
Version 1.0 · Draft pending legal review.
This Data Processing Agreement ("DPA") governs Handsom's Processing of Personal Data on behalf of merchants who install or use the Handsom application. It forms part of, and is incorporated into, the agreement between the parties.
This DPA is entered into between:
each a "party" and together the "parties". It takes effect on the date the Merchant installs the Handsom application or otherwise accepts this DPA (the "Effective Date"), and governs Handsom's Processing of Personal Data on the Merchant's behalf.
Where the Merchant acquires Handsom through the Shopify App Store, this DPA also gives effect to the sub-processor and data-protection obligations Shopify imposes on app developers under the Shopify API License Terms and Protected Customer Data requirements.
Capitalised terms not defined here have the meaning given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, the UK GDPR and other Data Protection Laws.
3.1 The Merchant is the Controller and Handsom is the Processor of the Merchant Personal Data. Where a party determines it acts as an independent controller for a given operation, that Processing falls outside this DPA.
3.2 Handsom Processes Merchant Personal Data only on the Merchant's documented instructions, including as set out in this DPA and the app's configuration, unless required to do otherwise by law (in which case Handsom will inform the Merchant first, unless the law prohibits it).
3.3 The subject-matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.
3.4 No automated decision-making with legal or significant effect. The Services produce a recommendation to a human agent (a brief), not an action taken toward a Data Subject. Handsom does not use Merchant Personal Data to make decisions producing legal or similarly significant effects on Data Subjects.
Handsom will:
(a) Instructions. Process Merchant Personal Data only on the Merchant's documented instructions (§3.2), and inform the Merchant if, in Handsom's opinion, an instruction infringes Data Protection Laws.
(b) Confidentiality. Ensure persons authorised to Process Merchant Personal Data are bound by confidentiality obligations.
(c) Security. Implement and maintain the technical and organisational measures in Annex II, appropriate to the risk under GDPR Article 32.
(d) Sub-processors. Engage Sub-processors only under §6 and Annex III.
(e) Data Subject requests. Taking into account the nature of the Processing, assist the Merchant by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, objection). Because Handsom stores no direct customer identifiers from Shopify (Annex I §3), most such requests are fulfilled by the Merchant in their source systems; Handsom will delete or export the limited derived records it holds on request.
(f) Assistance. Assist the Merchant in ensuring compliance with GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of Processing and the information available to Handsom.
(g) Deletion or return. At the choice of the Merchant, delete or return all Merchant Personal Data at the end of the provision of the Services, and delete existing copies unless law requires storage. See §7.
(h) Audit. Make available to the Merchant information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor it mandates, subject to reasonable confidentiality, notice, and frequency limits.
5.1 Handsom Processes Merchant Personal Data solely to provide the Services to the Merchant, and for no other purpose. Handsom does not sell Merchant Personal Data and does not use it for its own purposes or for competitive benchmarking.
5.2 No training of AI/ML models. Handsom will not use Merchant Personal Data (or any data derived from it, including anonymised, aggregated, or derived forms) to create, develop, train, fine-tune, or improve any machine-learning or artificial-intelligence system or model, including large language models, except with the Merchant's prior written consent. Handsom contractually binds each Sub-processor that Processes Merchant Personal Data to an equivalent no-training commitment (Annex III). This mirrors Shopify API License Terms §2.3.24.
6.1 The Merchant provides general authorisation for Handsom to engage the Sub-processors listed in Annex III to Process Merchant Personal Data in connection with the Services.
6.2 Handsom will impose on each Sub-processor, by written contract, data-protection obligations at least as protective as those in this DPA, including confidentiality, security, purpose limitation to providing services to Handsom, and the no-training commitment (§5.2). Handsom remains liable to the Merchant for its Sub-processors' performance.
6.3 Handsom will give the Merchant prior notice of the addition or replacement of a Sub-processor by updating Annex III (and, where feasible, notifying via the app or email), giving the Merchant a reasonable opportunity to object on reasonable data-protection grounds. If the parties cannot resolve a good-faith objection, the Merchant may terminate the Services for the affected Processing.
7.1 Retention. Handsom retains Merchant Personal Data for the life of the Merchant's installation of the Services, and only as long as needed for the purposes in §5. Operational logs are retained for approximately 30 days; database backups for up to 7 days.
7.2 Deletion on uninstall or request. Handsom deletes all Merchant Personal Data within 30 days of (a) the Merchant uninstalling the application, (b) it no longer being required to provide the Services, or (c) an enforceable deletion request from the Merchant, a Data Subject, or Shopify. On Shopify, uninstall triggers the shop/redact webhook, which erases the Merchant's environment and all derived records (integrations, tasks, briefs, evidence, memory, usage) by database cascade; backups age out within their 7-day window. This mirrors Shopify API License Terms §6.2.3.
