Data Processing Agreement

(relating to use of the Clubhouse loyalty platform)

This Data Processing Agreement (the "Agreement") is entered into between:

Clubhouse
c/o Mikkel Harley Ibsen
2500 Valby, Denmark
Business registration no. DK40035966
(the "Processor")

and

[Customer's company name]
[Address]
Business registration no. [XXXXXXXX]
(the "Controller")

The Processor and the Controller are jointly referred to as the "Parties" and each individually as a "Party".

1. Background and purpose

1.1. The Controller operates a webshop on the Shopify platform and has entered into an agreement with the Processor for use of the Clubhouse loyalty platform (the "Service"), which is integrated with the Controller's Shopify store via an OAuth connection.

1.2. In connection with providing the Service, the Processor processes personal data relating to the Controller's customers on behalf of the Controller. This Agreement sets out the Parties' rights and obligations in relation to such processing, pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the "General Data Protection Regulation" or "GDPR").

1.3. This Agreement takes precedence in the event of any inconsistency between this Agreement and any data protection provisions in other agreements between the Parties, including the Processor's standard terms of business.

2. Obligations of the Processor

2.1. The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information.

2.2. The Processor shall ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

2.3. The Processor shall assist the Controller in ensuring compliance with the obligations set out in GDPR Articles 32–36, including in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, data portability, etc.), taking into account the nature of the processing and the information available to the Processor.

2.4. In the event of a personal data breach, the Processor shall notify the Controller without undue delay and no later than 48 hours after becoming aware of the breach.

2.5. Following termination of the Service, including where the Controller uninstalls the Clubhouse app from its Shopify store, the Processor shall, at the Controller's choice, delete or return all personal data, unless EU or Member State law requires storage. Deletion occurs automatically via the mandatory shop/redact webhook sent by Shopify upon uninstallation.

2.6. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this Agreement and in GDPR Article 28, and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

3. Nature and purpose of the processing

3.1. The purpose of the processing is to deliver the Clubhouse loyalty program, including matching the Controller's Shopify customers to their loyalty status (points and tier) and generating personalised discount codes upon redemption of earned rewards.

3.2. The processing covers the following categories of data subjects: the Controller's customers who have made purchases in the webshop.

3.3. The processing covers the following categories of personal data:

  • Name (first and last name)
  • Email address
  • Date of birth (obtained via Shopify metafields, Klaviyo, or self-reported by the customer)
  • Order history and order value (used to calculate points)
  • Loyalty status (points, tier, redeemed discount codes)

3.4. The processing continues for as long as the Controller uses the Service and ceases upon uninstallation of the Clubhouse app, cf. clause 2.5.

4. Sub-processors

4.1. The Controller hereby grants general authorisation for the Processor to engage the following sub-processors:

  • Klaviyo, Inc. — for sending automated marketing flows on behalf of the Controller, to the extent the Controller has configured this in its own Klaviyo account, and as a source of date-of-birth data where the Controller has made this available in Klaviyo
  • Neon (database infrastructure) — hosting of the underlying Postgres database
  • Vercel Inc. — hosting and operation of the application
  • Resend — transactional email delivery (OTP, invitations, password resets, GDPR data-request notifications). Data processed: recipient email addresses and message content. Location: USA.
  • Upstash, Inc. — rate limiting infrastructure. Data processed: client IP addresses. Location: USA (with EU-region option).

4.2. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller at least 30 days' notice within which to object to such changes.

4.3. The Processor shall impose on every sub-processor the same data protection obligations as those set out in this Agreement.

5. Transfers to third countries

5.1. Some sub-processors, including Klaviyo, Inc. and Vercel Inc., are established in or process data from the United States. Such transfers take place on a transfer basis recognised under the GDPR, including the European Commission's standard contractual clauses.

6. Technical and organisational security measures

6.1. The Processor has implemented the following security measures:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest at the underlying infrastructure provider
  • Access restrictions, so that only authorised employees of the Processor have access to personal data
  • Separation of test and production environments
  • Automated, encrypted backups of data

6.2. The Processor shall continuously assess the risk to the rights and freedoms of data subjects and implement appropriate measures to mitigate that risk, cf. GDPR Article 32.

7. Liability

7.1. Each Party is liable for its own breaches of data protection law and of this Agreement in accordance with generally applicable rules.

7.2. The Processor shall indemnify the Controller for direct losses incurred by the Controller as a result of the Processor's failure to comply with its obligations under this Agreement or applicable data protection law.

8. Term and termination

8.1. This Agreement enters into force when the Controller installs the Clubhouse app on its Shopify store and remains in effect for as long as the Processor processes personal data on behalf of the Controller.

8.2. This Agreement terminates automatically upon termination of the underlying agreement for provision of the Service, subject to clause 2.5 regarding deletion of data upon termination.

9. Signature

This Agreement is deemed accepted by the Controller upon installation of the Clubhouse app on the Controller's Shopify store, or alternatively upon signature below.

For Clubhouse:

Date: _______________    Signature: _______________________________

For the Controller:

Date: _______________    Signature: _______________________________

Last updated: August 8, 2026