About this addendum
This DPA is designed for OppAction's business customers. It applies only when OppAction processes Customer Personal Data as a processor, service provider, contractor, or subprocessor on the Customer's behalf. OppAction's independent-controller processing remains governed by the Agreement and Privacy Policy.
Document information
- Provider
- Mugpire, LLC, a Wyoming limited liability company, doing business as OppAction
- Customer
- The business or organization identified in the Agreement or applicable Order
- Document status
- Effective
- Revision date
- September 2, 2026
- Public register
- https://oppaction.com/subprocessors
- DPA version
- OppAction DPA - September 2, 2026
This Data Processing Addendum ("DPA") forms part of the Agreement between the Customer and Mugpire, LLC, doing business as OppAction ("OppAction"). It governs OppAction's Processing of Customer Personal Data on Customer's behalf. Capitalized terms not defined in this DPA have the meanings given in the Agreement or Applicable Data Protection Law.
1. Definitions
1.1 "Agreement" means the Terms of Service, applicable Order, enterprise agreement, and incorporated supplemental terms governing Customer's use of the Services.
1.2 "Applicable Data Protection Law" means privacy, data protection, and data-security law that applies to OppAction's Processing of Customer Personal Data under the Agreement, including, when applicable, the GDPR, UK GDPR, Swiss FADP, CCPA, and other U.S. state comprehensive privacy laws.
1.3 "CCPA" means the California Consumer Privacy Act of 2018, as amended, and its implementing regulations.
1.4 "Customer Personal Data" means Personal Data included in Customer Content or otherwise Processed by OppAction on Customer's behalf in providing the Services. It excludes information for which OppAction determines the purposes and means of Processing as an independent controller or business, including OppAction's account administration, direct billing, security, legal-compliance, and business-contact records, except to the extent Applicable Data Protection Law provides otherwise.
1.5 "Data Subject Request" means a request by an individual to exercise a right under Applicable Data Protection Law concerning Customer Personal Data.
1.6 "EU SCCs" means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj, as completed by this DPA.
1.7 "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in OppAction's possession or control. It does not include an unsuccessful attempt or event that does not compromise Customer Personal Data.
1.8 "Process", "Processing", "Controller", "Processor", "Business", "Service Provider", "Contractor", "Sell", and "Share" have the meanings given by Applicable Data Protection Law. "Subprocessor" means a third party engaged by OppAction to Process Customer Personal Data on Customer's behalf.
2. Scope, effectiveness, and roles
2.1 This DPA becomes effective for a Customer on the earliest date that Customer: (a) affirmatively accepts an Agreement or Order that identifies or links to this DPA; (b) signs or countersigns this DPA; or (c) otherwise enters into a legally binding writing that expressly incorporates it (the "DPA Effective Date"). OppAction will provide a countersigned copy upon reasonable request. Publication or website access alone does not create acceptance.
2.2 This DPA applies only to Customer Personal Data. The subject matter, nature, purposes, duration, data categories, and data subjects are described in Schedule 1.
2.3 Customer acts as Controller or Business when it determines the purposes and means of Processing Customer Personal Data. OppAction acts as Processor, Service Provider, or Contractor. If Customer acts as a Processor for another Controller, OppAction acts as Customer's Subprocessor, and Customer represents that its instructions and appointment of OppAction are authorized by the relevant Controller.
2.4 For independent-controller information, including direct account, security, legal, and business-contact records, each party is independently responsible for its obligations under Applicable Data Protection Law. Nothing in this DPA converts one party into the other's controller for that independent Processing.
3. Customer instructions and responsibilities
3.1 OppAction will Process Customer Personal Data only on Customer's documented instructions, including with respect to transfers of Customer Personal Data, as reflected in the Agreement, Customer's authorized use and configuration of the Services, Orders, support instructions, and other written directions consistent with the Agreement, unless Applicable Data Protection Law requires otherwise. If law requires Processing contrary to Customer's instructions, OppAction will inform Customer before Processing unless legally prohibited.
3.2 OppAction will promptly inform Customer if, in OppAction's reasonable opinion, an instruction infringes Applicable Data Protection Law. OppAction may suspend the affected Processing while the parties work in good faith to resolve the issue.
3.3 Customer is responsible for: (a) the lawfulness, accuracy, quality, and minimization of Customer Personal Data; (b) required notices, permissions, consents, and legal bases; (c) the legality of Customer's instructions; (d) responding to individuals except to the extent OppAction must assist; and (e) ensuring that Customer and its Authorized Users do not submit prohibited data.
