Plain-language summaries appear in italics throughout this document. They are provided for convenience only and have no contractual value. Only the numbered paragraphs are legally binding.
This Data Processing Agreement (the “DPA”) forms an integral part of the Hokku Terms of Service and governs how H-MOON Digital (the “Processor”) processes personal data on behalf of the Shopify merchant (the “Controller”, “Merchant”) within the Hokku app.
By installing or using Hokku, the Merchant accepts this DPA. No separate signature is required.
Where this DPA sits. Hokku is distributed through the Shopify App Store. Shopify acts as a separate processor for the Merchant under the Shopify Data Processing Addendum, which covers everything Shopify handles directly. This DPA covers only what H-MOON Digital handles directly within the Hokku app — which is a distinct processing relationship from Shopify’s. Data collected on the marketing site
gethokku.comis covered separately by the Privacy Policy.
1. Roles and scope
The short version: Your store is the data controller. Hokku is the processor working under your instructions.
1.1. The Merchant operates as the Data Controller for personal data relating to the Merchant’s customers, prospects, staff and store-level activity, including data that flows into Hokku through the Shopify storefront and admin.
1.2. H-MOON Digital operates as the Data Processor for personal data the Merchant submits to or generates through Hokku, processing it only on the Controller’s documented instructions, as embodied in the Terms of Service, this DPA and the Hokku user interface.
1.3. Scope. This DPA applies to processing performed by H-MOON Digital inside the Hokku app and its supporting infrastructure. It does not apply to (a) processing performed by Shopify under the Shopify DPA, (b) processing performed on the marketing website gethokku.com, or (c) processing performed by the Merchant outside Hokku.
2. Categories of personal data and data subjects
The short version: The minimum needed to make Hokku work for your store. No advertising data. No tracking beyond what’s required.
2.1. Categories of data subjects.
-
The Merchant’s customers and prospects (end-users of the Merchant’s storefront).
-
The Merchant’s staff and collaborators with access to the Hokku admin.
-
The Merchant itself, where the Merchant is an individual sole trader.
2.2. Categories of personal data processed inside Hokku.
-
Customer-side (Merchant storefront): pseudonymous identifiers (Shopify cart token), product references viewed or added to cart, page URL where a Hokku widget is displayed. No customer-identifying field is processed — no name, no email address, no phone number, no billing or shipping address, and no customer ID. No third-party tracking, no advertising identifiers, no behavioral profiling.
-
Order-side (post-purchase): order ID, creation date, currency, order total, total discounts, total tax, test flag and origin channel; for each line item: line item ID, product ID, variant ID, quantity and price; shipping lines — their price only, to detect free shipping; applied discount codes and their values. Used to attribute revenue lift to specific Hokku offers (advanced analytics — Starter plan and up) and to count the monthly order volume that determines the subscription tier. No carrier, delivery address or delivery time is read.
-
Merchant-side (admin): Shopify store URL, shop owner email, Hokku admin user IDs, IP address and user agent for security logs.
2.3. Categories of data explicitly NOT processed.
-
Customer names, email addresses, phone numbers, billing addresses and shipping addresses — never; Hokku’s queries to the Shopify Admin API do not select the customer object, and order webhooks are parsed without reading any customer-identifying field.
-
Payment card data — never (Shopify Billing handles all payment processing for Hokku Subscription Fees).
-
Customer passwords or credentials — never.
-
Health data, biometric data, religious, political or sexual-orientation data — never; if such data is inadvertently submitted by a Merchant through Hokku custom fields, the Merchant is solely responsible.
2.4. Measurement on the Merchant’s storefront.
Hokku stores a technical identifier in the browser of the Merchant’s visitors, in order to count offer views and clicks without counting the same visitor twice, and to link a sale to the offer that triggered it. That identifier is specific to the Merchant’s shop, contains no personal data (no name, no email address, no IP address), and is renewed after thirteen (13) months.
On the raw view and click records, the visitor identifier is erased after twenty-four (24) hours by a daily job — its functional lifetime is thirty minutes.
What is kept on conversion records is the order ID, by necessity: it is the key through which H-MOON Digital honours a customers/redact request. Data that has to remain deletable on request cannot be anonymised.
3. Purposes of processing and lawful basis
The short version: We process data only to make Hokku work, support you, and improve the service. Your basis under GDPR is “performance of contract”.
