ONLLY · PARTNER TERMS
Data Processing Addendum
Effective 24 September 2026 · Version 1.0
This Addendum applies when an authorised administrator of a Shopify store accepts it in the ONLLY Partner Catalogue. It governs the limited order and refund information BUIDLERS LIMITED processes for that store to calculate and reconcile royalties on ONLLY artwork.
1. Parties and scope
The merchant that operates the Shopify store identified in the authenticated app session is the “Merchant”. BUIDLERS LIMITED, Flat E, 10/F, Tower 3, The Avenue, 200 Queen's Road East, Wan Chai, Hong Kong, is “ONLLY” or the “Processor”. For personal data contained in the limited order-event fields described below, the Merchant acts as controller and ONLLY processes that data only on the Merchant's documented instructions in connection with the ONLLY Partner Catalogue.
This Addendum supplements, and does not replace, the separate commercial and artwork licence terms between the parties. The Merchant's royalty rate and royalty calculation basis are set separately for each store.
2. Processing details and instructions
Purpose: match Shopify paid-order and refund events to products linked to ONLLY artwork, calculate the agreed store-specific royalty, prevent duplicate processing, and reconcile billing.
Data subjects: customers whose orders include an ONLLY-linked product, only to the extent order identifiers or transaction records can relate to an individual.
Personal data processed: Shopify store and order references; order name/reference; timestamps; line-item and product identifiers; quantity; currency; poster line subtotal after discounts; refund subtotal; linked ONLLY artwork ID; and the store-specific royalty percentage and resulting amount. Shopify's mandatory privacy-request webhooks may transiently include customer ID, name, email address, or phone number; ONLLY does not use or retain those request-body fields.
Duration: for the term of the app installation, subject to the retention and deletion rules in section 6 and Shopify's mandatory compliance requests.
Documented instructions: process only the fields and for the purposes in this Addendum; do not sell, advertise with, profile, or use the data for any unrelated purpose; and do not combine it with other customer profiles.
If a customer-redaction request overlaps a transaction record that BUIDLERS LIMITED is legally required to keep, ONLLY retains only the minimized accounting fields needed to substantiate the royalty and removes customer contact data and request-body contents. The retained transaction record is restricted to accounting, billing reconciliation, and legal compliance.
3. ONLLY's obligations
- Process personal data only on the Merchant's documented instructions, including this Addendum and the app's configuration.
- Ensure people authorised to handle the data are bound by confidentiality obligations and restrict access to personnel who need it to operate or secure the service.
- Apply the technical and organisational controls in section 7 and keep the app limited to the order fields required for royalty accounting.
- Notify the Merchant without undue delay after becoming aware of a personal-data breach affecting data processed under this Addendum, and provide information reasonably available to support the Merchant's response.
- Assist the Merchant, taking account of the processing, with data-subject requests, security obligations, breach response, and impact assessments where reasonably possible.
- Make available information reasonably necessary to demonstrate compliance with this Addendum. The Merchant may request a proportionate audit by contacting info@onlly.art, subject to confidentiality, security, and other merchants' rights.
- At the end of processing, delete store-linked data as described in section 6, unless applicable law requires a specific record to be retained.
4. Merchant responsibilities
The Merchant is responsible for having a lawful basis to use the app and instruct the processing, giving people any required privacy information, and configuring its Shopify store lawfully. The Merchant must not instruct ONLLY to process buyer identity, delivery, payment, or other information the app does not require. The Merchant's administrator who accepts this Addendum confirms they are authorised to bind the Merchant.
5. Service providers and international transfers
ONLLY uses Timeweb to host the application and database on a VPS. The current server address is in a Timeweb network allocation registered in Russia; the IP registry does not establish the physical data-centre location. Shopify provides the Merchant's store platform and APIs and receives usage-billing events where enabled. ONLLY will not appoint a new subprocessor that materially changes the processing without providing notice and a reasonable opportunity to object on data-protection grounds.
The Merchant acknowledges that ONLLY is established in Hong Kong and the hosting provider may process data outside the Merchant's country. If the Merchant is subject to the GDPR or UK GDPR and a transfer mechanism is required, the parties will put the applicable approved transfer terms and any required transfer assessment and supplementary measures in place before the app is enabled for that Merchant. This Addendum alone does not represent that a transfer assessment has been completed for every Merchant or that any specific data-centre location has been certified.
For transfers requiring the European Commission's Standard Contractual Clauses, the parties will use the controller-to-processor module and any applicable onward-transfer module, with the processing details and security measures in sections 2 and 7 as the relevant annex information. The clauses are available from the European Commission. For UK restricted transfers, the parties will use the applicable UK transfer addendum. If additional safeguards are required by applicable law, they must be agreed before the relevant transfer begins.
6. Retention, return, and deletion
- Processed or ignored webhook-delivery receipts are deleted after 12 months. Failed or unresolved deliveries are kept until resolved, then are subject to that 12-month period.
- The minimized royalty ledger and successfully submitted Shopify billing-event records are deleted after 7 years from the associated event, unless a billing event remains pending or failed and needs reconciliation.
- When the app is uninstalled, ONLLY clears the Shopify access token and removes the partner session. On Shopify's
shop/redactrequest, ONLLY deletes credentials, sessions, selections, Shopify product links, webhook receipts, agreement-acceptance state, and other operational data. Where required for BUIDLERS LIMITED's statutory accounting obligations, ONLLY retains only the merchant identity and minimized royalty/billing records for up to 7 years from each event; those records are then automatically deleted. If no accounting records remain, the store record is deleted on receipt of the request. Shopify's own records are governed by Shopify's terms. - Shopify privacy request bodies are not retained by ONLLY. The app stores no buyer contact profile, address, or payment credential.
For a copy of an accounting record retained for this statutory period, the Merchant may contact info@onlly.art and verify its authority over the relevant store. Provider-managed recovery copies, if enabled, may remain until overwritten under the provider's backup cycle and are not restored except for service recovery.
7. Security measures
- HTTPS/TLS for connections to and from the production app.
- AES-256-GCM encryption for Shopify access tokens and stored royalty amounts and event timestamps, with the encryption key kept outside the database.
- Keyed HMAC pseudonymisation for order, line-item, webhook and event identifiers used for matching and idempotency.
- Raw order, refund, and customer privacy-request webhook bodies are processed transiently and not written to the app database or application logs.
- Store-scoped access controls, authenticated sessions, webhook signature verification, and deletion on Shopify's shop-redact request.
ONLLY will review these controls when the processing or infrastructure materially changes.
8. Contact and acceptance
Questions or data-protection requests under this Addendum may be sent to info@onlly.art. The Addendum takes effect for the Merchant when its authenticated Shopify administrator selects the acceptance checkbox in the ONLLY Partner Catalogue. ONLLY records the store ID, accepted document versions, and timestamp as evidence of acceptance.