Skip to content
Legal

Data Processing Agreement

Last updated 3 October 2026

This is version 1.0 of the Data Processing Agreement ("DPA") that merchants accept in Fabrik Analytics when they turn on tracking. It forms part of our Terms of service. Our Privacy policy describes the same processing for the people whose data it is.

1. The parties and their roles

  • The merchant, the business that uses Fabrik Analytics for its store. The merchant is the controller of its customers' and storefront visitors' personal data.
  • Fabrik, meaning JMW Digital MENA LLC, SHAMS Media City, Al Messaned, Al Bataeh, Sharjah, United Arab Emirates, which provides Fabrik Analytics. Fabrik is the merchant's processor. Our UK affiliate, JMW Digital Marketing Ltd, is the contact for UK data protection matters.

2. What Fabrik processes, and why

The details are in Annex 1. Fabrik processes the merchant's customers' personal data only to provide the analytics the merchant has asked for: dashboards, reports, alerts and attribution. Fabrik does not sell it, share it for advertising, or use it for any other purpose.

3. Fabrik's obligations

Fabrik will:

  1. Act on instructions. Process personal data only on the merchant's documented instructions, which are this DPA, the Terms of service and the merchant's use of the app's settings, unless the law requires otherwise, in which case Fabrik tells the merchant first unless the law forbids it. Fabrik tells the merchant if it thinks an instruction breaks data protection law.
  2. Keep it confidential. Everyone Fabrik authorises to process the data is bound to confidentiality.
  3. Keep it secure. Apply the measures in Annex 3, and keep them under review.
  4. Use sub-processors only as allowed. The merchant authorises the sub-processors in Annex 2. Fabrik gives the merchant at least 30 days' notice of a new sub-processor, by email or in the app, during which the merchant may object on reasonable data protection grounds; if we cannot resolve the objection, the merchant may end the affected service and receive a refund of fees paid for the time after it ends. Fabrik imposes the same data protection obligations on each sub-processor by written contract and remains responsible for them.
  5. Help with data subjects' rights. Act on the access and deletion requests Shopify sends through its privacy webhooks (customers/data_request, customers/redact, shop/redact), and on erasure the merchant starts from the app's settings, and otherwise help the merchant answer requests from its customers.
  6. Report breaches. Tell the merchant of a personal data breach affecting its data without undue delay, and in any event within 72 hours of becoming aware of it, with what is known at the time and updates as more is learned, so the merchant can meet its own duties to its regulator and its customers.
  7. Help with assessments. Give the merchant the information it reasonably needs for a data protection impact assessment, prior consultation or a regulator's enquiry.
  8. Delete at the end. When the merchant uninstalls the app, Fabrik stops collecting at once and deletes the store's shoppers' personal data and order-level data when Shopify sends shop/redact, 48 hours after the uninstall. Klaviyo data is deleted 30 days after Klaviyo is disconnected. Figures that identify no one may be kept, and the law may require Fabrik to keep some records longer.
  9. Show compliance. Make available the information needed to show it meets this DPA. Audits are carried out by written questionnaire: Fabrik answers a reasonable security and data protection questionnaire from the merchant, no more than once a year unless a breach has occurred or a regulator requires it. Where a regulator requires more, or the questionnaire does not reasonably show compliance, Fabrik will allow an inspection by the merchant or an independent auditor it appoints, on reasonable notice, at the merchant's cost, under confidentiality.

4. The merchant's obligations

The merchant confirms it has a lawful basis for the personal data it has Fabrik process, including the shopper consent its store collects before Fabrik's pixel runs, and that its own privacy notice tells its customers about this processing.

5. International transfers

The merchant's data is stored and processed in the European Union (Ireland, Supabase in AWS eu-west-1). Fabrik is established in the United Arab Emirates and its team works from the UAE and the United Kingdom, and some sub-processors are in the United States, so personal data may be accessed from or transferred to countries outside the UK and the EEA.

Where personal data from the EU or the EEA is transferred to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), module two (controller to processor) between the merchant and Fabrik, and module three (processor to processor) between Fabrik and its sub-processors, or the EU-US Data Privacy Framework where a sub-processor is certified. Where personal data from the UK is transferred, the parties rely on the UK's International Data Transfer Agreement or the International Data Transfer Addendum to those clauses, or the UK extension to the Data Privacy Framework. These are incorporated into this DPA by reference. For the clauses: the optional docking clause applies; the general written authorisation option applies to sub-processors, with the notice period in section 3; the governing law and courts are those of Ireland for the EU clauses, and of England and Wales for the UK addendum.

6. Liability and precedence

Liability under this DPA is subject to the limits in the Terms of service, except where the law does not allow it to be limited. If this DPA conflicts with the Terms of service on the processing of personal data, this DPA prevails; if the Standard Contractual Clauses conflict with this DPA, the clauses prevail.

7. Changes

Fabrik may update this DPA to reflect changes in the law or in its sub-processors, with 30 days' notice. The app records when the merchant accepted the DPA and which version.

Annex 1. Details of the processing

  • Data subjects: the merchant's customers and storefront visitors.
  • Personal data: name and email address on orders and customer records; country and region; a one-way hash of the email address and a browser identifier on storefront events; post-purchase survey answers linked to an order; consent choices. Shopper data is minimised at ingest: street addresses, phone numbers and IP addresses are removed before storage, and IP addresses are used only to look up a country, in Fabrik's own database, and are not kept.
  • Special category data: none.
  • Purpose: analytics for the merchant: sales, customers, products, marketing attribution and storefront behaviour.
  • Nature of the processing: collection, storage, aggregation, analysis and deletion.
  • Frequency: continuous, while the app is installed.
  • Duration and retention: browser pixel events are kept for 90 days and server-side events for 365 days, then deleted; store data is kept for the duration of the subscription and deleted on shop/redact; Klaviyo data is deleted 30 days after Klaviyo is disconnected.

Annex 2. Sub-processors

  • Supabase, Inc.: database, file storage, sign-in and back-end functions. EU (Ireland).
  • Vercel, Inc.: hosts the app the merchant's staff use; sees staff requests, not stored shopper data. Global edge network.
  • Resend: sends emails to the merchant's staff, including data request links. United States.
  • Stripe: billing for the merchant's subscription; merchant billing details only, no shopper data. United States and EU.
  • Google (Google Workspace): our company email, for support correspondence with the merchant. United States and EU.
  • Zoho (Zoho Books): invoicing for agency clients; merchant billing details only. EU and United States.
  • Slack: delivers report digests and alerts, only to a Slack workspace the merchant or its agency connects; aggregate figures only. United States.

Platforms the merchant connects (Shopify, Klaviyo, Meta, Google Ads, and an agency's Teamwork, Xero, Zoho Books and Slack) are sources the merchant chooses, not sub-processors: Fabrik reads from them on the merchant's instruction.

Annex 3. Security measures

  • Encryption in transit (TLS 1.2 or higher) on every connection, and at rest (Supabase's platform encryption).
  • Access to each merchant's data limited to people who can reach that brand, enforced in the database by row-level security, with credential columns withheld from signed-in users.
  • Sign-in tokens for connected accounts such as Klaviyo kept in an encrypted secrets vault, readable only by the back-end functions that use them.
  • Personal data minimised at ingest: street addresses, phone numbers and IP addresses removed before storage.
  • Daily encrypted backups (Supabase).
  • Strong passwords, and two-factor sign-in for Fabrik staff who can reach merchant data.
  • A written incident response policy and data loss prevention policy.

Contact

Questions about this DPA to privacy@fabrik.ae.