3.1. Purposes. H-MOON Digital processes personal data inside Hokku exclusively to:
-
(a) display Hokku offers (bundles, upsells, cross-sells, etc.) on the Merchant’s storefront and admin;
-
(b) attribute revenue lift to Hokku offers for reporting in the Merchant’s dashboard;
-
(c) count the Merchant’s monthly order volume, which determines the applicable Hokku subscription tier;
-
(d) provide customer support to the Merchant when requested;
-
(e) maintain the security and integrity of the Service (rate limiting, abuse detection, audit logging);
-
(f) improve the Service (aggregated, non-identifying usage metrics; A/B testing of UI changes);
-
(g) comply with legal obligations (tax invoicing via Shopify, GDPR webhook responses, court orders).
3.2. Lawful basis. The Controller is responsible for establishing a lawful basis under Article 6 GDPR for the underlying processing of its customers’ data. H-MOON Digital, as Processor, processes data on the Controller’s documented instructions, primarily on the basis of “performance of contract” (Article 6.1.b) between the Controller and H-MOON Digital, and “legitimate interests” (Article 6.1.f) for security logging.
4. Sub-processors
The short version: A short list of EU-first providers. We’ll tell you 30 days before adding a new one.
4.1. Authorised sub-processors as of 27 June 2026.
| Sub-processor | Service | Region | Transfer mechanism |
|---|---|---|---|
| Supabase | Application database for Hokku offer configurations and metadata | Frankfurt (Germany), EU | None required (intra-EU) |
| Sentry | Error monitoring (back-end and admin UI) | EU region (Frankfurt) | None required (intra-EU) |
| Resend | Transactional email (account, billing notifications, support) | Multi-region | Standard Contractual Clauses 2021 where applicable |
| Vercel | Compute and edge delivery for the Hokku admin and widget assets | Compute in Frankfurt, EU; static assets served from Vercel’s global edge network. No personal data stored at rest (stateless) | Certified under the EU-US Data Privacy Framework (Decision (EU) 2023/1795) — relied on because Vercel Inc. is incorporated in the United States and may access the data, not because the data is hosted there |
| Anthropic | AI support assistant (Hokku Assistant) — chat conversation content, when the feature is enabled | United States | Anthropic Data Processing Addendum incorporating the EU Standard Contractual Clauses 2021 |
| Shopify International Limited | Authentication (OAuth), storefront API integration, GDPR webhook delivery | Ireland (EU) for EU/UK merchants; per-region for others | Covered by Shopify DPA for Shopify-handled data |
4.2. The up-to-date Sub-processors List is also published at gethokku.com/sub-processors.
4.3. Notice of new sub-processors. H-MOON Digital will notify Merchants by email and via update to /sub-processors at least thirty (30) days before adding a new sub-processor that materially affects the processing of personal data. The Merchant may object to the addition in writing within that 30-day period. If H-MOON Digital and the Merchant cannot agree on an alternative, the Merchant’s exclusive remedy is to terminate the Hokku subscription before the new sub-processor begins processing.
4.4. Sub-processor obligations. Each sub-processor is bound by data-protection obligations no less protective than those of this DPA.
4.5. AI assistant. When the Merchant enables the optional Hokku Assistant — an in-app AI support chat (see Terms §14) — conversation content (the Merchant’s messages and the generated responses) is processed by Anthropic solely to produce answers. This content is retained for thirty (30) days and then deleted. The Merchant is asked not to submit sensitive data through the Assistant.
5. International transfers
The short version: We default to EU infrastructure. When data leaves the EU, it’s covered by standard EU-recognized legal mechanisms.
5.1. Personal data processed by H-MOON Digital is stored primarily in the European Union (Supabase Frankfurt for application data; Sentry EU for error monitoring).
5.2. Where transfer outside the European Economic Area (EEA) is necessary (Vercel, incorporated in the United States — its access to the data is a transfer even though the Hokku admin runs on EU compute in Frankfurt; Resend multi-region for email delivery; Anthropic US for the optional AI assistant), H-MOON Digital relies on:
-
(a) the EU-US Data Privacy Framework (Decision (EU) 2023/1795) for transfers to certified US recipients (Vercel);
-
(b) the Standard Contractual Clauses 2021 (Decision (EU) 2021/914) where the Data Privacy Framework does not apply (Resend, Anthropic).
