Version of October 10, 2026.
This Data Processing Agreement (“DPA”) is between the merchant using Editorify (“Controller”) and Importify Limited, Unit 1603, 16th Floor, The L. Plaza, 367 - 375 Queen’s Road Central, Sheung Wan, Hong Kong, provider of the Editorify service (“Processor”). It forms part of the terms under which the Controller uses Editorify (the “Service”) and applies for as long as the Processor processes personal data for the Controller.
This DPA applies without signature. A signed copy is available on request from support@editorify.com.
1. Scope and roles
- Terms such as “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the meanings given in Regulation (EU) 2016/679 (“GDPR”).
- “Customer Personal Data” means the personal data of the Controller’s store customers and reviewers that the Processor processes to provide the Service, as described in Annex 1.
- The Controller is the controller of Customer Personal Data and the Processor is its processor.
- Account, billing and contact data of the Controller itself is not covered by this DPA. The Processor handles it as a controller under the Editorify Privacy Policy.
2. Processor obligations
The Processor shall:
- process Customer Personal Data only on the Controller’s documented instructions, including for transfers outside the EEA, unless the law requires otherwise, in which case it will inform the Controller first where the law allows. Installing, configuring and using the Service is the Controller’s instruction;
- tell the Controller if it believes an instruction infringes data protection law;
- ensure that everyone authorised to process Customer Personal Data is bound by confidentiality;
- apply the security measures in Annex 2;
- help the Controller, as far as reasonably possible, to respond to requests from individuals exercising their rights, and forward to the Controller any such request it receives directly;
- help the Controller meet its obligations on security, breach notification and data protection impact assessments, taking into account the information available to the Processor;
- not sell Customer Personal Data or use it for its own purposes.
3. Controller obligations
- The Controller is responsible for having a lawful basis for the processing and for informing its own visitors and customers, including that reviews are published on its store, that the review widget loads fonts from Google Fonts in the visitor’s browser, and that review request emails are sent on its behalf.
- The Controller is responsible for the reviews it imports, collects, edits and displays, and for having the right to use them.
- The Service is not designed for special categories of personal data (GDPR Article 9), and the Controller will not use it to process them.
4. Subprocessors
- The Controller authorises the Processor to use the subprocessors listed in Annex 3.
- The Processor will inform the Controller by email before adding or replacing a subprocessor. The Controller may object within 14 days. If the objection cannot be resolved, the Controller may stop using the Service.
- The Processor binds each subprocessor to data protection obligations equivalent to this DPA and remains responsible for its performance.
5. International transfers
- The Processor is established in Hong Kong. Customer Personal Data is hosted in the United States by the hosting subprocessors in Annex 3. Review photos and videos are stored by the media subprocessors in Annex 3.
- Where the Controller’s transfer of Customer Personal Data to the Processor is subject to the GDPR and is not covered by an adequacy decision, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference. The Controller is the data exporter and the Processor is the data importer. Annexes 1 to 3 of this DPA are the annexes to those Clauses, section 4 of this DPA is the general authorisation for subprocessors, and the Clauses are governed by the law and courts of the EU member state in which the Controller is established. Where the transfer is subject to UK data protection law, the International Data Transfer Addendum issued by the UK Information Commissioner applies to those Clauses in the same way.
- Transfers to the subprocessors in Annex 3 rely on the subprocessor’s certification under the EU-US Data Privacy Framework or on the Standard Contractual Clauses.
6. Personal data breaches
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will share the information the Controller needs to meet its own obligations.
7. Information and audits
The Processor will make available the information needed to show compliance with this DPA. The Controller, or an independent auditor bound by confidentiality, may audit that compliance once a year on 30 days’ written notice, at the Controller’s cost and without unreasonably disrupting the Processor’s business.
8. Return and deletion
After the Controller stops using the Service, the Processor will delete or return Customer Personal Data, at the Controller’s choice, within 30 days of the Controller’s written request to support@editorify.com, unless the law requires it to be kept.
9. General
- If this DPA conflicts with the terms that govern the Service, this DPA prevails on data protection matters.
- Liability under this DPA is subject to the limits in the Terms of Use, except where the law does not allow liability to be limited.
Annex 1: Details of the processing
| Item | Description |
|---|---|
| Purpose | To collect, import, store and display product reviews on the Controller’s store, and to send review request emails to the Controller’s customers when the Controller turns that feature on. |
| Duration | While the Controller uses Editorify, and until deletion under section 8. |
| Individuals | People whose reviews are shown on the Controller’s store, and customers of the store who place orders. |
| Personal data | Reviews: reviewer name, rating, review text, photos and videos, country and date; for reviews written on the store, also the email address if the reviewer gives one and the IP address. Review requests: the customer’s name, email address, order number and the products ordered, as received from the store platform, and the email address of a customer who is given a discount code for a review. Email addresses that bounced or complained, so that they are not emailed again. |
| Special categories | None. |
Annex 2: Security measures
- All connections to the Service use HTTPS (TLS).
- Server and database access is limited to authorised administrators, over encrypted connections (SSH).
- Data is backed up regularly by the hosting provider.
- Payment card data is handled by the payment providers and store platforms and never reaches Editorify.
Annex 3: Subprocessors
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Cloudways Ltd | Managed hosting | All Customer Personal Data | Malta |
| DigitalOcean LLC | Cloud servers | All Customer Personal Data | United States (New York region) |
| Publitio doo | Storage and delivery of review photos and videos | Review photos and videos | Serbia; media stored in the United States and other regions of its cloud providers |
| ImageKit Private Limited | Storage and delivery of review photos and videos for some stores | Review photos and videos | India; media stored on Amazon Web Services |
| AC PM LLC (Postmark) | Sending review request emails | Customer name, email address, order number and products ordered | United States |
Shopify, Wix, WooCommerce and BigCommerce are the Controller’s own store platforms and are not subprocessors of Editorify. The marketplaces that imported reviews come from are not subprocessors of Editorify.
Contact
Importify Limited
Unit 1603, 16th Floor, The L. Plaza, 367 - 375 Queen’s Road Central, Sheung Wan, Hong Kong.
Email: support@editorify.com
Website: https://editorify.com/