Overview
This Data Processing Agreement (“DPA”) forms part of Attravo’s terms of service and any Master Services Agreement between Attravo and Customer. It governs the processing of personal data by Attravo on Customer’s behalf and applies to the Shopify apps, services engagements, AI agents, and any related processing.
Installing an app or signing an MSA accepts this DPA. Customers who need a countersigned copy can request one at support@attravo.io.
Parties
Attravo
3072 Washington Rd, Atlanta, GA 30344, USA
support@attravo.io
Definitions
- Customer: the Shopify merchant or business using Attravo’s apps, services, or agents. Acts as the Data Controller.
- Attravo: acts as the Data Processor on behalf of Customer.
- Personal data, processing, and related terms have the meanings given in the GDPR (EU Regulation 2016/679) and equivalent applicable laws.
- Sub-processor: a third party engaged by Attravo to process personal data on Customer’s behalf.
Roles and scope
Customer is the Controller of personal data processed through the Services. Attravo is the Processor, and will process personal data only on documented instructions from Customer, typically expressed through the Services’ configuration, the MSA, or the relevant Statement of Work.
Categories of data subjects
- Customer’s end shoppers, being store visitors and buyers.
- Customer’s staff using the Shopify admin or integrated tools.
Types of personal data
- Contact data: name, email, phone, address.
- Order data: order history, line items, discount codes used.
- Behavioral data: page views, quiz responses, bundle selections, device and browser data.
- Staff data: store owner contact and role data.
Nature and purpose
Processing is carried out to provide the Services: rendering cart, bundle, and quiz experiences; reporting analytics back to Customer; delivering services engagements; and, where enabled, running AI agents. Processing continues for the duration of the app subscription or engagement.
Excluded data
The Services are not designed for special categories of personal data under GDPR Article 9, payment card numbers, or government identifiers. Customer must not configure the Services to send us such data.
Attravo's obligations
Attravo will:
- Process personal data only as necessary to provide the Services and in accordance with Customer’s documented instructions.
- Never sell personal data, share it for cross-context behavioral advertising, or use it for any purpose outside providing the Services to that Customer.
- Never use Customer’s personal data to train or fine-tune AI models, and contractually require the same of our model providers.
- Notify Customer if an instruction appears to infringe applicable data protection law.
- Comply with applicable law including GDPR, UK GDPR, CCPA and CPRA, and Shopify’s developer and Partner Program requirements.
Confidentiality of personnel
Attravo ensures that all personnel authorized to process personal data are bound by confidentiality obligations and are granted access on a least-privilege basis, limited to what their role requires.
Security measures
Attravo implements the following technical and organizational measures:
- Data in transit is encrypted using TLS.
- Data at rest is encrypted by our infrastructure providers.
- Production infrastructure runs on Google Cloud Platform, with application data in a managed MongoDB database. Access is restricted by role and protected by multi-factor authentication.
- Logical isolation per Shopify shop, so one shop’s data is not reachable from another.
- Dependency scanning and a defined patching process for known vulnerabilities.
- A documented incident response process with defined escalation paths.
- Encrypted backups on a fixed rotation, so deleted data ages out rather than persisting indefinitely.
- Source code is version controlled, and customer data is never committed to a repository.
Attravo is not currently certified under SOC 2 or ISO 27001, and does not claim to be. We describe the controls we operate rather than implying an audit we have not completed. Customers who need a written summary of current controls can request one at support@attravo.io.
Shopify scope verification
All Shopify scopes requested by Attravo apps are reviewed and verified by Shopify before publication to the App Store. We request the minimum scopes necessary to deliver each app’s functionality and operate under Shopify’s Partner Program requirements.
Sub-processors
Customer authorizes Attravo to engage the sub-processors listed in the sub-processors section of our privacy policy, which is incorporated into this DPA by reference and is the authoritative current list. Each sub-processor is bound by a written agreement requiring data protection terms no less protective than this DPA.
Attravo notifies Customer at least 30 days before a new or replacement sub-processor begins processing personal data. Customer may object on reasonable data protection grounds. If no workable resolution can be found, Customer may terminate the affected Service.
Attravo remains liable to Customer for the performance of its sub-processors’ obligations.
AI processing
Where Customer enables AI agents, additional processing terms apply.
- Agents transmit data to the model providers listed in the sub-processors section of our privacy policy, for the sole purpose of generating analysis and recommendations for that Customer.
- Attravo minimizes what is transmitted, excluding personal data from prompts where the analysis does not require it and aggregating or pseudonymizing where it does.
- No Customer data is used to train or fine-tune models, by Attravo or by its providers.
- Prompts and outputs are retained only as long as needed to operate the agent and to show Customer its reasoning, and are deleted on the schedule in this DPA.
- Agents do not carry out automated decision-making producing legal or similarly significant effects concerning individual data subjects.
Customer controls which actions an agent may take without human approval. Actions taken within scopes Customer granted are processing carried out on Customer’s instruction.
International data transfers
Attravo is established in the United States. Where personal data is transferred out of the EU, UK, or Switzerland, Attravo relies on Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, or another legally recognized transfer mechanism. The relevant clauses are incorporated into this DPA by reference. Processing regions for each sub-processor are listed on the sub-processors page.
Data subject rights
Taking into account the nature of the processing, Attravo will assist Customer by appropriate technical and organizational measures in responding to requests from data subjects exercising their rights under applicable law, including access, rectification, erasure, restriction, portability, and objection. If Attravo receives a request directly from a data subject relating to Customer’s data, Attravo will not respond substantively and will refer the request to Customer.
Personal data breaches
Attravo will notify Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting Customer’s data. The notification includes the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Attravo will assist Customer with its own notification obligations.
Data deletion and return
Attravo does not retain Customer data after the relationship ends. When the Services end, by app uninstall, expiry or termination of an MSA, or Customer’s written request, Attravo will:
- Cease all processing of personal data.
- Delete all personal data from production systems within 48 hours of app uninstall, or within 30 days of MSA termination.
- Purge residual copies from encrypted backups on the next rotation, within 30 days. Backups are not restorable into production for a deleted shop and are not used for any other purpose in the interim.
- Delete agent prompts, outputs, and stored reasoning for the Customer on the same schedule.
- Provide written confirmation of deletion on Customer request.
The only exceptions are records Attravo is legally required to retain, such as billing and tax records, and data subject to a legal hold. Neither includes shopper personal data.
Attravo implements Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact, and shop/redact.
Audits and compliance
Attravo makes available to Customer the information reasonably necessary to demonstrate compliance with this DPA. Customer may request a written summary of Attravo’s security controls. Where Customer has a justified concern, Attravo will cooperate with reasonable, non-disruptive audits, scoped and scheduled in advance and no more than once per year absent a security incident.
Liability
The liability of each party under this DPA is subject to the limitations of liability set out in the terms of service and the MSA. Nothing in this DPA limits any liability that cannot be limited under applicable law.
Term and termination
This DPA remains in force for as long as Attravo processes personal data on behalf of Customer, and terminates automatically when that processing ends and the deletion obligations above are fulfilled. Obligations that by their nature should survive, including confidentiality, do so.
Governing law
This DPA is governed by the laws of the State of Georgia, USA, except where applicable data protection law requires otherwise. Where an MSA specifies a different governing law for the engagement, that choice controls for that engagement.
Contact
For DPA questions, formal data protection inquiries, or sub-processor notifications:
Attravo
3072 Washington Rd, Atlanta, GA 30344, USA
support@attravo.io