Data Processing Agreement
EcomPulse AS (“Processor”) and the Customer (“Controller”)
Version: 1.0 · Effective: August 8, 2026 · Governing law: Norwegian law and the GDPR
1. Purpose and scope
This Data Processing Agreement (“DPA”) governs EcomPulse AS’s processing of personal data on behalf of the Customer when the Customer connects a store or advertising account to the EcomHero platform at app.ecomhero.io.
This DPA forms part of, and is subject to, the EcomHero Terms of Service. It is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 (“GDPR”) as implemented in Norwegian law through the EEA Agreement.
Where the Customer is a business established outside the EEA but processes personal data of EEA data subjects, this DPA applies to that processing.
Parties:
| Processor | EcomPulse AS, org. no. 936 175 678, Sofienberggata 3D, 0551 Oslo, Norway |
| Contact | henrik@ecomhero.io |
| Controller | The legal entity that has created an EcomHero account and accepted these terms |
By connecting a store or advertising account to EcomHero, the Customer accepts this DPA on behalf of the legal entity it represents.
2. Roles of the parties
The Customer is the data controller for personal data originating from its connected stores and advertising accounts, including end-customer data.
EcomPulse AS is the data processor for that data.
EcomPulse AS is a separate data controller for personal data relating to the Customer’s own EcomHero account — name, email, business details, login records and usage data. That processing is governed by the EcomHero Privacy Policy and falls outside this DPA.
3. Subject matter, duration, nature and purpose
Subject matter. Processing of order, product, inventory, advertising, analytics and email-marketing data retrieved from the Customer’s connected platforms.
Duration. For the term of the Customer’s EcomHero subscription, plus the retention period in Clause 10.
Nature and purpose. Retrieval, storage, structuring, aggregation and analysis of the Customer’s commercial data in order to produce profitability metrics, cohort analysis, customer lifetime value, advertising performance reporting and automated alerts, and to execute actions the Customer explicitly triggers within the platform.
Categories of data subjects. The Customer’s end customers; the Customer’s own personnel who hold EcomHero accounts.
Categories of personal data. See Annex I.
Special categories. EcomHero does not request, require or intentionally process special categories of personal data under Article 9 GDPR, nor data relating to criminal convictions under Article 10. The Customer shall not upload or transmit such data to the platform.
4. Processor obligations
EcomPulse AS shall:
(a) Documented instructions. Process personal data only on the Customer’s documented instructions, including with regard to transfers to third countries, unless required otherwise by EU or Norwegian law. The Customer’s instructions consist of this DPA, the Terms of Service, the scopes granted at the time of integration, and any actions the Customer triggers within the platform. Where EcomPulse AS is legally required to process beyond those instructions, it shall inform the Customer before processing unless the law prohibits such notification.
(b) Notification of unlawful instructions. Immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
(c) Confidentiality. Ensure that all persons authorised to process personal data are bound by an obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement. Access to production data is limited to one named individual on a need-to-know basis.
(d) Security. Implement the technical and organisational measures set out in Annex II, in accordance with Article 32 GDPR.
(e) Sub-processors. Engage sub-processors only in accordance with Clause 6.
(f) Assistance with data subject rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in fulfilling its obligation to respond to requests from data subjects exercising rights under Chapter III GDPR. Where a data subject contacts EcomPulse AS directly regarding data belonging to the Customer, EcomPulse AS shall refer the request to the Customer without undue delay and shall not respond substantively unless instructed to do so.
For Shopify stores, EcomPulse AS receives Shopify’s mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact). Redaction requests are executed against stored data; data-access requests are routed to EcomPulse AS’s data protection contact and handled together with the Customer without undue delay.
(g) Assistance with Articles 32–36. Assist the Customer in ensuring compliance with its obligations regarding security of processing, breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to EcomPulse AS.
(h) Deletion or return. At the Customer’s choice, delete or return all personal data at the end of the provision of services, and delete existing copies, unless EU or Norwegian law requires storage. See Clause 10.
(i) Audit. Make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits in accordance with Clause 9.
5. Controller obligations
The Customer shall:
- Ensure it has a valid legal basis for the processing it instructs, and that its own privacy notice discloses the use of analytics processors
- Ensure that the personal data it makes available is accurate and lawfully obtained
- Not instruct processing that would infringe applicable data protection law
- Configure integration scopes appropriately and revoke access it no longer requires
- Be responsible for responding to data subject requests relating to its own end customers
6. Sub-processors
The Customer grants EcomPulse AS general written authorisation to engage sub-processors. The sub-processors engaged at the effective date are listed in Annex III.