3.4 The Services do not intentionally support or authorize health information, payment-card data, government identifiers, biometric data, precise geolocation, children's Personal Data, GDPR special-category data, or comparable sensitive or regulated data (collectively, "Prohibited Sensitive Data"). Customer must not submit Prohibited Sensitive Data. No exception is permitted without OppAction's prior written Legal approval, a documented lawful basis, and an approved secure technical workflow.
3.5 Free-form inputs cannot guarantee technical prevention of accidental receipt. If OppAction identifies Prohibited Sensitive Data, it may restrict access, suspend affected Processing, contain and delete the data, invoke incident-response procedures, and notify Customer as appropriate. Customer will reasonably cooperate with containment and remediation.
4. Confidentiality and personnel
4.1 OppAction will ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations and receive instructions appropriate to their responsibilities.
4.2 Access to Customer Personal Data is limited to authorized persons and systems with a legitimate need, subject to role-appropriate access controls, confidentiality obligations, and multi-factor authentication where supported. Backup or emergency administrative access is restricted to authorized use.
5. Security
5.1 OppAction will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature, scope, context, and purposes of Processing and the risks to individuals. The current measures are described in Schedule 2.
5.2 Customer acknowledges that security measures evolve. OppAction may update Schedule 2 to reflect technical and organizational developments, provided that an update does not materially reduce the overall protection of Customer Personal Data during the applicable Subscription Term.
5.3 No service can guarantee absolute security. Customer remains responsible for its systems, credentials, Authorized Users, connected services, and configurations outside OppAction's control.
6. Personal Data Breaches
6.1 OppAction will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. OppAction does not promise a universal fixed-hour notification deadline.
6.2 To the extent information is reasonably available, notice will describe: (a) the nature of the breach; (b) affected data and individuals; (c) likely consequences; (d) measures taken or proposed; and (e) a contact for follow-up. OppAction may provide information in phases as its investigation progresses.
6.3 OppAction will take reasonable steps to contain, investigate, mitigate, and document the breach. Notification is not an admission of fault or liability. Customer is responsible for determining whether it must notify individuals, regulators, or others, with OppAction's reasonable assistance as required by law.
7. Assistance and individual rights
7.1 Taking into account the nature of Processing, OppAction will provide reasonable assistance through available technical and organizational measures so Customer can respond to Data Subject Requests. OppAction may direct an individual to Customer when Customer is the relevant Controller.
7.2 If OppAction receives a request concerning Customer Personal Data, it will not independently substantively respond unless authorized by Customer or required by law. OppAction will notify or refer the requester to Customer when reasonably practicable and lawful.
7.3 Taking into account the nature of Processing and information available to OppAction, OppAction will provide reasonable information and assistance for Customer's obligations concerning security of Processing, Personal Data Breach notifications, data-protection impact assessments, prior consultations, and regulator inquiries under Applicable Data Protection Law.
7.4 Standard assistance available through the Services and ordinary compliance materials is included in the fees. If Customer requests material assistance beyond OppAction's ordinary obligations or capabilities, the parties may agree on scope, timing, and reasonable fees, except where the assistance is required because of OppAction's breach of this DPA.
8. Subprocessors
8.1 Customer provides general written authorization for OppAction to engage the Subprocessors identified in Schedule 3 and at https://oppaction.com/subprocessors. OppAction remains responsible for Subprocessor performance to the extent required by Applicable Data Protection Law.
8.2 OppAction will impose written data-protection obligations on each Subprocessor that provide substantially equivalent protection for Customer Personal Data as required of OppAction under this DPA, to the extent applicable to the Subprocessor's Processing.
8.3 OppAction will ordinarily provide at least thirty (30) days' prior written notice before authorizing a new Subprocessor to Process Customer Personal Data or replacing an existing Subprocessor. Notice will identify the Subprocessor and the nature and location of Processing. OppAction will publish material changes at the public register and send advance notice to Customer's contractual or account contact when required by this DPA or Applicable Data Protection Law.
8.4 Where thirty days is not reasonably practicable because of an urgent security issue, legal or regulatory requirement, discontinuation or material failure of an existing provider, or another circumstance reasonably beyond OppAction's control, OppAction may provide a shorter period. OppAction will provide at least fifteen (15) days' advance notice where reasonably practicable and otherwise will notify Customer as soon as reasonably practicable. Where the EU SCCs, UK Addendum, or Applicable Data Protection Law require an opportunity to object before engagement, OppAction will provide that opportunity notwithstanding the shortened-notice exception.
