Data Processing Agreement
Effective date: August 26, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the merchant ("Controller") and Jobair Technologies ("Processor") for Cartiva Business OS hosted at https://cartivaos.com.
Subject matter and duration
Processor hosts the Cartiva workspace and processes personal data submitted by Controller and Controller's authorized users for the duration of the subscription and any reasonable wind-down period required to return or delete data.
Nature and purpose of processing
- Hosting and operating the Cartiva Business OS platform.
- Storing and displaying business, inventory, sales, HR, and related operational records.
- Authenticating users, enforcing permissions, and recording security events.
- Maintaining optional Shopify store connection metadata and compliance webhook handling.
Categories of data subjects and personal data
- Controller's staff and authorized users (account, contact, authentication, audit data).
- Controller's customers, suppliers, and employees where entered into Cartiva by Controller.
- Shopify connection metadata (shop domain, shop identifier, granted scopes, encrypted token, webhook delivery metadata).
Phase 1 Shopify integration does not import Shopify customer name, email, phone, address, order, or catalog personal data into Cartiva.
Processor obligations
- Process personal data only on documented instructions from Controller, including these Terms, this DPA, and product configuration.
- Ensure personnel with access are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures described in the Privacy Policy.
- Assist Controller with data subject requests where applicable and technically feasible.
- Notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data, to the extent required by law.
- Delete or return personal data when the service ends, subject to legal retention requirements and backup rotation.
Subprocessors
Controller authorizes the subprocessors listed in the Privacy Policy, including:
- Railway — hosting infrastructure.
- PostgreSQL — database engine in the hosted stack.
- Resend — transactional email delivery when enabled.
- Shopify — OAuth and webhook delivery for connected stores.
- Cloudflare — optional custom-domain edge routing when enabled by Controller.
Processor will provide notice of material subprocessor changes through service documentation or direct notice where practicable.
International transfers
Where personal data is transferred internationally, Processor will implement appropriate safeguards required by applicable law, such as standard contractual clauses where relevant.
Audits
Upon reasonable request, Processor will provide information necessary to demonstrate compliance with this DPA. On-site audits may be conducted no more than once annually with reasonable notice, subject to confidentiality and security restrictions.
Shopify compliance webhooks
For connected Shopify stores, Processor handles mandatory Shopify compliance webhooks as described in the Privacy Policy, including zero-record responses where no Shopify-derived customer personal data is stored and shop-scoped deletion on shop redaction.
Contact
Data protection inquiries: [email protected].