Radiant Size Chart
Data Processing Addendum
1. Parties and incorporation
This Data Processing Addendum ("DPA") is between the merchant that installs or uses Radiant Size Chart ("Merchant") and DAWSEN SA, trading as Ash Spark ("DAWSEN"). It forms part of the Terms of Service and applies whenever DAWSEN processes personal data on the Merchant's behalf through Radiant Size Chart.
Capitalized terms not defined here have the meaning given in the Terms or applicable data-protection law. If this DPA conflicts with the Terms on the processing of personal data, this DPA controls.
2. Roles and instructions
For shopper personal data processed through the Merchant's store, the Merchant acts as controller or business and DAWSEN acts as processor or service provider. If the Merchant acts as a processor for another controller, DAWSEN acts as its subprocessor. Each party remains responsible for obligations that apply to its role.
The Merchant instructs DAWSEN to process personal data only to provide, secure, maintain, troubleshoot, and support Radiant Size Chart; apply the Merchant's settings and Shopify consent signals; handle lawful privacy requests; and comply with law. Additional instructions must be documented, lawful, consistent with the service, and agreed in writing. DAWSEN will notify the Merchant if an instruction appears to violate applicable data-protection law, unless law prohibits notice.
3. Processing details
Subject and duration. Processing supports the Merchant's use of Radiant Size Chart for the period the app is installed, plus the limited deletion, backup, dispute, and legal retention periods described below.
Nature and purpose. DAWSEN receives, organizes, stores, retrieves, analyzes, transmits, restricts, deletes, and otherwise processes the minimum data needed for app authentication, merchant configuration, storefront delivery, consent-eligible reporting, billing entitlement, security, support, and privacy-request handling.
DAWSEN acts as an independent controller for the merchant account, contact relationship, service administration, and security. Support content falls under this DPA only to the extent the Merchant chooses to submit shopper or other Merchant-controlled personal data while requesting support.
Data subjects. Merchant account users, shoppers whose consent-eligible activity is linked to an order reference, and people included in a Shopify privacy request. Merchant account users who choose the in-app support chat are also data subjects for that support conversation.
Personal data. Shopify shop and merchant user identifiers and contact details; app session and permission data; product, chart, event, time, size-result, fit, quantity, and eligible order references; privacy-request identifiers and requested order references; support messages and up to eight recent entries supplied as conversation context; and standard request metadata processed by hosting and security systems.
Radiant does not intentionally receive or retain shopper body inputs, calculated measurements, payment-card data, shipping or billing addresses, or shopper names, emails, or phone numbers for its reporting flow. Body inputs used for a recommendation remain in the shopper's browser.
A mandatory Shopify privacy-request payload can contain contact fields while Shopify, the configured message transport, and Radiant process the request. DAWSEN processes that original payload transiently and persists only the minimized request and order references needed to locate, report, or delete applicable records. Those contact fields are not copied into Analytics.
For in-app support, DAWSEN processes the current merchant message and up to eight recent conversation entries to preserve context, compare the request with product help materials, and produce a reply. Support-message content is not copied into storefront Analytics. Any provider used for that optional processing must appear on the Subprocessors page before it begins processing Merchant-controlled personal data in production.
4. Merchant obligations
The Merchant will:
- provide lawful instructions and have a valid legal basis for the processing;
- provide required notices and obtain or record required consent;
- configure Shopify Customer Privacy and Radiant settings consistently with those notices and choices;
- limit access to authorized staff and protect Shopify credentials; and
- avoid placing unnecessary sensitive data, credentials, payment data, or shopper body details in merchant content or support messages.
5. Confidentiality and security
DAWSEN limits personal-data access to people and providers who need it to operate or support the service and who are subject to appropriate confidentiality obligations. DAWSEN maintains measures proportionate to the limited data processed, including authenticated Shopify Admin access, shop-scoped authorization, server-side credentials, input validation, privacy-aware event allowlists, mandatory privacy webhooks, private non-cacheable access reports, deletion workflows, and production monitoring.
Production traffic uses HTTPS/TLS. The managed application and database providers encrypt customer data at rest, including applicable provider-managed backups. DAWSEN reviews these safeguards and will not materially reduce the overall security of the service during the term. No system can guarantee absolute security.
6. Subprocessors
The Merchant gives DAWSEN general authorization to use subprocessors needed to provide the service. DAWSEN requires each subprocessor to protect personal data under written terms appropriate to the services it provides and remains responsible for its obligations under this DPA.
The current list, purpose, and processing location are published on the Subprocessors page. DAWSEN will update that page before a new subprocessor begins materially different processing where reasonably practicable. A Merchant may object on reasonable data-protection grounds by emailing info@ashspark.com. The parties will work in good faith on a reasonable solution; if none is available, the Merchant may stop the affected feature or terminate use of the service.
