Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Douglas Anthony Silkstone, trading as Benson ("Processor", "Benson") and the business using Benson ("Controller", "you"). It applies when Benson processes personal data on your behalf under the UK GDPR, the EU GDPR, or similar laws.
Roles and scope#
You're the controller of personal data collected through Benson on your storefronts. Benson is your processor and processes it only to provide the service, on your documented instructions. These terms, your configuration in the Benson dashboard, and your support requests are your instructions.
Our obligations#
Benson will:
- process personal data only on your instructions, unless the law requires otherwise (and then tell you, if allowed);
- make sure everyone with access is bound by confidentiality;
- apply the security measures in Annex 2;
- use subprocessors only as set out below;
- help you respond to data subject requests and meet your obligations on security, breach notification and impact assessments, taking into account the nature of the processing;
- notify you without undue delay, and within 48 hours, after becoming aware of a personal data breach affecting your data;
- delete or return personal data at the end of the service, as set out below;
- make available the information needed to show compliance, and allow reasonable audits (normally satisfied by our written responses and reports, at most once a year, with 30 days' notice).
Your obligations#
You'll make sure you have a lawful basis for the processing, show shoppers an accurate privacy notice, configure consent settings appropriate to your store (including making sure your consent banner covers the installed-extension check, if you turn it on; your per-site setting for that check is your instruction to us), and not send Benson special category data or direct identifiers in custom fields.
Subprocessors#
You authorise Benson to use the subprocessors listed here. We'll give at least 30 days' notice of any new subprocessor by updating this page and emailing workspace owners; you can object on reasonable data protection grounds, and if we can't address the objection you can end the affected service.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Railway Corporation | Application hosting, databases and queues | All service data (accounts, workspace settings, storefront events, orders) | EU (Netherlands data centre); US company |
| Cloudflare, Inc. | DNS, content delivery of the storefront script, file storage | Request metadata (IP address transiently), the public script, exports | Global edge network; US company |
| Resend (Plus Five Five, Inc.) | Transactional and notification email | Recipient email address, email content | US |
| Loops, Inc. | Lifecycle and product email (set-up tips, product news) | Account holder name and email, workspace name and role, plan and set-up progress | US (standard contractual clauses) |
| Stripe Payments Europe, Ltd.Workspaces that pay by card | Card payments and invoicing | Billing contact, payment details (held by Stripe), invoices | EU and US |
| Shopify International LimitedStores that install the Shopify app | App platform and billing for Shopify-installed stores | Shop domain, app subscription, order and discount data you let the app read | Ireland; global |
We impose data protection terms on each subprocessor that are at least as protective as this DPA, and remain responsible for them.
International transfers#
Where personal data is transferred outside the UK or EEA, we rely on adequacy decisions or the standard contractual clauses (with the UK addendum), which are incorporated into this DPA by reference.
Deletion and export#
- You can export your workspace data at any time from Settings → Data. The export link expires after a short period.
- When you delete a workspace, Benson deletes its personal data from live systems, then from backups on their normal rotation. Deletion is logged.
- Otherwise, data is kept for the periods in the Privacy Policy and deleted by automated jobs.
Annex 1: Processing details#
| Processing | Details |
|---|---|
| Subject matter | Measuring coupon and similar browser extensions on the controller's storefront, hiding their pop-ups by rule, applying checkout code policies, and showing the controller's discount widget |
| Duration | The term of the subscription, plus the retention periods above |
| Nature and purpose | Collection, storage, aggregation, analysis and deletion, to provide the service |
| Data subjects | Visitors to the controller's storefront; shoppers who give the widget an email address |
| Categories of data | Random session and visitor ids; page, device and country (from transient IP); extensions detected; device characteristics: installed coupon and cashback browser extensions (matched names only), where the controller turns on the installed-extension check; widget interactions; discount codes used; order totals; landing and campaign parameters; email addresses given to the widget, if enabled |
| Special categories | None |
| Frequency | Continuous, while the Benson script runs on the storefront |
Annex 2: Security measures#
- Encryption in transit (TLS) for all traffic, and encryption at rest for sensitive fields such as tokens and email addresses.
- Tenant isolation: every query is scoped to one workspace, with database row-level security as a backstop and tests that check cross-workspace access fails.
- Least-privilege access for staff, with every staff access logged and reviewed.
- IP addresses used only transiently and never stored; rate-limit keys are keyed hashes.
- Automated backups, retention jobs, dependency and security review, and an incident response process.
Contact#
Questions about this DPA: [email protected].

