Data Processing Agreement

Lightward Data Processing Addendum (Locksmith)

Last updated: 18 November 2025

This Data Processing Addendum is part of the agreement between Lightward and the customer who uses our services.

By using Locksmith, the customer agrees to this DPA.

1. Roles

The customer (as the controller) determines why and how Personal Data is processed.

Lightward (as the processor) processes Personal Data only as needed to provide our services and support the customer's use of them.

Lightward processes Personal Data only according to: (a) the customer's subscription, (b) the customer's configuration of Locksmith inside their shop, and (c) the customer's use of Locksmith's features.

2. Purpose

Lightward processes Personal Data only as needed to provide Locksmith and as otherwise allowed under the agreement.

3. Security

Lightward uses technical and organizational measures designed to keep Personal Data secure.

4. Confidentiality

Lightward ensures that team members who access Personal Data are bound by confidentiality obligations.

5. Sub-Processors

The customer allows Lightward to use sub-processors to help provide Locksmith.

6. International Transfers

Lightward may transfer Personal Data internationally as needed to provide the service, using lawful transfer mechanisms when required.

7. Assistance

Where required by law and technically feasible, Lightward will help the customer respond to data-subject requests.

8. Deletion

When the customer stops using Locksmith, Lightward will delete or return Personal Data according to the agreement unless the law requires us to keep it.

9. Breach Notification

Lightward will notify the customer without undue delay if we become aware of a Personal Data Breach.


Sub-Processors for Locksmith

Last updated: 18 November 2025

Lightward works with a small group of trusted service providers to operate Locksmith. These companies may process limited Personal Data as part of providing the service.

Infrastructure & Hosting

  • Fly.io — application hosting and managed database services

Platform Integrations

  • Shopify, Inc. — authentication, API platform, webhook delivery

Monitoring

  • Rollbar, Inc. — error monitoring and diagnostics

  • Cronitor — scheduled job monitoring

Optional Service Providers (enabled only when the merchant connects these integrations or uses these features)

  • Google LLC — file storage (Google Drive for access lists)

  • Mailchimp (Intuit Inc.) — email marketing list integration

  • Klaviyo — email marketing list integration

  • Mechanic (Lightward, Inc.) — automation platform integration

  • MaxMind — IP geolocation services

Last updated

Was this helpful?