Larchline

Data Processing Agreement

App
Larchline DATEV Export (the "app"), published under the Larchline brand.
Version 1.0, 2026-09-23.
Effective from the day the app is listed on the Shopify App Store.

This agreement is part of the Terms of Service of the app. It applies from the moment you install the app and governs the personal data we process for you under Article 28(3) of the GDPR. The English text is the binding one. A German translation is provided for convenience.

We change this agreement only after telling you at least 30 days before. If you do not agree, you can end it by uninstalling the app before the change applies. If your business needs a signed copy, write to support@larchline.co and we send one.

How we tell you. Where this agreement says we tell you something, you get the same notice in two places. The app shows it on every page until you mark it read. It stops showing 30 days after the change takes effect, or 60 days after we post it when it names no date. We also send it by email to the address Shopify holds for your store, when Shopify gives us one. The sender is noreply@larchline.co, and you can reply to support@larchline.co. The Privacy Policy says how we handle that address.

1. Parties

  • Controller: the merchant who installs the app, identified by its store's myshopify.com address ("you").
  • Processor: Scena Labs LLC, a limited liability company in Washington State, 522 W Riverside Ave, Ste N, Spokane, WA 99201, United States, support@larchline.co ("we", "us"). Contact for data protection: the owner of Scena Labs LLC, at support@larchline.co.

You accept this agreement when you install the app and accept the Terms of Service.

2. Subject matter and duration

We make booking batches in the DATEV format from your Shopify orders and refunds. We keep a record of each closed month and a receipt of each file. We hand a file to whoever opens a link you made for your tax adviser, and we act on Shopify's privacy notices for your store. This agreement lasts as long as the app is installed, and after that until we have deleted the data as section 9 says.

3. Nature and purpose

When you, your staff or your tax adviser download a file, we read the month's orders and refunds from Shopify. We write what the batch needs into a file. The file is sent to the browser that asked for it and not kept. We store the record of each closed month and a receipt of each file, so you and your tax adviser can prove which file went out. They hold counts, totals and checksums, and no order data. We process the data for no other purpose.

When you make a link for your tax adviser, you instruct us to hand the month's file to whoever opens that link while it works. You choose who receives the link. Your tax adviser receives the file from you and is not our sub-processor.

The transfer is continuous: data reaches us each time a file is made. You are responsible for having a lawful basis for this processing, including passing the file to your tax adviser, and for telling your customers about it. You may give us further instructions in writing, by email, at any time.

4. Data subjects and data

PeopleDataKept
Your customersShopify's order and refund identifiers, order numbers, dates, amounts, tax lines and fulfilment datesRead when a file is made, not stored
Your customersOrder numbers in the file's voucher field and booking text, with dates and amountsIn the file. It goes to your browser or through your link, and we keep no copy
Your customersShopify's customer number in a privacy notice Shopify sends usRead when the notice arrives, not stored
Your staff and customers named in an email to usWhatever the email contains.In the support mailbox, until you ask us to delete it, at most 24 months

No special categories of data (Article 9 GDPR) are processed. The app does not read your customers' names, addresses, email addresses, phone numbers or VAT IDs, and stores nothing about your staff.

5. Our obligations

  • Instructions. We process the data only on your documented instructions. These terms, your settings and your clicks in the app are those instructions, and they include the transfers in section 8. If a law of the European Union or a member state requires other processing, we tell you before, unless that law forbids it. If we think an instruction breaks data protection law, or we cannot follow it, we tell you at once.
  • Confidentiality. Only the two people who run the app can reach the data, and only as far as their work on the app needs it. Both are committed to keep it confidential. The AI tool they build and run the app with works under the written rule in section 6 and never reads the data.
  • Security. We keep the measures in section 6 in place. We check them at least once a year and after any incident, and improve them when a risk calls for it.
  • Sub-processors. We use only the sub-processors in section 7, under the rules there.
  • Your customers' rights. We help you answer requests from your customers. Shopify's privacy notices reach us directly and we act on them as the Privacy Policy describes. For any other request, write to us and we help without undue delay.
  • Your other duties. We help you with security, breach notices, impact assessments and consultations with an authority, as far as our part of the processing allows.
  • Breaches. We tell you without undue delay, and at the latest within 48 hours after we become aware of a personal data breach that affects your data. We tell you what we know: what happened, which data, and roughly how many people and records. We also tell you the likely effects, what we have done and plan to do, and who to contact for more. We add facts as we learn them. You decide whether to notify an authority or your customers.
  • Information and audits. We give you the information you need to show that we meet this agreement. If that is not enough, you may audit us, yourself or through an auditor bound to confidentiality. Ask in writing at least 30 days before. Audits take place at reasonable intervals, or sooner if there are signs that we do not meet this agreement. Each side bears its own costs.