7.3 Handsom will confirm deletion in writing on request.
8.1 Handsom will notify the Merchant without undue delay after becoming aware of a Personal Data Breach affecting Merchant Personal Data, and provide information reasonably available to assist the Merchant's own notification obligations.
8.2 Where the Merchant obtained Handsom through Shopify and the breach affects Shopify Merchant Data, Handsom will also notify Shopify no later than 24 hours after becoming aware, per Shopify API License Terms §6.2.10.
9.1 Handsom is established in the United Kingdom (Northern Ireland) and primarily hosts and Processes Merchant Personal Data in the European Union (AWS eu-west-1). For a Merchant established in the EEA, transfers of Merchant Personal Data to Handsom in the UK rely on the European Commission's adequacy decision for the United Kingdom. Certain Processing (LLM inference, and specific US-hosted Sub-processors in Annex III) may involve transfer to the United States.
9.2 Where Handsom transfers Merchant Personal Data outside the EEA/UK to a country without an adequacy decision, it will implement a valid transfer mechanism (for example, the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, or a Data Privacy Framework certification), which are incorporated by reference where used.
10.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the parties' underlying agreement / Handsom's Terms of Service.
10.2 This DPA remains in effect for as long as Handsom Processes Merchant Personal Data. Sections that by their nature should survive termination (including §5, §7, §8) survive.
10.3 In case of conflict between this DPA and the underlying agreement on the subject of data protection, this DPA prevails. This DPA is governed by the laws of Northern Ireland, and the parties submit to the exclusive jurisdiction of the courts of Northern Ireland. Where Standard Contractual Clauses or the UK International Data Transfer Addendum apply to a specific transfer (§9, Annex III), those instruments are governed as their own terms require.
10.4 Handsom may update this DPA to reflect changes in law, the Services, or Sub-processors; material changes reducing the Merchant's protections will be notified in advance.
Contact for data-protection matters: [email protected].
Subject-matter and duration. Processing of the Personal Data described below to provide the Services, for the duration of the Merchant's installation (§7).
Nature and purpose. To investigate a customer support case across the Merchant's connected systems and generate a research brief with a recommended action for a human support agent. Handsom does not contact Data Subjects and does not take actions toward them automatically.
1. Categories of Data Subjects. The Merchant's customers and prospective customers who are the subject of support cases and associated commerce records.
2. Data Handsom processes from the Merchant's connected commerce platform (e.g. Shopify). Order data (identifier, status, financial totals, currency, fulfillment status, tracking, line items, tags, order note, risk signals); fulfillment, refund, and return data; product data; and customer value/loyalty signals (Shopify customer identifier, number of orders, amount spent, tags, account creation date). Handsom uses the customer's email or identifier as a lookup input to fetch these records, but does not persist it from Shopify.
3. Protected customer fields NOT processed from Shopify (Level 1). Handsom does not request, receive, or store the customer's name, email address, phone number, or postal address from the Merchant's Shopify store. Customer identity, where needed, is supplied by the Merchant's own helpdesk (below), not by Shopify.
4. Data Handsom processes from the Merchant's connected helpdesk / other systems (e.g. Gorgias, Zendesk, Intercom, returns, subscriptions, carrier, loyalty). Support ticket content and metadata, and the customer identity the Merchant already holds there (which may include name and email), to the extent the Merchant connects those systems and they are needed to build the brief. This identity data originates from the Merchant's own systems, on the Merchant's instruction.
5. Merchant/account data. Shop domain and encrypted OAuth access tokens (a Merchant credential, not customer data), used to call the Merchant's connected APIs on the Merchant's behalf.
6. Special category data. None is intentionally Processed. The Merchant should not configure the Services to Process special-category data.
eu-west-1).Each Sub-processor is engaged under a written contract with data-protection terms at least as protective as this DPA, including the no-training commitment where it Processes Merchant Personal Data.
| Sub-processor | Role | Location | Data it processes | No-training / retention |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, storage, logging | EU (eu-west-1) | All hosted Merchant Personal Data, logs, backups | Does not use content to train models; encryption in place; GDPR/DPA addendum |
| Atlas Cloud | LLM inference (self-hosted DeepSeek models) | United States | Investigation prompts: order / value evidence and the brief (no name / email / phone / address from Shopify) | No training on Atlas-hosted models; content retained ≤ 7 days then deleted; Zero Data Retention available |
| PostHog | Product analytics / telemetry | EU (Frankfurt) | Event names and internal identifiers only (no order or customer record bodies) | Configurable retention; not used to train models |
| Resend | Transactional email delivery | United States | Recipient email address and message content for account / service emails | Delivery only |
Feature-gated (not on the default Shopify path; listed for completeness): OpenRouter / OpenAI (memory embeddings, only if the Merchant enables the memory feature), Groq (audio transcription, only if audio attachments are Processed).