VIP Alert

Data Processing Agreement · Updated July 22, 2026

Data Processing Agreement

This Data Processing Agreement (DPA) forms part of the agreement between the merchant who installs VIP Alert (the Controller) and Taylor Sicard Consulting, operator of VIP Alert (the Processor, we). It governs the Processor's processing of personal data on the Controller's behalf and reflects the requirements of Article 28 of the EU and UK General Data Protection Regulation (GDPR). By installing and using VIP Alert, the Controller agrees to this DPA. To execute a countersigned copy, contact us at the address below.

1. Roles and scope

The merchant is the Controller of their customers' personal data. VIP Alert acts as a Processor, processing that data only to provide the service. Where we engage third parties who process the data on our behalf, they act as sub-processors. Shopify is an independent controller or processor for the merchant under its own terms and is not a sub-processor under this DPA.

2. Subject matter, nature, and purpose

We process personal data to identify and classify the Controller's customers (VIP, business, and public-figure detection), score and grade them, and return results to the Controller. Processing lasts for as long as the Controller uses the app, plus the limited retention described below.

3. Categories of data and data subjects

4. Processor obligations

5. Sub-processors

The Controller provides general authorization for us to engage the sub-processors below. We remain responsible for their compliance and will give notice of any intended additions or replacements so the Controller may object on reasonable data-protection grounds.

Wikipedia and Wikidata are queried as public sources using only a customer's name and locality; they do not act as sub-processors holding data on our behalf.

6. Security measures

7. Retention and deletion

8. International transfers

Sub-processors are located in the United States. Where personal data is transferred out of the EU, UK, or other regulated regions, the transfer relies on an appropriate safeguard such as the Standard Contractual Clauses, incorporated by reference into this DPA.

9. Data breach

We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, with the information the Controller reasonably needs to meet its own obligations.

10. Term and changes

This DPA remains in effect while VIP Alert is installed. We may update it to reflect changes in law or our sub-processors, and will post the updated version here with a revised date.

Contact

Data-protection questions, audit requests, or to request a countersigned copy: VIPalert@taylorsicard.com. See also our privacy policy and support page.