Data Processing Addendum

How Praisin handles your customers' data on your behalf, under Article 28 of the GDPR.

In force from 25 September 2026. This addendum is part of the terms of service. The shop accepts it by installing Praisin.

1. Parties and roles

The shop that installs Praisin is the controller. AZOURANE OÜ, Järvevana tee 9, Tallinn 11314, Estonia ("Praisin") is the processor. Praisin processes the shop's customer data only to provide Praisin to the shop.

2. What is processed

Subject matterAsking for, collecting, moderating and showing product reviews; sending review requests, newsletters, automated emails and messages; reminders, store credit thank yous and parcel additions; results and reports.
DurationWhile Praisin is installed, then until deletion as in section 8.
PeopleThe shop's customers, newsletter subscribers and store visitors who reach Praisin features.
DataNames, email addresses, phone numbers (only when phone requests are on), order and product details, delivery status, reviews, photos and videos (location data removed), consent records, message and click records, store credit and reminder records.
Special categoriesNot intended. Shops must not ask Praisin to process them.

3. Praisin's commitments

  • Process the data only on the shop's documented instructions, which are these terms, the shop's settings in Praisin and its written requests, and tell the shop if an instruction seems to break the law.
  • Make sure everyone who can access the data is bound to confidentiality.
  • Keep the security measures described in section 11 of the privacy policy.
  • Help the shop answer data subject requests, including through Shopify's privacy webhooks, and with security, breach notification and impact assessments where needed.
  • Tell the shop without undue delay, and within 48 hours of becoming aware, of a personal data breach affecting its data, with the information the shop needs.
  • Make available the information needed to show compliance with this addendum, and allow reasonable audits, on 30 days written notice, at the shop's cost, at most once a year unless a breach or an authority requires more.

4. Sub processors

The shop authorises the sub processors listed in section 9 of the privacy policy. Praisin binds each one to data protection terms at least as protective as this addendum and stays responsible for them. Praisin tells the shop inside the app at least 30 days before adding or replacing a sub processor; the shop may object on reasonable grounds, and if we cannot solve it, uninstall Praisin before the change.

5. Transfers

Where data leaves the European Economic Area, Praisin uses the European Commission's standard contractual clauses, or the EU US Data Privacy Framework where the recipient is certified, plus appropriate extra measures.

6. The shop's commitments

The shop has a legal basis for the processing it asks for, gives its customers the required information, collects the consents it needs, and does not instruct Praisin to process data unlawfully.

7. Data subject requests

If a shop's customer contacts Praisin directly, we pass the request to the shop without undue delay and do not answer it on the shop's behalf unless the shop asks us to.

8. End of processing

When the shop uninstalls Praisin, Shopify sends a shop deletion request about 48 hours later, and Praisin then deletes the shop's data, media and exports, except what the law requires us to keep. Backups are overwritten within 30 days. The shop can export its data before uninstalling.

9. Liability and law

The liability terms of the terms of service apply. This addendum is governed by the laws of Estonia. If it conflicts with the terms of service on data protection, this addendum wins.

10. Contact

[email protected]