Handsom logo

Data Processing Agreement

Version 1.0 · Draft pending legal review.

This Data Processing Agreement ("DPA") governs Handsom's Processing of Personal Data on behalf of merchants who install or use the Handsom application. It forms part of, and is incorporated into, the agreement between the parties.


1. Parties and effective date

This DPA is entered into between:

  • Processor: HANDSOM LTD (registered in Northern Ireland, company number NI733489), trading as Handsom, of 18 The Baths, Ormeau Avenue, Belfast BT2 8HS, United Kingdom ("Handsom", "we", "us"); and
  • Controller: the merchant that installs or uses the Handsom application ("Merchant", "you"),

each a "party" and together the "parties". It takes effect on the date the Merchant installs the Handsom application or otherwise accepts this DPA (the "Effective Date"), and governs Handsom's Processing of Personal Data on the Merchant's behalf.

Where the Merchant acquires Handsom through the Shopify App Store, this DPA also gives effect to the sub-processor and data-protection obligations Shopify imposes on app developers under the Shopify API License Terms and Protected Customer Data requirements.

2. Definitions

Capitalised terms not defined here have the meaning given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, the UK GDPR and other Data Protection Laws.

  • Data Protection Laws — all laws applicable to the Processing of Personal Data under this DPA, including the GDPR, UK GDPR, and applicable US state privacy laws.
  • Personal Data, Processing, Controller, Processor, Sub-processor, Data Subject, Personal Data Breach, Supervisory Authority — as defined in the GDPR.
  • Merchant Personal Data — Personal Data that Handsom Processes on the Merchant's behalf under this DPA, described in Annex I.
  • Protected Customer Data — the category of customer Personal Data defined by Shopify; Handsom operates at Shopify Level 1 and does not request or store the protected customer fields (name, email, phone, address) from the Merchant's Shopify store (Annex I, §3).
  • Services — the Handsom application and related services: cross-system investigation of a support case and generation of a research brief with a recommended action for a human support agent.

3. Roles and scope of Processing

3.1 The Merchant is the Controller and Handsom is the Processor of the Merchant Personal Data. Where a party determines it acts as an independent controller for a given operation, that Processing falls outside this DPA.

3.2 Handsom Processes Merchant Personal Data only on the Merchant's documented instructions, including as set out in this DPA and the app's configuration, unless required to do otherwise by law (in which case Handsom will inform the Merchant first, unless the law prohibits it).

3.3 The subject-matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.

3.4 No automated decision-making with legal or significant effect. The Services produce a recommendation to a human agent (a brief), not an action taken toward a Data Subject. Handsom does not use Merchant Personal Data to make decisions producing legal or similarly significant effects on Data Subjects.

4. Handsom's obligations

Handsom will:

(a) Instructions. Process Merchant Personal Data only on the Merchant's documented instructions (§3.2), and inform the Merchant if, in Handsom's opinion, an instruction infringes Data Protection Laws.

(b) Confidentiality. Ensure persons authorised to Process Merchant Personal Data are bound by confidentiality obligations.

(c) Security. Implement and maintain the technical and organisational measures in Annex II, appropriate to the risk under GDPR Article 32.

(d) Sub-processors. Engage Sub-processors only under §6 and Annex III.

(e) Data Subject requests. Taking into account the nature of the Processing, assist the Merchant by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject requests to exercise their rights (access, rectification, erasure, restriction, portability, objection). Because Handsom stores no direct customer identifiers from Shopify (Annex I §3), most such requests are fulfilled by the Merchant in their source systems; Handsom will delete or export the limited derived records it holds on request.

(f) Assistance. Assist the Merchant in ensuring compliance with GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of Processing and the information available to Handsom.

(g) Deletion or return. At the choice of the Merchant, delete or return all Merchant Personal Data at the end of the provision of the Services, and delete existing copies unless law requires storage. See §7.

(h) Audit. Make available to the Merchant information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor it mandates, subject to reasonable confidentiality, notice, and frequency limits.

