Last updated: May 14, 2026 · Version 1.1.0
Data Processing Agreement
Summary
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Merchant", "Controller") and Dinero ("Processor"). It governs how Dinero processes personal data on your behalf in accordance with Article 28 of the EU General Data Protection Regulation (GDPR). By using Dinero, you and Dinero enter into this DPA.
1. Roles
For personal data of your customers, employees, or other individuals that flows through Dinero, you are the Controller and Dinero is the Processor. You determine the purposes and means of processing; Dinero processes only on your documented instructions.
2. Subject and duration
This DPA applies for as long as Dinero processes personal data on your behalf — i.e. while your subscription is active, plus the wind-down period defined in Section 11.
3. Nature, purpose, and types of data
| Item | Description |
|---|---|
| Nature of processing | Storage, analysis, automated advertising, and reporting |
| Purpose | Operating Dinero on the Merchant's behalf |
| Categories of data subjects | The Merchant's end customers (indirectly via Meta/Shopify aggregated data); the Merchant's authorized users |
| Categories of personal data | Account data, authentication tokens, advertising performance metrics, brand profile inputs, IP addresses, support communications, aggregated advertising audience data and pixel events from Meta and TikTok |
| Special categories | None. Dinero does not process special categories of personal data (Article 9 GDPR). |
4. Documented instructions
Dinero processes personal data only on the Merchant's documented instructions, which include: (a) these Terms and DPA, (b) configuration choices the Merchant makes in the Dinero dashboard, and (c) any further written instructions from the Merchant. If Dinero believes an instruction violates GDPR or other data-protection law, Dinero will inform the Merchant.
5. Confidentiality
All Dinero personnel with access to personal data are bound by written confidentiality obligations.
6. Security measures (Article 32)
Dinero implements appropriate technical and organizational measures, including:
- Encryption in transit (TLS, provided by the hosting platform) and at rest for OAuth tokens (AES-128 via Fernet)
- Hashed passwords (PBKDF2 with 200,000 iterations and per-user salt)
- CSRF protection on all state-changing endpoints
- Rate limiting on authentication endpoints
- Per-tenant data isolation at the application level
- Logging of administrative actions on merchant configurations
- Strict access control — only authorized personnel can access merchant data, and only for support, debugging, or security purposes
- Secure session cookies (Secure, HttpOnly, SameSite=Lax)
- HTTP Strict Transport Security (HSTS)
7. Sub-processors
The Merchant authorizes Dinero to use the sub-processors listed in our Privacy Policy. Dinero will:
- Notify the Merchant at least 30 days before adding or replacing a sub-processor
- Impose data-protection obligations on each sub-processor that are no less protective than this DPA
- Remain liable for the acts and omissions of each sub-processor
The Merchant may object to a new sub-processor in writing within 30 days. If the parties cannot resolve the objection, the Merchant may terminate the affected subscription with no penalty.
8. International data transfers
Where Dinero or a sub-processor transfers personal data outside the European Economic Area, transfers are protected by: (a) an adequacy decision from the European Commission, (b) the EU-US Data Privacy Framework, or (c) the EU Standard Contractual Clauses (Module 2: controller-to-processor) adopted by the European Commission in 2021/914.
9. Data subject rights
Dinero will assist the Merchant in responding to requests from data subjects to exercise their rights under GDPR Articles 15–22. Where a data subject contacts Dinero directly, we will refer them to the Merchant.
10. Personal data breaches
Dinero will notify the Merchant without undue delay (and in any case within 24 hours) after becoming aware of a personal data breach affecting the Merchant's data, and will provide the information needed by the Merchant to comply with its own notification obligations under Articles 33 and 34 GDPR.
11. Termination and deletion
On termination of the subscription, Dinero will, at the Merchant's choice, delete or return all personal data within 30 days. Access tokens are deleted immediately on uninstall; all other identifiable data is deleted within thirty (30) days. Aggregated, anonymized data that no longer identifies the Merchant or any data subject may be retained.
12. Audits
The Merchant has the right to audit Dinero's compliance with this DPA once per year, on at least 30 days' notice and during normal business hours, conducted in a way that does not unduly disrupt the Service. Dinero may satisfy this obligation by providing the Merchant with the most recent independent security assessment, when available.
13. AI processing
Dinero uses third-party large language models (currently OpenAI) to generate ad copy on the Merchant's behalf. The following applies to AI processing:
- Inputs to AI providers are limited to brand profile data, product information, and aggregated audience descriptors. They do not include end-customer personal data, order data, or pixel events.
- AI providers do not use API inputs to train their models by default. Dinero relies on the providers' standard API terms, which exclude API data from training.
- Dinero does not train or fine-tune any AI models on Merchant data.
- Automated decisions made by Dinero (pausing, scaling, or creating ads) operate at the campaign level and do not produce legal or similarly significant effects on individual data subjects within the meaning of Article 22 GDPR.
- The Merchant may, on written request, disable AI-generated ad creation for their account and retain only optimization features.
14. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service.
15. Order of precedence
If there is a conflict between this DPA and the Terms of Service, this DPA controls for matters relating to the processing of personal data.
16. Contact
For DPA matters: hello@dinero.agency.