Terms governing AirLock's processing of storefront visitor data on a merchant's behalf.
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the AirLock Terms of Service at [TOS URL] (the “Agreement”) between [LEGAL ENTITY NAME], a [STATE] limited liability company (“AirLock,” “Processor,” “we”), and the merchant that has installed the AirLock application (“Merchant,” “Controller,” “you”).
This DPA applies where AirLock processes Personal Data on your behalf in the course of providing the Service. It takes effect automatically upon your installation of AirLock. No signature is required, but a countersigned copy is available on request at [privacy@getairlock.com].
Where this DPA conflicts with the Agreement, this DPA controls with respect to the processing of Personal Data.
Terms not defined here have the meaning given in the Agreement or in Data Protection Law.
”Data Protection Law” means all laws applicable to the processing of Personal Data under this DPA, including: Regulation (EU) 2016/679 (“GDPR”); the UK GDPR and Data Protection Act 2018 (“UK GDPR”); the Swiss Federal Act on Data Protection (“FADP”); the California Consumer Privacy Act as amended by the CPRA (“CCPA”); and comparable US state privacy laws.
”Personal Data” means personal data, personal information, or equivalent as defined in Data Protection Law, that AirLock processes on your behalf under the Agreement.
”Storefront Visitor” means an individual who visits or attempts to transact on your Shopify storefront and whose visit is screened by the Service.
”Screening Data” means the Personal Data described in Annex I.B.
”Sub-processor” means a third party engaged by AirLock to process Personal Data on your behalf.
”Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
”SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
”UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
2.1 With respect to Screening Data, you are the Controller and AirLock is the Processor. Under the CCPA, you are the Business and AirLock is a Service Provider.
2.2 You determine the purposes and means of processing Screening Data. In particular, you decide which IP addresses, countries, and regions to block, allow, or redirect, and which detection features to enable. AirLock executes those decisions.
2.3 This DPA does not apply to Personal Data for which AirLock is an independent Controller, including your merchant account information, billing records, and support correspondence. That processing is governed by the AirLock Privacy Policy at getairlock.com/privacy.
2.4 Nothing in this DPA makes the parties joint controllers.
3.1 Lawfulness. You represent and warrant that you have a valid legal basis under Data Protection Law for the processing you instruct AirLock to perform, and that you have complied with all notice, transparency, and where applicable consent requirements owed to Storefront Visitors.
3.2 Disclosure. You are responsible for disclosing in your own storefront privacy policy that traffic to your store is screened, what categories of data are processed, and that a third-party service provider is engaged. AirLock does not communicate with your Storefront Visitors and cannot discharge this duty on your behalf.
3.3 Lawful instructions. Your instructions to AirLock must comply with Data Protection Law. You are responsible for the accuracy and legality of the block lists, allow lists, and redirect rules you configure.
3.4 Discriminatory use. You acknowledge that geographic and network-based blocking may, depending on how it is configured and the jurisdictions involved, implicate anti-discrimination, consumer protection, accessibility, or trade sanctions requirements. You are solely responsible for the lawfulness of your blocking configuration.
3.5 Non-instruction. You will not instruct AirLock to process Personal Data outside the scope of the Service, and will not submit to the Service any special categories of personal data under GDPR Article 9, data relating to criminal convictions under Article 10, or data concerning children.
4.1 Documented instructions. AirLock processes Screening Data only on your documented instructions, which comprise the Agreement, this DPA, and the configuration you set within the app. AirLock will not process Screening Data for its own purposes, and will not sell, rent, or license it.
4.2 Legally required processing. If AirLock is required by law to process Screening Data beyond your instructions, it will inform you before processing unless legally prohibited from doing so on important grounds of public interest.
4.3 Unlawful instructions. AirLock will inform you if, in its opinion, an instruction infringes Data Protection Law. AirLock may suspend the affected processing until the instruction is confirmed, amended, or withdrawn.
4.4 Confidentiality. AirLock ensures that personnel authorized to process Screening Data are subject to binding confidentiality obligations and receive appropriate training.
4.5 Access limitation. Access to Screening Data is limited to personnel who require it to provide, maintain, or support the Service.
4.6 Purpose limitation for derived data. AirLock may generate aggregate statistics from Screening Data for the purpose of improving detection accuracy and reporting on Service performance, provided such statistics are irreversibly aggregated, contain no IP addresses or other identifiers, and cannot be attributed to any Storefront Visitor or to your store.
5.1 AirLock implements and maintains the technical and organizational measures described in Annex II, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as required by GDPR Article 32.
5.2 AirLock may update these measures provided the level of protection is not materially reduced.
6.1 General authorization. You grant AirLock general authorization to engage Sub-processors. The Sub-processors engaged as of the effective date are listed in Annex III.
