Data Processing Agreement
Lightward Data Processing Addendum (Locksmith)
Last updated: 18 November 2025
This Data Processing Addendum is part of the agreement between Lightward and the customer who uses our services.
By using Locksmith, the customer agrees to this DPA.
1. Roles
The customer (as the controller) determines why and how Personal Data is processed.
Lightward (as the processor) processes Personal Data only as needed to provide our services and support the customer's use of them.
Lightward processes Personal Data only according to: (a) the customer's subscription, (b) the customer's configuration of Locksmith inside their shop, and (c) the customer's use of Locksmith's features.
2. Purpose
Lightward processes Personal Data only as needed to provide Locksmith and as otherwise allowed under the agreement.
3. Security
Lightward uses technical and organizational measures designed to keep Personal Data secure.
4. Confidentiality
Lightward ensures that team members who access Personal Data are bound by confidentiality obligations.
5. Sub-Processors
The customer allows Lightward to use sub-processors to help provide Locksmith.
6. International Transfers
Lightward may transfer Personal Data internationally as needed to provide the service, using lawful transfer mechanisms when required.
7. Assistance
Where required by law and technically feasible, Lightward will help the customer respond to data-subject requests.
8. Deletion
When the customer stops using Locksmith, Lightward will delete or return Personal Data according to the agreement unless the law requires us to keep it.
9. Breach Notification
Lightward will notify the customer without undue delay if we become aware of a Personal Data Breach.
Sub-Processors for Locksmith
Last updated: 18 November 2025
Lightward works with a small group of trusted service providers to operate Locksmith. These companies may process limited Personal Data as part of providing the service.
Infrastructure & Hosting
Fly.io — application hosting and managed database services
Platform Integrations
Shopify, Inc. — authentication, API platform, webhook delivery
Monitoring
Rollbar, Inc. — error monitoring and diagnostics
Cronitor — scheduled job monitoring
Optional Service Providers (enabled only when the merchant connects these integrations or uses these features)
Google LLC — file storage (Google Drive for access lists)
Mailchimp (Intuit Inc.) — email marketing list integration
Klaviyo — email marketing list integration
Mechanic (Lightward, Inc.) — automation platform integration
MaxMind — IP geolocation services
Last updated
Was this helpful?