8.5 Customer may object during the applicable notice period by sending a written objection to legal@oppaction.com that states reasonable and documented grounds relating to protection of Customer Personal Data or compliance with Applicable Data Protection Law. Customer does not have a discretionary commercial veto.
8.6 The parties will work in good faith to address a timely valid objection. OppAction may provide additional diligence information or safeguards, avoid the Subprocessor for Customer where reasonably practicable, or offer a commercially reasonable alternative. If the objection cannot be resolved and OppAction cannot reasonably provide the affected Services without the Subprocessor, Customer may terminate only the materially affected portion of the Services without termination penalty. Any refund of prepaid fees for the unused terminated portion is subject to the Agreement and applicable Marketplace or billing-provider mechanics.
9. Return, deletion, and retention
9.1 During the Agreement, Customer may use available functionality to access, correct, export, or delete Customer Personal Data. Upon termination of the affected Services, OppAction will, at Customer's choice and on Customer's lawful instructions, delete or return Customer Personal Data and delete existing copies, unless Applicable Data Protection Law requires or permits continued retention. Any return is subject to available secure methods and the Agreement.
9.2 Deletion from active systems is performed through OppAction's implemented privacy workflows. Residual copies may remain in protected backups, PITR archives, provider logs, security records, or other systems until overwritten or deleted under applicable provider schedules. While retained, residual data remains protected, access-restricted, and unavailable for ordinary business use.
9.3 Railway currently hosts OppAction's primary application and database processing in Virginia and maintains enabled PITR/archive storage in California. Provider backup and archive deletion occurs under Railway's published terms, retention schedules, and technical processes. OppAction does not represent its internal conservative planning assumptions as a provider contractual commitment and cannot provide provider-specific bespoke deletion certificates that the provider does not issue.
9.4 For Resend-held data that lacks a verified self-service deletion mechanism, OppAction follows its approved vendor-deletion procedure, requests scoped deletion or irreversible de-identification, preserves minimized evidence, and keeps the task open until Resend confirms disposition or a documented legal exception applies.
9.5 OppAction may retain minimized records as reasonably necessary for security, fraud prevention, legal compliance, disputes, enforcement, and proof of privacy-request handling. It will not retain deleted Customer content merely to prove deletion.
10. Audits and compliance information
10.1 OppAction will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, summaries, provider documentation, certifications, and responses to reasonable security questionnaires, subject to confidentiality, security, privilege, and third-party restrictions.
10.2 Customer may request an audit no more than once in any twelve-month period, unless a more frequent audit is reasonably required by Applicable Data Protection Law, a competent regulator, or a material Personal Data Breach. The parties will first use available independent reports and documentary evidence. An on-site or technical audit is permitted where documentary evidence is reasonably insufficient and must be conducted by an independent qualified auditor under confidentiality obligations, during normal business hours, with reasonable notice, and without accessing another customer's data or unreasonably disrupting the Services.
10.3 Customer bears its audit costs unless the audit identifies OppAction's material breach of this DPA, in which case reasonable allocation will be determined under the Agreement and Applicable Data Protection Law. Nothing requires OppAction to disclose credentials, penetration-test exploit details, another customer's information, or information whose disclosure would create a security risk or violate law or contract.
11. U.S. state privacy terms
11.1 Where Customer is a Business and OppAction Processes Customer Personal Data as a Service Provider or Contractor under the CCPA, the specific and limited Business Purposes are those stated in Schedule 1. Relevant service descriptions in the Agreement supplement, but do not replace, those specific purposes. Customer discloses Customer Personal Data to OppAction only for those limited and specified Business Purposes.
11.2 OppAction will not Sell or Share Customer Personal Data; retain, use, or disclose it outside the specific business purposes and services in the Agreement and this DPA or as otherwise permitted by the CCPA; retain, use, or disclose it for a commercial purpose other than those specified purposes; or retain, use, or disclose it outside the direct business relationship between Customer and OppAction, except as permitted by the CCPA.
11.3 OppAction will not combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from OppAction's own interaction with an individual, except as permitted by the CCPA and its regulations. OppAction will provide the same level of privacy protection required of Businesses by the CCPA for the Customer Personal Data it Processes under this DPA.
11.4 Customer may take reasonable and appropriate steps to help ensure OppAction uses Customer Personal Data consistently with Customer's CCPA obligations, including through the audit and information rights in Section 10. OppAction will notify Customer if it determines it can no longer meet its applicable CCPA obligations. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.
