Terms of Service and Data Processing Agreement
Effective Date: August 3, 2026 | Last Updated: August 3, 2026
Part I — Terms of Service
1. Scope and Parties
1.1 These Terms of Service (the "Terms") govern access to and use of the ShopAssist software-as-a-service product and related implementation, integration, support, and professional services (together, the "Service") provided by Kremic Ventures UG (haftungsbeschränkt), trading as ShopAssist ("ShopAssist," "Provider," "we," or "us"), to the contracting customer ("Customer" or "Merchant"). "Shopper" means an individual who visits or interacts with the Merchant's eCommerce store or the Service, including a prospective or actual purchaser, whether or not the individual completes a purchase.
1.2 The Service is offered exclusively to entrepreneurs within the meaning of § 14 German Civil Code (BGB), legal entities under public law, and special funds under public law. Consumers may not contract for the Service.
1.3 These Terms, the applicable Order Form or signed sales contract, the Data Processing Agreement in Part II, and any expressly incorporated service description form the "Agreement." If provisions conflict, the following order of precedence applies: (a) an individually negotiated and signed Order Form or sales contract; (b) Part II for data-protection matters; (c) the remaining provisions of these Terms; and (d) the general service description.
1.4 Customer terms do not apply unless ShopAssist expressly accepts them in text form.
2. The Service
2.1 Service description
ShopAssist is an AI shopping assistant for eCommerce stores. It helps shoppers discover, compare, understand, and buy products through a conversational interface. Depending on the Merchant's plan, platform, and configuration, the Service supports catalogue and variant synchronisation, inventory information, cart actions, order lookup, automatic syncing, shopper conversations, analytics, and order attribution.
2.2 Supported platforms
ShopAssist currently provides production integrations for Shopify, WooCommerce, BigCommerce, and Magento. ShopAssist may add or discontinue platform support in accordance with Section 12.
2.3 Integration channels
The Service is installed and implemented directly by ShopAssist or an authorised ShopAssist reseller partner. An integration may include custom API implementation and a signed sales contract. A reseller may support implementation and account management, but only the entity expressly identified in the applicable Order Form or sales contract is the contractual service provider.
2.4 Platform dependencies
The Service depends on the Merchant's eCommerce platform, APIs, access credentials, permissions, themes, and third-party services. ShopAssist is not responsible for failures caused by a platform provider, revoked permissions, Merchant modifications, unsupported customisations, or third-party changes outside ShopAssist's reasonable control.
2.5 AI and infrastructure providers
ShopAssist currently uses the OpenAI API for shopper-chat responses, prompt analysis, categorisation, summarisation, analytics and classification; the paid Google AI Studio/Gemini API for catalogue processing and knowledge base; and Cloudflare Workers AI for embedding and reranking shopper query text. Chat requests to OpenAI are proxied through Cloudflare AI Gateway. ShopAssist may change a provider where reasonably necessary to maintain, secure, or improve the Service, subject to Section 12 and the subprocessor requirements in the DPA.
The production OpenAI projects are configured for provider-approved Zero Data Retention as described in the DPA. Zero Data Retention governs retention by the relevant AI provider only and does not determine retention in ShopAssist systems, Cloudflare AI Gateway, Langfuse, or other authorised subprocessors.
2.6 AI limitations
AI outputs are probabilistic and may be incomplete, inaccurate, or unsuitable for a particular decision. The Service is designed to use Merchant product and policy information but does not guarantee that every answer will be error-free, current, or legally compliant. The Merchant must maintain accurate source information and appropriate human escalation for consequential product, health, safety, compatibility, legal, financial, or purchasing questions.
2.7 Availability
ShopAssist targets 99% annual availability, excluding announced or emergency maintenance, failures caused by the Merchant or third parties, force majeure, internet or platform outages, and suspension permitted under this Agreement. This target is not a service-level guarantee unless an Order Form expressly states otherwise.
2.8 AI Act roles
For Regulation (EU) 2024/1689 (the "AI Act"), ShopAssist is the provider of the AI system underlying the Service and the Merchant is the deployer. ShopAssist will meet the transparency obligations applicable to it, including disclosure that the Shopper is interacting with an AI system, and will make available the information a deployer reasonably requires.
The Merchant becomes the provider under Article 25 AI Act if it places the Service on the market under its own name or trade mark, substantially modifies the Service, or modifies its intended purpose. White-labelling and reseller arrangements may have this effect. Where it applies, the Merchant assumes the provider obligations and ShopAssist's obligations transfer accordingly. ShopAssist will supply the information and cooperation Article 25(2) requires. The Merchant must notify ShopAssist before white-labelling or substantially modifying the Service.
2.9 Terminal equipment and browser storage
The widget stores information on, and accesses information already stored on, the Shopper's terminal equipment. Where § 25 TDDDG, Article 5(3) of Directive 2002/58/EC, or an equivalent national implementation applies, the Merchant is responsible for obtaining consent for every entry not classified as strictly necessary in Annex 5, and for making that consent state available to the Service before any non-necessary entry is created. ShopAssist classifies each storage entry as strictly necessary or consent-dependent in Annex 5, and will not create a consent-dependent entry unless a positive consent signal has been received.
The necessity classification in Annex 5 is ShopAssist's assessment and does not bind a Supervisory Authority; the Merchant remains responsible for its own assessment.
3. Contract Formation, Accounts, and Implementation
3.1 A contract may be formed through an online subscription flow, an Order Form, or a signed direct-integration sales contract. A submitted order is an offer. The Agreement is concluded when ShopAssist accepts the order, grants access, or begins agreed implementation work, whichever occurs first.
3.2 The Merchant must provide accurate company, contact, billing, address, country, and VAT information and keep it current. Account credentials are personal to authorised users and must be protected against unauthorised access.
3.3 For a direct or custom integration, the Merchant must provide reasonably required API access, technical contacts, testing support, approvals, and platform permissions. Timelines dependent on the Merchant or a third party are extended for the period of the relevant delay.
3.4 If a reseller participates, the Merchant remains responsible for instructions, content, permissions, and configurations supplied through that reseller. Data access by the reseller must be covered by the Merchant's and reseller's own lawful arrangement unless the Order Form expressly appoints the reseller as ShopAssist's subprocessor.
