Legal
Data Processing Agreement
Last updated
This DPA carries every clause Article 28(3) requires, and incorporates the Standard Contractual Clauses with their annexes. It is written plainly first, with the operative terms underneath.
Parties, version and how this is agreed
This is version 2026-08-07.1. Today you accept it by using the service. There is no signature flow yet, and we are saying so.
This Data Processing Agreement is entered into between you, the merchant using Agentible (the Controller), and the provider of Agentible identified on our Legal Notice page (the Processor). It forms part of our Terms of Service and applies whenever we process personal data on your behalf.
Version 2026-08-07.1. Today this agreement is accepted by installing or continuing to use the service, and there is no click-accept and no countersignature. That is a real gap and we are not going to describe it as a design. We are building a route that records which version you accepted and when. Until it exists, if you need a countersigned copy for your own records, email privacy@agentibleapp.com and we will sign and return one.
Roles
You are the controller of your data. We are your processor and act on your instructions.
For the product data we handle on your behalf, you are the data controller and Agentible is the data processor under Art. 4 and Art. 28 of the GDPR. Separately, for the account and marketing data we hold about you as our own customer, we are the controller and our Privacy Policy governs it. The two relationships are different and this agreement covers only the first.
Subject matter, duration, nature and purpose
We process your product catalogue to audit it and rewrite it, for as long as the app is installed, and no longer.
Subject matter. The processing of personal data contained in, or associated with, the product catalogue of your Shopify store, in the course of providing the Agentible service.
Nature of the processing. Reading your catalogue through the Shopify Admin API; storing it; analysing it against a published checklist; generating replacement copy and structured data, partly by deterministic code and partly by submitting product text to Anthropic's API; writing approved changes back to your store; logging every write with its before and after value; and emailing you about the results.
Purpose. Providing the service you have subscribed to, and nothing else. We do not process your data to train models, to build a profile of your business, or for our own marketing.
Duration. For as long as the app is installed on your store, and then for the retention period in the "Deletion or return" section below. This agreement survives termination for as long as we hold any of your data.
Types of personal data and categories of data subject
Product text, and the people a merchant has named inside it. Never your shoppers, because we never request order or customer access.
Types of personal data. Product titles, descriptions, handles, vendor names, attributes, images and their alt text, SEO titles and meta descriptions, and any personal data a merchant has chosen to write into those fields (for example a founder's name in a brand story, a formulator's name, or a photographer's credit). Also the store domain and the store owner's email address as Shopify supplies them.
Categories of data subject. You and your staff who use the app; and any individual named in your product content.
Special categories. None are requested, required or expected. Our scopes are read_products and write_products only. If you write special-category data into a product description, we will process it because it is in the field, but you should not, and our supplements lane specifically refuses to generate health claims.
What is excluded. Orders, customers, payments and shopper personal data. We do not request those scopes on any plan, so that data never reaches us.
Instructions, and refusing an unlawful one
We process only as you instruct. If an instruction looks like it breaks data protection law, we tell you instead of following it.
We process personal data only on your documented instructions, which comprise this agreement, the Terms, the settings you choose in the app, and the actions you take in it (running a scan, generating a fix, approving a publish). We do not process your data for any other purpose, including our own.
Where we are required by EU or Member State law to process beyond your instructions, we will tell you of that requirement before processing, unless that law forbids the notification (Art. 28(3)(a)).
If we consider an instruction infringes the GDPR or other Union or Member State data protection law, we will inform you immediately (Art. 28(3), final paragraph). We may suspend the affected processing until the instruction is withdrawn or amended, and doing so is not a breach of the Terms.
Confidentiality of personnel
Anyone with access to your data is bound to keep it confidential.
We ensure that every person authorised to process your personal data, whether an employee, a contractor or a founder, is bound by an appropriate obligation of confidentiality, either contractual or statutory, and that the obligation survives the end of their engagement (Art. 28(3)(b)). Access is granted on a need-to-know basis and is removed when the need ends.
Security measures
We encrypt data, use least-privilege access, and rely on Shopify OAuth, not passwords.
We maintain technical and organisational measures appropriate to the risk (Art. 28(3)(c), Art. 32). The full list is Annex II below. In summary:
- Encryption of data in transit and at rest.
