Legal
Data Processing Addendum
Last updated: 20 July 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between HATCHED105 LEADERSHIP LIMITED, trading as Presterly, a company registered in the Republic of Ireland under company number 816748 with its registered office at 105 Baggot Street Lower, Dublin 2, D02 DX60, Ireland (“Presterly”, the “Processor”), and each merchant that uses the Presterly service (the “Merchant”, the “Controller”). It governs all personal data that Presterly processes on the Merchant’s behalf.
1. How this DPA takes effect (no signature needed)
This DPA is incorporated into and forms part of the Terms of Service. It takes effect automatically, and is binding on both parties, on the earliest of:
- the Merchant installing or using the Presterly app for Shopify;
- the Merchant granting Presterly access to its store, marketing platform, booking platform, or customer data in any form (including collaborator access, an admin seat, an API key, OAuth authorisation, or a data export); or
- the start of any Presterly service under a proposal, order form, or service agreement.
This DPA is executed by that acceptance. No separate signature is required, and it satisfies the requirement for a data processing contract under Article 28(3) of the GDPR. If the Merchant needs a countersigned copy for its records, email fergus@presterly.com and we will provide one; the countersigned copy will be this DPA as posted at that date. A Merchant’s own data processing agreement, or any amendment to this DPA, applies only if expressly agreed in writing and signed by us.
2. Roles and scope
The Merchant is the controller of its customers’ personal data and determines the purposes and means of processing. Presterly is the processor and processes that data solely on the Merchant’s documented instructions to provide the service. The subject matter, duration, nature and purposes of processing, and the categories of data subjects and personal data, are set out in Annex 1. Definitions from the GDPR apply. “Applicable Data Protection Law” means the GDPR, the Irish Data Protection Act 2018, the Irish ePrivacy Regulations (S.I. No. 336 of 2011), and any other privacy or electronic marketing law that applies to the processing, including United States federal and state law such as the TCPA and state privacy statutes where relevant.
The Merchant’s standing instructions to Presterly are: process customer personal data as needed to provide the services described in the Terms of Service (prediction, message triggering, campaign operation, list growth, attribution, and reporting), respect the consent and opt-out records held in the Merchant’s systems, and process for no other purpose. The Merchant warrants that its instructions comply with Applicable Data Protection Law.
3. Presterly’s obligations as processor
Presterly will:
- process personal data only on the Merchant’s documented instructions, unless required to do otherwise by law (in which case we will tell the Merchant first, unless the law prevents it);
- ensure everyone we authorise to process the data is bound by confidentiality obligations;
- implement and maintain the technical and organisational security measures in Annex 2;
- engage sub-processors only under section 5, and remain liable for their performance;
- taking into account the nature of the processing, assist the Merchant with data subject requests, security, breach notification, data protection impact assessments, and prior consultation under Articles 32 to 36 of the GDPR;
- delete or return personal data at the end of the service under section 8; and
- make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for audits under section 9.
4. Data subject requests and opt-outs
We will notify the Merchant without undue delay if we receive a request from one of its customers exercising their data protection rights, and we will not respond to it directly except to point the customer to the Merchant, unless the Merchant instructs us otherwise. We honour the deletion and redaction requests that Shopify relays for merchants automatically (the Shopify customer redact, shop redact, and customer data request webhooks). We never override a customer’s opt-out: STOP replies and unsubscribe signals update the consent records we read, and a customer who has opted out is not messaged again through Presterly.
5. Sub-processors
The Merchant gives Presterly general written authorisation to engage the sub-processors listed in Annex 3. We will impose data protection obligations on each sub-processor that are no less protective than this DPA. We will post changes to the list on this page at least 14 days before a new sub-processor starts processing Merchant customer data; the Merchant may object on reasonable data protection grounds within that period, and if we cannot resolve the objection the Merchant may terminate the affected service. Continued use of the service after the notice period is acceptance of the change.
Platforms the Merchant itself connects and contracts with (for example the Merchant’s own Shopify store, Klaviyo account, WhatsApp Business Account, or booking platform) are the Merchant’s own providers, not Presterly sub-processors, even where Presterly operates within them on the Merchant’s behalf.
6. Security
We implement the measures in Annex 2, including encryption of customer phone numbers and platform credentials at rest, TLS in transit, tenant isolation, and least-privilege access. We review these measures regularly and will not materially reduce the overall security of the service during a term.
7. Personal data breach
We will notify the Merchant without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Merchant’s customer data, with the information Article 33(3) GDPR requires (in phases if necessary), and we will reasonably assist the Merchant with its own notification obligations.