4. Merchant Responsibilities and Acceptable Use
4.1 Source information
The Merchant is responsible for the legality, completeness, accuracy, and currency of product catalogues, variants, inventory, pricing, policies, warnings, shipping information, returns information, and other content supplied to or made accessible through the Service.
4.2 Seller relationship
The Merchant, not ShopAssist, is the seller of record and the contractual counterparty of its shoppers. The Merchant is responsible for products, fulfilment, taxes, product safety, consumer information, warranties, returns, refunds, and decisions made in response to shopper inquiries.
4.3 Privacy and instructions
The Merchant is responsible for an appropriate legal basis, shopper notices, consent where required, and lawful instructions for its use of ShopAssist. The Merchant must not instruct ShopAssist to process data in violation of applicable law or the DPA.
4.4 AI transparency
The widget identifies the interaction as AI at or before the first conversation, and the Merchant may not remove or obscure that disclosure. The Merchant must provide any additional notices required for its store, products, jurisdiction, or use case.
4.5 Prohibited use
The Merchant must not, and must not permit others to:
- use the Service for unlawful, fraudulent, deceptive, discriminatory, or harmful activity;
- offer illegal goods or use the Service in a manner that infringes third-party rights;
- ask shoppers to submit payment-card data, passwords, government identifiers, special-category data, or other unnecessary sensitive information in chat;
- use the Service to make solely automated decisions that produce legal or similarly significant effects unless expressly agreed and lawfully implemented;
- bypass security, access another customer's data, introduce malicious code, overload the Service, or probe for vulnerabilities without written authorisation;
- reverse engineer, copy, resell, or create derivative works from the Service except where mandatory law permits; or
- remove ShopAssist legal, security, or AI-transparency notices.
4.6 Minors and regulated products
The Merchant is responsible for ensuring that its store and use of ShopAssist comply with applicable age restrictions, product-safety rules, advertising restrictions, and other requirements concerning regulated products. Regulated products include alcohol, tobacco and vaping products, medicines, weapons, gambling products, and other age-restricted or legally controlled goods or services. The Merchant must implement legally required age-verification, parental-authorisation, product-warning, content, and fulfilment controls and must notify ShopAssist before using the Service for such products or other high-risk use cases. ShopAssist may require additional safeguards, restrict affected functionality, or refuse an unsupported use case.
5. Plans, Trial, Fees, and Payment
5.1 Plans
Starter, Standard, and Premium plans are available with monthly or annual subscription periods, as stated in the order. Enterprise is offered on an annual subscription. Features, usage limits, implementation scope, and prices are those shown at checkout or agreed in the applicable Order Form.
5.2 Payment methods
Starter, Standard, and Premium may be paid by credit card through Stripe or by bank transfer, subject to the order flow. Enterprise is paid annually by bank transfer.
5.3 Due dates
Subscription fees are payable in advance. Bank-transfer invoices are due within 15 days of the invoice date unless the Order Form states otherwise. Card payments are charged on the applicable subscription or renewal date.
5.4 Taxes
All advertised prices and fees are net amounts exclusive of VAT and any other applicable taxes unless expressly stated otherwise. The tax treatment depends on the locations and tax status of ShopAssist and the Merchant, the Merchant's valid VAT identification number, and applicable law. ShopAssist will add VAT where legally required or apply reverse-charge treatment where the applicable conditions are met. The Merchant must provide complete and accurate billing, location, and tax information. The final checkout calculation and invoice control in the event of a pricing or tax-display discrepancy.
5.5 Trial
A 30-day trial requires a valid credit card. Unless cancelled before the trial ends, it automatically converts to the paid plan selected during registration and the card is charged. The Merchant may cancel the trial at any time before the end of day 30; the 15-day ordinary cancellation deadline does not apply to trial cancellation.
5.6 Renewal
Monthly subscriptions automatically renew for successive one-month periods. Annual subscriptions, including Enterprise, automatically renew for successive one-year periods. Either party may prevent renewal by giving notice at least 15 days before the end of the then-current subscription period.
5.7 No partial-period refunds
Except where mandatory law requires otherwise or ShopAssist expressly agrees in writing, paid fees are non-refundable and ShopAssist does not provide refunds or credits for an unused portion of a subscription period. Termination takes effect at the end of the paid period unless extraordinary termination applies.
5.8 Late payment
Statutory default interest and recovery costs apply to overdue amounts. Following reasonable notice, ShopAssist may suspend the affected Service while undisputed amounts remain overdue. The Merchant remains responsible for charges accrued before suspension.
5.9 Price changes
ShopAssist may change prices for a future renewal period by giving at least 30 days' notice. If an increase materially disadvantages the Merchant, the Merchant may prevent renewal by giving notice before the new price takes effect, even if the ordinary 15-day deadline has passed.
6. Intellectual Property and Data
6.1 ShopAssist rights
ShopAssist and its licensors retain all rights in the Service, software, interface, documentation, prompts, workflows, models, configurations, and improvements, excluding Customer Data. The Merchant receives a limited, non-exclusive, non-transferable, non-sublicensable right to use the Service internally during the Agreement.
6.2 Customer Data
"Customer Data" means information, content, and personal data submitted by or for the Merchant, obtained from its store under its instructions, or generated from its shoppers' use of the Service. As between the parties, the Merchant retains its rights in Customer Data. Personal data is not property, and this clause does not limit data-subject rights.
6.3 Processing permission
The Merchant instructs and authorises ShopAssist to host, copy, transmit, analyse, display, and otherwise process Customer Data only as necessary to provide, secure, support, and maintain the Service and as further described in the DPA.
6.4 No model training
ShopAssist does not use Customer Personal Data to train machine-learning models. Authorised personnel may manually review raw conversations to maintain and update only the prompt for the Merchant whose store generated them, and for support, security, and troubleshooting as permitted by the DPA. One Merchant's raw conversations are not used to update another Merchant's prompt or a global prompt.
7. Data Protection and Confidentiality
7.1 Compliance
Each party must comply with applicable data-protection law. For Customer Personal Data processed by ShopAssist on the Merchant's behalf, the DPA in Part II applies and is incorporated into the Agreement.
