Data Processing Agreement

Version 1.0 — Last updated: 22 July 2026

This Data Processing Agreement ("DPA") forms part of the BorderLens Terms of Service for merchants that use BorderLens. It applies where BorderLens processes personal data on behalf of a merchant.

1. Parties and roles

The merchant is the controller of personal data contained in its carrier invoices, Shopify order data, customs declarations, and related trade records. Adam Dyerson, trading as BorderLens, is the processor for that merchant data.

BorderLens is the controller for its own account, billing, support, and website contact data.

2. Subject matter and purpose

BorderLens processes merchant data to provide cross-border duty, tax, shipping, and carrier-invoice reconciliation. This includes ingestion, parsing, classification, pseudonymisation, matching, reconciliation, storage, and limited operator review.

BorderLens does not process merchant customer data for advertising, resale, customer profiling, or cross-merchant analysis.

3. Categories of data

The data may include merchant staff account identifiers, order and shipment records, customs declaration metadata, and end-customer names or limited route signals present in carrier invoices or Shopify orders.

BorderLens does not intentionally process special category data or criminal offence data. Merchants must not upload such data to the service.

4. Data minimisation

BorderLens minimises end-customer personal data by design. Shopify customer names are processed transiently during ingestion and immediately normalised and hashed using SHA-256 for matching. Readable Shopify customer names are not stored as order identifiers or displayed in merchant-facing UI.

Address handling is limited to route and matching signals needed for reconciliation. BorderLens does not use Shopify billing addresses or street address lines for reconciliation.

5. Processor obligations

BorderLens will:

  • process merchant personal data only on documented merchant instructions;
  • keep merchant data confidential;
  • apply appropriate technical and organisational security measures;
  • assist merchants with data-subject access, erasure, restriction, and portability requests;
  • notify affected merchants without undue delay after becoming aware of a personal data breach;
  • delete or return merchant personal data at the end of the service, unless legal retention is required;
  • make reasonable compliance information available to merchants on request.

6. Security measures

BorderLens uses TLS in transit, Google Cloud encryption at rest for database and file storage, Secret Manager for production secrets, tenant-scoped data access, restricted operator access, audit logging for cross-tenant operator access, and automated Cloud SQL backups with point-in-time recovery.

The current security process is summarised on the Security page and in internal operating runbooks.

7. Subprocessors

BorderLens uses subprocessors for hosting, authentication, document processing, and limited advisory analysis. Each subprocessor is subject to appropriate data processing terms. Merchants may request the current subprocessor list by emailing [email protected].

BorderLens will notify merchants at least 30 days before adding a new subprocessor that processes merchant trade data.

8. International transfers

Primary storage and processing are in Google Cloud's EU region. Where a subprocessor processes data outside the UK or EU, BorderLens relies on appropriate safeguards such as Standard Contractual Clauses or the UK International Data Transfer Addendum.

9. Retention and deletion

Merchant data is retained for the duration of the active subscription, then deleted on account closure unless legal retention is required. Unconfirmed upload files are deleted after 30 days. Source carrier invoice files retained for evidence review are retained for up to 6 months unless deleted earlier on account closure.

Data export and deletion requests can be made by emailing [email protected].

10. Contact

For questions about this DPA or merchant data processing, email [email protected].