5.3. The Merchant agrees that H-MOON Digital may sign Standard Contractual Clauses with sub-processors on the Merchant’s behalf to the extent necessary to perform the Service.
6. Shopify-mandated GDPR webhooks
The short version: When a customer or shop asks Shopify to delete their data, Shopify forwards the request to us. We act on it immediately, not at the end of the window we are given.
6.1. As required by Shopify’s GDPR webhook obligations, H-MOON Digital implements the three mandatory GDPR webhooks and processes each within the following timeline:
| Webhook | Triggered when | Action taken by H-MOON Digital |
|---|---|---|
customers/data_request | A Merchant’s customer requests their data | Within 30 days, H-MOON Digital sends to the Merchant (via the email associated with the Hokku admin) a structured export of all personal data H-MOON Digital holds for that customer within Hokku. The Merchant forwards the export to the customer. |
customers/redact | 10 days after a Merchant deletes a customer in Shopify | On receipt, H-MOON Digital deletes that customer’s pseudonymous identifiers and the order-linked records associated with them from active Hokku systems. Shopify allows 30 days; H-MOON Digital does not use that window. Backup cycles are covered in §11.4. |
shop/redact | 48 hours after a Merchant uninstalls Hokku | On receipt, H-MOON Digital erases the personal data held for that shop from active Hokku systems — access tokens, support tickets and Hokku Assistant conversations — and anonymises the order identifiers retained in analytics records, with no additional delay. Shopify allows 30 days; H-MOON Digital does not use that window. Offer configurations and aggregated analytics are kept for the recovery window set out in §11.3, then purged. Backup cycles are covered in §11.4. |
6.2. Webhook receipts are logged for audit purposes. The Merchant may request a record of webhook actions affecting its shop by emailing hello@gethokku.com.
7. Security measures
The short version: Encryption, access control, audit logs. Standard things, done seriously.
7.1. H-MOON Digital implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
-
Encryption in transit — TLS 1.3 for all Hokku traffic.
-
Encryption at rest — AES-256 on the Supabase Frankfurt database and on all backup copies.
-
Access control — least-privilege access to production data, restricted to H-MOON Digital staff and contractors bound by confidentiality, with multi-factor authentication mandatory.
-
Audit logging — all administrative actions on production data are logged with actor, timestamp and target, retained for twelve (12) months.
-
Vulnerability management — automated dependency scanning (OSV-Scanner) and security patches applied within reasonable timeframes after disclosure.
-
Network isolation — production systems are isolated from development and staging environments.
7.2. The list of technical and organisational measures may evolve over time; the current version is reflected in this DPA, kept aligned with industry standards.
8. Personal data breach notification
The short version: If something goes wrong with your data, we tell you within 24 hours.
8.1. H-MOON Digital will notify the affected Merchant by email within twenty-four (24) hours of becoming aware of a personal data breach affecting the Merchant’s data, with the information required by Article 33.3 GDPR (nature of the breach, categories and approximate number of data subjects concerned, likely consequences, measures taken or proposed to address the breach).
8.2. The 24-hour notification commitment exceeds the 72-hour minimum imposed by GDPR Article 33 and aligns with the obligation of Shopify Partner Program Agreement § 9.14.2(vi).
8.3. The Merchant remains solely responsible for any notification owed to data subjects or supervisory authorities under Articles 33 and 34 GDPR; H-MOON Digital will provide reasonable cooperation, at the Merchant’s request and reasonable expense.
9. Assistance with data-subject rights
The short version: When your customers exercise their GDPR rights, we help you respond.
9.1. H-MOON Digital, taking into account the nature of the processing, assists the Merchant by appropriate technical and organisational measures, insofar as possible, in fulfilling the Merchant’s obligation to respond to requests for exercising the data subject’s rights under Articles 12-23 GDPR (access, rectification, erasure, restriction, portability, objection, automated decision-making).
9.2. Requests received directly by H-MOON Digital that relate to the Merchant’s data subjects will be forwarded to the Merchant without undue delay.
10. Audit rights
The short version: You can ask us about our security and data practices. We answer in good faith.
10.1. H-MOON Digital will, on the Merchant’s reasonable written request and no more than once per twelve-month period (except in case of a documented incident), make available to the Merchant all information necessary to demonstrate compliance with this DPA, including a written summary of its security measures, the list of sub-processors and the position regarding the SCCs and the EU-US DPF.