7.2 Privacy Policy
The ShopAssist Privacy Policy explains processing for which ShopAssist is a controller and provides information about ShopAssist's processing on behalf of Merchants.
7.3 Confidentiality
Each party must protect the other party's non-public business, technical, security, and commercial information, use it only for the Agreement, and disclose it only to personnel and providers who need it and are bound by confidentiality. This does not cover information that is public without breach, already lawfully known, independently developed, or lawfully received from a third party.
8. Warranties, Defects, and Liability
8.1 Service warranty
ShopAssist will provide the Service with reasonable care and skill and materially in accordance with the applicable service description. The Merchant must report reproducible defects promptly and provide reasonable information needed to investigate.
8.2 Unlimited liability
Nothing in this Agreement excludes or limits ShopAssist's liability for intent, gross negligence, injury to life, body or health, fraudulent concealment, an expressly assumed guarantee, or any liability that cannot lawfully be excluded or limited.
8.3 Limited liability
For slight negligence, ShopAssist is liable only for breach of a material contractual obligation whose performance is necessary for the Agreement and on which the Merchant may reasonably rely. Liability is limited to foreseeable damage typical for this type of Agreement. To the extent legally permitted, ShopAssist's total liability under this Section 8.3 for all events occurring in a contract year is capped at the fees paid or payable by the Merchant under the Agreement during the 12 months preceding the first event giving rise to liability in that contract year. If that event occurs during the first 12 months of the subscription, the cap is the fees paid or payable for the first 12 months of the subscription. Claims arising from the same or related events count as one claim. This cap does not apply to Section 8.2.
8.4 Strict liability exclusion
Strict liability for defects existing when the Service was made available under § 536a(1), first alternative, BGB is excluded, except where Section 8.2 applies.
8.5 Excluded liability
Subject to Sections 8.2–8.4, ShopAssist is not responsible for inaccurate Merchant content, Merchant instructions, unsupported modifications, eCommerce-platform failures, or a shopper's purchasing decision based on an AI output. This does not exclude ShopAssist's liability for its own breach of duty.
8.6 Extension to representatives
The limitations in this Section also apply to ShopAssist's legal representatives, employees, and agents.
9. Third-Party Claims
9.1 Merchant indemnity
The Merchant will indemnify ShopAssist against a third-party claim to the extent it results from unlawful Customer Data, illegal or defective products, inaccurate product warnings or Merchant content, the Merchant's material breach of Sections 4 or 7, or an instruction that infringes law or third-party rights.
9.2 Indemnity procedure
ShopAssist must notify the Merchant promptly, permit the Merchant to control the defence and settlement, and provide reasonable cooperation at the Merchant's cost. The Merchant may not settle a claim in a manner that admits fault by ShopAssist, imposes non-monetary obligations on ShopAssist, or fails to release ShopAssist without ShopAssist's prior consent. The indemnity does not apply to the extent ShopAssist caused the claim through its own breach or unlawful conduct.
10. Term, Cancellation, Suspension, and Termination
10.1 Subscription term
The subscription begins on the date stated in the order. Trial, monthly, annual, renewal, and cancellation periods are governed by Section 5.
10.2 Cancellation procedure
Cancellation must be made through an available account cancellation function or sent in text form to the contact address stated in Section 13. Removing or disabling an integration may stop technical operation but does not by itself cancel the Agreement.
10.3 Termination for cause
Either party may terminate for good cause without notice. Where the cause is remediable, termination normally requires written warning and a reasonable cure period. Good cause may include a serious or repeated security breach, unlawful use, material uncured breach, or insolvency-related grounds to the extent permitted by law.
10.4 Suspension
ShopAssist may suspend the Service to address a material security risk, unlawful use, a binding legal requirement, or overdue undisputed fees. Where feasible, ShopAssist will give advance notice and limit suspension to what is reasonably necessary.
10.5 Return and deletion of Customer Data
Upon expiry or termination of the Agreement, and subject to any switching process under Section 10.6, the Merchant may instruct ShopAssist in text form either to return Customer Data to the Merchant or to delete it. ShopAssist will make Customer Data available in a structured, commonly used, machine-readable format for 30 calendar days after termination or completion of the applicable switching period (the "Retrieval Period"), unless the Merchant instructs ShopAssist to delete the data earlier.
After the Merchant confirms receipt, requests deletion, or the Retrieval Period expires, whichever occurs first, ShopAssist will delete Customer Data from its active systems and instruct its subprocessors to delete remaining copies, unless Union or Member State law requires particular data to be retained. Data retained because of a legal requirement will be isolated, protected, used only for that legal purpose, and deleted when the requirement ends.
Residual copies in disaster-recovery systems, database history, or backups will be overwritten or deleted according to the applicable recovery cycle and no later than 30 calendar days after deletion from active systems. Such copies will not be used for another purpose. If a recovery copy is restored during that period, the applicable deletion instruction will be reapplied. On request, ShopAssist will provide written confirmation that the return or deletion process has been completed. The DPA supplements this Section.
10.6 Switching and data export
Where Chapter VI of Regulation (EU) 2023/2854 (the "EU Data Act") applies, the Merchant may request: (a) an export of its Exportable Data and eligible Digital Assets for transfer to another provider or infrastructure chosen by the Merchant; or (b) erasure of that data and those assets.
For this Section, "Exportable Data" and "Digital Assets" have the meanings given to them by the EU Data Act. The categories ordinarily included in the ShopAssist export package are described in Annex 4.
ShopAssist will provide the export in a structured, commonly used, machine-readable format, such as JSON or CSV, together with reasonably necessary field descriptions. The export will include the categories identified in ShopAssist's Data Portability Schedule and will exclude ShopAssist or third-party source code, models, proprietary technology, trade secrets, and security-sensitive information, except to the extent their inclusion is required by mandatory law.
