Daily Brief

Data Processing Agreement

Last updated: 24 September 2026

This Data Processing Agreement ("DPA") applies when a merchant ("you", the controller) installs Daily Brief, provided by Kling Invest & Consulting AB, company number 559322-2317, Marielundsvägen 19, 647 35 Mariefred, Sweden ("we", the processor). It forms part of the terms under which Daily Brief is provided and meets the requirements of Article 28 of the EU General Data Protection Regulation (GDPR).

This DPA applies to the extent that the personal data processed through Daily Brief is subject to the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection. References to the GDPR include the corresponding provisions of those laws.

1. Subject matter and duration

We process personal data only to provide Daily Brief: to read the store's orders and products, build daily and weekly sales reports, and email them to the recipients you choose. The processing lasts as long as Daily Brief is installed, and ends with the deletion described in section 9.

2. Types of data and data subjects

3. Your instructions

We process personal data only on your documented instructions. Installing and configuring Daily Brief, and the settings you choose in the app, are your instructions. If we believe an instruction breaks data protection law, we will tell you.

4. Confidentiality

Everyone who processes the data on our behalf is bound by confidentiality.

5. Security

We maintain appropriate technical and organisational measures, including:

6. Subprocessors

You authorise the following subprocessors:

SubprocessorPurposeLocation
Render Services, Inc.Hosting of the app and databaseFrankfurt, Germany (EU)
Resend, Inc.Sending the report emailsIreland (EU); company in the United States

We impose data protection obligations on each subprocessor equivalent to this DPA. We will announce a new subprocessor on this page and in the app at least 30 days before it is used; if you object, you may uninstall Daily Brief, which ends the processing.

7. Transfers outside the EU/EEA

Where data may be processed outside the EU/EEA, the transfer is covered by the EU Standard Contractual Clauses or another transfer mechanism approved under the GDPR.

8. Assistance

Taking into account the nature of the processing, we help you respond to requests from data subjects, and with security, impact assessments and consultations with supervisory authorities as far as they concern Daily Brief. A recipient can also stop receiving reports with the link in every email.

We notify you without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations.

9. Deletion

When you uninstall Daily Brief, fetching and sending stop immediately, and all your store's data is deleted 48 hours later, when Shopify asks us to. Reports are otherwise deleted after 24 months, and order and refund IDs after 90 days. Deleted data may remain in encrypted backups for a limited period until they are overwritten.

10. Information and audits

We make available the information needed to show compliance with this DPA, and allow for and contribute to reasonable audits, on written request to support@dailybrief.report.

11. Law

This DPA is governed by Swedish law. If this DPA and other terms conflict regarding personal data, this DPA prevails.