Data Processing Agreement

Gulbrandsen Apps ENK · Version 1.0 · 29 August 2026

Version 1.0, in force. This document describes the service as built. Scheduled for external legal review before public launch.

This agreement applies between the merchant installing WarrantyBridge (the Controller) and Gulbrandsen Apps ENK, organisation number 938 324 484, registered in Norway (the Processor). It takes effect when the app is installed and ends when it is uninstalled and the deletion in clause 8 completes.

1. Subject matter and duration

The Processor processes personal data solely to provide WarrantyBridge: creating warranty records from the Controller's orders, issuing warranty cards to purchasers, and handling warranty claims. Processing lasts for the term of installation plus the retention periods in clause 7.

2. Nature and purpose

Collection, storage, organisation, retrieval, and erasure of purchaser data for the purpose of warranty documentation and claims handling. No other purpose.

3. Categories of data subject and personal data

Data subjects: the Controller's customers who place orders containing physical goods.

Personal data: email address, first name, last name, country code, and order and product details linked to that person. Claim submissions may contain further personal data supplied by the customer in free text or photographs.

Excluded: the Processor does not request or store telephone numbers, street addresses, cities, postal codes, or payment data. No special categories of data under Article 9 are sought.

4. Controller instructions

The Processor acts only on the Controller's documented instructions. This agreement, together with the app's configured settings and the Privacy Policy, constitutes those instructions. The Processor will inform the Controller if an instruction appears to infringe applicable data protection law.

5. Confidentiality

Access to personal data is restricted to the sole operator of Gulbrandsen Apps ENK, who is bound by confidentiality. There are presently no other staff. Should personnel be engaged, they will be bound by written confidentiality obligations before being granted any access.

6. Security measures

The Processor implements the measures described in the Security and Incident Response policy, including encryption in transit and at rest, logging of access to personal data, environment separation, and encrypted backups.

7. Retention and erasure

Personal data is retained on the schedule published in the Privacy Policy, clause 4. In summary: warranty coverage end plus 24 months, or purchase plus a country-specific period where local limitation regimes are longer, with claim-linked records held until at least 24 months after claim closure. Expiry triggers automated anonymisation rather than retention. This schedule is the Processor's default documented instruction; a Controller may request a shorter period.

8. Deletion on termination

When the Controller uninstalls WarrantyBridge, Shopify notifies the Processor. All personal data belonging to that Controller — warranty registrations, customers, claims, claim events, and attachments — is permanently deleted 48 hours after notification. Deletion is irreversible; the Controller should export any data it wishes to keep before uninstalling.

An audit record that access occurred is retained. It contains no personal data.

9. Sub-processors

Sub-processorPurposeLocation
Microsoft Ireland Operations LtdHosting, database, backupsEU — North Europe

The Processor will give the Controller notice before adding a sub-processor, and the Controller may object. A transactional email provider will be added before warranty card emails are enabled.

10. International transfers

Personal data is stored and processed within the European Union. The Processor makes no transfer outside the EEA in the ordinary course of providing the service.

11. Assistance to the Controller

The Processor assists the Controller in responding to data subject requests, and supports data protection impact assessments and consultation with supervisory authorities, taking into account the nature of processing and the information available.

Requests received through Shopify's privacy webhooks are actioned automatically: erasure requests erase the purchaser's identifying data, and access requests compile the records held.

12. Personal data breach

The Processor notifies the Controller without undue delay and in any case within 24 hours of becoming aware of a personal data breach affecting the Controller's data, providing the information the Controller needs to meet its own Article 33 obligation. The procedure is set out in the Security and Incident Response policy.

13. Audit

The Processor makes available the information necessary to demonstrate compliance with Article 28 and allows for audits by the Controller or an auditor it mandates, on reasonable notice and at reasonable frequency.

14. Liability and governing law

This agreement is governed by Norwegian law. Nothing in it limits either party's obligations under the GDPR.