ShopAssist is responsible for extracting and securely delivering the export and providing the assistance, information, interfaces, security, and service continuity required by applicable law. Unless mandatory law requires otherwise, the Merchant and its destination provider are responsible for assessing compatibility, mapping and transforming the exported data, uploading it to the destination system, and configuring that system. ShopAssist does not guarantee that another provider will accept the export, reproduce ShopAssist functionality, preserve every relationship or presentation, or achieve functional equivalence. ShopAssist is not required to rebuild the Service in another provider's environment or develop a destination-specific migration tool.
The applicable notice, transition, retrieval, and deletion periods will not exceed the limits imposed by mandatory law. Professional migration services requested beyond ShopAssist's mandatory obligations may be charged at rates agreed in advance.
11. Force Majeure
Neither party is liable for delay or failure caused by events beyond its reasonable control, including widespread internet or cloud outages, failures of eCommerce platforms or AI providers, natural disasters, war, labour disputes, epidemics, government action, or cyberattacks that could not reasonably have been prevented. Payment obligations already accrued remain due. If the event continues for more than 90 days, either party may terminate without penalty.
12. Changes to the Service and Agreement
12.1 Service changes
ShopAssist may make reasonable Service changes for security, legal compliance, provider changes, technical development, or improvement, provided the core contracted functionality is not materially reduced during a paid term without an appropriate remedy.
12.2 Agreement amendments
ShopAssist may amend standard Terms for future use or where reasonably required by law, security, or Service development. ShopAssist will give at least 30 days' advance notice of material adverse changes unless urgent legal or security reasons require a shorter period.
12.3 Consent and objection
Silence does not constitute acceptance unless the legal requirements for an agreed amendment mechanism are satisfied and the notice clearly explains the effect of silence and the Merchant's right to object. If a material amendment requires consent and the Merchant does not consent, either party may end the affected Service at the end of the current paid term. Individually negotiated terms may be changed only by agreement.
13. Final Provisions and Provider Information
13.1 Notices
Notices under the Agreement may be sent in text form, including email, unless law or an individually negotiated provision requires a stricter form.
13.2 Applicable law
German law applies, excluding the UN Convention on Contracts for the International Sale of Goods. Mandatory conflict-of-law rules remain unaffected.
13.3 Jurisdiction
To the extent a jurisdiction agreement is legally permitted, Berlin is the exclusive place of jurisdiction. In all other cases, the statutory rules apply.
13.4 Severability
If part of the Agreement is invalid or unenforceable, the remaining provisions remain effective. The invalid provision is replaced by the applicable statutory rule; § 139 BGB is excluded to the extent legally permitted.
13.5 Provider
Kremic Ventures UG (haftungsbeschränkt), trading as ShopAssist
Liselotte-Herrmann-Straße 12, 10407 Berlin, Germany
Managing Director: Tim Kremic
Commercial Register: HRB 237823, Amtsgericht Berlin-Charlottenburg
Part II — Data Processing Agreement
1. Scope, Definitions, and Roles
1.1 This Data Processing Agreement ("DPA") applies when ShopAssist processes Personal Data on behalf of the Merchant in connection with the Service. It forms part of the Agreement and is intended to satisfy Article 28 GDPR.
1.2 Definitions. "Data Protection Law" means the GDPR and applicable Union or Member State laws implementing or supplementing it. The terms Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Process, Processing, and Supervisory Authority have the meanings given to them in applicable Data Protection Law.
"Personal Data" has the meaning given to it in the GDPR.
"Customer Personal Data" means any Personal Data contained in or derived from Customer Data that ShopAssist processes on behalf of the Merchant in its capacity as Processor in connection with the Service. This includes Personal Data: (a) submitted by or for the Merchant; (b) accessed from the Merchant's store or eCommerce platform under the Merchant's instructions; (c) collected from Shoppers through the Service; or (d) generated or inferred from that data or from use of the Service.
Customer Personal Data includes pseudonymised data and online identifiers where the information relates to an identified or identifiable individual. It does not include Personal Data that ShopAssist processes solely as an independent Controller for its own account administration, contracting, billing, direct business communications, legal compliance, or similar independently determined purposes, as described in the Privacy Policy.
The classification of information as Personal Data and the parties' respective roles are determined by applicable law and the actual processing activity. Nothing in the Agreement excludes information from Customer Personal Data where it constitutes Personal Data processed by ShopAssist on the Merchant's behalf.
1.3 The Merchant is Controller and ShopAssist is Processor for Customer Personal Data. Each party remains independently responsible for processing for which it determines its own purposes and means, including ShopAssist's account administration, billing, security, and legal-compliance processing as described in the Privacy Policy.
1.4 If the Merchant acts as a Processor for another Controller, the Merchant appoints ShopAssist as a subprocessor and confirms that it has authority to give the instructions in this DPA. References to Controller include that other Controller where required by Article 28 GDPR.
2. Processing Details and Documented Instructions
2.1 Subject matter and duration
ShopAssist processes Customer Personal Data to provide the AI shopping assistant, platform integration, syncing, cart and order functions, analytics, dashboard, prompt maintenance, support, security, and related services during the Agreement and for the limited return, deletion, and recovery periods specified in Section 7 and Annex 2.
2.2 Nature and purpose
Processing may include collection, transmission, organisation, storage, retrieval, consultation, matching, analysis, generation, display, support access, restriction, export, deletion, and anonymisation. Purposes are limited to providing, securing, troubleshooting, maintaining, and supporting the Service under the Merchant's instructions.
2.3 Data Subjects
Data Subjects may include shoppers and visitors to the Merchant's store, purchasers using order lookup, and the Merchant's authorised users, employees, representatives, and technical contacts.
2.4 Categories of Customer Personal Data
Depending on configuration and shopper input, processing may include:
- complete shopper messages, AI responses, feedback, preferences, and conversation history;
- a pseudonymous guest identifier, conversation Session ID, and—when the shopper is logged in—an identifier containing the Merchant platform customer ID;
- IP addresses processed transiently by infrastructure and browser/device data, request metadata, security and application logs;
- product views, searches, comparisons, cart actions, and attribution events;
- order number and postcode submitted for order lookup;
- a link or identifier associating an AI-assisted conversation with the corresponding order in the Merchant's eCommerce platform;
- complete system prompts and provider inputs and outputs; prompt, response, trace, score, token, latency, analytics, and observability data; and
- Merchant authorised-user names, business contact data, account roles, and support communications.
