Data Processing Addendum

Effective date / last updated: August 11, 2026

This Data Processing Addendum ("DPA") supplements our Terms of Service (the "Agreement") entered into between the Shopify merchant using the Fedev EU VAT & VIES app ("Controller," "you") and MB Fe dev ("Processor," "we"), and forms part of that Agreement. It applies to the personal data the app processes on your behalf, and supplements — without replacing — our Privacy Policy, which describes this same processing from your customers' perspective.

1. Roles

You are the Controller for your own store's data, including your customers' data. We are the Processor, acting only on your instructions as set out in this DPA and given through your use of the app.

2. Subject matter, nature and purpose of processing

EU cross-border B2B VAT validation and reverse-charge exemption: the app checks a buyer-supplied VAT number against the EU's VIES registry and, where valid, causes Shopify's native tax-exemption mechanism to remove VAT from the order.

3. Duration of processing

Customer data (VAT checks and order records): retained for 90 days from the order date, or deleted sooner on notice that you've uninstalled the app (typically within 48 hours of that notice). Your own store data (VAT number, country, reverse-charge settings): kept for as long as the app is installed, deleted on uninstall.

4. Categories of data subjects

Your customers who use the VAT ID field at checkout.

5. Categories of personal data

Customer ID, VAT number, validation outcome, order tax data, and — read transiently at the moment of a VAT ID check, never stored — the country of a signed-in customer's saved default address, used only to select which cart-page message is shown (see our Privacy Policy). No special-category data, and none of your customers' names, email addresses, phone numbers, or full physical addresses (street, city, postal code), are processed.

6. Our obligations as Processor

7. Sub-processors

You authorize our use of Render (our hosting provider) as a sub-processor, which stores the app's database in Frankfurt, Germany, under a DPA that imposes data protection obligations on Render substantially similar to those in this DPA. Render's own DPA with us already authorizes Render to engage its own affiliates and sub-processors; the current list is published at render.com/trust. If we engage a new sub-processor of our own, we'll update this page and its effective date; you may object on reasonable data-protection grounds by contacting us within 10 days of that update.

8. International data transfers

Personal data is stored in the EU (Frankfurt). Render is a US-incorporated company whose primary processing operations take place in the United States, so its support and operations staff can access data from outside the EEA in the course of running that infrastructure. Any such transfer is made under the EU-US/UK/Swiss Data Privacy Framework or, where that doesn't apply, the EU Standard Contractual Clauses under Module Three (Processor to Subprocessor) — the module matching this chain, since we are your processor and Render processes on our behalf as our subprocessor.

9. Personal data breach notification

We will notify you without undue delay upon becoming aware of a personal data breach affecting your data (GDPR Art. 33(2)), and provide the information reasonably available to us to help you meet your own notification obligations.

10. Audits

On reasonable written request, we'll make available the information reasonably necessary to demonstrate our compliance with this DPA.

11. Return or deletion of data

On uninstall, your data is deleted according to the retention periods in Section 3 above. You can export your own copy (CSV or PDF) from the VAT Records screen at any time before deletion.

12. Term

This DPA takes effect when the app is installed and remains in effect for as long as it is, plus any period needed to complete the deletion described in Section 11.

Contact

Questions about this DPA: privacy@fedevapps.com.