Effective date: 17 September 2026 · Version 1.0
This Data Processing Agreement ("DPA") forms part of the Terms of Service published at https://cloudsearchapp.com/terms_of_service, between NP Apps, Westerstraat 10, Unit A0486, 3016 DH Rotterdam, the Netherlands ("Processor", "we"), and the merchant using the XCloud Search & Filter application ("Controller", "you").
It is concluded in electronic form as permitted by Article 28(9) GDPR and takes effect when you accept the Terms of Service. Where it conflicts with the Terms of Service, this DPA prevails in respect of the processing of personal data. The limitations of liability in the Terms of Service also apply to this DPA, to the extent permitted by law. Nothing in this DPA limits the rights of data subjects or any liability that cannot lawfully be excluded or limited.
We process personal data solely in order to provide and improve the search and filtering functions provided to your store, as described in Annex 1. In respect of that processing you act as the controller and we act as the processor.
You remain responsible for the lawfulness of the personal data you make available to us and of the instructions you give us. Your rights are those set out in Article 28 GDPR and in the clauses below.
We process personal data only on your documented instructions. Your instructions are given through your use and configuration of the application and through this DPA. Where we are required by Union or member state law to process personal data otherwise, we inform you of that requirement before processing, unless the law prohibits it. We inform you immediately if, in our opinion, an instruction infringes data protection law.
Persons authorised by us to process personal data are bound by an obligation of confidentiality.
We implement appropriate technical and organisational measures as required by Article 32 GDPR. The measures in place are described in Annex 2. We may change them provided that the level of protection is not reduced.
You give general written authorisation for us to engage the sub-processors listed in Annex 3. We impose data protection obligations on each sub-processor that are equivalent to those in this DPA, and we remain fully responsible to you for the performance of each sub-processor's obligations.
Before we add or replace a sub-processor, we inform you by email to your account address and update Annex 3, so that you have an opportunity to object. If you object on reasonable data protection grounds, you may terminate the agreement.
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects. As set out in Annex 1, the data we process for you is not linked to customer accounts, which limits our ability to identify the data of an individual data subject; we will say what we are able to establish in each case.
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR. In particular, we notify you without undue delay after becoming aware of a personal data breach affecting personal data processed for you, and provide the information available to us. We may charge reasonable fees, agreed in advance, for additional assistance you request beyond our obligations under applicable data protection law. Payment disputes will not delay or prevent performance of those obligations.
At your choice, we delete or return the personal data processed for you at the end of the provision of the services, and delete existing copies, unless Union or member state law requires continued storage. You may give us return instructions before the agreement ends. Copies contained in backups are deleted as those backups expire.
We make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate. Audits take place no more than once a year, unless a supervisory authority requires otherwise, a personal data breach has affected your data, or there are reasonable grounds to suspect non-compliance with this DPA. They require reasonable prior written notice and are carried out by you or by an independent auditor bound by confidentiality, at your reasonable expense; any charges by us are proportionate and do not prevent the effective exercise of your audit rights. Audits are ordinarily satisfied by the information and documentation we provide.
Our primary application infrastructure is hosted in Germany. Sub-processors process personal data in the locations described in Annex 3. Where a sub-processor established outside the European Economic Area is engaged, the transfer is based on the EU-US Data Privacy Framework or on the European Commission's Standard Contractual Clauses.
This DPA applies for as long as you use the application, and continues to apply to personal data retained after termination until that data is deleted. We may update it where necessary to comply with legal requirements. The current version, including the sub-processor list in Annex 3, is published at https://cloudsearchapp.com/dpa.
Categories of data subjects: visitors to your online store, and any other persons whose personal data is contained in your store's product data, content or settings.
Categories of personal data:
Nature and purpose of the processing: operating the search, autocomplete and filtering functions of your online store, improving those functions, reporting search activity to you, diagnosing errors and technical performance of the application, responding to your support requests, and handling privacy requests forwarded by Shopify.
Duration: for as long as you use the application.
Scope limits: the application has no access to your customers' accounts or orders, and search statistics are not linked to a customer account. Privacy requests forwarded by Shopify are not stored beyond a record that the request was received.
Personal data relating to your own account with us, such as the contact details of the store owner, is processed by us as a controller and is described in our privacy policy, not in this DPA.
This list is kept current on the page where this DPA is published. At the effective date it is:
| Sub-processor | Purpose | Location | Basis for transfer |
|---|---|---|---|
| Hetzner Online GmbH | Hosting | Germany | Not applicable — data stays in the EEA |
| New Relic | Performance monitoring | European Union data region | EU-US Data Privacy Framework, for transfers to covered US recipients |
| Postmark | Transactional email, including the weekly search activity report | United States | EU-US Data Privacy Framework |
| Slack | Internal error alerts | United States | EU-US Data Privacy Framework |
| Zendesk | Support ticketing | United States | EU-US Data Privacy Framework |
| Google Workspace | Support mailbox | United States | EU-US Data Privacy Framework |