The order-linking flow does not store or display the shopper's name, delivery address, or full order details in the ShopAssist dashboard; those details remain in the Merchant's eCommerce platform.
2.5 Special data
The Service is not intended to collect payment-card data, passwords, government identifiers, Article 9 special-category data, or criminal-conviction data. Because chat is free text, a shopper may nevertheless submit such information. The Merchant must minimise this risk and must not intentionally configure or instruct such processing without ShopAssist's prior written agreement and appropriate safeguards.
2.6 Instructions
The Agreement, Order Form, supported configuration, and documented Merchant support requests are the Merchant's instructions. ShopAssist will process Customer Personal Data only on those instructions unless Union or Member State law requires otherwise, in which case ShopAssist will inform the Merchant before processing unless legally prohibited.
2.7 Unlawful instructions
ShopAssist will promptly inform the Merchant if, in its opinion, an instruction infringes the GDPR or other applicable Data Protection Law. ShopAssist may suspend the affected processing until the parties resolve the issue.
2.8 AI and prompt use
OpenAI receives the complete current message, relevant conversation history, Merchant system prompt and identifier, product data, selected items, and generated responses for chat and related language-processing tasks. Google AI Studio/Gemini receives store catalogue, brand knowledge base and product information. Cloudflare Workers AI receives shopper query text and relevant product data for embedding and reranking. Production requests to OpenAI use provider-approved Zero Data Retention configurations, subject to the endpoint and feature limitations stated in Annexes 1 and 2. Zero Data Retention does not affect copies held in ShopAssist systems, Cloudflare AI Gateway, Langfuse, or another authorised subprocessor. ShopAssist will not use Customer Personal Data to train machine-learning models. Authorised personnel may manually review raw conversations only to maintain that Merchant's prompt or for authorised support, security, or troubleshooting. Raw conversations from one Merchant will not be used for another Merchant's prompt.
3. Processor Obligations
3.1 Confidentiality and access. ShopAssist will ensure that persons authorised to process Customer Personal Data are bound by confidentiality, receive appropriate data-protection and security guidance, and access data only as required for their role. Access to raw conversations is limited to authorised ShopAssist personnel, authorised users of the relevant Merchant dashboard, and authorised partner personnel granted access to the relevant Merchant account. ShopAssist will maintain role-based access controls and the measures described in Annex 3.
3.2 Security. ShopAssist will implement and maintain appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, costs, nature and context of processing, and risks to Data Subjects. The measures are described in Annex 3.
3.3 Data-subject requests. Taking account of the nature of processing, ShopAssist will assist the Merchant through appropriate technical and organisational measures with requests under GDPR Chapter III. If ShopAssist receives a request relating to Customer Personal Data, it will forward it to the Merchant and will not respond substantively unless instructed or legally required. ShopAssist may ask the Merchant for the relevant Merchant, guest, local-storage, conversation, or Session ID and other information reasonably necessary to locate the records without collecting excessive additional data.
3.4 Security and compliance assistance. Taking account of the nature of processing and information available, ShopAssist will reasonably assist the Merchant with Articles 32–36 GDPR, including security assessments, breach notification, data-protection impact assessments, and prior consultation.
3.5 Personal Data Breach. ShopAssist will notify the Merchant without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, affected data and Data Subjects, likely consequences, measures taken or proposed, and a contact point. ShopAssist's notice is not an admission of fault.
3.6 Compliance information and audits. ShopAssist will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow audits, including inspections, by the Merchant or an independent auditor bound by confidentiality. Except following a material incident, a regulator request, or reasonable evidence of non-compliance, audits are limited to once per year, during business hours, on reasonable notice, and in a way that protects other customers and avoids unnecessary disruption. The parties will first use current third-party reports, certifications, and written responses where these reasonably address the request. Each party bears its own costs; the Merchant bears exceptional external costs unless an audit identifies a material breach by ShopAssist.
3.7 Records and authorities. ShopAssist will maintain records required of it under Article 30(2) GDPR and cooperate with competent Supervisory Authorities as required by law.
4. Merchant Obligations
4.1 Legal compliance
The Merchant is responsible for the lawfulness, fairness, and transparency of its processing; the accuracy and minimisation of Customer Personal Data; an appropriate Article 6 legal basis and Article 9 condition where applicable; legally required consent under § 25 TDDDG or an equivalent implementation of Article 5(3) of Directive 2002/58/EC for each consent-dependent entry listed in Annex 5, obtained before widget initialisation and signalled to the Service through the interface described in DPA section 3.8;
4.2 Appropriateness assessment
The Merchant must assess whether ShopAssist is appropriate for its store, products, audience, and use case, including access by minors, regulated products, and any automated-decision risk.
4.3 Security measures
The Merchant must use reasonable security, limit authorised-user access, protect credentials and API tokens, and promptly notify ShopAssist of suspected unauthorised access or unlawful instructions.
5. Subprocessors
5.1 General authorisation
The Merchant generally authorises ShopAssist to appoint the subprocessors listed in Annex 1 to process Customer Personal Data for the specified purposes.
5.2 Changes
ShopAssist will give advance notice of an intended addition or replacement of a subprocessor. The Merchant may object within 14 days on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, ShopAssist may not use that subprocessor for the Merchant's data or either party may terminate the affected Service without penalty and ShopAssist will refund prepaid fees for the unused affected period.
5.3 Subprocessor obligations and responsibility
ShopAssist will engage each subprocessor under a written contract or other binding legal arrangement that requires the subprocessor, with respect to the Customer Personal Data and processing entrusted to it, to comply with the same data-protection obligations imposed on ShopAssist under this DPA insofar as those obligations apply to the subprocessor's services. The subprocessor must provide sufficient guarantees to implement appropriate technical and organisational measures. Where a subprocessor fails to fulfil its applicable data-protection obligations, ShopAssist remains responsible to the Merchant for the performance of those obligations as required by Article 28(4) GDPR.