11.5 OppAction will reasonably assist Customer with verifiable consumer requests and will require its applicable Subprocessors to comply with written restrictions appropriate to their role. These restrictions also apply, to the extent required, where OppAction acts as a processor under another U.S. state comprehensive privacy law.
12. De-identified data
12.1 OppAction may create aggregated or de-identified information from Customer Personal Data only as permitted by Applicable Data Protection Law and the Agreement. OppAction will take reasonable measures designed to prevent the information from being associated with Customer or an individual, will maintain and use it in de-identified form, and will not attempt to reidentify it except where law permits testing of de-identification safeguards or investigation of security or abuse.
12.2 OppAction will not use non-public Customer Content to train a generalized AI model made available to other customers or the public unless Customer expressly opts in through a separate legally sufficient authorization. OppAction does not authorize optional provider data sharing for model training in its documented production OpenAI project.
13. International transfers
13.1 Customer authorizes OppAction and its Subprocessors to Process Customer Personal Data in the locations described in Schedule 3 and the public Subprocessor register, subject to this DPA and Applicable Data Protection Law.
13.2 The parties will use an applicable adequacy decision or recognized certification when legally available and appropriately verified. Where another transfer mechanism is required, the EU SCCs, UK Addendum, and Swiss adaptations in Schedule 4 apply. A certification is supplemental rather than the sole documented safeguard unless OppAction has verified that the applicable recipient and transfer are covered.
13.3 Each party will reasonably cooperate with transfer-impact assessments and supplementary measures. OppAction may provide relevant provider documentation and information concerning government-access requests, subject to confidentiality, legal, and security restrictions.
14. Government requests
14.1 Unless legally prohibited, OppAction will notify Customer of a legally binding request from a public authority for Customer Personal Data. OppAction will review the request, seek clarification or challenge it where there are reasonable grounds and lawful means, and disclose only data it is legally required to provide.
15. Duration and termination
15.1 This DPA remains in effect while OppAction Processes Customer Personal Data under the Agreement. Processor obligations concerning retained Customer Personal Data survive termination until the data is deleted, returned, de-identified, or lawfully retained.
15.2 Termination of a transfer mechanism does not automatically terminate the entire Agreement. The parties will first work in good faith to implement a replacement lawful mechanism. If that cannot reasonably be done, termination will be limited to the Processing or affected Services requiring the restricted transfer, except where mandatory law requires otherwise.
16. Liability and precedence
16.1 The Agreement's exclusions, liability caps, remedies, indemnities, dispute-resolution terms, and governing-law provisions apply to this DPA, including any enhanced cap expressly applicable to DPA or security claims. Nothing limits liability or data-subject rights that cannot lawfully be limited, and nothing in the Agreement or this DPA modifies the EU SCCs or UK Addendum contrary to their mandatory terms.
16.2 If documents conflict, the Agreement's order of precedence applies, and each document controls only within its stated scope. Within the subject matter of Personal Data Processing, this DPA controls over inconsistent Terms, Feature Addenda, or policies unless a separately signed enterprise agreement or applicable Order expressly identifies the affected DPA provision and lawfully amends it. The EU SCCs or UK Addendum control over the Agreement and this DPA for an applicable Restricted Transfer to the extent of a conflict.
17. Notices and changes
17.1 Privacy, DPA, and Subprocessor objections or notices to OppAction may be sent to legal@oppaction.com or privacy@oppaction.com, or to Mugpire, LLC d/b/a OppAction, PO Box 2869, Jackson, Wyoming 83001. OppAction may send notices to Customer's contractual, Account Owner, or registered account contact.
17.2 OppAction may update this DPA prospectively to reflect law, providers, safeguards, or Services. It will provide notice and obtain affirmative reacceptance when required by the Agreement or Applicable Data Protection Law, including where a change materially alters Customer's data-use rights or obligations. Changes required for law, security, or urgent provider continuity may take effect on shorter notice where legally permitted.
18. Entire DPA and electronic acceptance
18.1 This DPA and its Schedules constitute the parties' data-processing agreement for Customer Personal Data and supersede prior data-processing terms concerning the same Processing, unless a separately signed enterprise agreement expressly controls.
18.2 Electronic acceptance, an incorporated Order, or another legally binding acceptance method has the same effect as a signature. OppAction's acceptance record identifies the accepted DPA version and acceptance timestamp. Upon request, OppAction will provide a countersigned copy identifying the Customer and DPA Effective Date; countersignature confirms rather than delays effectiveness already established under Section 2.1.
