Data Processing Agreement
Last updated: August 16, 2026
This is the convenience English translation. Use the language menu above to view the primary Simplified Chinese version for PRC operations.
1. Scope and incorporation
This Data Processing Agreement (DPA) applies when NINGBO ELIOT INTERNATIONAL TRADE CO., LTD., as the YiTaiCOS provider, processes personal information for a merchant under the YiTaiCOS service agreement, including through the public Shopify connector. It is incorporated into that agreement.
This DPA is designed to allocate entrusted-processing duties under applicable law, including the Personal Information Protection Law of the People’s Republic of China (PIPL), the Data Security Law, the amended Cybersecurity Law effective January 1, 2026, and applicable network-data regulations. It does not replace a transfer mechanism, separate consent, impact assessment, filing, or other form that the law requires separately.
2. Roles and documented instructions
The merchant determines the purposes and methods of processing its personnel, Shopify customer, order, fulfillment, inventory, and campaign data and acts as the personal information processor under the PIPL or controller under other applicable law. YiTaiCOS acts as the entrusted party under PIPL Article 21 or processor for that data.
YiTaiCOS processes personal information only to provide, secure, support, and improve the contracted service in accordance with the agreement, the merchant’s documented settings and instructions, and applicable law. If an instruction appears unlawful or materially unsafe, YiTaiCOS may pause the affected processing and request a lawful clarification.
3. Processing details
- Subject matter: tenant-scoped ERP operations and merchant-authorized Shopify synchronization, including consent-safe CRM and fulfillment workflows.
- Duration: the active service period plus the limited export, privacy-request, deletion, legal-hold, and backup-expiry periods stated in the agreement or deployment schedule.
- Individuals: merchant personnel, Shopify customers and prospects, recipients, suppliers and contacts, and other persons included by the merchant in authorized business records.
- Data: identity and contact information, account and permission data, customer and consent facts, products, inventory, orders, fulfillment, shipping, campaign and delivery events, files, support information, security logs, and related identifiers.
- Sensitive data: not intentionally required by default. The merchant must not provide sensitive personal information unless the feature, legal basis, necessity, separate consent where required, impact assessment, and safeguards have been documented in advance.
4. Merchant duties
The merchant must give lawful, clear instructions; provide required notices; identify a valid PIPL Article 13 or other applicable legal basis; limit data to what is necessary; maintain accurate consent and suppression records; handle individual requests; assess automated decisions; and complete any required personal information protection impact assessment or cross-border mechanism. A generic “legitimate interest” is not an independent PIPL basis.
The merchant must configure roles and connector scopes proportionately and must not use YiTaiCOS for unlawful scraping, purchased contact lists, sensitive profiling, or marketing without a valid legal basis.
The merchant must not provide sensitive personal information or information of a child under 14 unless necessity, specific purpose, separate or guardian consent where required, special processing rules, impact assessment, and enhanced safeguards have been documented.
5. YiTaiCOS duties
- Process personal information only on documented instructions and only for the agreed purposes.
- Bind authorized personnel to confidentiality and least-privilege access obligations.
- Maintain proportionate organizational and technical safeguards and review them as risk and law change.
- Assist the merchant with verified individual, Shopify privacy, regulator, security, impact-assessment, and audit requests to the extent relevant to YiTaiCOS processing.
- Notify the merchant if YiTaiCOS can no longer meet a material processing obligation and cooperate on a safe remediation, suspension, export, return, or deletion path.
- Keep records needed to demonstrate compliance without placing credentials, raw personal information, or provider payloads in general-purpose logs or documentation.
6. Security measures
The service applies server-side tenant and permission enforcement, least-privilege role design, transport encryption, encrypted connector secrets, input validation, anti-forgery and webhook-signature checks where applicable, bounded diagnostics, and audit evidence for sensitive mutations.
