Data Processing Agreement

Article 28 GDPR terms for Tomorrowfy services

Tomorrowfy GmbH · Version 1.3 · Effective 21 August 2026

1. Parties, scope, and roles

This Data Processing Agreement (DPA) forms part of the agreement under which Tomorrowfy provides the service to the Customer (Main Agreement). It applies when Tomorrowfy processes personal data on the Customer’s behalf. The Customer is the controller or a processor acting for another controller; Tomorrowfy is the processor or subprocessor, respectively.

This DPA is effective when the Main Agreement is accepted and continues until Tomorrowfy has deleted or returned the personal data as required below. Terms such as personal data, processing, controller, processor, and supervisory authority have the meanings in the GDPR.

2. Documented instructions

Tomorrowfy will process personal data only on the Customer’s documented instructions, including the Main Agreement, the Customer’s configuration and use of the service, and further lawful instructions agreed in text form. The Customer instructs Tomorrowfy to access connected Shopify resources; operate subscription, billing, notification, analytics, support, and integration functions; use the authorized subprocessors; and transfer data to Customer-directed destinations.

Tomorrowfy will promptly inform the Customer if, in its opinion, an instruction infringes applicable data-protection law, unless prohibited by law. Processing required by Union or Member State law is permitted; where legally allowed, Tomorrowfy will inform the Customer before that processing. The Customer is responsible for the lawfulness, accuracy, and scope of its instructions and for providing required notices to data subjects.

3. Confidentiality and personnel

Tomorrowfy ensures that persons authorized to process personal data are bound by confidentiality and receive access only where required for their role. Access is withdrawn when it is no longer required. Tomorrowfy remains responsible for its personnel’s compliance with this DPA.

4. Security

Tomorrowfy implements and maintains appropriate technical and organizational measures under Article 32 GDPR, taking account of the state of the art, implementation costs, the nature and purposes of processing, and risks to individuals. The measures current at the effective date are described in Tomorrowfy’s Technical and Organizational Measures (TOMs), version 2.2. Tomorrowfy may improve or replace measures if the overall level of protection is not materially reduced.

5. Subprocessors

The Customer gives general authorization for the subprocessors in Tomorrowfy’s current Subprocessor and Data Location List. Tomorrowfy will impose data-protection obligations appropriate to the processing, including Article 28(3) GDPR requirements where applicable, and remains responsible for their performance to the extent required by law.

Tomorrowfy will notify the Customer in writing at least 14 days before adding or replacing a subprocessor. During that period, the Customer may object on reasonable, substantiated data-protection grounds. The parties will work in good faith to resolve the objection. If no solution is available, the Customer may terminate only the materially affected service before the new subprocessor begins, without a termination fee and with a pro-rata refund of prepaid fees for the unused affected period. Urgent replacements needed for security or service continuity may be notified as soon as reasonably practicable and, if advance notice is not possible, without undue delay after appointment.

6. Customer-directed recipients and independent controllers

A recipient selected, enabled, or controlled by the Customer is not Tomorrowfy’s subprocessor. This includes Shopify, Klaviyo, Emarsys, Customer-owned BigQuery destinations, and custom webhook endpoints. The Customer instructs the related disclosure and is responsible for its agreement and lawful basis for that recipient.

When the Customer enables the “Date Picker per Location” functionality, Tomorrowfy may send delivery-address data to Google Maps Platform to geocode the address and determine the applicable delivery location. Under Google’s applicable terms, Google Maps Platform acts as an independent controller for that processing, not as Tomorrowfy’s subprocessor. The Customer instructs this disclosure by enabling or using “Date Picker per Location.” Tomorrowfy limits the data sent to the address fields needed for geocoding.

7. International transfers

Tomorrowfy will not transfer personal data outside the EEA unless the transfer is covered by an adequacy decision or another valid safeguard under Chapter V GDPR. Where required, Tomorrowfy will enter into the European Commission’s 2021 Standard Contractual Clauses, normally Module Three for processor-to-processor transfers, and implement supplementary measures appropriate to the transfer. Vendor DPAs and transfer mechanisms are summarized in the Subprocessor and Data Location List.

8. Assistance

Taking into account the nature of processing and the information available, Tomorrowfy will reasonably assist the Customer with:

  • responding to requests from data subjects;
  • security obligations under Articles 32 to 34 GDPR;
  • data-protection impact assessments and prior consultation under Articles 35 and 36 GDPR; and
  • information reasonably required for the Customer's compliance records.

