GetPPWR

Data processing agreement

The Article 28 GDPR terms under which Påster processes order data on a merchant's behalf. Accepted by installing the app; no signature required.

Last updated 2 September 2026

Parties and scope

This agreement is between the merchant (the controller) and Påster, business ID 2205201-2, Betaniankatu 12, 20810 Turku, Finland (the processor). It applies to all personal data we process on the merchant's behalf through GetPPWR, and it forms part of our terms of service.

It is accepted when the merchant installs the app. No separate signature is required, and the merchant may keep this page as their copy.

Subject matter, duration, nature and purpose

Subject matter: the calculation of statutory EU packaging reports from the merchant's fulfilled orders.

Duration: for as long as the app is installed, plus the retention period described below.

Nature and purpose: reading fulfilled order records from Shopify, storing them, and aggregating them into packaging weights per material, per destination country, per reporting period, so that the merchant can meet their EPR obligations.

Types of personal data

We process only the following, per fulfilled order:

  • The Shopify order ID and fulfilment ID
  • The date the order was fulfilled
  • The destination country code of the shipment (country only — no street address, city or postcode)
  • The product ID, quantity and unit weight of each fulfilled line

Categories of data subjects

The merchant's customers, indirectly: an order record can be linked back to a person through Shopify, even though we hold no name, contact detail or address. The merchant's own staff, in respect of the Shopify user account that installs and operates the app.

Our obligations as processor

We process personal data only on the merchant's documented instructions, which for this service are given by installing and configuring the app. We do not process it for any other purpose.

We ensure that people authorised to process the data are bound by confidentiality. We implement appropriate technical and organisational measures, including encryption in transit and at rest and restricted production access.

We assist the merchant, so far as the data we hold allows, with requests from data subjects and with data protection impact assessments and breach notifications. We will notify the merchant without undue delay after becoming aware of a personal data breach affecting their data.

Sub-processors

The merchant gives general authorisation for the following sub-processors. We will update this page before adding or replacing one, and a merchant who objects may uninstall the app.

  • Railway Corp. (United States) — hosting of the application server
  • Supabase Inc. (United States) — hosting of the PostgreSQL database, in the EU region configured for this app
  • Shopify Inc. (Canada) — the source of the order data, and the platform the app runs inside

International transfers

The database is hosted in the European Union. All three sub-processors are established outside the EU, so transfers to them rely on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism under Chapter V GDPR.

Return and deletion

Fulfilled-order records are kept for the current reporting year and the five preceding years, and are deleted automatically once older than that. Records of orders fulfilled before 2021-01-01 are no longer held. All records for a shop are deleted when the app is uninstalled, regardless of age.

Uninstalling the app deletes all of that store's data, overriding the 6-year period. Shopify's shop redaction webhook is implemented and triggers the same deletion.

Audits

We will make available to the merchant the information necessary to demonstrate compliance with Article 28 GDPR, and will contribute to audits conducted by the merchant or an auditor they appoint, on reasonable notice and no more than once a year unless a supervisory authority requires otherwise.

Contact

Data protection enquiries under this agreement: hello@getppwr.com.