Data Processing Agreement

Last updated: 30 July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Elias Gouatarbès, trading as Fielded (“Processor,” “we”), and the merchant using Fielded (“Controller,” “you”). It applies automatically once you connect your Shopify store and HubSpot account — no separate signature is required, in the same way the Terms of Service themselves are accepted by installing and using Fielded. It reflects Article 28 of the GDPR.

1. Roles

You are the Controller of your own customers' personal data — you decide to collect it and you decide to use Fielded to sync it into your HubSpot account. We are the Processor, acting only on your instructions as described below.

2. Subject matter, duration, nature, and purpose

We process personal data for as long as you have Fielded connected, for the sole purpose of syncing your Shopify orders and customers into your own HubSpot account as Contacts and Deals, and letting you configure how that sync is routed. Processing ends when you uninstall Fielded or otherwise disconnect it.

3. Categories of data subjects and personal data

Data subjects: your own customers who place orders through your Shopify store.

Personal data: name, email address, phone number, shipping/billing address, and order details (products, quantities, prices, payment and fulfillment status) — the same categories described in our Privacy Policy.

4. Your instructions

We process personal data only on your documented instructions — which consist of: the configuration you set in your Fielded dashboard (routing rules, default pipeline/stage), and the ordinary operation of syncing orders and customers as they occur in your store. We'll tell you if we believe an instruction you've given conflicts with GDPR or another data protection law, rather than simply carrying it out.

5. Confidentiality

Anyone we authorize to process personal data on our behalf (including any future employee or contractor) is bound by an obligation of confidentiality, whether contractual or statutory.

6. Security measures

We maintain the technical and organizational measures described in Section 6 of our Privacy Policy, specifically:

7. Sub-processors

You authorize our use of the following sub-processors, engaged to provide the infrastructure Fielded itself runs on:

Sub-processorFunctionLocation
RenderApplication hostingEU (Frankfurt)
SupabaseDatabase hostingEU (Ireland)

Shopify and HubSpot are not our sub-processors under this DPA — they're your own independently-contracted platforms, and your processing relationship with each of them is governed directly by your own agreements with Shopify and HubSpot respectively. We'll give you reasonable advance notice before adding or replacing any sub-processor listed above, and you may object on reasonable data-protection grounds.

8. Deletion or return of data

Because Fielded doesn't retain your customers' order or contact data itself — it lives in your own HubSpot account once synced — there's little for us to return at the end of processing. What we do hold (your connection tokens, routing configuration, and sync activity logs) is deleted automatically: connection data within 48 hours of uninstalling Fielded, and activity logs no later than 90 days after they're created regardless.

9. Assistance with data subject rights

We support your obligation to respond to your customers' GDPR requests directly: Shopify's data-deletion request for a specific customer removes our log records of them; a full uninstall removes everything we hold for your store. For a data-access request routed to us, we'll log it and notify you promptly so you can fulfil it — as the Controller, you're best placed to compile a complete answer across all your systems, not just ours.

10. Assistance with security and breach obligations

If we become aware of a personal data breach affecting your data, we'll notify you without undue delay, with whatever information is available to us at the time, so you can meet your own notification obligations under Article 33/34 GDPR.

11. Audits and information

We'll provide you with the information reasonably necessary to demonstrate compliance with this DPA on request. Given the scale of this operation, we ask that on-site audits be a last resort after a written information request — but we won't unreasonably refuse one.

12. Liability

Liability under this DPA is subject to the limitations set out in Section 8 of our Terms of Service, which this DPA does not expand.

13. Governing law

This DPA is governed by the laws of Finland, consistent with Section 13 of our Terms of Service.

14. Contact

Questions about this DPA: elias.gouatarbes@gmail.com

See also our Privacy Policy and Terms of Service.