← Back to Tiger Echo

Data Processing Agreement

Agreement between the Merchant (“Controller”) and Tiger Echo (“Processor”) for GDPR Compliance

Last Updated: July 27, 2026  |  Effective Date: July 27, 2026

Note: This DPA forms part of the Terms of Service. If you are a merchant using Tiger Echo to process customer reviews, this Agreement applies to you. It governs how Tiger Echo processes personal data on your behalf when you use our service.

1. Parties and Roles

This Data Processing Agreement (“DPA”) is entered into between:

  • Controller (You / the Merchant): The Shopify store owner who determines the purposes and means of processing personal data of their customers (e.g., names, email addresses, review content) through Tiger Echo.
  • Processor (Tiger Echo): Tiger Echo Pte. Ltd., operating at tigerecho.com, who processes personal data only on the documented instructions of the Controller in connection with the review management services provided.

Both parties acknowledge that, with respect to the processing of EU/UK personal data under this DPA, Tiger Echo acts as a Data Processor and the Merchant acts as the Data Controller, as defined under GDPR (EU) 2016/679 and UK GDPR.

2. Scope and Purpose of Processing

Tiger Echo processes personal data only for the following limited purposes:

  • Review Collection: Collecting, storing, and displaying customer reviews submitted on the Merchant’s Shopify store.
  • AI-Powered Summaries: Generating AI summaries of reviews using third-party AI providers (currently DeepSeek API).
  • Email Review Reminders: Sending automated email reminders to customers requesting review submissions.
  • Analytics and Insights: Providing review analytics and sentiment analysis to the Merchant.
  • Data Export: Enabling the Merchant to export review data in CSV format.

3. Types of Personal Data Processed

Data CategoryExamplesProcessing Activity
Identity DataCustomer name, email addressReview attribution, email reminders
Review ContentReview text, star rating, photosStorage, display, AI summarization
Order DataOrder number, product purchased, dateReview request matching
Communication DataEmail headers, delivery statusEmail campaign management
Technical DataIP address (if logged), device infoSecurity, fraud prevention
Consent RecordsOpt-in timestamp, method, scopeCompliance verification

Tiger Echo does not process special categories of sensitive data unless explicitly provided by the Controller.

4. Controller Obligations

The Controller shall:

  • Ensure all personal data submitted to Tiger Echo is collected and processed lawfully under Articles 6 and 9 GDPR.
  • Obtain all necessary consents from data subjects before their data is submitted for review collection.
  • Provide and maintain a clear, accessible privacy notice on their Shopify store informing customers that reviews may be processed by third-party services including Tiger Echo.
  • Notify Tiger Echo promptly (within 48 hours) if the Controller becomes aware of a personal data breach or receives a data subject request relating to data processed by Tiger Echo.
  • Ensure that the transfer of personal data to Tiger Echo is lawful under Chapter V GDPR.

5. Processor Obligations (Tiger Echo)

Tiger Echo, as Data Processor, shall:

  • Process lawfully: Process all personal data only on the documented instructions of the Controller.
  • Confidentiality: Ensure all authorised personnel are subject to binding confidentiality obligations.
  • Security: Implement appropriate technical and organisational measures per Article 32 GDPR, including encryption, access controls, regular security assessments, and incident response.
  • Sub-processors: Engage sub-processors only with the Controller’s prior written consent. See Section 8 for the current sub-processor list.
  • Assist Controller: Assist the Controller in fulfilling obligations under Articles 32–36 GDPR.
  • Data subject requests: Where feasible, assist the Controller in responding to data subject requests (access, rectification, erasure, portability, objection).
  • Delete or return data: At the Controller’s choice, either delete or return all personal data after the end of the provision of services.
  • Demonstrate compliance: Allow for and contribute to audits conducted by the Controller.

6. International Data Transfers

Personal data may be transferred to and processed in:

  • Singapore: Tiger Echo’s primary servers. Singapore has an EU adequacy decision (2023).
  • Hong Kong (Alibaba Cloud OSS): Review images stored in Alibaba Cloud OSS (Hong Kong region). Hong Kong has an EU adequacy decision (December 2024).
  • People’s Republic of China (DeepSeek API): AI summaries processed on DeepSeek servers in the PRC. Transfers require additional safeguards under GDPR Chapter V. The Controller acknowledges and agrees to such transfers by using the AI Summary feature.
  • Other third countries: Any new third-country sub-processors will be notified to the Controller with 14 days’ prior written notice.
Controller’s responsibility: The Controller is responsible for ensuring that its use of Tiger Echo’s AI Summary feature is consistent with its own GDPR obligations, including documentation in its records of processing activities (RoPA).

