lawful basis for the processing described in this DPA, including obtaining any visitor consent required under applicable law (including cookie and ePrivacy laws) before the tracking script runs on your store; (b) providing your visitors with all notices required by Data Protection Law, including a description of the Service in your privacy policy; (c) ensuring that your instructions and your configuration of the Service comply with Data Protection Law; and (d) not using or configuring the Service to collect special categories of Personal Data, data relating to children, or any Personal Data not described in Annex 1.
2.6 Consequences. MakkPress is not responsible for any non-compliance with Data Protection Law resulting from your failure to meet your obligations under Section 2.5 or from your configuration of the Service. To the extent permitted by law, you will indemnify MakkPress against claims, fines, penalties and reasonable costs arising from such failure.
3. Details of processing
The subject matter, duration, nature and purpose of processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
4. Processor obligations
MakkPress shall:
4.1 Instructions. Process Customer Data only on your documented instructions. Your instructions are: (a) the Terms, (b) this DPA, (c) your configuration of the Service, and (d) any further written instructions you provide that are reasonable and consistent with the Service. MakkPress will inform you if, in its opinion, an instruction infringes Data Protection Law. MakkPress is not liable for processing carried out in accordance with your instructions or configuration, except where MakkPress has failed to meet its own obligations under Data Protection Law.
4.2 Confidentiality. Ensure that persons authorised to process Customer Data are bound by confidentiality obligations and process Customer Data only as necessary to provide the Service.
4.3 Security. Implement and maintain the technical and organisational measures described in Annex 2, and not reduce the overall level of protection during the term of this DPA.
4.4 Sub-processors. Engage Sub-processors only in accordance with Section 5.
4.5 Data Subject requests. Assist you, taking into account the nature of the processing, in responding to requests from Data Subjects to exercise their rights under Data Protection Law, as described in Section 8.
4.6 Assistance. Assist you, taking into account the nature of the processing and the information available to MakkPress, in meeting your obligations relating to security, Personal Data Breach notification, data protection impact assessments and prior consultation with Supervisory Authorities.
4.7 Deletion and return. Delete or return Customer Data at the end of the Service in accordance with Section 9.
4.8 Audit. Make available the information necessary to demonstrate compliance with this DPA and allow for audits in accordance with Section 10.
4.9 Data minimisation. Not collect, store or use Customer Data beyond what is described in Annex 1. In particular, MakkPress does not collect or store the names, email addresses, phone numbers or postal addresses of your store's customers or visitors, and the Service does not collect order, transaction or payment data.
5. Sub-processors
5.1 You authorise MakkPress to engage the Sub-processors listed in Annex 3 for the purposes stated there.
5.2 MakkPress will give you at least 30 days' notice before adding or replacing a Sub-processor, by updating Annex 3 on this page and sending notice to the email address associated with your account. During that period you may object on reasonable data protection grounds by writing to support@makkpress.com. If the objection cannot be resolved, you may terminate the affected Service by uninstalling the app, and MakkPress will delete Customer Data in accordance with Section 9. Termination under this Section is your sole and exclusive remedy for an unresolved objection, and fees already paid are non-refundable.
5.3 Email notice under Section 5.2 is not required, and MakkPress may update Annex 3 on this page only, for changes that do not introduce a new Sub-processor, including: (a) removal of a Sub-processor; (b) a change in a Sub-processor's legal name, corporate structure or ownership; (c) a change in the location of processing within the same country or within the European Economic Area; (d) a reduction or clarification of the purpose for which an existing Sub-processor is used; and (e) engagement of an affiliate or successor entity of an existing Sub-processor for the same purpose and in the same location.
5.4 Where MakkPress must replace a Sub-processor on an urgent basis to maintain the security, availability or continuity of the Service, it may do so without prior notice and will notify you by email within 5 business days of the change. Your objection right under Section 5.2 applies from the date of that notice.
5.5 MakkPress will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains liable for the performance of its Sub-processors.
6. International transfers
6.1 Customer Data is hosted in the United States (New York region, DigitalOcean) and is accessed by MakkPress personnel located in India for the purposes of operating, maintaining and supporting the Service. The tracking script file is delivered to visitors through a global content delivery network, which receives only the technical request data (such as IP address and user agent) necessary to deliver that file. The performance data collected by the Service is not transmitted to or stored by that network.
6.2 Where Customer Data is subject to the GDPR and is transferred to a country outside the European Economic Area that is not covered by an adequacy decision, the parties agree that the SCCs (Module Two: Controller to Processor) are incorporated into this DPA by reference and apply as follows: you are the data exporter and MakkPress is the data importer; Clause 7 (docking clause) applies; Option 2 of Clause 9 applies with the notice period in Section 5.2; the optional language in Clause 11 does not apply; Clause 13 and the governing law and forum under Clauses 17 and 18 are Ireland; Annex I and II of the SCCs are completed by Annex 1, 2 and 3 of this DPA.
