Last Updated: September 15, 2026
This Data Processing Agreement (“DPA”) forms part of and is incorporated into the Terms of Service (“Terms”) between AZIDY PTE. LTD (“AZIDY”, “Company”, “we”, “us”, or “our”) and the entity or individual using the Service (“Customer”, “you”, or “your”).
This DPA applies to the extent that AZIDY processes Personal Data on behalf of Customer in connection with the Service.
By using the Service, Customer agrees to this DPA as part of the Terms. This DPA is published at https://bixgrow.com/dpa and is available to Customer at all times. No separate signature or countersignature is required for this DPA to apply.
1. Definitions
For purposes of this DPA:
“Applicable Data Protection Laws” means all applicable laws and regulations relating to the protection of Personal Data, privacy, and data security, including, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK GDPR, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (“CCPA”), the Singapore Personal Data Protection Act 2012, and applicable data protection laws of other jurisdictions.
“Customer Data” means Personal Data submitted to, collected through, or otherwise processed by AZIDY on behalf of Customer through the Service.
“Personal Data” means information relating to an identified or identifiable natural person, or equivalent term under Applicable Data Protection Laws.
“Personal Data Breach” means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by AZIDY on behalf of Customer.
“Processing”, “Controller”, “Processor”, and “Data Subject” have the meanings given to them under Applicable Data Protection Laws.
“Service” means the BixGrow affiliate and referral marketing services provided by AZIDY.
“Sub-processor” means a third party engaged by AZIDY to process Personal Data on behalf of Customer in connection with the Service.
2. Parties and Roles
The parties are:
AZIDY PTE. LTD
3 Coleman Street, #03-24
Peninsula Shopping Complex
Singapore 179804
Email: [email protected]
and
Customer, being the merchant or other entity using the Service.
For Personal Data processed through the Service:
- Customer acts as the Controller; and
- AZIDY acts as the Processor.
Customer remains responsible for determining the purposes and means of processing Personal Data and for ensuring that its processing instructions and use of the Service comply with Applicable Data Protection Laws.
AZIDY will process Personal Data only on Customer’s documented instructions, including instructions provided through Customer’s use and configuration of the Service, unless otherwise required by Applicable Data Protection Laws.
AZIDY will inform Customer without undue delay if, in AZIDY’s reasonable opinion, an instruction given by Customer infringes Applicable Data Protection Laws. To the extent AZIDY cannot comply with such an instruction, AZIDY may, without liability to Customer, temporarily suspend Processing of the affected Personal Data (other than securely storing it) until the parties resolve the issue.
3. Scope and Description of Processing
AZIDY provides an affiliate and referral marketing platform that enables merchants to:
- create and manage affiliate and referral programs;
- manage affiliates and advocates;
- track referrals, clicks, conversions, and sales;
- calculate commissions and rewards;
- generate and manage affiliate links and coupons;
- provide reporting and analytics;
- communicate with affiliates and customers where configured by Customer; and
- provide customer support and maintain the Service.
AZIDY may process Personal Data as reasonably necessary to provide, secure, maintain, and support the Service. This includes access by authorized AZIDY support personnel to Customer’s account within the Service where reasonably necessary to respond to support requests, diagnose errors, verify configuration, or maintain the security and integrity of the Service.
The duration of processing is the period during which Customer uses the Service, together with any limited period necessary for deletion, backup retention, legal compliance, dispute resolution, or other legitimate purposes permitted by Applicable Data Protection Laws.
4. Categories of Personal Data
AZIDY may process the following categories of Personal Data on behalf of Customer:
4.1 End-Customer Data
- Name
- Email address
- Phone number, where provided
- Shipping address, where made available through the Service
- Order and transaction information
- Order ID and related identifiers
- Products purchased
- Purchase value
4.2 Affiliate and Advocate Data
- Name
- Email address
- Phone number, where provided
- Affiliate account identifiers
- Username, referral ID, or similar identifiers
- Referral links and coupon codes
- Performance information
- Clicks, conversions, sales, commissions, and rewards
- Affiliate payout information or identifiers, such as PayPal email or other payment-related information provided for payout purposes
4.3 Technical and Online Identifiers
- IP address
- Cookies and similar tracking technologies
- Device information
- Browser information
- Online identifiers
- Usage and interaction information
4.4 Referral and Attribution Data
- Referral source
- Referral links and codes
- Campaign information
- Attribution records
- Information connecting affiliates, customers, referrals, and transactions
- Commission and reward calculation information
4.5 System and Support Data
- Application logs
- Diagnostic information
- Error information
- Support requests
- Communications with Customer or its users relating to support
Customer should not intentionally submit special categories of Personal Data to the Service unless such processing is necessary, lawful, and expressly supported by the Service.
