Data Processing Agreement.
How Mocha processes personal data on your behalf under GDPR Article 28.
Last Updated: July 2026
1. Introduction and scope
This Data Processing Agreement ("DPA") forms part of the agreement between Mocha Analytics ("Mocha", "Processor", "we") and the customer that uses the Mocha Analytics service ("Customer", "Controller", "you") (the "Agreement"). It governs Mocha's processing of Personal Data on the Customer's behalf and reflects the parties' obligations under Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and comparable data-protection laws ("Data Protection Laws").
Where the Customer acts as a processor for its own end customers, Mocha acts as a sub-processor; the obligations below apply accordingly.
If there is a conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA prevails.
2. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings given in the GDPR. "Sub-processor" means any processor engaged by Mocha to process Personal Data. "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement.
3. Roles of the parties
The Customer is the Controller (or a processor acting for a third-party Controller) of the Personal Data it submits to, or has Mocha collect through, the Service. Mocha is the Processor and processes Personal Data only on the Customer's documented instructions, which comprise the Agreement, this DPA, and the Customer's configuration and use of the Service.
4. Subject matter and details of processing (Article 28(3))
- Subject matter: provision of the Mocha Analytics dashboard and related analytics features.
- Duration: for the term of the Agreement, plus the deletion period in Section 11.
- Nature and purpose: collecting, aggregating, storing, and displaying commerce and marketing analytics so the Customer can analyse its business.
- Categories of Data Subjects: the Customer's end customers, store visitors, and the Customer's own authorised users.
- Categories of Personal Data: contact and order details drawn from connected sources (for example name, email, order history, and store-activity data); the Customer's authorised-user account data. The Customer must not submit special categories of Personal Data (Article 9) through the Service.
5. Processor obligations (Article 28(3))
Mocha shall:
- process Personal Data only on the Customer's documented instructions, including on international transfers, unless required by law (in which case Mocha will inform the Customer unless legally prohibited);
- ensure persons authorised to process Personal Data are bound by confidentiality;
- implement the technical and organisational measures in Section 8;
- respect the conditions in Section 6 for engaging Sub-processors;
- assist the Customer, by appropriate measures, in responding to Data Subject requests (Section 7);
- assist the Customer with security, breach notification, data-protection impact assessments, and prior consultation (Articles 32–36);
- at the Customer's choice, delete or return Personal Data as set out in Section 11; and
- make available information necessary to demonstrate compliance and allow for audits as set out in Section 10.
6. Sub-processors
The Customer provides general authorisation for Mocha to engage the Sub-processors listed at Sub-processors. Mocha imposes data-protection obligations on each Sub-processor at least as protective as those in this DPA and remains liable for its Sub-processors' performance. Mocha will maintain the Sub-processor list and, for customers who request it, provide notice before adding a new Sub-processor so the Customer may object on reasonable data-protection grounds.
7. Data Subject rights
Taking into account the nature of the processing, Mocha will assist the Customer with appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligation to respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, and objection). Where a Data Subject contacts Mocha directly, Mocha will forward the request to the Customer and will not respond except on the Customer's instructions or as legally required.
8. Security (Article 32)
Mocha implements and maintains appropriate technical and organisational measures to protect Personal Data, including: encryption of data in transit and at rest; credential encryption; strict tenant isolation so each Customer's data is segregated; least-privilege access controls and authentication for staff; regular backups; monitoring and logging with Personal Data minimised; and a documented process to restore availability after an incident. Mocha reviews these measures and updates them as appropriate; any change will not materially reduce the level of protection.
9. Personal-data breach notification
Mocha will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal-data breach affecting the Customer's Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations. Where the breach involves Shopify-sourced data, Mocha will also meet its notification obligations to Shopify.
10. Audits
Mocha will make available to the Customer information necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits are subject to reasonable notice, confidentiality, and frequency limits, and may be satisfied by Mocha providing up-to-date third-party certifications or reports where available.
11. Return and deletion
On termination of the Agreement, and at the Customer's choice, Mocha will delete or return all Personal Data and delete existing copies, unless retention is required by law. In the ordinary course, Personal Data is deleted within the retention window described in our Privacy Policy after an account or store connection is removed.
12. International transfers
Where processing involves a transfer of Personal Data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (and the UK Addendum, as applicable), which are incorporated by reference and completed with the details in Section 4.
13. Shopify Protected Customer Data
Where Mocha processes Shopify Protected Customer Data, it does so in accordance with Shopify's Protected Customer Data requirements and API Terms, including applying the required data-protection, minimisation, and retention practices to that data.
14. General
This DPA takes effect on the date the Customer accepts the Agreement or begins using the Service, whichever is earlier, and remains in force while Mocha processes Personal Data for the Customer. Except as amended here, the Agreement remains in full force.
To request a countersigned copy of this DPA, contact support@mochadash.com.
Register interest.
Tell us where to find you. We'll be in touch shortly.
Thanks. We'll be in touch shortly.
Currently invitation-only. Connect Shopify in 60 seconds.