7. Data Security Measures

MeasureDescription
Encryption in TransitTLS 1.2+ for all data transmissions.
Encryption at RestPersonal data encrypted at rest where technically feasible.
Access ControlsRole-based access control (RBAC); access on a need-to-know basis only.
Network SecurityFirewalls, IDS/IPS, and DDoS protection at network perimeter.
API AuthenticationHMAC signatures and OAuth 2.0 tokens for all API requests.
Vulnerability ManagementRegular vulnerability scanning and patching.
Backup and RecoveryAutomated daily backups; tested restoration procedures; 30-day retention.
Incident ResponseDocumented security incident response procedure with defined escalation timelines.

8. Sub-Processors

The Controller provides general written authorisation for all sub-processors by accepting this DPA:

Sub-ProcessorPurposeLocationSafeguards
Alibaba Cloud (OSS)
Alibaba Cloud Computing Co. Ltd.
Object storage for review images and attachments Hong Kong SAR Adequacy decision (HK) + DPA
DeepSeek
Hangzhou DeepSeek Artificial Intelligence Basic Software Technology Co. Ltd.
AI-powered review summary generation People’s Republic of China Controller consent for AI feature + SCCs where applicable
Shopify Inc. E-commerce platform providing order/customer data via API Canada / Singapore Shopify DPA + Adequacy decision (Canada)
Cloudflare Inc. CDN, DDoS protection, and web application firewall United States DPA + EU Standard Contractual Clauses

Tiger Echo will notify the Controller of any intended sub-processor changes with 14 days’ prior written notice. The Controller may object, and the parties will work in good faith to find an alternative.

9. Data Breach Notification

In the event of a personal data breach, Tiger Echo shall:

  • Notify the Controller without undue delay, and in any event within 48 hours of becoming aware of the breach.
  • Provide: the nature of the breach, categories and number of data subjects concerned, likely consequences, and measures taken or proposed to address the breach.
  • Assist the Controller in notifying the relevant supervisory authority and affected data subjects where required.

10. Data Retention and Deletion

  • Active data: Retained for as long as the Controller maintains an active subscription.
  • Post-termination: Within 30 days of account termination, Tiger Echo shall delete all personal data from active systems, except where required by law to retain.
  • Backups: Personal data in backups retained for up to 30 days, then securely overwritten.
  • Anonymous statistics: Aggregated, anonymised statistical data may be retained indefinitely and does not constitute personal data.

11. Audit Rights

The Controller may audit Tiger Echo’s compliance by:

  • Requesting a copy of Tiger Echo’s most recent security audit or certification report (e.g., SOC 2 Type II) within 30 days of written request.
  • Conducting an on-site audit, subject to: (a) 30 days’ prior written notice, (b) Tiger Echo’s availability, and (c) the Controller bearing its own costs.

12. Liability and Indemnification

  • Tiger Echo’s liability is subject to the limitations in the Terms of Service.
  • Tiger Echo shall not be liable for claims arising from the Controller’s failure to comply with its obligations as Data Controller.
  • Each party shall indemnify the other against claims from supervisory authorities or data subjects arising from the indemnifying party’s breach of this DPA.

13. Supervisory Authority and Complaints

Tiger Echo is subject to oversight by the Personal Data Protection Commission (PDPC) of Singapore as its lead supervisory authority for GDPR purposes (Article 56 GDPR).

EU/EEA Controllers may also lodge complaints with their local supervisory authority: EDPB Members List.

UK-specific matters: Information Commissioner’s Office (ICO): ico.org.uk.

14. Governing Law and Jurisdiction

This DPA is governed by the laws of Singapore. Any dispute shall be subject to the exclusive jurisdiction of the courts of Singapore.

15. Amendments

Tiger Echo reserves the right to amend this DPA. Material amendments will be communicated at least 30 days before the effective date. Continued use of the Service after the effective date constitutes acceptance.

16. Contact Information

Tiger Echo Data Protection Officer
Email: hanhui30081986@163.com
Website: https://tigerecho.com

For GDPR data subject requests: Please include “GDPR Request” in the subject line.
This Data Processing Agreement is an integral part of the Tiger Echo Terms of Service. © 2026 Tiger Echo Pte. Ltd. All rights reserved.