This agreement applies between the merchant installing WarrantyBridge (the Controller) and Gulbrandsen Apps ENK, organisation number 938 324 484, registered in Norway (the Processor). It takes effect when the app is installed and ends when it is uninstalled and the deletion in clause 8 completes.
The Processor processes personal data solely to provide WarrantyBridge: creating warranty records from the Controller's orders, issuing warranty cards to purchasers, and handling warranty claims. Processing lasts for the term of installation plus the retention periods in clause 7.
Collection, storage, organisation, retrieval, and erasure of purchaser data for the purpose of warranty documentation and claims handling. No other purpose.
Data subjects: the Controller's customers who place orders containing physical goods.
Personal data: email address, first name, last name, country code, and order and product details linked to that person. Claim submissions may contain further personal data supplied by the customer in free text or photographs.
Excluded: the Processor does not request or store telephone numbers, street addresses, cities, postal codes, or payment data. No special categories of data under Article 9 are sought.
The Processor acts only on the Controller's documented instructions. This agreement, together with the app's configured settings and the Privacy Policy, constitutes those instructions. The Processor will inform the Controller if an instruction appears to infringe applicable data protection law.
Access to personal data is restricted to the sole operator of Gulbrandsen Apps ENK, who is bound by confidentiality. There are presently no other staff. Should personnel be engaged, they will be bound by written confidentiality obligations before being granted any access.
The Processor implements the measures described in the Security and Incident Response policy, including encryption in transit and at rest, logging of access to personal data, environment separation, and encrypted backups.
Personal data is retained on the schedule published in the Privacy Policy, clause 4. In summary: warranty coverage end plus 24 months, or purchase plus a country-specific period where local limitation regimes are longer, with claim-linked records held until at least 24 months after claim closure. Expiry triggers automated anonymisation rather than retention. This schedule is the Processor's default documented instruction; a Controller may request a shorter period.
When the Controller uninstalls WarrantyBridge, Shopify notifies the Processor. All personal data belonging to that Controller — warranty registrations, customers, claims, claim events, and attachments — is permanently deleted 48 hours after notification. Deletion is irreversible; the Controller should export any data it wishes to keep before uninstalling.
An audit record that access occurred is retained. It contains no personal data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Ireland Operations Ltd | Hosting, database, backups | EU — North Europe |
The Processor will give the Controller notice before adding a sub-processor, and the Controller may object. A transactional email provider will be added before warranty card emails are enabled.
Personal data is stored and processed within the European Union. The Processor makes no transfer outside the EEA in the ordinary course of providing the service.
The Processor assists the Controller in responding to data subject requests, and supports data protection impact assessments and consultation with supervisory authorities, taking into account the nature of processing and the information available.
Requests received through Shopify's privacy webhooks are actioned automatically: erasure requests erase the purchaser's identifying data, and access requests compile the records held.
The Processor notifies the Controller without undue delay and in any case within 24 hours of becoming aware of a personal data breach affecting the Controller's data, providing the information the Controller needs to meet its own Article 33 obligation. The procedure is set out in the Security and Incident Response policy.
The Processor makes available the information necessary to demonstrate compliance with Article 28 and allows for audits by the Controller or an auditor it mandates, on reasonable notice and at reasonable frequency.
This agreement is governed by Norwegian law. Nothing in it limits either party's obligations under the GDPR.