DPA

Samita Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the Terms of Service or other written or electronic agreement between the merchant using Samita applications (“Merchant”, “Customer”, “Controller”, or “you”) and PowerfulForm Technology Company Limited, a company incorporated in Vietnam with its registered address at 19 Tuyen, Soc Son, Hanoi, Vietnam (“Samita”, “Processor”, “we”, “us”, or “our”).

This DPA applies to all Samita applications and services, including but not limited to the Shopify applications published under the Samita brand (the “Services”), such as:

  • SA Request a Quote, Hide Price
  • Sami B2B Lock, Password Protect
  • Sami B2B Wholesale Pricing
  • Sami Bulk Price Editor
  • Sami AI Product Labels & Badge
  • Countdown Timer Bar Samita
  • Sami Order Limits Quantity

The Services are published under the Samita and SamiSales by Samita developer accounts on the Shopify App Store. This DPA applies to each of them, and also to any new application later released by Samita, unless that application is accompanied by its own separate data processing terms.

By installing, accessing, or using the Services, Merchant agrees to this DPA in respect of any Personal Data that Samita processes on Merchant’s behalf.

1. Definitions

Applicable Data Protection Laws means all privacy and data protection laws that apply to the processing of Personal Data under this DPA, including, where relevant, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, and applicable US state privacy laws.

Controller means the party that decides the purposes and means of processing Personal Data.

Processor means the party that processes Personal Data on behalf of the Controller.

Personal Data means any information relating to an identified or identifiable natural person that Samita processes on Merchant’s behalf through the Services.

Sub-processor means any third party engaged by Samita to process Personal Data on Merchant’s behalf in connection with the Services.

2. Roles of the Parties

In respect of Personal Data processed through the Services on Merchant’s behalf:

  • Merchant acts as the Controller;
  • Samita acts as the Processor;
  • Samita processes Personal Data only on Merchant’s documented instructions, which include Merchant’s configuration and everyday use of the Services, except where processing is required by applicable law.

Merchant remains responsible for having a lawful basis to collect and process Personal Data through its Shopify store, and for giving its customers all privacy notices required by law.

3. Subject Matter and Duration of Processing

The subject matter of the processing is the supply, operation, maintenance, support, and improvement of the Services.

Processing continues for as long as Merchant uses the Services, plus any further retention period set out in this DPA or required by applicable law.

4. Nature and Purpose of Processing

Samita processes Personal Data as needed to deliver the Services to Merchant, including in order to:

  • run app functionality inside Merchant’s Shopify store and storefront;
  • receive, store, and manage quote requests, wholesale registration forms, and other forms submitted by visitors or customers;
  • identify which customers, customer tags, customer groups, or company records qualify for wholesale pricing, volume discounts, tax exemption, net payment terms, or restricted access;
  • apply pricing rules, discounts, shipping rules, order limits, or additional fees to carts, draft orders, and orders;
  • control access to locked pages, products, collections, or prices, including through passcodes, customer login status, or email-based access lists;
  • convert approved quotes or registrations into draft orders or customer accounts where Merchant has enabled that feature;
  • apply, schedule, and automatically revert bulk price or compare-at-price changes across Merchant’s catalogue, and keep a record of the original values so that changes can be rolled back;
  • display product labels, badges, banners, and countdown timers on the storefront according to the conditions Merchant sets, which may include customer tags, customer login status, market, or location;
  • enforce minimum and maximum order quantities or cart value limits by product, variant, collection, customer tag, or customer group;
  • store files or attachments uploaded through supported form features (for example business licences, tax certificates, or artwork);
  • send transactional or service emails triggered by the apps, such as quote replies, registration approvals, or access notifications;
  • provide technical support, troubleshooting, debugging, and customer service;
  • maintain security, prevent abuse, and monitor performance of the Services.

Samita does not sell Personal Data processed on Merchant’s behalf and does not use it for its own marketing purposes.

