Data Processing Agreement
Last updated: August 6, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer," the data controller or business) and Run Octopus LLC ("RunOctopus," "we," "us," the data processor or service provider). It applies to the extent RunOctopus processes personal data on your behalf in connection with the Service, and reflects the requirements of the GDPR, UK GDPR, Swiss FADP, and the CCPA/CPRA where applicable.
1. Roles
You are the controller (or "business," under CCPA) of the personal data in your account. RunOctopus is the processor (or "service provider"). RunOctopus processes personal data only on your documented instructions, as set out in this DPA, the Terms of Service, and our Privacy Policy, except where we're required to do otherwise by law, in which case we'll tell you before processing unless the law prohibits it.
2. What We Process
This describes the actual processing today, not a hypothetical maximum. If it changes, we'll update this section.
| Subject matter | Providing the RunOctopus content platform: generating and installing SEO content on your store, and the account, billing, and analytics functions that support it |
|---|---|
| Duration | For as long as your account is active, plus the retention periods in our Privacy Policy's Data Retention section |
| Categories of data subjects | You and the individuals on your team who use your RunOctopus account. Not your store's end customers, we don't access customer, order, or payment data from your store |
| Types of personal data | Account holder name and email, Google profile information (if you sign in with Google), your store's URL and niche, IP address and approximate location, and, if you connect Google Search Console, your search-performance data. The full list is in our Privacy Policy's "Information We Collect" section, this DPA doesn't maintain a separate copy of that list so the two can't drift out of sync |
| Nature and purpose | Building and installing your content engine, sending you tool results and account communications, processing payment through Stripe, and improving the Service |
3. Sub-processors
You authorize RunOctopus to use the sub-processors listed in our Privacy Policy's "Third-Party Services" section, that page is the current, maintained list, kept in one place rather than duplicated here. If we add a sub-processor that materially changes how your data is handled, we'll update that section and, for material additions, email the address on your account. You may object on reasonable data-protection grounds by emailing hello@runoctopus.com within 30 days. If we can't resolve the objection, either party may terminate the affected part of the Service.
4. International Transfers
Run Octopus LLC is established in the United States, and personal data is processed in the United States as described in our Privacy Policy. If you're located in the European Economic Area, the United Kingdom, or Switzerland, transfers of personal data to the United States rely on the Standard Contractual Clauses approved by the European Commission (and, where applicable, the UK International Data Transfer Addendum and the Swiss Federal Data Protection and Information Commissioner's requirements) as the lawful transfer mechanism. Those clauses are incorporated into this DPA by reference.
5. Security
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit (HTTPS/TLS) for all data transmission
- Encryption at rest for sensitive credentials, including Shopify access tokens, using AES-256-GCM with a random initialization vector per token
- Access to your data restricted to authorized Run Octopus LLC personnel
- Encryption keys stored only in our deployment environment, never logged or transmitted
These match what's stated in our Privacy Policy's "Data Storage and Security" section. We'll notify you without undue delay, and in any case within 72 hours of becoming aware, if we confirm a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of your personal data.
6. Confidentiality
Everyone with access to your personal data on our side, employees and contractors alike, is bound by a written confidentiality obligation before they ever get that access, and only has it because their role requires it. That obligation survives even after someone stops working with us.
7. Assistance
We'll help you respond to data subject requests (access, correction, deletion, portability) and, where reasonably required, provide information relevant to a data protection impact assessment, to the extent we're able given the nature of our processing. Requests for assistance can be sent to hello@runoctopus.com.
8. Deletion on Termination
When your account is deleted, we delete your personal data within 30 days, matching our Privacy Policy's Data Retention section. If you uninstalled through the Shopify App Store, store-specific data (sessions, content builds, install records) is deleted within 48 hours of uninstall, per our GDPR compliance webhook handling. Content already installed on your store is yours and isn't affected by account deletion.
9. Audits
On reasonable written request, no more than once per 12 months, we'll provide information reasonably necessary to demonstrate compliance with this DPA, such as responding to a security questionnaire. If that's not sufficient, we'll discuss a mutually agreed audit, conducted during business hours, with reasonable notice, and at your expense, without unreasonably disrupting our operations.
10. Liability
Liability under this DPA is subject to the limitations set out in the "Limitation of Liability" section of our Terms of Service. Nothing in this DPA expands either party's liability beyond what's stated there.
11. Precedence and Changes
If there's a conflict between this DPA and the Terms of Service on a data protection question, this DPA controls. For anything else, the Terms of Service controls. We may update this DPA the same way we update our Terms of Service, with notice for significant changes as described there.
12. Contact
Questions about this DPA, or need a countersigned copy for your own compliance records? Email hello@runoctopus.com.
Run Octopus LLC
6 W Tower Cir, 101-C
Ormond Beach, FL 32174
United States
hello@runoctopus.com