7. International transfers
DAWSEN and its subprocessors may process personal data outside the country where the Merchant or data subject is located. When applicable law requires a transfer mechanism, DAWSEN will rely on a valid adequacy decision, the European Commission's Standard Contractual Clauses with the applicable module, the UK transfer addendum, or another lawful safeguard.
On request, DAWSEN will provide information reasonably necessary for the Merchant to evaluate the transfer mechanism, subject to confidentiality and provider restrictions.
8. Rights requests and compliance assistance
Taking into account the nature of processing, DAWSEN will provide reasonable assistance with data-subject requests, security obligations, impact assessments, and regulator consultations where the Merchant cannot access the relevant information itself. Shoppers should submit requests to the Merchant; applicable Shopify privacy webhooks route access and deletion requests to Radiant.
If DAWSEN receives a request directly concerning Merchant-controlled data, it will direct the requester to the Merchant or notify the Merchant where legally permitted. DAWSEN will not respond on the Merchant's behalf unless instructed or required by law.
9. Security incidents
DAWSEN will notify the Merchant without undue delay after confirming a personal-data breach affecting data processed under this DPA. Notice will include available information about the nature of the incident, affected data, likely consequences, mitigation, and a contact point, and may be provided in phases as information becomes available.
DAWSEN will take reasonable steps to contain, investigate, and remediate the incident and will cooperate with the Merchant's lawful notification obligations. Notice does not constitute an admission of fault or liability.
10. Retention and deletion
DAWSEN applies the retention periods described in the Privacy Policy. Shopper body inputs are not retained server-side. Device results stop being eligible for restoration at the configured visit, 1-day, 7-day, or 30-day boundary. Because longer-lived results use browser-controlled local storage, the physical entry can remain until the widget next reads or cleans that storage, or until the shopper clears site data. Direct Shopify order references in Operational Analytics are removed after 60 days; non-linked event totals, product references, and quantities can remain available for reporting. Smart Selector usage events become eligible for cleanup after 62 days, monthly aggregate usage buckets after 13 months. The Google Cloud Pub/Sub source topic retains published webhook messages for up to seven days, including messages already acknowledged by its subscription; the dead-letter topic retains published dead-letter messages for up to 31 days. The subscriptions use those same respective windows and do not add separate acknowledged-message retention. For completed privacy access requests, report snapshots and token inputs are cleared on completion, stored Shopify order identifiers are cleared within seven days, and a minimal receipt without customer or order identifiers can remain for up to 30 days after completion before the full request record is deleted. After a customer deletion request, a keyed, non-reversible shop-and-order fingerprint remains only to prevent erased analytics from being recreated; it contains no raw order or customer identifier and is removed when the retained shop lifecycle marker is safely deleted after Shopify's shop-erasure request.
On uninstall, DAWSEN starts a durable, retryable purge of shop-scoped operational data. Bounded processing can complete after the webhook response. A minimal shop lifecycle marker remains until Shopify's shop-redaction webhook permits its safe removal. A completed purge receipt has its direct shop reference cleared, remains for at least 30 days for idempotency and operational verification, and is then eligible for recurring cleanup. Shopify customer-redaction webhooks provide an additional customer-data deletion path. Return details requested from Shopify are not persisted. Limited residual copies can remain temporarily in provider-managed backups, security logs, or records required by law or a legal claim; they remain protected, are not restored for ordinary business use, and expire under the applicable provider or legal lifecycle.
The current application route does not deliberately write in-app support messages or their recent conversation context to Radiant's application database. It transmits that content to prepare the active reply. No optional external support-response or help-content provider may process Merchant-controlled personal data in production until its identity, purpose, processing location, transfer safeguards, and confirmed retention or deletion lifecycle are published in the Privacy Policy and Subprocessors list.
11. Information and audit
DAWSEN will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant product documentation, provider assurances, and written responses. A Merchant may request an audit no more than once in a 12-month period, unless a confirmed incident or regulator reasonably requires another review.
Audits must be proportionate, preserve confidentiality and service security, avoid access to other merchants' information, and use existing independent reports where they reasonably satisfy the request. The requesting Merchant bears its audit costs unless applicable law requires otherwise.
12. Termination and contact
This DPA ends after the Merchant stops using the service and DAWSEN deletes personal data under the retention terms above. Data-protection, confidentiality, and deletion obligations survive for any protected residual copy. The governing-law provisions in the Terms apply unless mandatory data-protection law requires otherwise.
DAWSEN SATrading as Ash Spark
Juan María Pérez 2965
CP 11300
Montevideo, Uruguay
info@ashspark.com
