Data Processing Agreement (DPA)
Last updated: 14 July 2026 · COD Fraud Guard
This Data Processing Agreement ("DPA") forms part of the terms under which SC COVERED SRL, trading as TrackWise ("Processor"), CUI: RO47818139, registered office: Str. Principală nr. 98, Strei, Hunedoara county, Romania, provides the COD Fraud Guard app to the merchant installing it ("Controller"). It applies automatically upon installation of the App and reflects Article 28 GDPR.
1. Subject matter, duration, nature and purpose
- Subject matter: processing of the Controller's customer data required to provide the App's features (COD risk scoring, checkout rules, shipment tracking, SMS order confirmation)
- Duration: from installation until uninstall of the App plus the deletion window described in Section 7
- Nature: collection via Shopify APIs/webhooks, storage, scoring, transmission to sub-processors listed in Section 5
- Purpose: reducing failed cash-on-delivery deliveries for the Controller
2. Categories of data and data subjects
- Data subjects: customers of the Controller's store who place orders
- Data categories: name, phone, email, shipping/billing address, order details, shipment tracking numbers and statuses, derived risk scores and delivery/return history
- No special categories of data (Art. 9 GDPR) are processed
3. Processor obligations
The Processor shall:
- process personal data only on the Controller's documented instructions, which are given by installing and configuring the App
- ensure persons authorised to process the data are bound by confidentiality
- implement the technical and organisational measures in Section 6 (Art. 32 GDPR)
- assist the Controller with data subject requests and with obligations under Articles 32-36 GDPR
- notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably needed for the Controller's own notifications
- delete the Controller's personal data as described in Section 7
- make available information necessary to demonstrate compliance and allow audits as described in Section 8
4. Controller obligations
The Controller warrants it has a lawful basis for the processing, informs its customers about the processing (e.g. in its own privacy policy), and uses the App's features — in particular blocking validations and automatic cancellation — in accordance with applicable law and Shopify's terms.
5. Sub-processors
The Controller authorises the following sub-processors:
- Shopify International Ltd. (platform APIs)
- Railway Corp. (hosting, PostgreSQL database)
- 17TRACK or TrackingMore (shipment tracking — tracking numbers only)
- SMSLink.ro and/or Twilio Inc. (SMS delivery — phone number and message text)
The Processor remains fully liable for its sub-processors and will inform the Controller of intended additions or replacements, giving the Controller the opportunity to object; continued use of the App after notice constitutes acceptance. Where a sub-processor is outside the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
6. Security measures (Art. 32)
- TLS encryption in transit for all connections; database encryption at rest
- Application-level AES-256-GCM encryption for courier credentials
- HMAC-signed, expiring links for customer-facing pages; no login or password storage
- Access to production restricted to the Processor with strong authentication and 2FA
- Separation of test and production environments; versioned, reviewed deployments
7. Deletion and return
Upon uninstall, Shopify issues the shop/redact webhook and the Processor deletes all personal data of the Controller. Individual customer data is deleted upon the customers/redact webhook. The Controller may request earlier deletion or an export of stored data at support@trackwise.studio; requests are fulfilled within 30 days.
8. Audits
The Processor will answer reasonable written audit questionnaires within 30 days, no more than once per year unless a breach has occurred. On-site audits may be agreed where legally required, at the Controller's cost.
9. Governing law
This DPA is governed by the law of Romania, without prejudice to mandatory provisions of the GDPR. Contact: support@trackwise.studio.