5. Purposes of Processing
AZIDY may process Personal Data for the following purposes:
- providing the Service;
- tracking affiliate and referral activity;
- attributing sales and conversions;
- calculating commissions, rewards, and bonuses;
- generating reports and analytics;
- managing affiliate and customer relationships;
- sending transactional or service-related communications;
- providing customer support;
- maintaining, securing, and troubleshooting the Service;
- preventing fraud, abuse, and unauthorized activity; and
- complying with applicable legal obligations.
AZIDY will not sell Customer Data as part of the Service.
6. Sub-processors
AZIDY may engage Sub-processors to assist in providing the Service.
AZIDY’s current Sub-processors include:
| Sub-processor | Purpose | Processing Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, infrastructure, and delivery of emails sent on Customer’s behalf to affiliates, advocates and customers (Amazon SES) | United States / AWS us-west-2 |
| Crisp | Customer support and communications | As determined by Crisp |
Customer authorizes AZIDY to engage these Sub-processors.
AZIDY may engage additional Sub-processors where reasonably necessary to provide or improve the Service, provided that AZIDY imposes data protection obligations on such Sub-processors that are no less protective than those set out in this DPA.
AZIDY maintains a current list of its Sub-processors in this Section, as published at https://bixgrow.com/dpa.
Advance Notice and Right to Object. AZIDY will provide at least thirty (30) days’ prior notice before engaging any new Sub-processor, by updating the Sub-processor list published at https://bixgrow.com/dpa and by email to Customers who have subscribed to Sub-processor change notifications through the Subprocessor Notification Form. For clarity, in the event that Customer does not subscribe to the foregoing, Customer waives any right to object to any new Sub-processor engaged by AZIDY.
If Customer has subscribed to the Subprocessor Notification Form and has a reasonable, documented objection to AZIDY’s engagement of a new Sub-processor on data protection grounds, Customer may object by written notice to AZIDY within fifteen (15) days of receipt of the applicable email notification. Upon receipt of a timely objection, AZIDY will work with Customer in good faith to address the objection, which may include providing additional information about the Sub-processor’s data protection safeguards.
If the parties are unable to reach a mutually acceptable resolution within a reasonable period, Customer may, as its sole and exclusive remedy, terminate the Service to the extent it cannot reasonably be provided without use of the objected-to Sub-processor, by providing written notice to AZIDY. If Customer does not object within the period described above, Customer will be deemed to have authorized the new Sub-processor for purposes of Article 28(2) of the GDPR and equivalent provisions of other Applicable Data Protection Laws.
Where AZIDY reasonably determines that engaging a new Sub-processor on shorter notice is necessary to address an urgent security, legal, or operational requirement, AZIDY may provide notice as soon as reasonably practicable, which may be after such engagement, and Customer’s right to object under this Section will apply on the same basis following such notice.
AZIDY remains responsible for its Sub-processors’ processing of Personal Data to the extent required by Applicable Data Protection Laws.
7. Customer-Configured Third-Party Integrations
The Service may allow Customer to connect third-party services, including email marketing, analytics, or other platforms selected by Customer.
Where Customer chooses to enable such an integration:
- Customer instructs AZIDY to transmit the relevant information to the selected third-party service;
- the third-party service processes the information under its own terms and privacy practices;
- Customer is responsible for determining whether the integration is appropriate and lawful for its intended use; and
- AZIDY is not responsible for the third party’s independent processing of Personal Data after the data has been transferred to that third party.
