Data Processing Addendum
Effective and last updated: 5 September 2026
This Data Processing Addendum (“DPA”) forms part of the CM6 Terms of Service between Hypus Ltd, trading as CM6, a company registered in England and Wales under company number 09256123 with its registered office at Fourth Floor, 33 Cavendish Square, London, England, W1G 0PW (“CM6”, the “Processor”), and the customer that installs or uses the CM6 Service (the “Customer”, the “Controller”). It applies automatically whenever CM6 processes personal data on the Customer’s behalf and does not need to be signed. If you require a countersigned copy, email info@cm-six.com.
“Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679) where it applies, and any other applicable data protection law. “Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in Data Protection Law. “Customer Personal Data” means personal data that CM6 processes on the Customer’s behalf in providing the Service, as described in Annex 1.
1. Roles and scope
For Customer Personal Data the Customer is the controller and CM6 is the processor. This DPA does not apply to personal data for which CM6 is a controller, such as the Customer’s own users’ account data, which is covered by the Privacy Policy. The Customer warrants that it has a lawful basis for, and has given any notices required for, the disclosure of Customer Personal Data to CM6 and its processing as contemplated by the Service, and that its instructions comply with Data Protection Law.
2. Processing on instructions
CM6 will process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to third countries, unless required to do otherwise by law, in which case CM6 will inform the Customer before processing unless the law prohibits it. The Customer’s instructions are: the Terms of Service, this DPA, the configuration and settings the Customer applies in the Service, and the Customer’s use of the Service’s features. CM6 will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
3. Confidentiality
CM6 ensures that persons authorised to process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and process it only as needed to provide the Service.
4. Security
CM6 implements appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks to individuals. The current measures are described in Annex 2. CM6 may update them from time to time provided the overall level of protection is not reduced.
5. Sub-processors
- The Customer gives CM6 general written authorisation to engage the sub-processors listed in Annex 3 and to replace or add sub-processors in accordance with this section.
- CM6 will publish changes to Annex 3 on this page and will notify the Customer by email or in the Service at least 30 days before a new sub-processor begins processing Customer Personal Data. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected Service by uninstalling the app, and any prepaid fees for the remaining period will be refunded.
- CM6 will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable to the Customer for the sub-processor’s performance.
6. Assistance with data subject rights
Taking into account the nature of the processing, CM6 will assist the Customer with appropriate technical and organisational measures to respond to requests from data subjects exercising their rights. In particular, CM6 supports Shopify’s mandatory privacy webhooks: on a customer data request CM6 provides the data it holds to the Customer within 30 days; on a customer erasure request CM6 deletes the customer’s record from the customer tables promptly, retaining order records only in pseudonymised form (internal customer reference and coarse shipping geography, with no name or contact details) as needed for the integrity of the Customer’s financial reporting. If CM6 receives a request directly from a data subject it will, where lawful, refer the data subject to the Customer and not respond substantively without the Customer’s instruction.
7. Assistance with security, breach notification and impact assessments
- CM6 will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the likely consequences, the measures taken or proposed, and a point of contact, and CM6 will provide further information as it becomes available.
- CM6 will provide reasonable assistance to the Customer with its obligations regarding security of processing, breach notification to supervisory authorities and data subjects, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to CM6.
8. International transfers
CM6 processes Customer Personal Data in the locations set out in Annexes 1 and 3, which include the United States. Where processing involves a transfer of Customer Personal Data out of the United Kingdom or the European Economic Area to a country without an adequacy decision, CM6 ensures the transfer is covered by an appropriate safeguard: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses (Commission Decision 2021/914), or, where the recipient is certified under the EU-US Data Privacy Framework and its UK Extension, that certification. To the extent a transfer from the Customer to CM6 itself requires a safeguard, the parties agree that the EU Standard Contractual Clauses (Module 2, controller to processor) and, for UK transfers, the UK Addendum are incorporated by reference, with the Customer as data exporter, CM6 as data importer, the details in Annex 1, the measures in Annex 2, the optional clauses not applied, and Ireland (EU) and England and Wales (UK) as the governing law and forum.
9. Deletion and return
On termination of the Service, including when the Customer uninstalls the CM6 app, CM6 will delete the Customer’s store dataset and stored configuration on receipt of Shopify’s shop-redaction notice, which Shopify issues 48 hours after uninstallation, and will delete residual copies in backups and logs within 30 days. The Customer may export its order data to CSV at any time before termination, which constitutes return of the data. CM6 may retain Customer Personal Data only to the extent required by law, and only for as long as required, keeping it confidential.