6.3 Where Customer Data is subject to the UK GDPR, the SCCs apply as amended by the UK Addendum, with Table 4 of the UK Addendum permitting either party to end the UK Addendum in accordance with its terms.
6.4 MakkPress will notify you if it becomes aware that the law applicable to it or its Sub-processors prevents it from complying with the SCCs, and will apply the supplementary measures described in Annex 2.
7. Personal Data Breach
7.1 MakkPress will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. Notice will be sent to the email address associated with your account.
7.2 The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point. Information may be provided in phases as it becomes available.
7.3 MakkPress will cooperate with you and take reasonable steps to contain, investigate and remediate the breach.
7.4 Notification of or response to a Personal Data Breach by MakkPress is not an acknowledgement of fault or liability.
8. Data Subject requests
8.1 If MakkPress receives a request from a Data Subject relating to Customer Data, it will not respond directly except to direct the Data Subject to you, unless required by law, and will forward the request to you without undue delay.
8.2 Because the Service stores only pseudonymous identifiers and truncated IP addresses for visitors, and no names or contact details, MakkPress will generally not be able to identify a specific individual within Customer Data on its own. Where you can identify the relevant records, MakkPress will assist you in accessing, exporting or deleting them.
8.3 MakkPress implements the Platform's mandatory privacy mechanisms, including Shopify's customers/data_request, customers/redact and shop/redact webhooks and the equivalent Wix app data deletion requests, and will act on such requests automatically.
9. Retention, deletion and return
9.1 Retention during the Service. The period of history available to you in the Service depends on your subscription, as shown in the Service.
Customer Data outside the history window available to you is no longer accessible in the Service. Raw event data is deleted automatically by a scheduled process within 30 days after it leaves that history window. Aggregated statistics that do not identify any visitor may be retained while your account is active. Records needed to resolve a specific billing or service dispute are retained only until that dispute is resolved. Backups are handled under Section 9.4.
9.2 Uninstall. When you uninstall the Service, collection of Customer Data stops immediately. For Shopify, all Customer Data for your store is deleted on receipt of the shop/redact webhook that Shopify sends after uninstall. For Wix, Customer Data is deleted on receipt of the Platform's app removal or data deletion request. In any other case, existing Customer Data expires under the retention rules in Section 9.1 unless you request earlier deletion.
9.3 Deletion on request. On your written request to support@makkpress.com, MakkPress will delete your Customer Data from live systems within 30 days and confirm deletion in writing.
9.4 Backups. Encrypted backups are retained for 30 days on a rolling basis. Deletion requests are recorded and reapplied if a backup is restored, so that deleted Customer Data is not reinstated.
9.5 Export. Before deletion, you may export your Customer Data through the Service or by request to support@makkpress.com.
9.6 MakkPress may retain Customer Data to the extent required by applicable law, in which case it will continue to protect the data under this DPA and process it only for the purpose required by that law.
10. Audit
10.1 MakkPress will, on written request no more than once in any 12-month period, provide you with the information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable written security questionnaire and copies of relevant policies and documentation.
10.2 If the information provided under Section 10.1 is not sufficient to demonstrate compliance, or an audit is required by a Supervisory Authority or following a confirmed Personal Data Breach affecting your Customer Data, you or an independent auditor bound by confidentiality may conduct an audit of MakkPress's processing of Customer Data, subject to: (a) at least 30 days' prior written notice; (b) conduct during normal business hours and in a manner that does not unreasonably disrupt MakkPress's operations; (c) the audit being limited to systems and records relevant to Customer Data; and (d) you bearing the costs of the audit unless it reveals a material breach of this DPA by MakkPress. Where an audit requires more than one business day of MakkPress personnel time, you will reimburse MakkPress's reasonable costs for that time, unless the audit reveals a material breach of this DPA by MakkPress.
10.3 Audit findings are confidential information of MakkPress and may be shared with Supervisory Authorities where required by law.
11. CCPA
To the extent Customer Data includes personal information subject to the CCPA, MakkPress acts as a Service Provider and: (a) will not sell or share Customer Data; (b) will not retain, use or disclose Customer Data for any purpose other than providing the Service under the Terms, or as otherwise permitted by the CCPA; (c) will not combine Customer Data with personal information received from other sources except as permitted by the CCPA; (d) will notify you if it determines it can no longer meet its obligations under the CCPA; and (e) grants you the right to take reasonable steps to stop and remediate unauthorised use of Customer Data. MakkPress certifies that it understands these restrictions.