5.4 Platform and reseller roles
Shopify, WooCommerce, BigCommerce, and Magento are not automatically ShopAssist subprocessors merely because the Service integrates with them. Their roles depend on the Merchant's direct platform relationship and the data flow. An implementation reseller is a ShopAssist subprocessor only if ShopAssist appoints it to process Customer Personal Data on ShopAssist's behalf; otherwise the Merchant must establish the reseller's role and lawful access separately.
6. International Transfers
6.1 International transfers
To the extent applicable Data Protection Law restricts international transfers, ShopAssist will not transfer Customer Personal Data to, store it in, or make it remotely accessible from a country outside the European Economic Area unless the transfer complies with Chapter V GDPR. Where the UK GDPR applies, ShopAssist will also comply with its international-transfer requirements. ShopAssist may use an applicable adequacy decision, the EU-US Data Privacy Framework or UK Extension where the recipient and processing are covered, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or International Data Transfer Agreement, or another lawful transfer mechanism.
6.2 Merchant location and access
The Merchant authorises ShopAssist to make Customer Personal Data available to the Merchant and its authorised users in the countries identified in the Order Form or account configuration. Where such access constitutes a restricted international transfer, the parties will apply the transfer mechanism required by applicable Data Protection Law. The Merchant's instruction or authorisation does not replace a legally required transfer safeguard.
6.3 Subprocessor transfers
ShopAssist will ensure that international transfers to or through its subprocessors are covered by an appropriate transfer mechanism and any supplementary measures required by applicable Data Protection Law.
6.4 Standard Contractual Clauses
If the Standard Contractual Clauses are required for a transfer from the Merchant to ShopAssist, the 2021 controller-to-processor module applies, or the processor-to-processor module where the Merchant is itself a processor. The docking clause applies; the optional independent-dispute-resolution clause does not. The competent authority and governing law are determined under the GDPR and the Agreement. Annexes 1–3 of this DPA supply the relevant processing, subprocessor, and security information to the extent applicable.
7. Return, Export, Retention, and Deletion
7.1 Retention
ShopAssist will retain Customer Personal Data only for the periods specified in Annex 2 or for a shorter period agreed with the Merchant. At the end of the applicable period, ShopAssist will automatically delete or irreversibly anonymise the data unless Union or Member State law requires storage. Data retained because of a legal requirement will be isolated, protected, used only for that legal purpose, and deleted when the requirement ends.
7.2 Return and deletion after termination
On expiry or termination of the Agreement, ShopAssist will retain Customer Personal Data for a period of thirty (30) calendar days (the "Retrieval Period" described in Terms Section 10.5), during which the Merchant may instruct ShopAssist in writing to return Customer Personal Data in a commonly used, machine-readable format, or to delete it earlier. ShopAssist will delete Customer Personal Data from active systems without undue delay upon the earliest of (a) the Merchant's confirmation of receipt of the returned data, (b) the Merchant's written instruction to delete, or (c) expiry of the Retrieval Period. During the Retrieval Period, ShopAssist will not otherwise process Customer Personal Data except as required by Union or Member State law.
7.3 Provider and recovery copies
ShopAssist will instruct its subprocessors to delete Customer Personal Data in accordance with the applicable instruction and Annex 2. OpenAI provider-side retention is governed by their verified Zero Data Retention configurations; those configurations do not control copies in ShopAssist systems, Cloudflare AI Gateway, Langfuse, or other subprocessors. Residual copies in disaster-recovery systems, database history, or backups will expire or be deleted no later than 30 calendar days after deletion from active systems, will not be used for another purpose, and will have the deletion instruction reapplied if restored.
7.4 Return and export
ShopAssist will provide Customer Personal Data that is available for return in a structured, commonly used, machine-readable format. Where the EU Data Act applies, ShopAssist will also provide the export and switching assistance required by Terms Section 10.6 and mandatory law. ShopAssist is not required to disclose source code, models, proprietary technology, trade secrets, or security-sensitive information except where mandatory law requires disclosure.
7.5 Data-subject and Merchant deletion requests
ShopAssist will use appropriate technical and organisational measures to locate and delete or return Customer Personal Data using the identifiers and account information reasonably available to it. ShopAssist will propagate applicable deletion instructions to relevant subprocessors and, on request, provide the Merchant with written confirmation when the process is complete. Personal Data processed by ShopAssist as an independent Controller remains subject to ShopAssist's own legal obligations and retention schedule rather than the Merchant's processor instruction.
7.6 Retention controls and records
ShopAssist will monitor automated retention and deletion processes, investigate failures, and retain a limited record of material return and deletion actions for accountability and security purposes. Such records will not contain the deleted conversation content and will themselves be retained only for a documented period appropriate to those purposes.
8. Liability, Precedence, and Term
8.1 Liability
Liability relating to this DPA is governed by Section 8 of the Terms, subject to mandatory Data Protection Law and Data Subjects' statutory rights.
8.2 Precedence
If this DPA conflicts with another part of the Agreement on processing Customer Personal Data, this DPA controls. The European Commission's Standard Contractual Clauses control over inconsistent contractual terms for a transfer governed by them.
8.3 Term
This DPA takes effect with the Agreement and continues while ShopAssist processes Customer Personal Data.
Annex 1 — Authorised Subprocessors
| Provider | Processing purpose | Location |
|---|---|---|
| Cloudflare | Cloud Service Provider and content delivery network | Europe |
| OpenAI OpCo, LLC | AI research and deployment company | United States |
| Google Cloud EMEA Limited | AI research and deployment company | United States |
| Langfuse | LLM observability and prompt management | Europe |
| PostHog | Product analytics | Europe |
Stripe processes card-payment information under the applicable payment relationship. Shopify, WooCommerce, BigCommerce, and Magento process platform data under the Merchant's platform relationship unless the specific arrangement establishes a different role. Neither Stripe nor an eCommerce platform is automatically a Service subprocessor under this DPA.
Annex 2 — Retention and Deletion Schedule
1. General rules
The periods below are maximum default periods for Customer Personal Data. A shorter period agreed with the Merchant applies where technically supported. At expiry, ShopAssist will automatically delete or irreversibly anonymise the data unless applicable law requires retention. Genuinely anonymised statistics that no longer relate to an identifiable person may be retained outside this schedule.