10. Information and audit
CM6 will make available the information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the UK and EU GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits will be limited to once in any 12-month period unless required by a supervisory authority or following a personal data breach, conducted on at least 30 days’ written notice during business hours, subject to reasonable confidentiality and security requirements, and at the Customer’s cost. CM6 may first satisfy an audit request by providing written responses, documentation or relevant third-party audit reports covering its sub-processors.
11. Liability and precedence
Each party’s liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails. This DPA is governed by the laws of England and Wales.
Annex 1 — Details of processing
| Subject matter | Provision of the CM6 contribution-profit analytics service to the Customer. |
|---|---|
| Duration | For as long as the Customer uses the Service, plus the deletion period in section 9. |
| Nature of processing | Collection from the Customer’s Shopify store and connected platforms via API, storage, organisation, enrichment with cost data, analysis, aggregation, display to the Customer’s authorised users, export, email notification, AI-assisted analysis of order-level economic data, and deletion. |
| Purpose | Calculating and presenting order-level contribution profit and related analytics, alerts, reports and insights for the Customer’s business; security and support of the Service. |
| Categories of data subjects | The Customer’s customers (shoppers); the Customer’s staff and other users whose details appear in orders, uploaded documents or configuration; the Customer’s suppliers and carriers where their details appear in uploaded documents. |
| Categories of personal data | Identity and contact data (name, email address, phone number, billing and shipping addresses); order and transaction data (products purchased, prices, discounts, taxes, refunds, shipping and fulfilment details, payment gateway and method, order tags and notes); customer identifiers, tags and order history; advertising campaign performance data (aggregate, not identifying individuals); any personal data contained in documents the Customer uploads. |
| Special category data | None intended. The Customer must not upload special category or criminal-offence data. |
| Processing locations | Google Cloud: London and European Union regions (application services, operational database) and the United States multi-region (store data warehouses, or the United Kingdom or European Union where agreed with the Customer); sub-processor locations per Annex 3. |
Annex 2 — Technical and organisational security measures
- Encryption. All data in transit is encrypted with TLS. Data at rest in Google Cloud storage, databases and warehouses is encrypted using Google-managed keys. Platform credentials and secrets are stored in Google Cloud Secret Manager and encrypted with Cloud KMS.
- Tenant isolation. Each Customer store’s data is held in its own dedicated BigQuery dataset. Every request is authorised against the signed-in user’s store permissions and role; requests cannot address another store’s dataset.
- Access control. Access to production systems is restricted to authorised CM6 personnel using individually identified accounts on a least-privilege basis. Service accounts are scoped to the minimum permissions required. Access to Shopify stores is read-only and limited to the scopes approved at installation.
- Authentication. Users authenticate through Google Sign-In or a verified Shopify admin session. Sensitive links (store grants, exports) are single-use or time-limited and bound to the requesting session.
- Logging and monitoring. Application, access and audit events are logged, including administrative actions, syncs, exports and data-protection requests, and are monitored for anomalies.
- Data minimisation. AI features receive order-level economic data with pseudonymous customer references only; customer names and contact details are not sent to AI providers.
- Resilience. Services run on managed, redundant Google Cloud infrastructure with automated recovery; warehouse data can be restored from point-in-time history for a limited period.
- Deletion. Automated, idempotent deletion routines respond to Shopify erasure and uninstall notices; report share links expire automatically.
- Supply chain. Software dependencies are pinned and verified at build time; container images are built in a controlled pipeline.
- Organisational. Personnel with access to Customer Personal Data are bound by confidentiality obligations; data-protection requests and incidents are recorded and tracked to closure.
Annex 3 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud (Google Ireland Limited / Google LLC) | Hosting, data warehouse (BigQuery), operational database, task queues, secrets and key management, user sign-in | United Kingdom, European Union, United States |
| Fivetran, Inc. | Connectors that copy advertising-platform spend and performance data into the Customer’s dataset | United States, European Union |
| Brevo (Sendinblue SAS) | Transactional email delivery (alerts, notifications, onboarding, export links) | European Union (France) |
| OpenAI, L.L.C. | AI-generated insights and document extraction | United States |
| Anthropic, PBC | AI-generated insights and document extraction | United States |
| Vercel Inc. | Hosting of the cm-six.com marketing website and its cookieless analytics (no Customer store data) | United States |
Shopify International Limited / Shopify Inc. operates the platform through which the Customer’s store data is made available, handles billing and issues privacy webhooks. Shopify acts as an independent controller under its own terms and is not a sub-processor of CM6.
Contact
Data protection enquiries: info@cm-six.com. Hypus Ltd (trading as CM6), Fourth Floor, 33 Cavendish Square, London, England, W1G 0PW.