Schedule 1 - Processing details
Subject matter | Providing, securing, supporting, maintaining, and improving the merchant-directed OppAction Services, including Shopify-connected catalog workflows, AI-assisted analysis and generation, transactional/support communications, and related privacy and compliance operations. |
|---|---|
Duration | For the term of the Agreement and afterward only for deletion, return, backup overwrite, legal retention, dispute, security, and compliance periods described in the Agreement, this DPA, and applicable provider schedules. |
Nature | Collection, receipt, access, organization, hosting, storage, retrieval, consultation, transmission, AI analysis, generation, scoring, modification at Customer direction, support, security monitoring, backup, export, deletion, and de-identification. |
Purposes | Provide Customer-requested functionality; authenticate and administer authorized use; process merchant-directed catalog/listing workflows; generate and store outputs; deliver operational and support email; secure, troubleshoot, and maintain the Services; comply with documented instructions and law. |
Frequency | Continuous for hosting and security; otherwise as initiated by Customer, Authorized Users, connected Shopify events, scheduled plan operations, support activity, or legally required privacy workflows. |
Categories of data subjects
- Customer's Account Owners, Authorized Users, personnel, contractors, and business contacts.
- Shopify store personnel and other individuals whose business-contact or identity information is provided through authorized scopes.
- Merchant customers, order participants, catalog contributors, product subjects, or other individuals whose information is included in Customer Content or authorized Shopify data.
- Recipients and senders of transactional, support, privacy, legal, security, billing, and operational communications.
- Other individuals whose Personal Data Customer lawfully directs OppAction to Process within the supported Services.
Categories of Customer Personal Data
- Identifiers and business-contact data, such as name, business name, email address, user/account identifiers, Shopify staff identity, and communication identifiers.
- Merchant, catalog, listing, product, variant, collection, and limited order information available through authorized Shopify scopes, including product IDs, titles, descriptions, tags, types, vendors, SEO fields, images, image URLs, alt text, SKUs, dates, quantities, amounts, and currency.
- Customer Content and AI interaction data, including prompts, instructions, preferences, blocked terms, catalog context, previous suggestions, scores, refinement context, eligible Shopify-hosted product-image URLs, and generated output.
- Communications and support data, including message content, subjects, sender/recipient data, attachments supplied through supported channels, ticket references, and delivery metadata.
- Internet, device, session, access, diagnostic, security, audit, and operational metadata, including IP address and timestamps where connected to Customer's use.
- Inferences and derived data, such as classifications, scores, recommendations, workflow status, and usage patterns, where they constitute Personal Data.
Prohibited data
The Services do not authorize Prohibited Sensitive Data described in Section 3.4. Accidental receipt is handled through restricted-data containment, deletion, and incident-response procedures.
Customer instructions
The Agreement, Customer's authorized configuration and use of the Services, Orders, authenticated requests, support instructions, privacy requests, and other documented directions consistent with the Agreement.
Schedule 2 - Technical and organizational measures
1. Governance and accountability
- Documented privacy, access-control, data-protection, retention, incident-response, vendor-governance, and deletion procedures with assigned ownership and review triggers.
- Provider DPAs, terms, subprocessor records, security evidence, and transfer reviews retained in restricted compliance folders.
- DPA, security, and subprocessor changes monitored for all active direct providers through provider notices, official feeds, and weekly monitoring.
2. Access control and authentication
- Unique human accounts; no shared production credentials; least-necessary access based on operational role.
- MFA enabled for all known human production-access accounts where supported. Shared mailboxes block direct sign-in.
- Privileged production access is limited to authorized personnel. A separate MFA-protected Microsoft 365 Global Administrator is restricted by written obligations to authorized backup or emergency use.
- Sessions and provider access are reviewed and unrecognized access is investigated and revoked.
3. Service accounts, secrets, and credentials
- Application runtime secrets are stored in Railway variables or references; applicable integration credentials use provider-managed stores. Secrets are excluded from source control.
- Permissions are scoped to service purpose. Credentials can be revoked or rotated following compromise, personnel or provider change, material deployment, or other risk-based trigger.
- A category-level inventory and rotation policy supports risk-based credential management.
4. Encryption and transport protection
- HTTPS/TLS protects external service connections. Cloudflare enforces a minimum TLS version of 1.2 and supports TLS 1.3 for the production proxy.