- Your Shopify access token encrypted by us before it is stored, on top of that.
- Authentication through Shopify OAuth, with no passwords stored by us.
- Least-privilege access, limited to the two product scopes we request.
- Row-level security in the database, scoped per store.
- Logging of every write to your store, with before and after, for review and rollback.
Personal data breach
If your data is breached we tell you without undue delay, and we help you notify.
We will notify you of a personal data breach affecting your personal data without undue delay after becoming aware of it (Art. 28(3)(f), Art. 33(2)). We aim to do so within 24 hours of becoming aware, and we will not wait for a complete picture before telling you, because your own 72-hour clock under Art. 33(1) starts when we tell you.
The notification will describe, so far as we know it at the time:
- the nature of the breach, including the categories and approximate number of records affected;
- the likely consequences;
- the measures we have taken or propose to take, including to mitigate any adverse effects;
- a contact point for further information.
Where we cannot provide all of that at once, we will provide it in phases without further undue delay. We will also assist you in meeting your own obligations under Art. 33 and Art. 34, and we will not notify a supervisory authority or a data subject on your behalf unless you ask us to or the law requires it of us directly.
Data subject requests
If a person asks us about their data, we forward it to you and help you answer.
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR (Art. 28(3)(e)). If we receive such a request relating to your data, we will not respond to it directly: we will forward it to you without undue delay and help you access, correct, export or delete the data it concerns.
Assistance with impact assessments and prior consultation
If you have to run a DPIA or consult a regulator, we give you what you need.
Taking into account the nature of the processing and the information available to us, we will assist you in ensuring compliance with your obligations under Art. 32 to Art. 36, which includes security of processing, breach notification, data protection impact assessments and prior consultation with a supervisory authority (Art. 28(3)(f)). In practice that means answering a security questionnaire, supplying the detail behind Annex II, and describing our processing accurately for your own record.
Information and audits
We give you what you need to check us, and we will accept an audit on reasonable notice.
We will make available to you all information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate (Art. 28(3)(h)).
In the first instance we will answer in writing, and supply the documents we hold: this agreement, the sub-processor list, our Article 30 record and our transfer impact assessment. If that is not enough for your own compliance obligation, you may audit us on 30 days' written notice, no more than once in any twelve-month period unless a breach or a regulator's instruction makes another necessary. An audit must be during business hours, must not unreasonably disrupt the service, and must not require us to disclose another customer's data. You bear your own costs, and ours where the audit is repeated in the same period without cause.
We hold no SOC 2, ISO 27001 or equivalent certification and no third-party penetration test has been carried out. We would rather you knew that before asking than after.
Sub-processors
We use a short list and publish it. We tell you before we add one. We did not, once, and it is named below.
You give us general written authorisation to engage the sub-processors listed in Annex III below, which is generated from the same definition our code uses (Art. 28(2), Art. 28(3)(d)). Each is bound by a written contract imposing data protection obligations at least as protective as those in this agreement, and we remain fully liable to you for their performance.
Before adding or replacing a sub-processor we will update our Subprocessors page and notify active merchants, giving you 30 days to object on reasonable data protection grounds. If you object and we cannot offer an alternative, you may terminate the affected part of the service and we will refund any prepaid, unused fees for it.
That promise has been broken once, and we are not going to leave it out of the contract. Resend began processing on 2026-07-30 and was first disclosed on 2026-08-07; Google began processing on 2026-08-04 and was first disclosed on 2026-08-07. The Subprocessors page records the same thing, along with the change that stops it recurring: the list is now generated from code and a test fails our build if the app can reach a company the page does not name.
Deletion or return
At the end, you choose: we delete your data or we give it back. If you do not choose, we delete it within 30 days.
On termination of the service, and at your choice, we will either delete or return all personal data we process on your behalf, and delete existing copies, unless Union or Member State law requires us to keep it (Art. 28(3)(g)). The choice is yours, not ours.
- Return. Email privacy@agentibleapp.com within 30 days of uninstalling and we will export your data in a structured, machine-readable format and send it to you, then delete it. The app also has an export function you can use at any time before you leave.