5. Purpose limitation and no AI training

5.1 Handsom Processes Merchant Personal Data solely to provide the Services to the Merchant, and for no other purpose. Handsom does not sell Merchant Personal Data and does not use it for its own purposes or for competitive benchmarking.

5.2 No training of AI/ML models. Handsom will not use Merchant Personal Data (or any data derived from it, including anonymised, aggregated, or derived forms) to create, develop, train, fine-tune, or improve any machine-learning or artificial-intelligence system or model, including large language models, except with the Merchant's prior written consent. Handsom contractually binds each Sub-processor that Processes Merchant Personal Data to an equivalent no-training commitment (Annex III). This mirrors Shopify API License Terms §2.3.24.

6. Sub-processors

6.1 The Merchant provides general authorisation for Handsom to engage the Sub-processors listed in Annex III to Process Merchant Personal Data in connection with the Services.

6.2 Handsom will impose on each Sub-processor, by written contract, data-protection obligations at least as protective as those in this DPA, including confidentiality, security, purpose limitation to providing services to Handsom, and the no-training commitment (§5.2). Handsom remains liable to the Merchant for its Sub-processors' performance.

6.3 Handsom will give the Merchant prior notice of the addition or replacement of a Sub-processor by updating Annex III (and, where feasible, notifying via the app or email), giving the Merchant a reasonable opportunity to object on reasonable data-protection grounds. If the parties cannot resolve a good-faith objection, the Merchant may terminate the Services for the affected Processing.

7. Retention and deletion

7.1 Retention. Handsom retains Merchant Personal Data for the life of the Merchant's installation of the Services, and only as long as needed for the purposes in §5. Operational logs are retained for approximately 30 days; database backups for up to 7 days.

7.2 Deletion on uninstall or request. Handsom deletes all Merchant Personal Data within 30 days of (a) the Merchant uninstalling the application, (b) it no longer being required to provide the Services, or (c) an enforceable deletion request from the Merchant, a Data Subject, or Shopify. On Shopify, uninstall triggers the shop/redact webhook, which erases the Merchant's environment and all derived records (integrations, tasks, briefs, evidence, memory, usage) by database cascade; backups age out within their 7-day window. This mirrors Shopify API License Terms §6.2.3.

7.3 Handsom will confirm deletion in writing on request.

8. Personal Data Breach

8.1 Handsom will notify the Merchant without undue delay after becoming aware of a Personal Data Breach affecting Merchant Personal Data, and provide information reasonably available to assist the Merchant's own notification obligations.

8.2 Where the Merchant obtained Handsom through Shopify and the breach affects Shopify Merchant Data, Handsom will also notify Shopify no later than 24 hours after becoming aware, per Shopify API License Terms §6.2.10.

9. International transfers

9.1 Handsom is established in the United Kingdom (Northern Ireland) and primarily hosts and Processes Merchant Personal Data in the European Union (AWS eu-west-1). For a Merchant established in the EEA, transfers of Merchant Personal Data to Handsom in the UK rely on the European Commission's adequacy decision for the United Kingdom. Certain Processing (LLM inference, and specific US-hosted Sub-processors in Annex III) may involve transfer to the United States.

9.2 Where Handsom transfers Merchant Personal Data outside the EEA/UK to a country without an adequacy decision, it will implement a valid transfer mechanism (for example, the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, or a Data Privacy Framework certification), which are incorporated by reference where used.

10. Liability, term, and general

10.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the parties' underlying agreement / Handsom's Terms of Service.

10.2 This DPA remains in effect for as long as Handsom Processes Merchant Personal Data. Sections that by their nature should survive termination (including §5, §7, §8) survive.

10.3 In case of conflict between this DPA and the underlying agreement on the subject of data protection, this DPA prevails. This DPA is governed by the laws of Northern Ireland, and the parties submit to the exclusive jurisdiction of the courts of Northern Ireland. Where Standard Contractual Clauses or the UK International Data Transfer Addendum apply to a specific transfer (§9, Annex III), those instruments are governed as their own terms require.

10.4 Handsom may update this DPA to reflect changes in law, the Services, or Sub-processors; material changes reducing the Merchant's protections will be notified in advance.