- External connector credentials stored by the application use AES-256-GCM application-level encryption. Ordinary application and catalog data relies on Railway-managed encryption at rest.
- Cloudflare-managed certificates protect the public proxy; certificate-transparency monitoring routes notices to monitored OppAction contacts.
5. Tenant and authorization separation
- Customers share application and database infrastructure. Logical separation is enforced through authenticated Shopify identity, shop-scoped authorization, and shop-domain-scoped database operations.
- Authorization and cross-shop regression tests are used. OppAction does not claim a dedicated database or schema for each Customer.
6. Logging, monitoring, and alerts
- Application audit events, security-session events, billing and credit records, privacy-job monitoring, provider logs, and operational events support investigation and accountability.
- Logging is designed to exclude credentials and unnecessary Customer payloads. Sensitive evidence is minimized, redacted, and stored outside source control.
- Critical operational alerts are production-routed through Resend to the monitored OppAction Security mailbox, with a secondary copy to an authorized administrator. Routing has been production-verified using synthetic content that excludes Customer Personal Data and secrets.
7. Backups, availability, and recovery
- Railway-managed backups and PITR are enabled. Primary application/database processing is in Virginia; the PITR/archive bucket is in California.
- A non-destructive PITR recovery test completed successfully after the database region move, validating the restored schema, migrations, indexes, constraints, and per-table row counts without altering the live production database.
- Backup and PITR retention and overwrite follow Railway's published terms and technical schedules. Residual protected copies are not used for ordinary processing.
8. Secure development and vulnerability management
- Secure-development controls include automated testing and production builds, authorization and CSRF safeguards, security headers, dependency and repository checks, and secret scanning where configured.
- Semgrep is used to identify potential code vulnerabilities. Findings are reviewed and remediated based on nature, severity, exploitability, and risk.
9. Data minimization, restricted data, and AI controls
- The Services are designed for merchant-directed business, catalog, listing, and operational data. Prohibited Sensitive Data is contractually restricted.
- OpenAI Responses requests use store:false and background mode is disabled. The production project uses Global residency and default abuse-monitoring retention; store:false disables Responses application-state storage but does not disable abuse-monitoring retention. OppAction does not claim Zero Data Retention. Exceptional safety retention may apply to flagged image inputs under OpenAI's documented controls.
- OppAction transmits eligible Shopify product images as Shopify-hosted URLs and does not download, cache, or separately store source image files for OpenAI processing.
- Optional OpenAI API data sharing is disabled and Customer Content is not authorized for generalized provider-model training.
10. Privacy rights, retention, and deletion
- Authenticated workflows support relevant access, correction, restriction, portability, deletion, appeal, legal-hold, Shopify redaction, resumable deletion, vendor deletion, and monitoring actions.
- Deletion from active systems is scoped and evidenced. Provider-held data and protected backups follow applicable provider mechanisms and overwrite schedules.
- The Resend-specific procedure requires initial action and provider request within two business days, follow-up within five business days, and confirmation or documented escalation within ten business days; it does not guarantee provider deletion within ten days.
11. Incident response and business continuity
- A versioned incident-response plan defines severity, command, containment, evidence, legal-hold, recovery, and notification-decision processes.
- The Privacy/Legal Lead determines legally required customer, individual, regulator, Shopify, and provider notifications based on applicable facts and law. Decisions and timing are documented.
- Customer breach notice under this DPA is provided without undue delay; internal SEV1 acknowledgement targets are not represented as customer-notification deadlines.
12. Provider and physical security
- Physical infrastructure and data-center controls are provided by approved hosting and cloud providers under their applicable contractual and security programs.
- OppAction reviews provider evidence and uses contractual transfer and subprocessor safeguards appropriate to each provider's role.
Schedule 3 - Authorized subprocessors
The current public register is maintained at https://oppaction.com/subprocessors. The following direct providers are authorized as of this DPA's revision date. The public register controls for current effective dates, historical changes, and updated location details.
Current direct providers
Railway
Legal entity: Railway Corporation
Service and purpose: Application hosting, PostgreSQL database, encrypted credential storage, logs, jobs, managed backups, and PITR.
High-level data: Customer Personal Data hosted or processed by the application; authentication and operational metadata; logs; and backups.
Locations: Primary application and database processing in Virginia, USA; PITR/archive storage in California, USA. Global support, monitoring, and authorized onward subprocessors may involve additional documented locations.