5. Categories of Personal Data

Depending on which Samita app Merchant uses and how Merchant configures it, the Personal Data processed may include:

  • merchant account details, such as store owner name, email address, Shopify store domain, and contact information;
  • store information, such as shop domain, shop ID, products, variants, collections, price rules, markets, locales, and app settings;
  • customer details, such as name, email address, phone number, company or business name, billing and shipping address, tax or VAT identifiers, customer tags, and Shopify customer or company identifiers;
  • quote requests and B2B registration submissions, including requested products, quantities, target prices, and any message or custom field completed by the person submitting the form;
  • cart, checkout, draft order, and order information, including line items and applied discounts;
  • access-control data, such as passcodes entered, allowed email addresses or domains, and records of granted or denied access;
  • files or documents uploaded through app forms;
  • storefront display and campaign data, such as label, badge, banner, timer, and order-limit rules, the pricing campaigns scheduled by Merchant with their original and revised price values, and the conditions under which each rule is shown or enforced;
  • limited storefront session data used to render app elements correctly, such as a countdown timer state stored in the visitor’s browser or an anonymous session identifier;
  • technical data, such as IP address, browser and device information, application logs, and error reports;
  • support correspondence between Merchant and Samita.

Samita does not intentionally process payment card data. Payments are handled by Shopify or by the payment providers Merchant selects.

6. Categories of Data Subjects

  • Merchant and Merchant’s staff or representatives;
  • Merchant’s retail and wholesale customers, and prospective B2B buyers;
  • visitors who submit a quote request, registration form, or passcode through Merchant’s store;
  • storefront visitors who view pages where app elements such as labels, badges, timers, or hidden prices are displayed;
  • individuals who contact Samita support on Merchant’s behalf.

7. Processor Obligations

Samita will:

  • process Personal Data only on Merchant’s documented instructions;
  • ensure that personnel authorised to process Personal Data are bound by confidentiality obligations;
  • put in place appropriate technical and organisational measures to protect Personal Data;
  • assist Merchant, so far as is reasonably possible and taking into account the nature of the processing, in responding to data subject requests;
  • assist Merchant with security, breach notification, and data protection compliance duties required by Applicable Data Protection Laws;
  • make available the information reasonably needed to demonstrate compliance with this DPA;
  • tell Merchant if, in Samita’s view, an instruction would breach Applicable Data Protection Laws.

8. Merchant Obligations

Merchant will:

  • comply with Applicable Data Protection Laws when using the Services;
  • give appropriate privacy notices to data subjects;
  • obtain any necessary consent, or otherwise establish a valid legal basis for the processing;
  • ensure that Personal Data submitted to the Services is lawful, accurate, and relevant;
  • configure the Services, including form fields and access rules, in a way consistent with Merchant’s own privacy obligations, and avoid collecting special category data through app forms unless Merchant has a valid basis for doing so;
  • handle data subject requests itself, except where Samita’s assistance is genuinely required.

9. Sub-processors

Merchant gives Samita general authorisation to engage Sub-processors in order to provide the Services. Samita will bind each Sub-processor by written terms offering an appropriate level of protection for Personal Data.

Entity Type of Service Location
Amazon Web Services Inc. Email communication and infrastructure provider Canada
Crisp IM Support ticket management France
DigitalOcean Cloud hosting and infrastructure provider United States of America

Samita may update this list from time to time. Where Applicable Data Protection Laws require it, Samita will give notice of material changes to its Sub-processors and allow Merchant to object on reasonable data protection grounds.

10. International Data Transfers

Samita is established in Vietnam and relies on infrastructure and service providers that may process Personal Data outside the European Economic Area (“EEA”), including in the United States and other jurisdictions.

Where Personal Data subject to the GDPR is transferred outside the EEA to a country not recognised as providing an adequate level of protection, Samita will rely on appropriate safeguards, which may include the EU Standard Contractual Clauses (“SCCs”).

For transfers from Merchant as Controller to Samita as Processor, Module Two (Controller to Processor) of the SCCs will normally apply, unless another module better reflects the parties’ actual roles.