Tomorrowfy may charge reasonable fees for assistance that is unusually extensive or caused by the Customer’s systems or instructions, after giving an estimate, unless the assistance is required because Tomorrowfy breached this DPA.

9. Personal data breaches

Tomorrowfy will notify the Customer without undue delay and, where feasible, within 24 hours after becoming aware of a personal data breach affecting Customer personal data. This is an initial-notification target, not a promise that investigation or remediation will be complete within 24 hours. Information may be provided in phases without undue further delay.

The notice will include, as information becomes available:

  • the nature of the breach and affected systems, data, and data subjects;
  • likely consequences;
  • containment, remediation, and mitigation measures; and
  • a contact for follow-up information.

Tomorrowfy will document the breach and cooperate reasonably with the Customer. Notice is not an admission of fault. The Customer remains responsible for determining whether and how to notify authorities and data subjects. Security incidents should be coordinated through security@tomorrowfy.com.

10. Audit and information rights

Tomorrowfy will make available information reasonably necessary to demonstrate compliance with this DPA, including the TOMs, relevant third-party assurance reports available to Tomorrowfy, and written responses to reasonable security questionnaires. The Customer should first use this information.

If reasonably necessary after reviewing that information, the Customer may conduct one audit per 12-month period with at least 30 days’ notice during normal business hours, subject to confidentiality, security, and non-disruption requirements. Additional audits are permitted after a material breach or where required by a supervisory authority. The Customer bears its audit costs; Tomorrowfy may charge reasonable support costs for an audit unless it reveals a material breach by Tomorrowfy. Audits must not expose other customers’ information or provider-confidential material.

11. Return and deletion

During the term, the Customer may export data using available service functions or request reasonable assistance. After termination or the Customer’s lawful instruction, Tomorrowfy will delete Customer personal data from Tomorrowfy-controlled active production systems within 30 days, unless the Customer requests return before deletion or applicable law requires retention.

Residual copies in provider-managed recovery systems, logs, and subprocessors are deleted or rendered unavailable under their normal retention cycles and contractual terms. Until deletion, they remain protected and are not restored or otherwise processed except for recovery, security, legal compliance, or deletion. Tomorrowfy will confirm completion on request.

12. Liability and priority

Liability under this DPA is governed by the liability provisions of the Main Agreement, without limiting data-subject rights or liability that cannot legally be limited. If this DPA conflicts with the Main Agreement on personal-data processing, this DPA prevails.

Annex 1 — Details of processing

Subject matter and purpose

Providing and supporting the ordered Tomorrowfy software service, including Shopify-connected subscription management, billing workflows, customer communications, analytics, customer support, security, integrations, and service administration.

Duration

For the term of the Main Agreement and the limited deletion period described in this DPA.

Nature of processing

  • collection and retrieval from the Customer, authorized users, Shopify, and Customer-directed systems;
  • hosting, recording, structuring, organizing, querying, analyzing, updating, and displaying;
  • transmission to authorized subprocessors and Customer-directed recipients;
  • sending transactional communications and operating support; and
  • restriction, export, redaction, and deletion.

Categories of data subjects

  • the Customer's staff, contractors, account users, and contacts;
  • the Customer's Shopify customers, subscribers, prospective customers, and message recipients; and
  • individuals whose information is included in support requests, logs, or Customer-directed integrations.

Categories of personal data

  • identifiers and contact data, including names, email addresses, customer IDs, shop domains, and account roles;
  • subscription, order, product, fulfillment, delivery, and communication data;
  • delivery addresses and derived geocoding or fulfillment-location information where "Date Picker per Location" is used;
  • billing-attempt and payment-method metadata supplied by Shopify, such as status and limited card metadata, but not full card numbers handled by Shopify's payment systems;
  • authentication and integration credentials, encrypted tokens, settings, and permissions; and
  • usage, device, request, diagnostic, audit, and support information.

Special categories

No special-category data under Article 9 GDPR or criminal-conviction data is intentionally required. The Customer will not submit such data unless expressly agreed and supported by additional safeguards.

Processing frequency

Continuous or event-driven during use of the service, with scheduled processing for configured workflows.

Annex 2 — Contacts

Processor: Tomorrowfy GmbH, Isarwinkel 2, 81379 Munich, Germany, Commercial Register of the Local Court of Munich, HRB 305176

The Customer’s contacts are the addresses stated in the Order Form or customer account.