Documentation

Policy

Data processing addendum

Controller and processor terms for store data, security measures and CampaignKoi's subprocessors.

Last updated: 4 October 2026.

This Addendum is part of the CampaignKoi Terms of Service between the merchant ("Merchant") and Joseph McIlhargey, a sole proprietor doing business as CampaignKoi ("CampaignKoi"). Personal Data, Processing, Controller, Processor and Data Subject have their GDPR meanings, and the equivalent meanings under the UK GDPR, Swiss law and the CCPA (for example, "service provider"). The Privacy Policy describes what CampaignKoi collects and how long it keeps it; this Addendum doesn't repeat it.

1. Roles

  • Merchant Personal Data is Personal Data in the store data and content the Merchant gives CampaignKoi to process, including Personal Data in privacy requests Shopify forwards. For it, the Merchant is the Controller and CampaignKoi is the Processor, or "service provider" under the CCPA.
  • For account data about the Merchant's own users, such as names, emails and sign-in records, CampaignKoi is a Controller under its Privacy Policy.

2. Instructions

CampaignKoi processes Merchant Personal Data only to provide the Service, as described in Annex 1, on the Merchant's documented instructions, unless the law requires otherwise. The Terms, this Addendum and the Merchant's settings and approvals in the Service are those instructions. CampaignKoi will tell the Merchant if it believes an instruction breaks data protection law.

CampaignKoi won't:

  • sell or share Merchant Personal Data, as the CCPA defines those terms;
  • retain, use or disclose it outside its direct business relationship with the Merchant, or combine it with other data except as the law allows;
  • use it to train AI models.

3. Confidentiality

Everyone who processes Merchant Personal Data for CampaignKoi is bound by confidentiality. Today that's the operator; in future it includes any staff or contractors.

4. Security

CampaignKoi maintains the measures in Annex 2. It may update them, but won't reduce overall protection.

5. Subprocessors

  • The Merchant authorizes the subprocessors in Annex 3.
  • CampaignKoi gives at least 30 days' notice of a new subprocessor, by email or in the app. The Merchant may object on reasonable data protection grounds. If the objection can't be resolved, the Merchant may stop using the affected Service.
  • CampaignKoi puts data protection terms in place with each subprocessor that protect Merchant Personal Data at least as well as this Addendum, and remains responsible for its subprocessors.

6. Privacy requests and assistance

  • CampaignKoi honors Shopify's mandatory privacy webhooks for the data it holds, within 30 days as Shopify requires:
    • Customer data request and customer redaction: CampaignKoi doesn't access customer or order records, so it normally holds nothing linked to the customer. It checks the store records it holds and provides or deletes anything it finds.
    • Shop redaction: CampaignKoi deletes the store's remaining records as the Privacy Policy describes.
  • Personal Data the Merchant puts into its own content is the Merchant's to find and remove with the Service's editing tools.
  • CampaignKoi passes requests it receives directly from Data Subjects to the Merchant without undue delay, and reasonably assists with data subject requests, data protection impact assessments and regulator consultations, to the extent they concern its processing.

7. Audits

CampaignKoi makes available the information needed to show compliance with this Addendum, including by answering a reasonable written questionnaire once a year, or after a breach. If that isn't enough, or a regulator requires it, the Merchant or an independent auditor bound by confidentiality may audit CampaignKoi's processing with reasonable notice, at the Merchant's cost.

8. Personal data breaches

CampaignKoi notifies the Merchant without undue delay after becoming aware of a breach affecting Merchant Personal Data. The notice includes the information the Merchant needs to meet its own obligations. CampaignKoi also takes reasonable steps to contain the breach and fix it.

9. Deletion and return

  • When the Merchant uninstalls or closes its account, CampaignKoi deletes Merchant Personal Data as the Privacy Policy describes, including its exceptions for backups, privacy-request records and legal requirements.
  • Before then, the Merchant can ask for a copy of the Merchant Personal Data CampaignKoi holds.
  • Published theme files belong to the Merchant's store, so they aren't CampaignKoi data to delete.

10. International transfers

  • CampaignKoi processes data in the United States.
  • For Personal Data from the EEA, the Standard Contractual Clauses (Commission Decision 2021/914, Module 2, controller to processor) are incorporated, with the Annexes below:
    • The parties are the Merchant as data exporter and CampaignKoi as data importer (info@campaignkoi.com). The competent supervisory authority is determined under Clause 13.
    • Clause 7 (docking) applies.
    • Clause 9 uses option 2, with 30 days' notice.
    • Clause 11's optional language doesn't apply.
    • Clause 17 selects the law of Ireland, and Clause 18 the courts of Ireland.
  • For the UK, the UK International Data Transfer Addendum applies. For Switzerland, the clauses apply with the FADP as the governing law of data protection.

11. Order of precedence

If this Addendum conflicts with the Terms, this Addendum prevails for Merchant Personal Data. The Standard Contractual Clauses prevail over both.

Annex 1: Details of processing

  • Subject matter and duration: providing the Service while the Merchant uses it, then until deletion under section 9.
  • Nature and purpose: reading the Merchant's catalog, store content and own content to draft and edit pages with AI; storing the Merchant's projects; publishing approved pages to the Merchant's theme; answering privacy requests.
  • Data subjects: people named or shown in store data or the Merchant's content, such as staff or people quoted in testimonials the Merchant supplies; the Merchant's customers only as identified in privacy requests Shopify forwards.
  • Categories of Personal Data: names, images and other details in store data and the Merchant's content. In privacy requests: a Shopify customer ID (or an email address when no ID is given) and order numbers.
  • Special categories: none intended. The Merchant shouldn't include them.
  • Frequency: continuous while the store is connected.

Annex 2: Security measures

  • Encryption: HTTPS for data in transit. Shopify access credentials are encrypted before storage, and passwords are stored only as hashes.
  • Access: production access is limited to the operator. Development and production use separate environments and Shopify apps.
  • Isolation: every record is scoped to its workspace, and queries enforce that.
  • Integrity: Shopify webhooks are verified by signature, password sign-in requires a verified email address, and requests are rate-limited.
  • Data minimization: the Service requests only the Shopify permissions it needs, and optional ones only when a feature needs them. It has no access to orders or customer records.
  • Change control: code changes run through automated tests and checks.

Annex 3: Subprocessors

SubprocessorPurposeDataLocation
Amazon Web Services, Inc.Hosting, databases, file storage and background processingAll Service dataUnited States
OpenAI, L.L.C.AI models that draft and edit pagesThe request, relevant content and store dataUnited States
Anthropic, PBCAI models that draft and edit pagesThe request, relevant content and store dataUnited States
ResendAccount and service emailEmail address, name and message contentUnited States

Google, used only when someone chooses Google sign-in, and Shopify, the Merchant's own platform under its own agreement with Shopify, aren't CampaignKoi subprocessors.