Where AZIDY independently engages a third party to process Personal Data on AZIDY’s behalf in providing the Service, that third party will be treated as a Sub-processor under Section 6.
8. Security Measures
AZIDY will maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Such measures include:
- encryption of data in transit using industry-standard technologies;
- encryption at rest of End-Customer Data obtained through the Shopify platform;
- access controls and authentication mechanisms;
- restricted access to Personal Data based on business need;
- access to Customer accounts by authorized support personnel only where necessary to provide, maintain, or secure the Service, with such access being logged;
- secure cloud infrastructure;
- logging and monitoring;
- backup and recovery procedures;
- measures designed to maintain confidentiality and integrity of Personal Data; and
- procedures for responding to security incidents.
AZIDY may modify its security measures from time to time provided that such modifications do not materially reduce the overall level of protection provided to Personal Data.
9. Data Subject Rights
Taking into account the nature of the processing, AZIDY will provide reasonable assistance to Customer in responding to requests from Data Subjects concerning their Personal Data, including requests for:
- access;
- correction;
- deletion;
- restriction of processing;
- data portability; and
- objection to processing,
where applicable under Applicable Data Protection Laws.
Taking into account the nature of the processing and the information available to AZIDY, AZIDY will also provide reasonable assistance to Customer with data protection impact assessments and, where required by Applicable Data Protection Laws, prior consultations with supervisory authorities, in each case to the extent required and reasonably possible.
Where AZIDY receives a Data Subject request relating to Personal Data processed on behalf of Customer, AZIDY may direct the Data Subject to Customer unless AZIDY is required by law to respond directly.
Customer remains responsible for responding to Data Subject requests and determining whether a request should be fulfilled.
AZIDY may charge a reasonable fee for assistance that is excessive, repetitive, or requires substantial additional resources, to the extent permitted by Applicable Data Protection Laws.
10. Data Retention and Deletion
AZIDY will retain Personal Data only for as long as reasonably necessary to provide the Service and fulfill the purposes described in this DPA, unless a longer retention period is required or permitted by law.
10.1 Uninstallation or Termination
Following Customer’s uninstallation of the Service or termination of the Customer’s account, AZIDY will, at Customer’s election, return Customer Data to Customer or delete it. Customer may make such election by written notice to AZIDY within thirty (30) days of uninstallation or termination, and return will be provided in a commonly used electronic format to the extent technically feasible. If Customer makes no election within that period, AZIDY will initiate the deletion of Customer Data in accordance with its applicable deletion procedures and Applicable Data Protection Laws.
AZIDY will delete or anonymize applicable Personal Data within a reasonable period after receiving the applicable deletion request, subject to:
- data that must be retained to comply with applicable law;
- data reasonably necessary to establish, exercise, or defend legal claims;
- limited data retained for legitimate security or fraud-prevention purposes; and
- Personal Data contained in backups that cannot reasonably be immediately deleted.
10.2 Backups
Personal Data may remain temporarily in encrypted or otherwise secured backup systems following deletion from active systems.
Backup copies will remain subject to appropriate security protections and will not be restored to active processing except where necessary for disaster recovery or other legitimate operational purposes.
Such data will be deleted or overwritten in accordance with AZIDY’s applicable backup retention procedures.
10.3 Customer Responsibility
Customer is responsible for exporting any information it requires before uninstalling or terminating the Service, to the extent export functionality is available.
11. Personal Data Breach
If AZIDY becomes aware of a Personal Data Breach affecting Personal Data processed on behalf of Customer, AZIDY will notify Customer without undue delay after becoming aware of the breach.
Where reasonably practicable, AZIDY will provide such notification within 72 hours after becoming aware of the Personal Data Breach.
The notification will, to the extent reasonably available at the time, include:
- a description of the nature of the Personal Data Breach;
- the categories of Personal Data affected;
- the approximate number of Data Subjects or records affected, where known;
- the measures taken or proposed to address the breach; and
- relevant information regarding measures to mitigate potential adverse effects.
AZIDY will take reasonable steps to contain, investigate, and remediate the Personal Data Breach.