2. Active-system and provider retention
| Data category or system | Maximum default retention | Treatment at expiry |
|---|---|---|
| Complete Shopper messages, AI responses, and conversation history in Cloudflare D1 | 365 days after the last activity in the conversation | Delete the conversation and directly associated identifiable records, subject to a shorter agreed Merchant period |
| Conversation summaries, topics, categories, inferred preferences, and other conversation-derived data | 365 days after the last conversation activity | Delete with the underlying conversation; derived data must not remain as an identifiable orphaned record |
| Order-attribution links and associated conversation or order identifiers | 365 days after the last conversation activity | Delete the identifiable link; genuinely anonymous revenue totals may be retained |
| Structured order-number and postcode fields used for order lookup | For the duration needed to complete and troubleshoot the lookup, and no longer than 30 days | Delete; if the Shopper also included the information in a retained chat message, the conversation period applies unless the field is redacted earlier |
| Merchant prompts, knowledge entries, widget configurations, and account settings containing Customer Personal Data | Duration of the Agreement plus the Retrieval Period | Return or delete under Sections 7.2 and 7.4 |
| OAuth state and temporary authentication records | Until the authentication process completes, subject to a short technical timeout | Automatically delete |
| Cloudflare Queues job payloads | Until successful completion, and no longer than 7 days | Automatically delete |
| Cloudflare dead-letter queue payloads | No longer than 14 days after failure | Delete after successful reprocessing or expiry |
| Cloudflare Workers Observability and application logs containing Customer Personal Data | 30 days after creation | Automatically delete |
| Cloudflare AI Gateway prompts and completions | 30 days after the request | Automatically delete under the configured provider setting; longer logging and datasets are disabled |
| Langfuse prompts, responses, traces, spans, scores, identifiers, and metadata | 30 days after creation | Automatically delete; delete an individual trace earlier through the API where required and identifiable |
| Cloudflare Workers AI query text used for embedding and reranking | No at-rest retention by ShopAssist or the provider | Process in transit only |
| PostHog Widget events and event properties | 365 days after the event | Automatically delete |
| Resend delivery copies of weekly reports | No longer than 30 days in ShopAssist or provider delivery systems | Delete provider and ShopAssist delivery copies; copies delivered to the Merchant are under the Merchant's control |
| Support copies containing Customer Personal Data | Duration of the support request and no longer than 30 days after closure | Delete unless linked to an unresolved security incident or legal claim |
3. Shopper-facing controls
The widget provides a control that clears locally stored entries. This control must not be labelled or presented in a way that implies erasure of server-side records. Requests for erasure of server-side Customer Personal Data are handled under DPA sections 3.3 and 7.5 and are directed to the Merchant as Controller.
4. Termination, retrieval, and active-system deletion
Unless earlier deletion is instructed, Customer Personal Data remains available for return during the 30-day Retrieval Period. After the Merchant confirms receipt, requests deletion, or the Retrieval Period expires, ShopAssist will delete Customer Personal Data from active systems without undue delay and no later than 30 calendar days after the applicable trigger. ShopAssist will propagate the instruction to relevant subprocessors and will provide written confirmation on request.
5. Recovery copies
D1 Time Travel and other disaster-recovery or database-history copies may retain residual Customer Personal Data for no more than 30 calendar days after deletion from active systems. Recovery copies will remain protected and will not be used for ordinary processing. If a recovery copy is restored, outstanding deletion instructions will be reapplied before the restored data returns to ordinary use.
6. Deletion accountability
ShopAssist will run and monitor automated retention jobs, record material failures and remediation, and keep a limited deletion record that identifies the Merchant, relevant record scope, action, status, and completion time without preserving deleted conversation content. Retention periods and technical controls will be reviewed at least annually and after a material system or provider change.
Annex 3 — Technical and Organisational Measures
ShopAssist will maintain the following measures, taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks to Data Subjects. ShopAssist may update a measure where the replacement provides materially equivalent or better protection.
1. Governance, confidentiality, and personnel
- persons authorised to process Customer Personal Data are subject to contractual or statutory confidentiality obligations;
- personnel with relevant access receive appropriate privacy and security guidance;
- roles and responsibilities for security, privacy, incident response, access approval, and deletion are documented; and
- access is granted only for an authorised operational purpose and is revoked when no longer required.
2. Identity and access management
- unique accounts and role-based permissions for ShopAssist operators, Merchants, and authorised partners;
- least-privilege access to production databases, AI observability tools, and administrative functions;
- multi-factor authentication for privileged infrastructure and internal administrative access where supported;
- periodic review of privileged access and prompt revocation following a role change or departure; and
- logging of material operator, impersonation, or administrative access to Customer Personal Data.
3. Encryption, secrets, and network protection
- TLS or equivalent protection for Customer Personal Data in transit between supported Service components;
- provider-managed encryption at rest for production data stores where supported;
- API keys, tokens, and credentials stored separately from application data and restricted to authorised services and personnel;
- no deliberate logging of passwords, complete payment-card data, or authentication tokens; and
- network, content-delivery, rate-limiting, and platform-security controls appropriate to the Service architecture.
4. Environment and tenant separation
- separate production and development environments and databases;
- no use of production Customer Personal Data in development or testing unless expressly authorised and protected by equivalent controls;
- logical association of Customer Personal Data with the relevant Merchant and authorisation checks intended to prevent cross-Merchant access; and
- controlled deployment and configuration-change procedures for production systems.
5. Data minimisation and logging
- Workers application logs are configured not to deliberately record raw request bodies, complete messages or responses, order numbers, postcodes, IP addresses, authentication tokens, or AI-provider payloads;
- secrets and API keys are excluded from application logs;
- order attribution keeps the Shopper's name, delivery address, and full order details in the Merchant's eCommerce platform rather than the ShopAssist dashboard; and
- error handling and redaction controls are used to reduce the risk that order-lookup inputs or unexpected sensitive data enter logs.
- browser storage entries are limited to those inventoried in Annex 5, are created only where the applicable necessity classification or a positive consent signal permits, and carry an enforced expiry timestamp;
- no authentication token, order number, postcode, or free-text message content is written to browser storage;
- the Merchant platform customer identifier is held server-side and is not written to the Shopper's terminal equipment.
