DiscoCollabs

Data Processing Agreement

Last updated: September 9, 2026

Parties. This DPA forms part of the Terms of Service between Quorra Agency, a sole proprietorship, operating as DiscoCollabs (“Processor”, “DiscoCollabs”, “we”) and the merchant installing the DiscoCollabs application (“Controller”, “Merchant”, “you”). It applies whenever we process Personal Data on your behalf. A countersigned copy is available on request.

1. Roles & scope

1.1 You are the Controller of Personal Data processed through the Service; we are the Processor. 1.2 We process Personal Data only: (a) to provide the Service as documented; (b) per your instructions given through the app’s settings and features; (c) as required by law. We do not sell Personal Data or use it for advertising.

2. Details of processing

  • Subject matter & duration: operation of the DiscoCollabs creator-gifting service, for the term of your installation plus the retention window in §7.
  • Nature & purpose: creator identification and consent capture at QR scan; order attribution; content collection; transactional reminder emails to consented creator addresses; dashboards.
  • Categories of data subjects: creators; order customers; merchant staff users.
  • Categories of data: as set out in the Data Map annex (contact details, social handles, order/fulfillment data, submitted content and consent flags). The launch service does not collect payout destinations or tax forms. No GDPR special-category data is intentionally processed.

3. Your instructions

The Service’s features and settings constitute your documented instructions. We will inform you if, in our opinion, an instruction infringes applicable data protection law.

4. Confidentiality & personnel

Persons authorized to process Personal Data are bound by confidentiality obligations.

5. Sub-processors

5.1 You generally authorize the sub-processors listed in the annex below. 5.2 We will update the published sub-processor list at least 10 days before adding a new sub-processor; continued use of the Service after that period constitutes acceptance. If you object on reasonable data-protection grounds, you may terminate and export your data. 5.3 We impose data-protection obligations on sub-processors no less protective than this DPA and remain responsible for their performance.

6. Security

We maintain appropriate technical and organizational measures, including: encryption in transit (TLS) and at rest (provider-level); unguessable per-order keys; least-privilege platform scopes; access controls on production data (including tooling that prevents test environments from reaching production); logging of provisioning and consent events. We will not materially degrade the overall security of the Service.

7. Retention, return & deletion

7.1 During the term (including any payment-lapsed period), Personal Data is retained; your access to features may be gated by payment, but export and deletion rights are never gated. 7.2 On uninstall, we honor Shopify’s shop/redact webhook: shop data rows and stored media are purged, in any event within 90 days of uninstall (automated purge). 7.3 We honor customers/redact (delete a specific customer’s data on your instruction via Shopify) and customers/data_request (provide the data held). 7.4 You may export creator content via the built-in ZIP export at any time.

8. Assistance & data subject rights

Taking into account the nature of processing, we assist you with data subject requests (access, deletion, portability) via the Service’s built-in tools, and with your obligations regarding security, breach notification, and impact assessments, with reasonable additional assistance at your cost.

9. Personal data breach

We will notify you without undue delay after becoming aware of a Personal Data breach affecting your data, with the information reasonably required for your own notification obligations, and will take reasonable steps to mitigate and remediate.

10. International transfers

Data is hosted in the United States (see annex). Where data protection law requires a transfer mechanism for data originating elsewhere (e.g., EEA/UK), the parties incorporate the EU Standard Contractual Clauses (Module 2: Controller→Processor) and the UK Addendum by reference, with this DPA supplying the appendices.

11. Audit

On written request no more than once per year, we will make available information reasonably necessary to demonstrate compliance with this DPA (e.g., this DPA, the Data Map, sub-processor list, and summaries of security practices).

12. Liability & order of precedence

Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms regarding Personal Data processing, this DPA controls.

Annex — Data Map: sub-processors

Sub-processorPurposeRegion
Supabase (Postgres + Auth)Primary database, merchant authUS (us-east-2)
RailwayApplication hosting (web + worker)US
Cloudflare R2Creator content file storageUS/global (Cloudflare network)
ResendTransactional email deliveryUS
ShopifyPlatform, order data source, billingPer Shopify infrastructure
Discord (optional, per-brand toggle)Community/DM notifications when a brand enables itPer Discord infrastructure
Slack (optional)Merchant workspace notificationsPer Slack infrastructure
TikTok (optional)Creator account connection and content authorizationPer TikTok infrastructure
Shippo (optional)Return-label rating and purchasePer Shippo infrastructure

We do NOT collect: payment card data, passwords for external platforms, precise location, payout destinations, or tax forms. Order-event ingestion transforms Shopify buyer email into a tenant-scoped HMAC and masked hint rather than storing the raw address. Merchant-managed roster contacts, including historical contacts added from tagged orders, are separate email-bearing records. New order tagging does not import those addresses. Transactional creator messages go only to the creator-provided, verified address. Retention: 90 days after uninstall at most, automated purge; see the Retention & Deletion page.

See also our Privacy policy and Terms of service. Contact: cayla@quorra.agency.