AZIDY will provide reasonable cooperation and assistance to Customer in connection with Customer’s obligations under Applicable Data Protection Laws.
AZIDY will not notify any Data Subject, supervisory authority, or other third party regarding a Personal Data Breach on behalf of Customer unless required by law or otherwise instructed by Customer.
Customer remains responsible for determining whether notification to a supervisory authority or affected Data Subjects is required.
Except where required by law or by a supervisory authority, Customer will not issue any public statement or communication that identifies AZIDY by name in connection with a Personal Data Breach without AZIDY’s prior written consent, such consent not to be unreasonably withheld.
AZIDY’s notification of, or response to, a Personal Data Breach will not be construed as an acknowledgement by AZIDY of any fault or liability with respect to the Personal Data Breach.
12. International Data Transfers
AZIDY may process Personal Data in countries outside the country in which Customer or the relevant Data Subjects are located, including the United States, Singapore, and Vietnam, and in other countries in which AZIDY or its Sub-processors maintain operations.
Where an international transfer of Personal Data is subject to Applicable Data Protection Laws requiring an appropriate transfer mechanism, AZIDY will rely on an applicable lawful transfer mechanism.
Where required for transfers subject to the GDPR, the parties may rely on the Standard Contractual Clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914 (“SCCs”). The European Commission identifies these SCCs as the modernized contractual mechanism for transfers of Personal Data from the EU/EEA to third countries.
Where the SCCs apply to a Controller-to-Processor transfer:
- Customer will act as the data exporter; and
- AZIDY will act as the data importer.
Where required by Applicable Data Protection Laws, the parties enter into Module Two (Controller to Processor) of the SCCs. The SCCs are incorporated into this DPA by reference and apply together with the selections and appendices set out below and in the SCC Annexes to this DPA. The SCCs prevail over this DPA to the extent of any conflict concerning the international transfer of Personal Data.
- Clause 7 (Docking Clause): not included;
- Clause 9 (Use of Sub-processors): Option 2 (general written authorization) applies, with a minimum prior notice period of thirty (30) days, consistent with Section 6 of this DPA;
- Clause 11 (Redress): the optional language requiring data subjects to be permitted to lodge a complaint with an independent dispute resolution body is not included;
- Clause 13 and Annex I.C: the competent supervisory authority will be determined in accordance with Clause 13 of the SCCs;
- Clause 17 (Governing Law): the SCCs are governed by the law of Ireland;
- Clause 18(b) (Choice of Forum and Jurisdiction): disputes will be resolved before the courts of Ireland; and
- Annexes I, II, and III to the SCCs are populated with the information set out in Annex I, Annex II, and Annex III to this DPA, respectively.
Where Personal Data transferred is subject to the UK GDPR, the parties additionally incorporate the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner’s Office, which shall be read together with, and shall amend, the SCCs as completed above for the purposes of the relevant transfer. Where Personal Data transferred is subject to the Swiss Federal Act on Data Protection, the parties will apply the SCCs with the adaptations required for transfers from Switzerland.
Where another lawful transfer mechanism is available and applicable, including an adequacy decision or other recognized safeguard, the parties may rely on that mechanism instead.
13. California Consumer Privacy Act
This Section applies to the extent that AZIDY processes Personal Data that is subject to the CCPA. Terms used in this Section that are defined in the CCPA have the meanings given to them in the CCPA.
The parties acknowledge that Customer is a Business and that AZIDY acts as a Service Provider with respect to Personal Information processed on behalf of Customer through the Service.
AZIDY will:
- not sell or share Personal Information, as those terms are defined in the CCPA;
- not retain, use, or disclose Personal Information for any purpose other than the business purposes specified in this DPA, including outside of the direct business relationship between the parties, except as permitted by the CCPA;
- not combine Personal Information received from or on behalf of Customer with Personal Information received from or on behalf of any third party, except as permitted by the CCPA;
- comply with the obligations applicable to a Service Provider under the CCPA and provide the same level of privacy protection required of a Business by the CCPA; and
- notify Customer if AZIDY determines that it can no longer meet its obligations under the CCPA.