6. AI and observability safeguards
- production OpenAI requests use the verified Zero Data Retention configurations described in Annexes 1 and 2;
- Customer Personal Data is not used to train machine-learning models;
- raw conversations may be reviewed only for the relevant Merchant's prompt maintenance or authorised support, security, and troubleshooting;
- Langfuse trace retention is limited to 30 days, with earlier trace deletion where required and identifiable; and
- Cloudflare AI Gateway and other observability retention is limited and automatically deleted as specified in Annex 2.
7. Availability, recovery, and resilience
- Cloudflare D1 Time Travel or an equivalent protected recovery mechanism is maintained for a maximum 30-day recovery cycle;
- recovery procedures preserve access controls and outstanding deletion instructions; and
- restore procedures and the ability to recover availability after a material incident are tested periodically and material findings are remediated.
8. Incident management
- a documented process for identifying, assessing, containing, investigating, and remediating security incidents and Personal Data Breaches;
- escalation to responsible personnel and preservation of information necessary to assess affected data, Data Subjects, consequences, and mitigation; and
- notification to the Merchant without undue delay in accordance with DPA Section 3.5, using an established notification channel and template.
9. Retention, deletion, and rights support
- automated retention and deletion controls implementing Annex 2;
- monitoring and remediation of failed deletion jobs;
- ability to locate relevant records using reasonably available Merchant, guest, local-storage, or conversation identifiers;
- propagation of applicable deletion requests to relevant subprocessors; and
- limited accountability records that do not preserve deleted conversation content.
10. Subprocessor and transfer management
- due diligence appropriate to the subprocessor's role and processing risk;
- a binding written data-processing arrangement meeting Article 28(4) GDPR where the provider acts as a subprocessor;
- maintenance of the authorised subprocessor schedule and advance change notice under Section 5.2; and
- an applicable Chapter V transfer mechanism and supplementary measures where required.
11. Review and improvement
ShopAssist will review these measures at least annually and after a material architectural, provider, processing, or risk change. Material weaknesses will be recorded, prioritised, and remediated according to risk.
Annex 4 — Data Portability Schedule
1. Export package
Subject to the Merchant's rights, the Service configuration, and applicable law, the export package may include:
- Shopper conversation records and associated timestamps;
- AI responses, feedback, summaries, topics, categories, and other Merchant-specific conversation-derived records;
- Merchant analytics records and available field descriptions.
The export package additionally includes: Merchant Prompt Content and knowledge base entries; widget configuration and display settings; authorised user records and roles; order-attribution records within the applicable retention period; and available field descriptions and a schema document. Data outside these categories may be requested and will be provided where it constitutes Exportable Data or an eligible Digital Asset under the EU Data Act.
2. Format and delivery
ShopAssist will provide available tabular data as CSV or another commonly used tabular format and structured or nested data as JSON or another commonly used structured format. ShopAssist will use a reasonably secure delivery method and may require authentication or identity verification before release.
3. Exclusions
Unless mandatory law requires otherwise, an export does not include:
- ShopAssist or third-party source code, model weights, proprietary base prompts, algorithms, infrastructure configuration, security credentials, vulnerability information, or internal fraud and security logic;
- Third-party data that the Merchant is not entitled to receive;
- Personal Data that ShopAssist cannot lawfully disclose to the Merchant; or
- genuinely anonymised aggregate data that is not associated with the Merchant's account or an identifiable person.
4. Allocation of responsibilities
ShopAssist is responsible for extracting and securely delivering the export and for the assistance required by mandatory law. The Merchant and its destination provider are responsible for compatibility assessment, mapping, transformation, import, configuration, and validation in the destination environment. ShopAssist does not guarantee functional equivalence or destination-provider acceptance.
5. Timing and charges
Applicable notice, transition, retrieval, and deletion periods will comply with mandatory law. Until 12 January 2027, any reduced switching charge will not exceed ShopAssist's costs directly linked to the switching process. From 12 January 2027, ShopAssist will not charge a switching charge where Article 29 of the EU Data Act applies. Separately requested professional services outside mandatory switching obligations may be charged at rates agreed in advance.
Annex 5 — Browser Storage Inventory
This Annex lists each entry the Service stores on, or reads from, the Shopper's terminal equipment. It supports the Merchant's obligations under § 25 TDDDG and Article 5(3) of Directive 2002/58/EC, and may be reproduced in the Merchant's own cookie or storage notice.
1. Inventory
| Key / entry | Mechanism | Necessity | Rolling period | Absolute maximum | Purpose |
|---|---|---|---|---|---|
| sa_conv_id | localStorage | Strictly necessary | 30 days from last use | 12 months | Maintains conversation continuity for the assistant expressly invoked by the Shopper |
| sa_session | sessionStorage | Strictly necessary | Tab session | Tab session | Request correlation and abuse prevention |
| sa_history | localStorage | Consent-dependent | 30 days from last use | 12 months | Local conversation history for Shopper convenience |
| sa_favourites | localStorage | Consent-dependent | 30 days from last use | 12 months | Saved and compared items |
| sa_prefs | localStorage | Consent-dependent | 30 days from last use | 12 months | Widget display and notification preferences |
2. Expiry mechanics
Where an entry is held in localStorage or another mechanism without native expiry, expiry is enforced by the widget: a stored timestamp is evaluated on each read, and expired entries are purged. Periods marked as rolling restart on each qualifying interaction, subject to the stated absolute maximum.
3. Test-mode and diagnostic entries
Test-mode, diagnostic, and settings-cache entries are created only in a non-production configuration and expire with the documented function they support. No such entry is created in a production deployment.
4. Exclusions
No authentication token, order number, postcode, free-text message content, or Merchant platform customer identifier is written to the Shopper's terminal equipment. Those values are held server-side and are governed by Annex 2, section 2.
6. Shopper-facing controls
The widget provides a control that clears locally stored entries. This control clears the local copy only and is not presented as effecting erasure of server-side records. Requests for erasure of server-side Customer Personal Data are handled under DPA sections 3.3 and 7.5 and are directed to the Merchant as Controller.