Contact for data-protection matters: [email protected].


Annex I — Details of the Processing

Subject-matter and duration. Processing of the Personal Data described below to provide the Services, for the duration of the Merchant's installation (§7).

Nature and purpose. To investigate a customer support case across the Merchant's connected systems and generate a research brief with a recommended action for a human support agent. Handsom does not contact Data Subjects and does not take actions toward them automatically.

1. Categories of Data Subjects. The Merchant's customers and prospective customers who are the subject of support cases and associated commerce records.

2. Data Handsom processes from the Merchant's connected commerce platform (e.g. Shopify). Order data (identifier, status, financial totals, currency, fulfillment status, tracking, line items, tags, order note, risk signals); fulfillment, refund, and return data; product data; and customer value/loyalty signals (Shopify customer identifier, number of orders, amount spent, tags, account creation date). Handsom uses the customer's email or identifier as a lookup input to fetch these records, but does not persist it from Shopify.

3. Protected customer fields NOT processed from Shopify (Level 1). Handsom does not request, receive, or store the customer's name, email address, phone number, or postal address from the Merchant's Shopify store. Customer identity, where needed, is supplied by the Merchant's own helpdesk (below), not by Shopify.

4. Data Handsom processes from the Merchant's connected helpdesk / other systems (e.g. Gorgias, Zendesk, Intercom, returns, subscriptions, carrier, loyalty). Support ticket content and metadata, and the customer identity the Merchant already holds there (which may include name and email), to the extent the Merchant connects those systems and they are needed to build the brief. This identity data originates from the Merchant's own systems, on the Merchant's instruction.

5. Merchant/account data. Shop domain and encrypted OAuth access tokens (a Merchant credential, not customer data), used to call the Merchant's connected APIs on the Merchant's behalf.

6. Special category data. None is intentionally Processed. The Merchant should not configure the Services to Process special-category data.


Annex II — Technical and organisational security measures

  • Encryption in transit. All API calls to connected systems use TLS/HTTPS. Edge traffic terminates TLS at a load balancer with a managed certificate.
  • Encryption at rest. OAuth access/refresh tokens are encrypted with AES-256-GCM before storage. The primary database enables storage-level encryption at rest (managed KMS key); object storage and queues use managed encryption.
  • Network isolation. The database runs in private, isolated subnets with no public access; IAM authentication; deletion protection; administrative access via session-manager only (no public SSH).
  • Hosting region. Primary hosting and data storage in the EU (AWS eu-west-1).
  • Access control. Least-privilege access; authorised personnel bound by confidentiality.
  • Least data / least scope. Handsom requests the minimum API scopes needed and, on Shopify, operates at Level 1 (no protected customer fields).
  • Integrity of webhooks. Inbound platform webhooks (including deletion/compliance webhooks) are verified by HMAC signature before processing.
  • Deletion. Environment-scoped cascade deletion on uninstall/redact (§7).

Annex III — Authorised Sub-processors

Each Sub-processor is engaged under a written contract with data-protection terms at least as protective as this DPA, including the no-training commitment where it Processes Merchant Personal Data.

Sub-processorRoleLocationData it processesNo-training / retention
Amazon Web Services (AWS)Cloud hosting, database, storage, loggingEU (eu-west-1)All hosted Merchant Personal Data, logs, backupsDoes not use content to train models; encryption in place; GDPR/DPA addendum
Atlas CloudLLM inference (self-hosted DeepSeek models)United StatesInvestigation prompts: order / value evidence and the brief (no name / email / phone / address from Shopify)No training on Atlas-hosted models; content retained ≤ 7 days then deleted; Zero Data Retention available
PostHogProduct analytics / telemetryEU (Frankfurt)Event names and internal identifiers only (no order or customer record bodies)Configurable retention; not used to train models
ResendTransactional email deliveryUnited StatesRecipient email address and message content for account / service emailsDelivery only

Feature-gated (not on the default Shopify path; listed for completeness): OpenRouter / OpenAI (memory embeddings, only if the Merchant enables the memory feature), Groq (audio transcription, only if audio attachments are Processed).