Fasty Connector Data Processing Addendum
Last updated: August 13, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the Shopify merchant (“Merchant”) and FIRMA LUI ADI SRL, Romania (“Processor”) for use of Fasty Connector.
Processor: FIRMA LUI ADI SRL, CUI RO47956859, Aleea Detunata 13, Cluj-Napoca, Cluj 400434, Romania. Contact: fastyconnector@gmail.com.
Instructions and purpose
Processor handles customer data only on Merchant's documented instructions to create and manage Speedy shipments. Processing is limited to order identifiers, recipient name, address, phone, email when required for international delivery, and the pickup point a customer selects when Merchant offers office or locker delivery.
Where Merchant enables automatic AWB creation, Merchant's instruction is the configuration they set in the app: the waiting period, the qualifying payment types and destinations, the per-run ceiling, and whether carrier address confirmation is required. Processor stores only the order identifier, order name, and scheduled time for that purpose, and reads the order's personal data from Shopify at the moment of processing.
Where Merchant creates a return AWB, Merchant's instruction is to send that customer's name, address, phone and email to Speedy as sender of the return, and, where Merchant emails the label, to deliver the message to that customer. Processor stores the order identifier, order name, AWB number, quoted price, chosen cost bearer, and the customer's email address for that order until the return record or the shop's data is deleted.
Where Merchant enables Fasty to act on Shopify's return flow, Merchant's instruction is the configuration they set in the app: whether an approved return creates a carrier AWB, and whether a customer's request is approved without Merchant. Processor reads the return and its order from Shopify at the moment of the event and returns the label and tracking number to Shopify, which notifies the customer.
Where Merchant uses the in-app support assistant, Merchant's instruction is the question they type. Processor sends that question, the conversation so far, and a generated summary of Merchant's own configuration and recent AWB errors to the model provider named below in order to answer it. Carrier credentials are never included. The assistant may also offer to create or cancel a carrier AWB for a named order, or to refresh tracking. Nothing runs on the model's output: Merchant presses a confirmation carrying the consequence, and Processor resolves the order from Merchant's own records rather than from anything the model produced. Each run is written to Merchant's audit log.
Confidentiality and security
Processor applies data minimization, least-privilege access, HTTPS in transit, encryption for carrier credentials at rest, environment separation, access logging, encrypted-backup requirements, and an incident response process. Personnel with access are bound to confidentiality and use strong authentication.
Subprocessing and international transfers
Shopify supplies order data and Speedy receives shipment data as the carrier chosen by Merchant. Infrastructure providers may process encrypted or operational data only as necessary to host the service and under appropriate data protection terms. OpenAI processes support assistant conversations as a subprocessor and does not use them to train models.
Retention, deletion, and assistance
Recipient fields read from Shopify are processed transiently. AWB-only corrections explicitly saved by Merchant are encrypted at rest, retained for no longer than 90 days, and removed by applicable privacy webhooks. Labels and exports are reached only through signed links that expire 30 minutes after issue, and neither labels nor exports are stored by Processor. Product ideas submitted by Merchant are stored with the shop domain until deletion is requested or the shop's data is deleted. Processor supports Shopify's mandatory privacy webhooks and assists Merchant with data-subject requests, security inquiries, and legally required incident notifications. Speedy credentials, settings, shipment records, return records, pending automation entries, submitted ideas, and job records are deleted when the app is uninstalled; Shopify's later shop-redaction webhook removes any remaining shop and audit record, except where retention is legally required.
Contact: fastyconnector@gmail.com