- Deletion. If you make no choice, we delete. Your store data is deleted within 30 days of uninstalling by a scheduled sweep, and the deletion is recorded so that it can be shown to have happened. You can ask for immediate deletion at any time.
What we keep afterwards, and why, is listed table by table in our Privacy Policy. In summary: records of what we charged you, because accounting law requires it; a record that a deletion happened, because we have to be able to demonstrate it; and a one-way digest of any address that asked never to be emailed again, because deleting it would let us email you again.
International transfers
The database is in the EU. Five providers are in the US and one is in Canada, so data does leave the EEA, and the Standard Contractual Clauses are incorporated below with their annexes.
Your data is stored in Supabase's European Union region. Personal data is nonetheless transferred outside the EEA, because several of our sub-processors are established in the United States (Vercel, Anthropic, Resend, Stripe) or in Canada and the United States (Shopify), and Google receives advertising measurement data in the United States as a separate controller.
Incorporation of the Standard Contractual Clauses. Where personal data is transferred from the EEA to a third country not covered by an adequacy decision, the parties incorporate by reference the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor), with you as the data exporter and us as the data importer, on the following terms:
- Clause 7 (the docking clause) is included.
- Clause 9: Option 2, general written authorisation, with a notice period of 30 days, matching the sub-processor section above.
- Clause 11(a): the optional independent dispute resolution body is not included.
- Clause 17: the Clauses are governed by the law of Portugal. Clause 18(b): the forum is the courts of Portugal.
- Annex I, Annex II and Annex III are the sections below.
For transfers to the United Kingdom, or from it, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs (version B1.0), with the above as the Approved EU SCCs.
Transfer impact assessment. We maintain one internally, covering the destination countries, the receiving parties, the laws that could compel disclosure, and the supplementary measures in place. It is available on request under the "Information and audits" section. One thing is open and we will not paper over it: we have not yet confirmed in writing, on file, that we have accepted each provider's own data processing agreement and verified each Data Privacy Framework certification. That is recorded as open work in the assessment rather than presented as done.
Annex I: parties and description of the processing
Who the exporter and importer are, and exactly what is transferred, about whom, how often, and for how long.
A. List of parties.
- Data exporter (controller): you, the merchant, identified by the Shopify store on which the app is installed and the account email associated with it. Contact: the store owner email held by Shopify. Activities relevant to the transfer: operating an online store whose catalogue is audited and edited by the service. Signature and date: acceptance of this agreement as described in "Parties, version and how this is agreed".
- Data importer (processor): the provider of Agentible, identified on our Legal Notice page. Contact: privacy@agentibleapp.com. Activities relevant to the transfer: providing the Agentible service as described above.
B. Description of the transfer.
- Categories of data subject: the merchant and their staff; individuals named in the merchant's product content.
- Categories of personal data: store domain and owner email address; product titles, descriptions, handles, vendor, attributes, images and alt text, SEO titles and meta descriptions, including any personal data written into them.
- Sensitive data: none is requested or required. No special-category data is knowingly processed, and no additional restrictions are agreed because none is expected.
- Frequency: continuous for hosting and storage; on each scan, fix generation and publish for the rest.
- Nature and purpose: as set out in "Subject matter, duration, nature and purpose" above.
- Retention: for the duration of the installation, then deleted within 30 days as set out in "Deletion or return". Sub-processors retain only for as long as needed to perform their function.
- Transfers to sub-processors: subject matter, nature and duration as stated per sub-processor in Annex III.
C. Competent supervisory authority. The Comissão Nacional de Proteção de Dados (CNPD), Portugal, being the authority of the Member State in which the importer's representative is established. Where the exporter is established in another Member State, its own authority is competent for it.
Annex II: technical and organisational measures
The actual controls, and an honest note about the two things we have not done.
Measures in place, described as they are implemented rather than as a checklist of intentions (Art. 32, SCC Annex II):
- Encryption. All traffic over TLS. Data at rest encrypted by our database and hosting providers. Your Shopify access token is additionally encrypted by us with an application key before it is written to the database, so a database copy alone does not yield a usable token.
