Data Processing Addendum

Data Processing Addendum (DPA) — Checkout Sentry App

Last updated: July 2, 2026

This Data Processing Addendum (“DPA”) forms an integral part of and supplements the Terms of Use of the Checkout Sentry app and governs the processing of Personal Data carried out by IDCLIP APLICATIVOS E SOLUÇÕES LTDA (CNPJ 67.687.255/0001-45, “Processor” or “IDCLIP”) on behalf of the Merchant (“Controller”), in compliance with Law No. 13.709/2018 (“LGPD”). In the event of conflict regarding Personal Data, this DPA prevails over the Terms of Use.

1. Definitions

The terms “Personal Data”, “Data Subject”, “Processing”, “Controller”, “Processor”, “Data Protection Officer”, and “ANPD” have the meaning assigned under the LGPD. “Subprocessor” means a third party engaged by the Processor to assist in Processing.

2. Purpose and roles

2.1. The Merchant acts as Controller and IDCLIP as Processor of Consumers' Personal Data processed through the App.

2.2. The Processor will process Personal Data solely to provide the App's features and in accordance with the Controller's documented instructions, of which these Terms and the Privacy Policy form part.

2.3. Details of Processing (data categories, data subjects, purposes, and duration) are set forth in Annex I.

3. Processor obligations

The Processor undertakes to:

  1. process Personal Data only in accordance with the Controller's lawful instructions and applicable law, informing the Controller if it considers that an instruction violates the LGPD;
  2. ensure confidentiality of Personal Data, ensuring that persons authorized to process it are bound by a duty of confidentiality;
  3. adopt the technical and organizational security measures described in Annex III;
  4. assist the Controller in handling data subject requests and complying with legal obligations (security, incidents, and impact assessments), to a reasonable extent;
  5. not use Personal Data for its own purposes distinct from service provision, except for aggregated and anonymized data;
  6. maintain records of Processing operations performed.

4. Subprocessors

4.1. The Controller generally authorizes engagement of the Subprocessors listed in Annex II, notably Cloudflare (data ingestion) and Supabase (data persistence).

4.2. The Processor will impose on each Subprocessor, by contract, data protection obligations equivalent to those of this DPA, and will be liable to the Controller for compliance with such obligations.

4.3. The Processor will inform the Controller of the addition or replacement of Subprocessors by reasonable means, allowing the Controller to object on legitimate data protection grounds.

5. International transfers

5.1. Where international transfer of Personal Data occurs (for example, hosting on servers outside Brazil), the Processor will adopt mechanisms compatible with Art. 33 of the LGPD, including contractual clauses and guarantees of an adequate level of protection.

6. Data subject requests

6.1. Upon receiving a data subject request directly, the Processor will, unless legally required otherwise, forward or direct the data subject to the Controller, and provide, to a reasonable extent, technical assistance so the Controller can respond promptly.

7. Security incidents

7.1. The Processor will notify the Controller without undue delay after becoming aware of a security incident involving Personal Data processed under this DPA, providing reasonably available information so the Controller can fulfill its duties to notify the ANPD and data subjects.

7.2. The Processor will take reasonable measures to mitigate effects and prevent recurrence of the incident.

8. Deletion and return

8.1. Upon termination of Processing (due to end of subscription or App uninstallation), the Processor will, at the Controller's choice and where technically feasible, delete or return Personal Data, except where legal retention is required, in which case confidentiality will be maintained.

8.2. History retention periods follow the contracted plan, as set forth in the Privacy Policy.

9. Audit and demonstration

9.1. The Processor will make available to the Controller, upon reasonable request and under confidentiality, information necessary to demonstrate compliance with this DPA, which may be provided through reports, certifications, or questionnaire responses, while preserving security and third-party confidentiality.

10. Liability

10.1. Each party is responsible for obligations assigned to it under the LGPD according to its role (Controller or Processor). Liability limitations set forth in the Terms of Use also apply to this DPA, to the maximum extent permitted by law.

11. Term and final provisions

11.1. This DPA remains in effect while Personal Data is processed within the scope of the App and is governed by Brazilian law, with the courts of Vila Velha, State of Espírito Santo, Brazil elected as the forum.

ANNEX I — Description of Processing

ItemDescription
Subject matterCheckout monitoring and detection of failures, errors, and friction
Nature and purposeCollection, analysis, diagnosis, generation of alerts and reports
DurationWhile the App is installed; retention according to plan
Data subjectsConsumers/buyers of the Merchant's Store
Data categoriesIdentification and contact (name, email, phone, address); order and checkout data; checkout navigation and behavior; technical errors and anomalies; device and activity data
Sensitive dataIt is not the purpose to process sensitive data; if the platform makes them available, enhanced safeguards and minimization apply

ANNEX II — Subprocessors

SubprocessorPurpose
Cloudflare, Inc.Data ingestion, network delivery (CDN), and security/proxy layer
Supabase, Inc.Data persistence and storage (database)
Shopify Inc.E-commerce platform and data provision via API
Alert channel providersDelivery of alerts configured by the Merchant (email, Slack, WhatsApp, webhooks)

*Note: keep this list updated according to the stack actually in use. Remove providers that are not contracted.

ANNEX III — Security Measures

  • Encryption of Personal Data in transit (TLS) and at rest;
  • Least-privilege access control, authentication, and periodic permission review;
  • Environment segregation (development, staging, and production);
  • Logging, monitoring, and security alerts;
  • Backups and recovery procedures;
  • Vulnerability management and vendor/subprocessor assessment;
  • Internal information security and confidentiality policies.