EcomPulse AS shall:
- Impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA
- Remain fully liable to the Customer for the performance of each sub-processor’s obligations
- Give the Customer at least 30 days’ written notice before adding or replacing a sub-processor, by email to the account contact and by updating Annex III at ecomhero.io/dpa
The Customer may object to a proposed change on reasonable data protection grounds within 30 days of notice. If the parties cannot resolve the objection, the Customer may terminate its subscription without penalty and receive a pro-rata refund of prepaid fees.
Providers from which EcomHero retrieves data at the Customer’s instruction — Shopify, Meta, Google, Microsoft, Klaviyo and the Customer’s own WooCommerce host — act under their own agreements with the Customer and are not sub-processors of EcomPulse AS in respect of that retrieval. They are listed for transparency in the “Connected data sources” note under Annex III.
7. International transfers
EcomPulse AS stores all Customer data on infrastructure located within the EEA (Hetzner, Helsinki, Finland).
Certain sub-processors listed in Annex III are established outside the EEA. Where personal data is transferred to such a sub-processor, the transfer is made on the basis of:
- an adequacy decision under Article 45 GDPR, including the EU–US Data Privacy Framework where the sub-processor is certified; or
- Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c), as incorporated into the relevant sub-processor’s data processing terms; together with
- supplementary measures where required following a transfer impact assessment
EcomPulse AS shall make available, on request, details of the transfer mechanism applicable to each sub-processor.
Note on AI processing. To generate insights and recommendations, EcomHero transmits business and advertising performance data to Anthropic PBC (United States): aggregated revenue, cost and profitability metrics, campaign, ad-set and ad names, advertising creative text, aggregated search-query statistics, and publicly available content from the Customer’s own storefront website. End-customer personal data — names, email addresses, postal addresses, and order-level records — is not transmitted to Anthropic.
8. Personal data breach
EcomPulse AS shall notify the Customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting the Customer’s data.
The notification shall include, so far as known at the time:
- the nature of the breach, including categories and approximate numbers of data subjects and records affected
- the likely consequences
- the measures taken or proposed to address the breach and mitigate its effects
- a contact point for further information
Where full information is not available at the time of initial notification, it shall be provided in phases without further undue delay.
EcomPulse AS shall not notify supervisory authorities or data subjects on the Customer’s behalf unless instructed to do so in writing.
9. Audit
EcomPulse AS shall, on request, provide the Customer with documentation reasonably necessary to demonstrate compliance with this DPA, including its current security measures, sub-processor list and relevant certifications.
Where such documentation is insufficient, the Customer may conduct an audit, subject to:
- at least 30 days’ written notice
- no more than once per calendar year, unless following a personal data breach or a supervisory authority instruction
- conduct during normal business hours and in a manner that does not unreasonably disrupt operations
- the auditor being bound by confidentiality obligations, and not being a competitor of EcomPulse AS
- the Customer bearing its own costs and those of any third-party auditor
10. Retention and deletion
On termination of the Customer’s subscription, or on written request:
- Customer data is permanently deleted within 30 days
- Backup copies are purged within a further 30 days
- Billing and transaction records may be retained for up to 5 years where required by the Norwegian Bookkeeping Act (bokføringsloven)
The Customer may request export of its data in a structured, commonly used, machine-readable format before deletion.
Disconnecting an integration stops further retrieval but does not by itself delete data already stored. Deletion must be requested, or occurs automatically on account termination.
11. Liability and term
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the EcomHero Terms of Service, save to the extent such limitation is not permitted under applicable law.
This DPA takes effect when the Customer first connects a store or advertising account, and remains in force for as long as EcomPulse AS processes personal data on the Customer’s behalf.
12. Amendments and governing law
EcomPulse AS may update this DPA where necessary to reflect changes in law, sub-processors or the service. Material changes will be notified at least 30 days in advance by email to the account contact.
This DPA is governed by Norwegian law. Disputes are subject to the exclusive jurisdiction of Oslo District Court (Oslo tingrett), without prejudice to any mandatory rights of the Customer under consumer or data protection law.
Signed on behalf of EcomPulse AS
Henrik Lund, CEO EcomPulse AS
The Customer accepts this DPA electronically by connecting a store or advertising account to EcomHero. No countersignature is required. A countersigned copy is available on request to henrik@ecomhero.io.