Safeguards: Provider DPA and applicable contractual transfer safeguards; encryption at rest and in transit; access, backup, and security controls documented in retained provider materials.
OpenAI
Legal entity: OpenAI OpCo, LLC or OpenAI Ireland Ltd., as applicable under the executed DPA
Service and purpose: AI-assisted analysis, generation, scoring, and refinement of Customer-directed catalog and listing content.
High-level data: Catalog/listing content, instructions, metadata, eligible Shopify-hosted product-image URLs, and generated output. General file uploads and merchant support attachments are not sent.
Locations: Global production project; processing may occur in the United States and other authorized Subprocessor locations.
Safeguards: Executed provider DPA; applicable SCC, UK, Swiss, or adequacy safeguards; store:false; background mode disabled; optional data sharing disabled. Default abuse-monitoring retention may retain limited content for up to 30 days, and exceptional safety retention may apply to flagged image inputs. No Zero Data Retention representation.
Resend
Legal entity: Plus Five Five, Inc.
Service and purpose: Transactional, service, privacy, renewal, onboarding, support, security, and operational email.
High-level data: Sender and recipient addresses, message subject and content, attachments where applicable, limited account context, and delivery metadata.
Locations: Resend states that certain account data, email metadata, logs, and API records are stored in the United States. Email delivery may use the configured sending region, and authorized onward subprocessors may process in other documented locations.
Safeguards: Provider DPA; applicable SCC, UK, Swiss, and supplemental transfer safeguards; scoped deletion procedure. Open and click tracking are disabled in the documented production configuration.
Microsoft 365
Legal entity: Microsoft Corporation
Service and purpose: Hosting and delivery of support, privacy, legal, security, billing, and related OppAction mailbox communications.
High-level data: Sender and recipient details, message content, attachments, and related email metadata.
Locations: Workload-specific data-at-rest locations displayed in the Microsoft 365 tenant are in the USA, subject to Microsoft-displayed No Commitment or unavailable-location qualifications. Support, telemetry, and authorized onward Processing may occur elsewhere.
Safeguards: Microsoft Customer Agreement; May 22, 2026 Microsoft Products and Services DPA; applicable Product Terms, SCCs, and other transfer safeguards.
Cloudflare
Legal entity: Cloudflare, Inc.
Service and purpose: Global reverse proxy, TLS/security, traffic delivery, certificate management, and protection for app.oppaction.com.
High-level data: IP addresses, connection and request metadata, TLS traffic, and potentially request content passing through the proxy.
Locations: Cloudflare's global network. The Free plan does not provide a customer-selected metadata boundary, regional traffic-processing restriction, or geographic private-key restriction. Logpush is not configured.
Safeguards: Cloudflare Self-Serve Subscription Agreement, Customer DPA v6.4, Service-Specific Terms, applicable SCCs and transfer safeguards; minimum TLS 1.2 and TLS 1.3 enabled.
Customer-selected platform/source
Shopify is not an OppAction-appointed Subprocessor. The merchant selects and directly uses Shopify as the authoritative platform and source for merchant, catalog, limited order, OAuth, billing, staff-identity, and webhook data. Shopify's independent and merchant-directed Processing is governed by the merchant's Shopify relationship and applicable Shopify terms.
Schedule 4 - International transfer terms
A. EU Standard Contractual Clauses
A.1 For a Restricted Transfer of Customer Personal Data governed by the GDPR that is not covered by an applicable adequacy decision, the parties enter into and agree to the EU SCCs by reference. The EU SCCs are deemed signed through the binding acceptance mechanism in Section 2.1.
A.2 Module Two applies where Customer is a Controller and OppAction is a Processor. Module Three applies where Customer is a Processor and OppAction is a Subprocessor. Clause 7 (Docking Clause) applies. Clause 9 uses Option 2 (general written authorization) with the notice period and exceptions in Section 8. Clause 11 (optional independent dispute-resolution body) does not apply.
A.3 For Clause 17, the EU SCCs are governed by the law of Ireland. For Clause 18, the courts of Ireland have jurisdiction, without limiting mandatory data-subject rights. The competent supervisory authority is determined under Clause 13 based on Customer's establishment, representative, or relevant data subjects; Customer will identify the authority upon reasonable request where it is not apparent from the Agreement.
A.4 If this DPA conflicts with the EU SCCs, the EU SCCs control for the Restricted Transfer. The parties may add supplementary measures that do not contradict the EU SCCs or prejudice data-subject rights.