6. Security measures

  • No data about your customers is stored. Files are made in memory and sent to the browser, not written to disk, a database or a cache.
  • The app's order query asks for no name, address, email address, phone number or VAT ID. A check in the code stops the query before it reaches a store if it ever would. The app does not read Shopify's customer records.
  • Data travels encrypted: the app is served over https only and reaches its database through Google's encrypted connector. The database and its backups are encrypted at rest.
  • The database is backed up daily and backups are kept for 7 days, so it can be restored.
  • The app's own Shopify key and the database password are kept in Google Secret Manager, never in code. Each store's Shopify access token is kept in the app's database, which is encrypted at rest.
  • Test and production are separate: separate app records, databases, secrets and servers. Test data comes from a test store only.
  • The app's server accounts can reach only the database and the secrets they need. A file leaves the app only to a signed-in session of your store, or through a link you made on the Pro plan. A link works only with its secret, which is shown to you once and never stored; only its checksum is. A link stops working after 30 days at most, and when you withdraw it, reopen its month or uninstall the app. While your store is below the Pro plan, no link works. If a link is opened in that time, or a month's page is viewed in the app, every link of your store stops working for good.
  • Nothing about the person who opens a link is stored: no network address, no browser details, no name.
  • The database can be reached only through Google's sign-in.
  • Two-factor sign-in is on for the Google Cloud, Shopify Partner and Microsoft 365 accounts.
  • A written rule binds the AI tool the operators build and run the app with. It never reads the personal data this agreement covers, from any source: email, logs, the database or screenshots. It acts only through the operators' own Google sign-in and works with counts and test data.
  • Logs hold identifiers, numbers and counts, such as a keyed tag that stands for the store, the month, file sizes and checksums. The app's logger refuses a name, an address, a customer number and a staff user number. The address of a request is logged without anything after a question mark, so a link's secret never reaches a log. Lines that Node or React Router write by themselves are kept as they are written, outside that rule. The history of each month records what was done to it and when, and Google Cloud records administrative actions on the project.
  • A written incident procedure covers personal data breaches, including the 48-hour notice to you.

7. Sub-processors

You give us general written authorisation to use sub-processors. We use these today:

Sub-processorWhat it doesWhere
Google LLC (Google Cloud)Hosting, database, backups and technical logsBelgium (europe-west1); backups in the European Union
Microsoft Corporation (Microsoft 365)Support email. Your customers' data reaches it only if you or a customer put it in an email to usMay include the United States

Shopify is not a sub-processor. Shopify holds your store's data under your own agreement with Shopify. When a file is made, the app receives from Shopify, over an encrypted connection, the order data that file needs.

Your tax adviser is not a sub-processor either. You choose to send your tax adviser a link, and your tax adviser receives the file from you.

The company that sends the notice emails in the introduction is not a sub-processor under this agreement. Those emails carry the address Shopify holds for your store and the notice text. They carry none of your customers' personal data. The Privacy Policy names that company and says where it keeps the emails.

We tell you at least 30 days before we add or replace a sub-processor, in the way the introduction describes. You may object in that time. If we cannot resolve your objection, you may end this agreement by uninstalling the app. Each sub-processor is bound by a written contract with the same data protection obligations as this agreement. We remain fully liable to you for their work. On request we send you a copy of those terms, with confidential parts removed.

8. Transfers outside the European Union

We are a company in the United States. The app runs in Belgium. You make the data available to a United States company, and the people who run the app can reach the app's systems from the United States. So the rules on transfers apply.

For any transfer of personal data from the European Economic Area to us, the European Commission's standard contractual clauses apply and are part of this agreement. These are the clauses of Implementing Decision (EU) 2021/914, Module Two (controller to processor). You are the data exporter and we are the data importer. The choices in the clauses are:

  • Clause 7 (docking clause): not used.
  • Clause 9(a): option 2, general written authorisation, with the 30 days' notice in section 7.
  • Clause 11(a): the optional wording is not used.
  • Clause 13: the supervisory authority of the EU member state where you are established.
  • Clause 17: option 2, the law of the EU member state where you are established. Where that law does not allow third-party beneficiary rights, the law of Ireland.
  • Clause 18: the courts of the EU member state where you are established.
  • Annex I is sections 1 to 4 of this agreement, Annex II is section 6 and Annex III is section 7.

Clause 14 of those clauses asks both sides to look at the law of the United States for these transfers and to write down what they found. We have written down our assessment. Write to support@larchline.co and we send it to you.

If the European Commission adopts standard contractual clauses for importers that are themselves subject to the GDPR, those clauses replace these, and we tell you.

For transfers from Switzerland, the same clauses apply. The Swiss Federal Data Protection and Information Commissioner is the authority. The Swiss Federal Act on Data Protection is read in place of the GDPR where it applies. For transfers from the United Kingdom, the International Data Transfer Addendum issued by the UK Information Commissioner applies. If the clauses conflict with this agreement or the terms, the clauses win.

9. End of processing

When you uninstall the app, the access token and every link for your tax adviser are deleted at once. Everything else is deleted when Shopify sends us the removal notice, 48 hours after you uninstall. One record stays: that the notice was handled, with your store's web address, the kind of notice and its date, so the same notice is not processed twice. We delete that record at the earliest 23 days after it arrives, and in any case within 30 days of its arrival. The record of the removal notice is deleted within 30 days after you uninstall. You can ask us to delete the rest sooner. Deleted data leaves our encrypted backups within 8 days. When the deletion is done, we confirm it to you by email if you ask.

We keep no copy of your files and store no personal data of your customers, so there is none to return. If you want your settings, your mapping or the receipts of your files, write to us before you uninstall and we send them to you. Support emails that contain your customers' data are deleted when you ask, and otherwise within 24 months.

10. Liability and precedence

The limitation of liability in the Terms of Service applies to this agreement, to the extent the law allows. It does not limit liability under the standard contractual clauses in section 8. This agreement is governed by the law chosen in Clause 17 of those clauses, and disputes about it go to the courts chosen in Clause 18. On data protection, this agreement takes precedence over the rest of the terms.