Customer may take reasonable and appropriate steps to help ensure that AZIDY uses Personal Information in a manner consistent with Customer’s obligations under the CCPA, and to stop and remediate any unauthorized use of Personal Information, in accordance with Section 14 of this DPA.
14. Audit and Compliance
Upon reasonable written request, AZIDY will make available information reasonably necessary to demonstrate compliance with its obligations as a Processor under this DPA.
Where required by Applicable Data Protection Laws, Customer may conduct or request an audit of AZIDY’s relevant processing activities, subject to:
- reasonable advance notice;
- reasonable confidentiality requirements;
- reasonable security requirements;
- the protection of AZIDY’s confidential information and trade secrets; and
- the audit not unreasonably interfering with AZIDY’s business operations or the security of other customers’ data.
Where appropriate, AZIDY may satisfy audit requests by providing relevant security documentation, certifications, summaries, or other available compliance materials instead of permitting an on-site audit.
Customer will bear its own costs associated with an audit unless otherwise required by Applicable Data Protection Laws.
15. Customer Responsibilities and Limitations
Customer is responsible for:
- determining the lawful basis for processing Personal Data;
- providing appropriate notices to Data Subjects;
- obtaining any required consents;
- ensuring that its instructions to AZIDY comply with Applicable Data Protection Laws;
- configuring the Service appropriately;
- determining whether Customer’s use of third-party integrations is lawful;
- responding to Data Subject requests; and
- complying with applicable laws relating to Customer’s products, services, marketing activities, and use of Personal Data.
AZIDY is not responsible for:
- Customer’s failure to comply with Applicable Data Protection Laws;
- Personal Data processed by Customer outside the Service;
- third-party services independently selected or controlled by Customer;
- Customer’s instructions that violate Applicable Data Protection Laws; or
- the acts or omissions of third parties that are not acting as AZIDY’s Sub-processors.
Except to the extent expressly required by Applicable Data Protection Laws, this DPA does not create any additional warranties, indemnities, or liability beyond those set out in the Terms. Any limitation or exclusion of liability in the Terms applies to this DPA to the same extent it applies to the Terms.
Nothing in this DPA relieves either party of obligations imposed directly upon it by Applicable Data Protection Laws.
16. General Provisions and Contact
16.1 Order of Precedence
If there is a conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA will control solely with respect to such processing.
16.2 Changes to this DPA
AZIDY may update this DPA from time to time to reflect changes in the Service, applicable law, or its data processing practices.
The current version of this DPA is published at https://bixgrow.com/dpa. Where AZIDY makes a material change to this DPA, AZIDY will notify Customer through the Service or by email to the address associated with Customer’s account.
16.3 Term
This DPA remains effective for as long as AZIDY processes Personal Data on behalf of Customer.
16.4 Governing Terms
Unless otherwise required by Applicable Data Protection Laws, this DPA is governed by the governing law and dispute resolution provisions contained in the Terms.
16.5 Contact
Questions regarding this DPA or AZIDY’s processing of Personal Data may be directed to:
AZIDY PTE. LTD
3 Coleman Street, #03-24
Peninsula Shopping Complex
Singapore 179804
Privacy Contact: [email protected]
End of Data Processing Agreement
ANNEX I TO THE STANDARD CONTRACTUAL CLAUSES
A. List of Parties
Data Exporter:
- Name: Customer, as identified in the Customer’s Service account or applicable order;
- Activities relevant to the transfer: use of the Service to operate an affiliate and referral marketing program;
- Role: Controller;
- Contact details: the email address and other contact details associated with Customer’s Service account; and
- Acceptance: Customer accepts this Annex I and the applicable SCCs electronically by accepting the Terms and/or this DPA, or by using the Service where such use constitutes acceptance of the Terms and this DPA. No separate wet-ink signature is required unless Applicable Data Protection Laws require otherwise.
Data Importer:
- Name: AZIDY PTE. LTD;
- Address: 3 Coleman Street, #03-24, Peninsula Shopping Complex, Singapore 179804;
- Activities relevant to the transfer: provision of the BixGrow affiliate and referral marketing Service, including hosting, storage, and processing of Personal Data as described in Section 3 of this DPA;
- Role: Processor; and
- Contact details: [email protected].