Annex I — Description of processing
Categories of personal data
From connected stores (Shopify, WooCommerce)
| Data | Purpose |
|---|---|
| End-customer name | Identifying repeat customers across orders for cohort and lifetime-value analysis |
| End-customer email address | Primary key for linking orders to a single customer across time |
| Shipping and billing address | Geographic performance analysis and shipping cost attribution |
| Order contents, totals, currency, timestamps | Revenue, margin and profitability calculation |
| Product catalogue and inventory state | Product-level performance and stock analysis |
From connected advertising and marketing accounts (Meta, Google, Microsoft, Klaviyo)
Account, campaign, ad set, ad group, creative, keyword, flow, list and template metadata; performance metrics including impressions, spend, clicks, conversions and revenue attribution. Aggregated at account, campaign and daily level.
From analytics platforms (GA4, Search Console)
Channel, event, page, query and traffic metrics. Aggregated; no individual user identifiers.
Authentication data
OAuth access and refresh tokens for each connected integration, encrypted at rest at the application layer and used solely within the granted scopes.
Scopes requested per integration
| Platform | Scopes | Write capability |
|---|---|---|
| Shopify | read_orders, read_all_orders, read_products, read_inventory | None — read-only |
| Google Analytics 4 | analytics.readonly | None — read-only |
| Google Search Console | webmasters.readonly | None — read-only |
| Klaviyo | accounts:read, campaigns:read, campaigns:write, flows:read, lists:read, metrics:read, forms:read, templates:read, templates:write | Write scopes requested for planned features; not currently exercised |
| WooCommerce | read_write | Write access used solely to register and remove EcomHero’s own order webhooks; no store data is written |
| Meta | ads_read, ads_management, business_management, pages_show_list, pages_read_engagement | Pause/enable campaigns, ad sets and ads; update daily budgets — only on Customer instruction |
| Google Ads | adwords (Google offers no read-only scope for the Ads API) | Pause/enable campaigns and ad groups; update campaign daily budgets — only on Customer instruction with confirmation |
| Microsoft Ads | openid, offline_access, msads.manage | Pause/enable campaigns and ad groups; update campaign daily budgets — only on Customer instruction |
read_all_orders is required because EcomHero computes cohort and lifetime-value analysis beyond Shopify’s default 60-day order window.
Frequency
Continuous, via scheduled synchronisation and platform webhooks.
Annex II — Technical and organisational measures
Encryption TLS 1.2 or higher for all data in transit. Integration credentials (OAuth tokens, API keys) are encrypted at rest at the application layer (AES-256-GCM via Active Record Encryption). User passwords are stored as bcrypt hashes.
Access control Production data access restricted to one named individual. Authentication required for all administrative access; multi-factor authentication enabled on infrastructure accounts.
Tenant isolation EcomHero is a multi-tenant platform. Customer data is logically segregated; all queries are scoped to the authenticated tenant.
Hosting Hetzner, Helsinki, Finland, within the EEA. Hetzner is ISO 27001 certified.
Availability and resilience Daily automated backups.
Logging Application and error logging retained for a limited operational period. Sensitive parameters (tokens, secrets, email addresses) are filtered from application logs. Error tracking is self-hosted on the same EEA infrastructure.
Secure development Version-controlled codebase, automated dependency vulnerability monitoring, and pull-request review before deployment.
Sub-processor management Written data processing terms with all sub-processors; annual review of the sub-processor list.
Incident response Documented breach detection and notification procedure per Clause 8.
Annex III — Approved sub-processors
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Hetzner | Infrastructure and database hosting | Finland | EEA — none required |
| Anthropic PBC | AI-generated insights from business and advertising performance data (see Clause 7) | United States | Standard Contractual Clauses (2021 EU SCCs, incorporated in Anthropic’s Data Processing Addendum) |
| Resend Inc. | Transactional email (reports, notifications, sign-in links) | United States | EU–US Data Privacy Framework (certified); SCCs in Resend’s Data Processing Addendum |
| Stripe Payments Europe Ltd | Subscription billing (direct subscriptions) | Ireland | EEA — none required |
Connected data sources (not sub-processors)
EcomHero retrieves data from the following platforms at the Customer’s instruction, using access the Customer grants directly. Each acts under its own agreement with the Customer and is not a sub-processor of EcomPulse AS: Shopify, Meta (Facebook), Google (Ads, Analytics 4, Search Console), Microsoft Advertising, Klaviyo, and the Customer’s own WooCommerce store.
Merchants who install EcomHero through the Shopify App Store are billed by Shopify under its own terms; no payment data is shared with EcomPulse AS or Stripe.
Last updated: August 8, 2026 · ecomhero.io/dpa