Before a deployment is approved for protected customer data, the applicable deployment record must verify database and object-storage protection, backup encryption and retention, restore readiness, production/test separation, monitoring, employee access controls, and the coverage of personal-data access logging. A policy statement does not substitute for that technical evidence.
These deployment gates implement Shopify’s Protected Customer Data requirements for data minimization, purpose limitation, consent and opt-out handling, retention, encryption at rest and in transit, encrypted backups, and separation of test and production data. No party may represent an unverified gate as complete.
7. Security incidents
YiTaiCOS maintains an incident-response procedure covering triage, containment, evidence preservation, eradication, recovery, risk assessment, and corrective action. YiTaiCOS will notify the merchant without undue delay after confirming an incident affecting merchant personal information and will provide available facts needed for the merchant’s legal assessment and notices.
Notifications will not include another tenant’s information or unsupported conclusions. Each party remains responsible for regulator and individual notices assigned to it by law; the parties will coordinate where their duties overlap.
8. Subprocessors
The merchant authorizes the use of subprocessors needed for contracted hosting, database, storage, communications, security, and support only after the deployment-specific provider, purpose, region, and safeguards are documented. YiTaiCOS remains responsible for imposing data-protection duties no less protective than the relevant parts of this DPA.
YiTaiCOS will provide reasonable advance notice of a material new subprocessor where required by the agreement. A substantiated objection will be addressed in good faith through an alternative, affected-feature suspension, or termination path.
9. Cross-border processing
Neither party may initiate a cross-border transfer merely because the connector is technically capable of it. Before a regulated transfer, the parties must document the overseas recipient, contact method, purpose, method, data categories, retention, onward-transfer limits, security measures, and rights channel and complete any applicable separate consent, impact assessment, certification, standard contract, filing, or security assessment.
If the agreed lawful mechanism becomes invalid or unavailable, the affected transfer must be suspended until a valid replacement or lawful localization path is established.
10. Individual and Shopify privacy requests
YiTaiCOS will promptly forward or record a request it receives for merchant-controlled data and will not independently respond beyond confirming receipt unless authorized or legally required. The merchant must provide the verified scope and lawful instruction needed for access, correction, export, restriction, deletion, or explanation.
Shopify customers/data_request, customers/redact, and shop/redact webhooks are signature-verified and their raw bodies are not retained as business records. Bounded request metadata may be retained to prevent duplicates, coordinate fulfillment, and demonstrate compliance. Shopify’s standardized privacy rights apply regardless of where the individual is located.
11. Return, deletion, and retention
On a valid instruction or termination, YiTaiCOS will return, delete, or irreversibly anonymize merchant personal information unless law requires retention. The instruction must preserve records subject to a legal hold, an unresolved transaction, fraud prevention, or a mandatory accounting, tax, employment, consumer, or security period.
Absent a different documented schedule, verified deletion is initiated without undue delay and targeted for completion within 30 days. Isolated backups, where present, remain protected, are not restored to active use except for disaster recovery, and expire according to the verified deployment backup schedule.
12. Compliance information and audit
YiTaiCOS will provide information reasonably necessary to demonstrate compliance. Audits must protect other tenants, credentials, source-code security, and service continuity; use existing reports and remote evidence first; remain proportionate; and be subject to confidentiality. Material deficiencies require a documented remediation owner and due date.
13. Liability, language, precedence, and law
Liability is governed by the main service agreement and mandatory law. If this DPA conflicts with the main agreement on personal information protection, this DPA prevails to the extent of that conflict. Stronger mandatory protections and an executed lawful transfer mechanism remain unaffected.
This DPA is governed by the laws of the People’s Republic of China unless the parties’ signed agreement requires another governing law that may lawfully apply.
The Simplified Chinese version is the primary version for YiTaiCOS operations in the People’s Republic of China. The English version is provided for convenience. If the versions differ, the Chinese version controls to the extent permitted by mandatory law.
14. Privacy contact
DPA notices and privacy requests may be sent to kris@nb-eliot.com.