10.2. For Merchants with a substantiated, specific concern, H-MOON Digital will respond to a documented audit questionnaire within thirty (30) days. On-site audits are not offered for self-serve plans; for enterprise engagements, audit arrangements may be agreed separately in writing.
11. Return and deletion of data on termination
The short version: Your data lives for as long as you use Hokku — except your exchanges with our support team and with Hokku Assistant, which erase themselves on their own schedule, without waiting for an uninstall. When you uninstall, we erase everything that identifies a person straight away, and we keep your own offers and analytics for 60 days in case you come back — then we delete them too.
11.1. While the app is installed. H-MOON Digital retains Merchant Data for as long as the Merchant uses Hokku, because the Merchant’s own analytics — including all-time figures — are built from it.
Exchanges with our support team and with Hokku Assistant have their own retention periods, even while the app is installed: H-MOON Digital deletes each support ticket twelve (12) months after it was sent and erases the reply email address it contains after ninety (90) days; the same ninety (90) day rule applies to messages received at support@gethokku.com. Hokku Assistant conversations are deleted after thirty (30) days. The Merchant may also request immediate deletion of their data at any time from Settings, which includes their support tickets and Assistant conversations.
11.2. After uninstall — what is erased at once. Shopify notifies H-MOON Digital through the shop/redact webhook 48 hours after a Merchant uninstalls Hokku. On receipt, H-MOON Digital erases from active Hokku systems the data that identifies a person — access tokens, support tickets and Hokku Assistant conversations — and anonymises the order identifiers retained in analytics records, with no additional delay. No buyer personal data is retained beyond this point.
11.3. After uninstall — what is kept, and for how long. The Merchant’s own configuration (offers and settings) and aggregated analytics are retained in active systems for sixty (60) days from uninstall, so that a Merchant who reinstalls within that window recovers their work. Offer delivery stops at uninstall in every case. At the end of that period an automated purge deletes this data permanently; the same purge applies should the shop/redact webhook never be delivered.
11.4. Backups. Encrypted backups held by our hosting provider are purged in line with rolling backup cycles, with full purge completed within an additional thirty (30) days; data deleted under §11.2 or §11.3 disappears from them at the same term.
11.5. On written request at any time while the app is installed, H-MOON Digital will provide a structured export of Merchant Data in a commonly used machine-readable format. Because the Merchant’s access ends at uninstall and the retained data is deleted sixty (60) days later, the Merchant should request any export before uninstalling.
11.6. H-MOON Digital may retain data after termination only to the extent required by applicable law (e.g. accounting records, tax obligations), in which case retention is limited to the minimum legal duration and the data is segregated from active processing.
12. Term and survival
The short version: This DPA runs as long as your Hokku subscription. The data obligations survive after.
12.1. This DPA enters into force on first installation of Hokku and remains in force for as long as H-MOON Digital processes personal data on behalf of the Merchant.
12.2. Sections 5 (Transfers), 7 (Security), 8 (Breach notification), 10 (Audit), 11 (Return and deletion) and 13 (Miscellaneous) survive termination to the extent necessary to perform the deletion and any cooperation obligations.
13. Miscellaneous
13.1. Governing law and jurisdiction. This DPA is governed by the same law and subject to the same jurisdiction as the Terms of Service (French law, exclusive jurisdiction of the courts of Paris — see Terms §12).
13.2. Order of precedence. In case of conflict between this DPA and the Terms of Service regarding personal data processing, this DPA prevails.
13.3. Translations. This DPA is published in English (canonical) with courtesy translations into other languages. In case of substantive discrepancy between the English version and a translation, the English version available at gethokku.com/dpa prevails. Exception — where a translation includes clauses or clarifications required by mandatory local law in the jurisdiction of the translation (for example, references to local data-protection authorities or formal-notice formats), those locally-mandated provisions apply within that jurisdiction and do not constitute a “discrepancy” within the meaning of this clause. Available languages are listed at the foot of this document.
13.4. Modifications. Material modifications to this DPA are notified to Merchants under the same conditions as modifications to the Terms (see Terms §11).
13.5. Contact. Data-protection queries, sub-processor objections, data-subject requests, audit requests and breach inquiries: hello@gethokku.com. Subject line [DPA] is appreciated for routing.
Last updated: 5 August 2026.