Last updated: 20 August 2026 · Effective date: 20 August 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the merchant using Heliosync services (the "Merchant", acting as data controller) and MYRA SUPPLIER LTD ("Heliosync", acting as data processor). By installing a Heliosync application, connecting a store, or otherwise using Heliosync fulfillment services, the Merchant accepts this DPA.
Heliosync processes personal data on behalf of the Merchant for the purpose of providing order management, warehousing, picking, packing, shipping, delivery coordination, tracking and fulfillment (3PL) services. Processing lasts for the duration of the service relationship and ends in accordance with Section 9 (Deletion).
Data subjects: the Merchant's customers (order recipients) and the Merchant's authorized users.
Personal data processed: recipient name; shipping address (street, city, state/province, postal code, country); phone number; email address (only where required for shipping label generation or carrier delivery notifications); order details (order ID and number, date, product titles, variants, SKUs, quantities); fulfillment and shipping status; tracking numbers and carriers; store identifier. Heliosync processes no special categories of personal data.
Heliosync shall: (a) process personal data only on the Merchant's documented instructions, including with regard to international transfers, unless required by law; (b) ensure persons authorized to process the data are bound by confidentiality; (c) implement the technical and organizational measures described in Section 8; (d) respect the conditions of Section 6 for engaging sub-processors; (e) taking into account the nature of processing, assist the Merchant in responding to data subject requests; (f) assist the Merchant with security, breach notification and data protection impact obligations; (g) delete or return personal data at the end of services per Section 9; and (h) make available information necessary to demonstrate compliance and allow for reasonable audits.
Heliosync processes Merchant customer data solely to provide the fulfillment services requested by the Merchant. Customer data is never sold, rented, or used for advertising, behavioral profiling, model training or any purpose unrelated to fulfillment.
The Merchant authorizes the following categories of sub-processors: (i) Cloudflare, Inc. — network delivery, security and DNS; (ii) hosting providers operating professional data centers in Europe; (iii) shipping carriers and logistics partners strictly as needed to deliver shipments. Heliosync remains responsible for its sub-processors and will inform Merchants of material changes, giving an opportunity to object.
Where processing involves transfers outside the EEA or the UK, Heliosync relies on appropriate safeguards such as adequacy decisions or standard contractual clauses.
Customer delivery data is deleted or anonymized no later than 90 days after the related fulfillment is completed. Upon termination of services or uninstallation of a Heliosync application, access to new data ends immediately and stored personal data is deleted or anonymized on the same schedule, unless retention is required by law. Written confirmation of deletion is available on request.
Heliosync will notify the affected Merchant without undue delay after becoming aware of a personal data breach affecting the Merchant's data, and will provide information reasonably required for the Merchant to meet its own notification obligations.
Data access and erasure requests relayed through connected platforms (for example Shopify's customer data request and redaction mechanisms) are honored within 30 days.
This DPA is subject to the limitations of liability in our Terms of Service unless mandatory data protection law provides otherwise. In case of conflict between this DPA and other terms regarding personal data, this DPA prevails.
This DPA is governed by the laws of England and Wales. Questions: MYRA SUPPLIER LTD — [email protected]
If we enable additional bot protection (e.g. a verification widget on the contact form), the verification provider may set strictly necessary cookies solely to confirm you are human. No such technology is used for tracking or advertising.
Security cookies protect the Site — and you — against automated attacks, credential abuse and denial-of-service attempts. Because the Site cannot be delivered safely without them, they are exempt from consent requirements under applicable e-privacy rules. Everything else on this Site is either not used at all or stays on your own device.
Where cookie data involves personal data (such as an IP address processed by our security provider), the legal basis is our legitimate interest in operating a secure, reliable website (GDPR Art. 6(1)(f)). The language preference involves no personal data and never leaves your browser.
You can control and delete cookies through your browser settings. Every major browser lets you block or remove cookies:
You can also clear localStorage from the same settings screens. Note that blocking strictly necessary cookies may prevent parts of the Site from functioning correctly — for example, security checks may repeat more often, and your language preference may reset on each visit.
We do not track you across other websites; our only measurement is first-party and session-scoped: the Site behaves the same whether or not your browser sends "Do Not Track" or "Global Privacy Control" signals.
For details on how Cloudflare processes data, see Cloudflare's own privacy documentation on their website. We choose providers that process data as processors on our behalf and only for the purposes described here.
Cookie lifetimes are listed in the table above. Server-side security logs that may correlate with cookie activity are retained for up to 12 months, as described in our Privacy Policy.
If we ever introduce new cookie categories (for example analytics), we will update this page before doing so and, where legally required, ask for your consent first. The current version, with its effective date, is always available at this address.
This Policy is provided for transparency and does not constitute legal advice to any reader. While we keep this page accurate and current to the best of our ability, third-party providers may change the technical names or durations of their cookies; such changes do not alter the purposes described here.
Questions about this Cookie Policy or our data practices:
MYRA SUPPLIER LTD — [email protected]