6.2 Notice of changes. AirLock will notify you of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance, by email to the address associated with your account and by notice in the dashboard. A current list is maintained at [SUBPROCESSOR PAGE URL], where you may subscribe to change notifications.
6.3 Objection. You may object to a new Sub-processor on reasonable data protection grounds by written notice within the 30-day notice period. The parties will discuss the objection in good faith. If AirLock cannot reasonably accommodate it, you may terminate the affected portion of the Service without penalty and receive a pro-rated refund of prepaid fees.
6.4 Flow-down. AirLock imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA. AirLock remains fully liable to you for each Sub-processor’s performance.
6.5 IP intelligence providers. Where AirLock transmits Storefront Visitor IP addresses to a Sub-processor for geolocation or risk lookup, AirLock’s contract with that Sub-processor prohibits the Sub-processor from retaining, using, or disclosing those IP addresses for its own purposes, including for building or enriching any commercial dataset or for advertising.
7.1 Taking into account the nature of the processing, AirLock will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests from Storefront Visitors exercising rights under Data Protection Law.
7.2 If AirLock receives a request directly from a Storefront Visitor, it will not respond substantively, and will promptly forward the request to you unless legally prohibited.
7.3 Practical limitation. You acknowledge that Screening Data is keyed to IP addresses and is not linked to any account, order, or identity record. AirLock therefore generally cannot verify that a requester is the individual to whom a given IP address relates, and cannot search Screening Data by name, email, or customer identifier. Where AirLock is not in a position to identify the data subject, GDPR Articles 11 and 12(2) apply.
7.4 AirLock provides deletion and export functionality within the dashboard that enables you to respond to most requests without our involvement. Where our direct assistance is required beyond that functionality, we provide it at no additional charge for reasonable volumes.
8.1 AirLock will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting Screening Data.
8.2 The notification will describe, to the extent known: the nature of the incident and categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Where the full picture is not immediately available, AirLock will provide information in phases without undue further delay.
8.3 AirLock will take reasonable steps to mitigate and remediate the incident, and will assist you in meeting your own obligations under GDPR Articles 33 and 34 and applicable US breach notification laws.
8.4 AirLock’s notification is not an acknowledgment of fault or liability.
AirLock will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority that you are required to carry out under GDPR Articles 35 and 36, to the extent it relates to AirLock’s processing and taking into account the information available to AirLock.
10.1 Upon uninstallation of the Service, AirLock deletes or irreversibly anonymizes Screening Data within 48 hours of receiving Shopify’s shop/redact webhook.
10.2 During the term, Screening Data is retained on a rolling 30-day basis, as set out in the retention schedule in the Privacy Policy, and is deletable by you at any time through the dashboard.
10.3 You may request export of your Screening Data in a structured, commonly used, machine-readable format at any time during the term and for [30] days following termination.
10.4 AirLock may retain Screening Data to the extent required by applicable law, and will continue to protect it under this DPA for as long as it is retained.
11.1 AirLock makes available to you the information reasonably necessary to demonstrate compliance with GDPR Article 28, including this DPA, Annex II, and responses to reasonable written security questionnaires.
11.2 Where the above is insufficient, you may request an audit no more than once per twelve (12) month period, on at least thirty (30) days’ prior written notice, during business hours, subject to confidentiality obligations, and conducted so as not to unreasonably disrupt AirLock’s operations.
11.3 Audits must not extend to any data, systems, or premises relating to other customers of AirLock.
11.4 You bear the costs of any audit you request, except where the audit reveals a material breach of this DPA by AirLock, in which case AirLock bears reasonable costs.
11.5 A supervisory authority exercising statutory audit powers is not subject to the limits in 11.2 or 11.4.
12.1 AirLock processes Screening Data in [the United States / SPECIFY ALL REGIONS].
12.2 EEA transfers. Where the transfer of Personal Data from the EEA to AirLock is subject to Chapter V of the GDPR, the SCCs are incorporated by reference and apply as follows:
12.3 UK transfers. The UK Addendum is incorporated by reference. Tables 1 to 3 are populated by the corresponding Annexes of this DPA; Table 4 designates the Importer as the party that may end the Addendum under Section 19.
12.4 Swiss transfers. The SCCs apply with references to the GDPR read as references to the FADP, the competent authority read as the Swiss Federal Data Protection and Information Commissioner, and the term “member state” read so as not to prevent data subjects in Switzerland from enforcing their rights in their place of habitual residence.
12.5 Alternative mechanisms. If a new or replacement transfer mechanism is adopted or the SCCs are invalidated, the parties will work in good faith to implement an appropriate alternative.
12.6 Government access. AirLock will, unless legally prohibited, notify you of any binding request from a public authority for Screening Data, will challenge requests it considers unlawful, and will disclose only the minimum amount of data required.