11. Security Measures

Samita maintains technical and organisational measures designed to protect Personal Data against unauthorised access, loss, misuse, alteration, or disclosure. These may include:

  • HTTPS/TLS encryption in transit;
  • access controls restricting data access to authorised personnel on a least-privilege basis;
  • confidentiality commitments for personnel with access to Personal Data;
  • hashing or equivalent protection of passcodes used by access-control features;
  • regular backups and tested restore procedures;
  • infrastructure monitoring, logging, and security controls;
  • hosting with reputable cloud infrastructure providers;
  • documented internal procedures for handling security incidents.

Merchant acknowledges that no system can guarantee absolute security, but Samita will keep in place commercially reasonable safeguards appropriate to the nature of the Services and the data processed.

12. Personal Data Breach

Samita will notify Merchant without undue delay and, where feasible, within 72 hours of becoming aware of a confirmed Personal Data Breach affecting Personal Data processed on Merchant’s behalf.

The notice will include the information reasonably available to Samita that Merchant needs in order to assess the incident and meet its own notification duties, including where known:

  • the nature of the breach;
  • the categories and approximate number of affected data subjects;
  • the categories and approximate number of affected records;
  • the likely consequences;
  • the measures taken or proposed in response.

13. Data Subject Requests

If Samita receives a request from a data subject concerning Personal Data processed on Merchant’s behalf, Samita will, where reasonably possible, refer that person to Merchant or notify Merchant, unless prohibited from doing so by law.

Samita will give Merchant reasonable assistance in responding to requests to access, correct, delete, restrict, or export Personal Data, taking into account the nature of the Services and the information available to Samita. Samita also supports the mandatory Shopify GDPR webhooks for customer data requests, customer redaction, and shop redaction.

14. Data Retention and Deletion

Samita keeps Personal Data only for as long as needed to provide the Services, comply with legal obligations, resolve disputes, maintain security, and enforce agreements.

Unless applicable law requires otherwise or Merchant agrees otherwise:

  • app data, including quote requests, registration submissions, pricing rules, and lock settings, is deleted or anonymised within 30 days after Merchant uninstalls the relevant app or submits a verified deletion request;
  • backups are kept for up to 30 days and then removed through normal backup rotation;
  • uploaded files are retained according to Merchant’s app plan and configuration, and are deleted after uninstall or a verified deletion request in line with this section;
  • security and application logs are generally kept for up to 90 days, unless a longer period is needed for security, fraud prevention, debugging, or legal compliance.

After termination, Merchant may request deletion or return of Personal Data by contacting contact@samita.io.

15. Audit and Compliance

On reasonable written request, Samita will provide Merchant with the information needed to demonstrate compliance with this DPA.

Any audit or inspection must be carried out in a way that does not compromise the security, confidentiality, or availability of Samita’s systems or other customers’ data. Samita may satisfy an audit request by supplying relevant documentation, security summaries, or written answers.

16. Confidentiality

Samita will ensure that personnel authorised to process Personal Data are bound by confidentiality commitments or an appropriate statutory duty of confidence.

17. Return or Deletion of Personal Data

At Merchant’s choice, and subject to what the Services technically allow, Samita will delete or return Personal Data after the Services end, unless applicable law requires continued storage.

Deletion requests may be sent to contact@samita.io.

18. Changes to this DPA

Samita may update this DPA from time to time to reflect changes to the Services, legal requirements, or operational practices. The updated version will be published on Samita’s website. Material changes take effect no earlier than the date stated in the updated DPA, unless the law requires an earlier date.

19. Governing Law

This DPA is governed by the laws of Vietnam, unless Applicable Data Protection Laws require otherwise. Where the EU Standard Contractual Clauses apply, the governing law and jurisdiction provisions of those clauses will apply to them.

20. Contact

For any privacy, data protection, or DPA-related question, please contact:

PowerfulForm Technology Company Limited
19 Tuyen, Soc Son, Hanoi, Vietnam
Email: contact@samita.io

Last updated: 15 August 2026