- Access control. Merchant authentication is Shopify OAuth and Shopify session tokens; we store no passwords. Administrative access is a separate identity that cannot be granted through any merchant-facing flow, and an administrative route reached without it returns a 404 rather than a 403, so the surface is not enumerable.
- Tenant isolation. Row-level security is enabled on every table and scoped per store. Privileged operations use a separate service credential that never reaches a browser.
- Least privilege on your store. Two Shopify scopes,
read_productsandwrite_products. No orders, no customers, no theme write access. - Integrity and reversibility. Every write to your store is logged with the value before and after, and can be reverted. Nothing is published without your approval.
- Input handling. Merchant text is fenced as data in every prompt sent to Anthropic, and model output that breaks the expected shape is refused rather than cleaned up and used.
- Webhook authenticity. Every inbound webhook is signature-verified, and unauthenticated public routes are rate limited.
- Administrative accountability. Every support action against a merchant account writes an audit row recording the administrator, the action, and the value before and after.
- Deletion. A scheduled sweep deletes uninstalled stores after 30 days and records that it did. IP addresses held for abuse prevention are purged after 30 days by a nightly job.
- Backups. Provided by our database provider under its own standard policy. We have not independently configured, tested or documented a restore, so we do not state a recovery time or recovery point objective.
What is not in place, stated rather than omitted. There is no SOC 2 or ISO 27001 certification, and no third-party penetration test has been performed. There is no formal on-call rota. The organisation is very small, which is a strength for access control and a weakness for separation of duties, and both halves of that are true.
Annex III: authorised sub-processors
The list you are authorising, rendered from the same definition our code uses.
The sub-processors you authorise under Clause 9 of the SCCs and the "Sub-processors" section above. This list is generated from a single definition in our code, cross-checked by a test against the hosts the application actually contacts, and published in full at /legal/subprocessors.
- Vercel: Hosting and delivery of the app and the website, plus aggregate visit counts. Data: Request metadata, including IP address and user agent, and anything you type into a form on its way to us. Location: United States, with edge delivery worldwide. Since: 2026-06-10.
- Supabase: Database and authentication. Data: Your store domain, owner email address, settings, audit results, and the sign-in session behind them. Location: European Union region. Since: 2026-06-10.
- Shopify: The app platform, the source of the product data we audit, and the script that makes the embedded app work in your admin. Data: Your store domain and owner email address. Shopify also receives the IP address of anyone loading a page on this site, because the App Bridge script is served from its CDN. Location: Canada and the United States. Since: 2026-06-10.
- Anthropic: Writing product copy with Claude, on the fixes you ask us to generate. Data: Product text from your catalogue. No customer data, and no name or email address of yours. Location: United States. Data is not used to train models. Since: 2026-06-10.
- Resend: Sending the emails the product sends: welcome, scan complete, fixes ready, billing. Data: Your email address, your store domain, and the contents of the message. Location: United States. Since: 2026-07-30.
- Stripe: Payment processing for the small number of stores that did not install through Shopify. If you installed from the Shopify App Store, Stripe receives nothing about you. Data: Billing email address and payment details, for non-Shopify stores only. Location: United States and Ireland. Since: 2026-06-10.
Not sub-processors, and listed so the distinction is visible. The following receive personal data and decide their own purposes, so they are separate controllers rather than links in this Art. 28 chain:
- Google: Measuring which of our own adverts produced a customer. We upload a file of click identifiers and the value of the plan bought. Data: The click identifier Google itself put on the link you followed, plus the amount and date. No name, no email address, and no product data. Location: United States. Since: 2026-08-04.
Liability, precedence and changes
Where this agreement and the Terms disagree about data protection, this one wins.
In the event of a conflict between this agreement and the Terms of Service on a matter of data protection, this agreement prevails. In the event of a conflict between this agreement and the Standard Contractual Clauses incorporated above, the Clauses prevail.
Any limitation or exclusion of liability in the Terms applies to this agreement, except where the GDPR or the Standard Contractual Clauses do not permit it, in which case it does not apply to that extent.
We may update this agreement to reflect a change in law, in our processing or in our sub-processors. The version number and date at the top change with it, we notify active merchants of a material change, and the previous version stays available on request.