SectionheroesSectionheroes
HomeHelpdeskRoadmapDemo
Install on ShopifyStatus
ENDE

Last updated: 31 July 2026

Data Processing Annex (AVV)

This page reproduces the Data Processing Annex that forms an integral part of our Terms of Service and is accepted upon installing or continuing to use the App. It is provided here as a standalone document so that merchants can file it for their own data-protection records. The version contained in the Terms of Service is the binding instrument.

This Data Processing Annex (“Annex”) forms part of the Terms of Service between Martins Alves, Julian & Lücking, Joel GbR (“Processor”, “Sectionheroes”) and the Merchant (“Controller”) and governs the processing of personal data by Sectionheroes on behalf of the Merchant pursuant to Art. 28 GDPR. It is accepted by installing or continuing to use the App.

A.1 Subject matter, duration, nature and purpose

Subject matter: provision of those App features that involve personal data of the Merchant’s store visitors and customers (“End Customers”), in particular the built-in analytics feature and the rendering of personalized elements within sections, bundles, and upsells.

Duration: the term of the Terms of Service. This Annex ends when the App is uninstalled and the data has been deleted in accordance with Section A.8.

Nature and purpose: collection, storage, and transmission of End Customer data strictly as needed to render the features, measure their performance, and provide aggregated reporting to the Merchant.

Scope of the AI Hub: the AI Hub processes product and store configuration data submitted by the Merchant on request. It does not process End Customer data. Where product data submitted by the Merchant contains personal data in an individual case, the provisions of this Annex apply to that processing accordingly.

A.2 Categories of data and data subjects

Data subjects: visitors and customers of the Merchant’s online store.

Categories of personal data:

  • pseudonymous usage data (random session identifier where applicable, interaction events, store domain, timestamps, technical device and browser information);
  • cart and order references where required for the feature (order number, items included, order value);
  • where the Merchant connects Klaviyo for the customer-timeline feature: the End Customer’s email address and the subject/name of the campaigns or flows they received.

No special categories of data (Art. 9 GDPR) are intentionally processed.

A.3 Instructions

Sectionheroes processes End Customer data only on documented instructions from the Merchant. The Terms of Service, this Annex, and the Merchant’s configuration of the App constitute the Merchant’s instructions. Sectionheroes will inform the Merchant if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

A.4 Confidentiality

Sectionheroes ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

A.5 Security (Art. 32 GDPR)

Sectionheroes implements appropriate technical and organizational measures. These are described in a separate TOM annex, made available in its current version upon request. They include in particular: encryption of data in transit and at rest; access controls and authentication for production systems, with access limited to authorized personnel; separation of production and development environments; logging and monitoring of production systems; and regular review of the measures.

A.6 Sub-processors

The Merchant grants general authorization for the engagement of the sub-processors listed in the Privacy Policy. Sectionheroes will inform Merchants of intended additions or replacements of sub-processors (in the App or by email), giving the Merchant the opportunity to object on reasonable data protection grounds. If an objection cannot be resolved, the Merchant may terminate by uninstalling the App. Sectionheroes imposes data protection obligations on sub-processors that are substantially equivalent to those in this Annex.

AI sub-processor: for the AI Hub feature, Sectionheroes engages Anthropic PBC (United States) as a sub-processor. Data submitted through this feature is transmitted to Anthropic solely for the purpose of generating the requested analysis or content suggestion and is not used by Anthropic to train its models. The transfer is safeguarded in accordance with Section A.7.

A.7 International transfers

Where processing involves transfers to countries outside the EU/EEA without an adequacy decision, Sectionheroes ensures appropriate safeguards pursuant to Art. 44 ff. GDPR, in particular the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

A.8 Deletion and return

Upon uninstallation of the App or termination of the Terms, Sectionheroes deletes the End Customer data processed on the Merchant’s behalf (order analytics and, where applicable, customer-timeline data), unless statutory retention obligations require otherwise. Sectionheroes honors Shopify’s GDPR compliance webhooks:

  • upon a shop/redact request, the store’s End Customer data is deleted;
  • upon a customers/redact request, the personal data held about the identified End Customer (in particular customer-timeline data) is deleted;
  • upon a customers/data_request, Sectionheroes compiles the data it holds about the requesting End Customer and provides it to the Merchant so that the Merchant can respond to the request.

Aggregated bundle and upsell analytics is stored pseudonymously and cannot be linked to an individual End Customer; it is deleted at store level on uninstallation or shop/redact.

A.9 Assistance

Taking into account the nature of the processing, Sectionheroes assists the Merchant with appropriate technical and organizational measures in fulfilling data subject rights (Art. 12–23 GDPR) and in complying with Art. 32–36 GDPR (security, breach notification, data protection impact assessments), insofar as the Merchant cannot do so via the App itself.

A.10 Personal data breaches

Sectionheroes notifies the Merchant without undue delay after becoming aware of a personal data breach affecting End Customer data processed under this Annex, providing the information required by Art. 33(3) GDPR as it becomes available.

A.11 Audits

Sectionheroes makes available the information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Merchant or an auditor mandated by the Merchant, at reasonable intervals, upon reasonable notice, and at the Merchant’s expense. Sectionheroes may satisfy audit requests by providing current certifications, audit reports, or written self-assessments where appropriate.

A.12 Liability

The liability provisions in Section 9 of the Terms of Service apply to this Annex accordingly, unless Art. 82 GDPR mandatorily provides otherwise.

A.13 Miscellaneous

In case of conflict between this Annex and the remainder of the Terms of Service, this Annex prevails with respect to data protection. German law applies; Sections 11 and 12 of the Terms of Service apply accordingly.

Contact for data protection matters: support@sectionheroes.com

SectionheroesSectionheroes

Sectionheroes helps Shopify merchants Build better stores. Faster. Sections, Blocks, Bundles and upsells — with built-in analytics.

Legal
ImprintPrivacy policyTerms of ServiceData Processing AnnexContact
Sites
HelpdeskRoadmapDemoStatus
2026 © Sectionheroes ‒ Sectionheroes is an independent application and is not affiliated with, endorsed by, or sponsored by Shopify Inc. Shopify® is a registered trademark of Shopify Inc.