EU SCC Annex I.A - Parties
Data exporter | Customer, as identified in the Agreement or Order. Address and contact details are those in Customer's account, Order, or countersigned copy. Customer is Controller for Module Two or Processor for Module Three. |
|---|---|
Exporter activities | Use of the OppAction Services and transfer of Customer Personal Data described in Schedule 1. |
Data importer | Mugpire, LLC d/b/a OppAction, PO Box 2869, Jackson, Wyoming 83001, United States; legal@oppaction.com. |
Importer activities | Provision, hosting, security, support, AI-assisted Processing, communications, deletion, and other activities described in Schedule 1. |
Signatures | The parties' legally binding electronic acceptance, incorporated Order, or countersignature under Section 2.1 constitutes signature for the EU SCCs. |
EU SCC Annex I.B - Transfer description
The categories of data subjects, Personal Data, nature, purposes, frequency, and duration are stated in Schedule 1. Prohibited Sensitive Data is not authorized. Transfers occur continuously for hosting and security and otherwise as Customer or the Services initiate authorized Processing. Retention is described in Section 9 and the applicable provider schedules.
EU SCC Annex I.C - Supervisory authority
The competent supervisory authority is determined in accordance with EU SCC Clause 13. Customer will identify its authority in a countersigned copy or upon request where the authority cannot be determined from Customer's establishment or appointed representative.
EU SCC Annex II - Technical and organizational measures
Schedule 2 applies. The measures are allocated to OppAction's Processing and, where identified, to provider-dependent infrastructure or Subprocessor Processing.
EU SCC Annex III - Subprocessors
Customer provides general written authorization under Clause 9 Option 2. Schedule 3 and the current register at https://oppaction.com/subprocessors identify authorized Subprocessors and their Processing.
B. United Kingdom Addendum
B.1 For a Restricted Transfer governed by the UK GDPR that is not covered by UK adequacy regulations, the parties enter into the ICO International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0 in force March 21, 2022, as lawfully revised ("UK Addendum"), available at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf.
Table 1 - Parties | Exporter: Customer. Importer: Mugpire, LLC d/b/a OppAction. Contact and signature information is completed by Section 2.1 and EU SCC Annex I.A. |
|---|---|
Table 2 - SCCs | The Approved EU SCCs, Modules Two and/or Three as applicable; Clause 7 applies; Clause 9 Option 2 applies; Clause 11 does not apply. |
Table 3 - Appendix | The information in Schedules 1, 2, and 3 and the EU SCC Annexes above. |
Table 4 - Approved Addendum changes | Importer may terminate: selected. Exporter may terminate: selected. Neither Party: not selected. |
B.2 The UK Addendum is deemed executed through Section 2.1. If an Approved Addendum change gives rise to a Section 19 termination right, either Importer or Exporter may exercise it. The parties will first seek a replacement lawful mechanism; if none can reasonably be implemented, termination is limited to affected Processing or Services unless mandatory law requires otherwise.
C. Switzerland
C.1 For a Restricted Transfer governed by the Swiss Federal Act on Data Protection (FADP), the EU SCCs apply with these adaptations: references to the GDPR include the FADP to the extent applicable; references to EU or EU Member State law include Swiss law where appropriate; references to an EU Member State must not be interpreted to exclude Switzerland; and the competent authority is the Swiss Federal Data Protection and Information Commissioner.
C.2 The EU SCCs' governing-law and forum selections apply without depriving Swiss data subjects of mandatory rights or the ability to bring proceedings in Switzerland where the FADP requires. The parties will use the FDPIC-recognized form or additional adaptations if required by a change in Swiss law or guidance.
D. Transfer-mechanism continuity
D.1 If a transfer mechanism is invalidated, materially changed, or no longer available, the parties will cooperate in good faith to implement a valid replacement. Pending replacement, OppAction may suspend the affected transfer or Processing where reasonably necessary. Termination is limited to the affected Processing or Services unless broader termination is required by law or the Agreement.
Optional countersignature record
This section may be completed when Customer requests a countersigned copy. It confirms the DPA Effective Date established under Section 2.1 unless the parties expressly agree otherwise.
Customer legal name | To be completed for the requesting Customer |
|---|---|
Customer address | To be completed for the requesting Customer |
Customer contact | To be completed for the requesting Customer |
DPA Effective Date | Acceptance date recorded in the Agreement or applicable countersignature date |
Customer authorized signatory | Name / title / signature / date |
Mugpire, LLC d/b/a OppAction | Authorized signatory / title / signature / date |