8. Deletion and return
When the service ends (including on uninstall of the App), we will, at the Merchant’s choice, delete or return the Merchant’s customer personal data within 30 days, unless the law requires us to keep it longer, and we will tell the Merchant if so. Where we hold consent, opt-out, or suppression records, we may retain them as evidence of compliance for as long as a claim could be brought. Deletion from encrypted backups happens on the backup-rotation cycle.
9. Audit
On request, we will provide the documentation reasonably necessary to demonstrate compliance with this DPA (including summaries of our security measures and sub-processor terms). Where that is not enough, the Merchant (or an independent auditor that is not our competitor) may audit our compliance no more than once in any 12-month period, on at least 30 days’ written notice, during business hours, without disrupting our operations, subject to confidentiality, and at the Merchant’s cost, except where the audit follows a breach we caused or reveals material non-compliance.
10. International transfers
Our primary application infrastructure is hosted in the European Economic Area. Where a sub-processor processes personal data outside the EEA (for example in the United States), the transfer is protected by an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or the European Commission’s Standard Contractual Clauses, which are incorporated by reference into this DPA to the extent a transfer requires them, together with the UK Addendum where UK data protection law applies.
11. Aggregated and anonymised data
Presterly may create and use data that has been aggregated or anonymised so that it no longer identifies any person or Merchant (for example, reorder-interval statistics across product categories) to operate, benchmark, and improve the service. Such data is not personal data and falls outside this DPA.
12. Liability, precedence, law
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Applicable Data Protection Law does not allow that. If this DPA conflicts with the Terms of Service or any other agreement, this DPA prevails on data protection matters. This DPA is governed by the laws of the Republic of Ireland and the courts of the Republic of Ireland have exclusive jurisdiction.
Annex 1: Details of processing
Subject matter and purpose. Processing of the Merchant’s customer personal data to predict reorder timing, trigger and operate reorder, win-back, and retention messages on the Merchant’s behalf, grow the Merchant’s consented marketing lists, attribute resulting orders, and report results to the Merchant.
Nature. Collection (via platform APIs the Merchant authorises, data exports the Merchant provides, and opt-in surfaces operated on the Merchant’s storefront), storage, analysis and prediction, event triggering and message dispatch through the Merchant’s connected platforms or Presterly’s delivery providers, attribution, and reporting.
Duration. The term of the service, plus the deletion window in section 8.
Data subjects. The Merchant’s customers and prospective customers.
Categories of personal data. Identity data (name, email address); contact data (telephone number); order and purchase history (orders, products, quantities, values, dates, discount codes, order attributes including attribution tokens); appointment and purchase records from booking or point-of-sale platforms the Merchant connects; marketing consent and opt-out status per channel; message delivery, open, click, and reply events; storefront opt-in submissions (including phone numbers captured through checkout and post-purchase surfaces); technical data connected with link clicks (IP address, device and browser information, timestamps); and derived data (predicted reorder dates and scores). No special categories of personal data (Article 9 GDPR) are anticipated; the Merchant must not submit any.
Annex 2: Security measures
- Encryption at rest (AES-256-GCM) for platform credentials, API tokens, and customer telephone numbers held as opt-in evidence; encrypted databases and backups.
- Encryption in transit (TLS 1.2 or higher) for all API traffic.
- Tenant isolation: each Merchant’s data and credentials are scoped so one Merchant cannot access another’s data.
- Least-privilege, role-based access for Presterly personnel, limited to those who need it to operate the service, under contractual confidentiality.
- No raw credentials or customer phone numbers written to application logs.
- Kill switches and consent gates in the send pipeline so messages cannot be dispatched to customers without an active consent record for the channel.
- Incident response procedures, with breach notification under section 7.
Annex 3: Sub-processors
Current sub-processors engaged by Presterly:
- Supabase (database hosting for the Presterly backend).
- Railway (application hosting for the Presterly backend, EU region).
- Vercel (hosting and content delivery for presterly.com).
- Resend (transactional email delivery).
- Twilio (SMS and WhatsApp delivery, where messages are sent through Presterly’s own channel rather than the Merchant’s connected platform).
- Meta Platforms Ireland Limited (WhatsApp Business Platform transport, where the Merchant’s WhatsApp Business Account is connected through Presterly).
Shopify, Klaviyo, and any booking or point-of-sale platform the Merchant connects are engaged and contracted by the Merchant directly (see section 5). Updates to this list are posted on this page under section 5. Questions to fergus@presterly.com.