12. India DPDP Act
To the extent Customer Data is subject to the DPDP Act, you are the Data Fiduciary and MakkPress is the Data Processor. MakkPress will process Customer Data only under this DPA and your instructions, implement the security safeguards in Annex 2, notify you of a Personal Data Breach in accordance with Section 7, and delete Customer Data in accordance with Section 9, so as to enable you to comply with your obligations under the DPDP Act.
13. Liability
To the extent permitted by Data Protection Law, MakkPress's total aggregate liability arising out of or related to this DPA and the Terms combined shall not exceed the greater of (a) the fees paid by you for the Service in the 12 months preceding the event giving rise to the claim, or (b) USD 100. MakkPress is not liable for any indirect, incidental, consequential or special damages, or for any loss of profits, revenue, goodwill or data. This limit is not in addition to any limit in the Terms. Nothing in this section limits either party's liability towards Data Subjects under the SCCs, or any liability that cannot be limited under applicable law.
14. Term and termination
This DPA takes effect when you install the Service and remains in effect for as long as MakkPress processes Customer Data on your behalf. Sections 9 and 13 survive termination.
15. Governing law
This DPA is governed by the laws of India, and the courts of New Delhi have exclusive jurisdiction, except where the SCCs require otherwise for the matters they govern.
16. Changes
MakkPress may update this DPA to reflect changes in law, Sub-processors or the Service. Material changes will be notified to the email address associated with your account at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance. The "Last updated" date at the top of this page identifies the current version.
17. Contact
MakkPress Technologies Private Limited 28/6, 3rd Floor, Double Storey Building, Ashok Nagar, Tilak Nagar, New Delhi, Delhi 110018, India Email: support@makkpress.com
Annex 1: Details of processing
Subject matter. Provision of real user monitoring for the Customer's online store, including collection of page performance data from visitors.
Duration. From installation of the Service until deletion of Customer Data under Section 9.
Nature and purpose. Collection, storage, aggregation, analysis and display of performance metrics in dashboards and reports for the Customer; storage of raw events for the retention period; computation of daily aggregates; operation, security and support of the Service.
Categories of Data Subjects.
- Visitors to the Customer's online store.
Categories of Personal Data.
| Data Subjects | Personal Data | Notes |
|---|---|---|
| Visitors | Pseudonymous identifier generated by the Service | Not linked to any name or account |
| Visitors | Truncated IP address | IPv4 truncated to /24, IPv6 truncated to /48, before storage. The full address is not stored in the Service database. |
| Visitors | Approximate location (country, region, city) | Derived at ingestion |
| Visitors | Device type, operating system, browser | |
| Visitors | Page paths and timing and performance metrics |
Special categories of Personal Data. None. The Service is not designed to collect special category data or data relating to children, and the Customer must not configure it to do so.
Frequency of transfer. Continuous, for as long as the Service is installed.
Annex 2: Technical and organisational security measures
Encryption in transit. TLS is used throughout. The app, the collector and all API calls are HTTPS only.
Encryption at rest. Platform credentials are encrypted with AES-256-CBC. Backups are encrypted with AES-256-CBC with an authenticated message code and stored with restricted file permissions.
Data minimisation. IP addresses are truncated before being written to the Service database, and the full address is not stored there. The Service does not collect order, transaction or payment data. The Service requests only the Platform permissions it uses.
Access control. Server and database access is restricted to a limited number of authorised personnel. Multi-factor authentication is enforced on all administrative accounts, including DigitalOcean, BunnyCDN, Postmark and Google Workspace.
Backups. Backups are encrypted and retained for 30 days on a rolling basis. Deletion requests are recorded and reapplied if a backup is restored.
Logging and monitoring. Application and webhook activity is logged for security and troubleshooting. Server access logs may contain IP addresses for security purposes and are deleted automatically within 14 days. Application logs are designed not to contain Customer Data.
Pseudonymisation. Visitor identifiers are generated by the Service and are not used by MakkPress to identify a natural person.
Confidentiality. Personnel with access to Customer Data are bound by confidentiality obligations.
Incident response. Personal Data Breaches are handled in accordance with Section 7.
Supplementary measures for international transfers. Data is encrypted in transit and backups are encrypted at rest; access is limited to a single administrator under MFA; MakkPress will challenge any government access request that it considers unlawful and will notify the Customer where legally permitted.
Annex 3: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Hosting of the Service, including the collector endpoint, database and portal | United States (New York) |
| BunnyWay d.o.o. (BunnyCDN) | Delivery of the tracking script file to visitors' browsers. Receives only the technical request data (such as IP address and user agent) needed to deliver the file; no performance data is transmitted to or stored by BunnyCDN. | Global edge network; company based in Slovenia |
| ActiveCampaign, LLC (Postmark) | Delivery of one-time passcode emails to the Customer's account email | United States |
| Google LLC (Google Workspace) | Hosting of the support@makkpress.com mailbox used for support correspondence with the Customer, which may include Customer Data you choose to send in support requests | United States |