13.1 With respect to Screening Data, AirLock is a Service Provider (CCPA) and a Processor (Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and comparable state laws).
13.2 AirLock is prohibited from, and certifies that it will not:
13.3 AirLock will comply with applicable obligations under the CCPA and provide the same level of privacy protection required of a Service Provider.
13.4 You may take reasonable and appropriate steps to ensure AirLock’s use of Screening Data is consistent with your obligations, and to stop and remediate unauthorized use.
13.5 AirLock will notify you promptly if it determines it can no longer meet its obligations under the CCPA.
14.1 Liability. Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits liability that cannot be limited under Data Protection Law, including liability to data subjects under the SCCs.
14.2 Term. This DPA takes effect on installation and continues until AirLock has ceased all processing of Screening Data. Sections 4.4, 10, 12, and 14 survive termination.
14.3 Changes. AirLock may update this DPA where required by changes in Data Protection Law, changes to the Service, or adoption of new transfer mechanisms, on thirty (30) days’ notice, provided the update does not materially reduce protections.
14.4 Governing law. Except where the SCCs specify otherwise, this DPA is governed by the law specified in the Agreement, being [e.g. the State of Illinois, USA].
14.5 Severability. If any provision is held invalid, the remainder continues in effect.
Data Exporter (Controller): The Merchant. Name, address, and contact details are those associated with the Shopify store on which AirLock is installed, as provided to AirLock through Shopify’s OAuth flow. Activities relevant to the transfer: Operation of an e-commerce storefront. Role: Controller.
Data Importer (Processor): Name: [LEGAL ENTITY NAME] Address: [REGISTERED ADDRESS] Contact: [privacy@getairlock.com] Activities relevant to the transfer: Provision of the AirLock storefront traffic screening service. Role: Processor.
Categories of data subjects: Visitors to the Merchant’s Shopify storefront, including individuals attempting to complete checkout.
Categories of Personal Data:
Sensitive data: None. The Service is not designed to process, and Merchants are contractually prohibited from submitting, special categories of data under GDPR Article 9 or data relating to criminal convictions under Article 10.
Note for review: IP-derived geolocation can in some circumstances indirectly reveal information touching on Article 9 categories (for example, an IP resolving to a location strongly associated with a particular community). AirLock does not use location for any such inference. Counsel may wish to consider whether an express statement to that effect belongs here.
Frequency of transfer: Continuous, on each screened request.
Nature of processing: Automated collection, lookup, evaluation against Merchant-configured rules, logging, storage, display in the Merchant dashboard, and deletion.
Purpose of processing: To screen storefront traffic and apply the access control rules configured by the Merchant, for the purposes of fraud prevention, abuse mitigation, and network security.
Duration: For the term of the Merchant’s subscription, with Screening Data retained on a rolling 30-day basis per the retention schedule in the Privacy Policy, and deleted on uninstallation per Section 10.
Sub-processor transfers: See Annex III. Duration and purpose as described therein.
The supervisory authority of the EEA member state in which the Merchant is established, or where the Merchant is not established in the EEA, the supervisory authority of the member state in which the Merchant’s EU representative under GDPR Article 27 is established. Where neither applies, the [Irish Data Protection Commission], consistent with the choice of law in Section 12.2.
[REVIEW EVERY LINE. This annex is contractually binding and is the first document an enterprise merchant’s security team will read. Delete anything you do not actually do — an aspirational TOM annex is a breach of contract waiting to happen, not a marketing page.]
Encryption
wss://Access control
Network and application security
Data minimization
Resilience and recovery
Logging and monitoring
Personnel
Vendor management
Incident response
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Shopify Inc. | App platform, authentication, billing | Merchant account data | Canada / United States |
| [HOSTING PROVIDER] | Application hosting, databases, real-time infrastructure | All categories of Screening Data | [REGION] |
| [IP INTELLIGENCE PROVIDER] | Geolocation and VPN/proxy/bot risk lookup | Storefront Visitor IP addresses | [REGION] |
| [CDN / EDGE PROVIDER] | Content delivery, TLS termination, DDoS protection | Request metadata | Global |
| [ERROR MONITORING] | Application diagnostics | Technical logs, may incidentally include IP addresses | [REGION] |
| [TRANSACTIONAL EMAIL] | Service and support email | Merchant email address only | [REGION] |
Current list maintained at [SUBPROCESSOR PAGE URL].
This DPA is effective without signature upon installation of the Service. Where a countersigned copy is required:
Merchant Name: _______________________ Title: _______________________ Entity: _______________________ Date: _______________________
[LEGAL ENTITY NAME] Name: _______________________ Title: _______________________ Date: _______________________