B. Description of Transfer
Categories of data subjects: Customer’s customers, affiliates and advocates, and website visitors, as described in Section 4 of this DPA.
Categories of personal data transferred: the categories of Personal Data described in Section 4 of this DPA (End-Customer Data, Affiliate and Advocate Data, Technical and Online Identifiers, Referral and Attribution Data, and System and Support Data).
Sensitive data transferred: none intended. Customer should not intentionally submit special categories of Personal Data to the Service, as described in Section 4 of this DPA.
Frequency of the transfer: continuous, for as long as Customer uses the Service.
Nature of the processing: the processing activities described in Section 3 of this DPA, including hosting, storage, transmission, tracking, calculation, reporting, and support activities necessary to provide the Service.
Purpose of the transfer and further processing: the purposes described in Section 5 of this DPA.
Duration of processing: for the duration described in Section 3 of this DPA.
For transfers to (sub-)processors, also specify subject matter, nature, and duration of the processing: as set out in Annex III to this DPA.
C. Competent Supervisory Authority
The competent supervisory authority will be determined in accordance with Clause 13 of the SCCs, based on the EU/EEA Member State in which Customer’s representative is established or, where no such representative is required, the Member State in which the data subjects whose Personal Data is transferred are primarily located.
ANNEX II TO THE STANDARD CONTRACTUAL CLAUSES
Technical and Organisational Measures
AZIDY implements the following technical and organisational measures, in accordance with Section 8 of this DPA, to ensure a level of security appropriate to the risk:
- Encryption: encryption of Personal Data in transit using industry-standard protocols (e.g., TLS), and encryption at rest of End-Customer Data obtained through the Shopify platform;
- Confidentiality: contractual confidentiality obligations imposed on personnel authorized to process Personal Data, and access restricted to personnel on a need-to-know basis;
- Integrity: access controls and authentication mechanisms designed to prevent unauthorized modification of Personal Data;
- Availability and resilience: use of secure cloud infrastructure with built-in redundancy, together with backup and recovery procedures;
- Ability to restore availability and access: backup and disaster recovery procedures designed to restore access to Personal Data in a timely manner following a physical or technical incident;
- Testing and monitoring: logging and monitoring of relevant systems and periodic review of security measures and access logs;
- User identification and authorization: unique credentials for personnel accessing systems processing Personal Data, and role-based access controls;
- Support access: AZIDY makes Customer accounts accessible only to authorized support personnel, and only as necessary to respond to support requests, diagnose errors, verify configuration, or maintain and provide the Service; such access is logged;
- Data minimization and storage limitation: collection of Personal Data limited to the categories described in Section 4 of this DPA, and retention consistent with Section 10 of this DPA;
- Incident response: documented procedures for detecting, investigating, containing, and notifying Personal Data Breaches, as described in Section 11 of this DPA;
- Accountability: maintenance of records of processing activities and this DPA, and internal policies governing the handling of Personal Data; and
- Sub-processor oversight: imposition of data protection obligations on Sub-processors that are no less protective than those set out in this DPA, as described in Section 6.
For transfers to Sub-processors, the technical and organisational measures to be implemented by the Sub-processor are those Sub-processor’s own applicable security measures, which AZIDY has assessed as providing a level of protection appropriate to the nature of the Personal Data and the risk of the processing.
ANNEX III TO THE STANDARD CONTRACTUAL CLAUSES
List of Sub-processors
Customer authorizes the engagement of the Sub-processors listed in Section 6 of this DPA (and any additional Sub-processors engaged in accordance with the notice and objection procedure described in Section 6), as follows:
| Sub-processor | Purpose / Subject Matter | Processing Location | Duration |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, infrastructure, and delivery of emails sent on Customer’s behalf to affiliates, advocates and customers (Amazon SES) | United States / AWS us-west-2 | Duration of this DPA |
| Crisp | Customer support and communications | As determined by Crisp | Duration of this DPA |
The current, up-to-date list of Sub-processors is set out in Section 6 of this DPA, as published at https://bixgrow.com/dpa.