Data Processing Agreement
Last updated: 20 July 2026
This Data Processing Agreement (the "DPA") forms part of, and supplements, the Howzit Terms of Service between you (the Shopify merchant, the "Controller") and Mika Dekker, trading as AskMario, the operator of Howzit (the "Processor"). It governs the Processor's processing of personal data on the Controller's behalf when the Controller uses Howzit. Where this DPA conflicts with the Terms of Service on the subject of personal data processing, this DPA prevails.
1. Parties and roles
Howzit is a South-Africa-focused SMS marketing application for Shopify, operated by Mika Dekker (trading as AskMario), website askmario.co.za, contact mika@askmario.co.za.
- The Controller is the Shopify merchant who installs and uses Howzit. The Controller determines the purposes and means of processing its own customers' personal data.
- The Processor is Howzit (Mika Dekker, trading as AskMario). Howzit processes personal data only on behalf of, and on the documented instructions of, the Controller.
Each party is responsible for complying with the data protection laws that apply to it. Under this DPA, the applicable frameworks include POPIA (the Protection of Personal Information Act, South Africa), the GDPR (EU and EEA, where relevant), and CPA and WASPA rules governing SMS marketing.
2. Definitions
- Personal data means any information relating to an identified or identifiable natural person that the Processor processes on the Controller's behalf under this DPA.
- Data subject means the individual to whom personal data relates, namely the Controller's customers and message recipients.
- Processing means any operation performed on personal data, such as collection, storage, use, transmission, and deletion.
- Controller and Processor have the meanings given in section 1, and are equivalent to "responsible party" and "operator" respectively under POPIA.
- Subprocessor means a third party engaged by the Processor to process personal data on the Controller's behalf.
- Personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
- Terms not defined here have the meaning given in the Terms of Service or in applicable data protection law.
3. Details of processing
Nature of processing. The Processor sends SMS marketing (campaigns and automations, including abandoned-checkout recovery, welcome, post-purchase, and winback messages); operates a two-way conversational inbox for customer service; captures and manages marketing consent; and produces revenue attribution and reporting.
Purpose of processing. To enable the Controller to run SMS marketing to its own customers, respond to inbound replies, maintain accurate consent records, and measure results. The Processor does not use the Controller's personal data for its own independent purposes.
Duration. Processing continues for as long as the Controller uses Howzit, subject to the automated retention and purge schedule described in section 10 and to deletion on termination.
Categories of data subjects. The Controller's customers and other individuals who receive, reply to, or interact with SMS messages sent through Howzit.
Categories of personal data. The Processor processes:
- customer first and last name;
- mobile phone number in E.164 format;
- SMS marketing consent state and consent records (source and timestamp);
- optional email address;
- limited order data (order total and checkout token) used for abandoned-checkout recovery and revenue attribution;
- inbound SMS replies.
The Processor does not process payment details or postal addresses. The Processor does not sell personal data and does not carry out automated decision-making that produces legal or similarly significant effects.
4. Processor obligations
The Processor undertakes to:
- Process only on documented instructions. Process personal data solely on the Controller's documented instructions, including as set out in this DPA and the Terms of Service and as given through the Howzit application, unless required to act otherwise by applicable law.
- Confidentiality. Ensure that any person authorised to process the personal data is bound by confidentiality. Access is limited to individual accounts, with no shared logins.
- Security. Implement and maintain the technical and organisational measures described in section 6.
- Assist with data subject requests. Assist the Controller in responding to requests from data subjects to exercise their rights, honoured through Shopify's mandatory privacy webhooks: customers data-request (compile an export), customers redact (delete a customer's data), and shop redact (delete all of a shop's data). The nightly retention purge additionally enforces data minimisation.
- Assist with breach notification. Assist the Controller in meeting its breach notification and related obligations, as described in section 8.
- Delete or return on termination. Delete or return personal data at the end of the engagement, as described in section 10.
- Consent and opt-out. Send only to subscribed contacts; include a free opt-out ("Reply STOP") in every message; process STOP to unsubscribe, suppress, and write the opt-out back to Shopify; support optional double opt-in (reply YES to confirm); and provide a suppression list merchants can add numbers to. WASPA Do-Not-Contact screening is applied to outbound traffic by our network provider.
