Effective August 18, 2026 · Version 1.1

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the terms between BroFam and a merchant using a BroFam application. It applies when BroFam processes personal data for that merchant through an application. The merchant is the controller or business and BroFam is the processor or service provider for merchant-directed customer data. BroFam may act as an independent controller where required for its own account administration, security, abuse prevention, legal compliance, and contractual records.

Documented instructions and purpose

BroFam processes merchant-directed personal data only to provide, secure, support, and meter the application the merchant authorized; comply with Shopify, marketplace, privacy, or legal obligations; and follow the merchant’s lawful documented instructions. App-specific purposes and data categories appear in the application’s privacy supplement. BroFam does not sell merchant customer data, share it for cross-context behavioral advertising, or use it to benefit another merchant.

Merchant responsibilities

The merchant is responsible for lawful collection, notices, consent, campaign content, audience choices, instructions, and responding to individuals where the merchant controls the relationship. The merchant must not direct BroFam to process data unlawfully or beyond the application’s documented purpose.

Confidentiality and security

BroFam limits personal-data access to authorized personnel and services with a need to operate or support the application. Controls include tenant isolation, least-privilege authorization, encryption in transit and at rest, credential protection, PII-minimized operational logging, finite retention, Development and Production separation, monitoring, and incident handling. App-specific security information appears in the relevant application supplement.

Subprocessors

The merchant authorizes the subprocessors listed in the applicable application-specific subprocessor notice for their stated purposes. BroFam remains responsible for its processing obligations and will update the notice before a material new subprocessor begins processing merchant personal data when practicable.

Individual rights and merchant assistance

BroFam currently supports Shopify uninstall and redaction workflows and provides verified merchant-support assistance for access requests. An application may not provide self-service export, correction, restriction, or portability workflows unless its privacy supplement says otherwise. The merchant remains responsible for responding to individuals where it controls the relationship. BroFam will reasonably assist with verified requests, security information, and required impact assessments, considering the nature of processing and information available.

Retention, return, and deletion

BroFam retains personal data only for documented service, security, accounting, dispute, or legal needs. App-specific periods and deletion behavior appear in the relevant privacy or retention supplement. At uninstall, termination, verified deletion request, or loss of authority, BroFam deletes or de-identifies data no longer required, subject to limited lawful retention and backup expiry.

Security incidents

BroFam investigates suspected unauthorized access, acquisition, disclosure, alteration, loss, or destruction of merchant personal data under its incident-response process. BroFam will notify affected merchants without undue delay after confirming a reportable incident and provide available information needed for the merchant’s obligations. See Incident response.

International processing and law

BroFam currently hosts application infrastructure in the United States. The parties will use legally required transfer safeguards when applicable. If a binding authority requests personal data, BroFam will limit disclosure and notify the merchant when legally permitted.

Audit and changes

BroFam will provide reasonable evidence of these controls and cooperate with proportionate merchant assessments. This DPA does not claim a third-party certification. Material changes receive a new version and effective date.

Contact

Privacy requests: contact form. Security incidents: contact form.

Change history

Version 1.1 — clarified controller roles, app-specific security and subprocessors, and currently implemented rights workflows on August 18, 2026.

Version 1.0 — initial shared DPA published August 18, 2026.