5. Subprocessors
The Controller authorises the Processor to engage the following subprocessors to deliver the service:
- Shopify — platform and source of the merchant's data.
- SMSPortal — SMS gateway, South Africa.
- Neon — managed PostgreSQL database, hosted on AWS eu-central-1 (Frankfurt), encrypted at rest including backups.
- Fly.io — application hosting, Frankfurt region ("fra").
The Processor imposes on each subprocessor data protection obligations consistent with this DPA. If the Processor intends to add or replace a subprocessor, it will inform the Controller, and the Controller may object on reasonable data protection grounds. Where an objection cannot be resolved, the Controller may terminate its use of Howzit as its remedy.
6. Technical and organisational security measures
The Processor maintains the following measures:
- Encryption in transit. TLS everywhere: sslmode require to the database, HTTPS and force_https to the application, and HTTPS to SMSPortal.
- Encryption at rest. AES-256 encryption at rest via Neon, including backups.
- Secrets management. Secrets are stored in Fly secrets and never committed to code.
- Suppression hashing. Phone numbers in the suppression list are stored only as SHA-256 hashes.
- Anti-phishing. Outbound message text is URL-stripped so that only Howzit's own tracked link is sent.
- Access control. Admin access is via authenticated Shopify session tokens. Cron endpoints use a timing-safe shared secret and fail closed.
- Account security. Individual accounts with 2FA on Shopify, Neon, and Fly, and no shared logins.
- Environment separation. Test and production data are kept separate: production uses a dedicated Neon project, while development uses synthetic data and SMSPortal test mode.
- Logging. Access to customer data flows through Shopify's Admin API (logged by Shopify), together with Fly and Neon platform logs.
7. International transfers and data residency
Personal data processed through Howzit is hosted in the EU (Frankfurt, via Neon on AWS eu-central-1 and Fly.io region "fra") and in South Africa (via the SMSPortal SMS gateway). This data residency is aligned to POPIA and the GDPR. By using Howzit, the Controller instructs and authorises these transfers as necessary to provide the service. Data at rest in the EU is encrypted, including backups, and all transfers occur over encrypted connections as described in section 6.
8. Personal data breach notification
On a suspected personal data breach, the Processor will rotate or revoke affected credentials (Fly secrets, the Neon role, and the Shopify API secret), assess the scope from available logs, and notify affected merchants and the South African Information Regulator within the applicable window. The Processor will provide the Controller with the information reasonably available to it to assist the Controller in meeting its own notification obligations to data subjects and regulators.
9. Audit and information rights
The Processor will make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, including the details of processing, subprocessors, and security measures set out above. On reasonable prior written request, and no more than once per year unless required by a supervisory authority or following a personal data breach, the Processor will respond to reasonable questions relating to its processing under this DPA. Audit rights are exercised in a manner that respects the confidentiality and security of the Processor's systems and those of its subprocessors.
10. Deletion and return on termination
The Processor operates an automated nightly purge that enforces the following retention rules:
- unconfirmed contacts deleted after 30 days;
- opted-out contacts' personal information scrubbed 30 days after opt-out (the legal consent record is retained as proof of opt-out);
- delivery and engagement events kept 365 days;
- webhook receipts kept 7 days;
- data-request exports kept 90 days;
- completed message jobs kept 180 days;
- uninstalled shops purged after 35 days.
On termination or uninstall, the Processor will delete the Controller's personal data in accordance with the schedule above, and will honour customer and shop redaction requests received through Shopify's privacy webhooks. Where the Controller requires a return of data before deletion, it may request an export while its account remains active. Legal consent records may be retained only as proof of consent and opt-out, and for no longer than necessary.
11. Governing law
This DPA is governed by the laws of South Africa and is to be read consistently with POPIA, and, where applicable, the GDPR and CPA and WASPA rules for SMS. This DPA supplements the Howzit Terms of Service; all other terms of that agreement remain in full force.
Questions? Contact mika@askmario.co.za.