Data Processing Addendum
Last updated: August 28, 2026
This Data Processing Addendum ("Addendum") is entered into between Chatoly LLC ("Chatoly," "we," "us," the "Processor") and the business that installs or uses the Chatoly app (the "Merchant," "you," the "Controller").
Version 1.0. This Addendum forms part of, and is incorporated by reference into, the Chatoly Terms of Service (https://chatoly.com/terms) at Section 6, "Data protection roles." Where this Addendum conflicts with the Terms, this Addendum governs in respect of the processing of End Customer Personal Data.
1. Definitions
- Applicable Data Protection Law — the EU GDPR, the UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and any other data protection law applicable to the processing.
- End Customer — a shopper, visitor, or other individual whose Personal Data is processed through the Merchant's use of the Service.
- End Customer Personal Data — Personal Data relating to End Customers that we process on the Merchant's behalf. Described in Annex I.
- Personal Data, processing, controller, processor, sub-processor, and personal data breach have the meanings given in the GDPR.
- Sub-processor — a third party engaged by us to process End Customer Personal Data.
2. Roles
The Merchant is the controller of End Customer Personal Data. Chatoly is the processor.
Chatoly is an independent controller of Merchant account data (the account holder's name, email address, Google account identifier, and app usage). That processing is governed by our Privacy Policy (https://chatoly.com/privacy), not by this Addendum.
Where the CCPA/CPRA applies, Chatoly acts as a service provider. We do not sell or share End Customer Personal Data, and we do not retain, use, or disclose it for any purpose other than performing the Service.
3. Scope and instructions
We process End Customer Personal Data only:
- (a) to provide the Service as described in the Terms and the Documentation;
- (b) in accordance with the Merchant's documented instructions, of which this Addendum, the Terms, and the Merchant's configuration of the Service are the complete set; and
- (c) as required by applicable law, in which case we will notify the Merchant before processing unless the law prohibits that notice.
If we consider an instruction to infringe Applicable Data Protection Law, we will inform the Merchant without undue delay and may suspend that processing.
Merchant responsibilities. The Merchant is responsible for establishing a lawful basis for the processing, for providing notice to End Customers, and for obtaining any consent required — in particular for the marketing and lead-capture features described in Annex I. Chatoly honours the marketing-consent signals it receives from the connected store and channels, but does not determine whether that consent was validly obtained.
4. Confidentiality
We ensure that every person authorised to process End Customer Personal Data is subject to a duty of confidentiality, and that access is limited to those who need it to provide the Service or to comply with law.
Chatoly staff access to a Merchant's workspace requires an explicit, time-limited grant. Each grant records the acting individual, the stated reason, the expiry, and the originating IP address, and is retained as an auditable record.
5. Security
We implement appropriate technical and organisational measures as required by GDPR Article 32. The measures in force are set out in Annex II. We may update them, provided the level of security is not materially reduced.
6. Sub-processors
The Merchant grants general written authorisation for us to engage Sub-processors. The current list is at Annex III.
We will give at least 30 days' notice before adding or replacing a Sub-processor, by email to the Merchant's account address and by updating Annex III. If the Merchant reasonably objects on data protection grounds within that period, the parties will work in good faith to find an alternative; if none is available, the Merchant may terminate the affected Service without penalty for the unused portion of any prepaid term.
We impose data protection obligations on each Sub-processor no less protective than this Addendum, and remain fully liable to the Merchant for their performance.
7. Assistance with data subject rights
Taking into account the nature of the processing, we assist the Merchant by appropriate technical and organisational measures in responding to End Customer requests to access, rectify, erase, restrict, port, or object to the processing of their Personal Data.
The Service provides self-service deletion and export of End Customer conversation data. Where the Merchant cannot fulfil a request through the Service, we will assist on request. We respond to Shopify's customer data request, customer redaction, and shop redaction webhooks as required by the Shopify Partner Program.
If a request is made directly to us, we will not respond to it substantively but will refer the individual to the Merchant without undue delay.
8. Personal data breach
We will notify the Merchant without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting End Customer Personal Data.
The notification will describe, so far as known at the time: the nature of the breach, the categories and approximate number of records and individuals concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. We will not delay an initial notification in order to complete an investigation; further information will follow as it is established.
We assist the Merchant in meeting its own obligations under GDPR Articles 33 and 34. Our internal handling of such events follows our documented Security Incident Response Policy, a copy of which is available to Merchants on request.
9. Data protection impact assessments
We provide reasonable assistance to the Merchant with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to us.
10. Deletion and return
On termination of the Service, we delete End Customer Personal Data within 90 days, except where retention is required by law.
During the term, End Customer Personal Data is deleted automatically according to the retention windows in Annex I. Backups are encrypted and expire on their own schedule (14 daily, plus the first backup of each month retained for 12 months); data present only in backups is deleted as those backups expire, and is not restored except as part of a documented recovery.
11. Audits
We make available to the Merchant the information reasonably necessary to demonstrate compliance with this Addendum, and allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor it mandates.
Audits are limited to once per twelve months unless required by a supervisory authority or following a personal data breach, must be requested at least 30 days in advance, must not unreasonably disrupt our operations, and are subject to confidentiality. We may satisfy an audit request by providing existing documentation, security-measure descriptions, or a third-party report where one is available.
12. International transfers
Chatoly is established in the United States and processes End Customer Personal Data there and in the locations of the Sub-processors listed in Annex III.
Where End Customer Personal Data is transferred from the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor, Decision (EU) 2021/914), which are incorporated into this Addendum by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies. In those Clauses the Merchant is the data exporter and Chatoly the data importer; Annexes I, II, and III of this Addendum supply the corresponding annex information; and the governing law and forum are those stated in the Terms, to the extent permitted by the Clauses.
13. Liability and precedence
The limitations of liability in the Terms apply to this Addendum. Nothing here limits a right an End Customer has directly under Applicable Data Protection Law.
Order of precedence: (1) the Standard Contractual Clauses, (2) this Addendum, (3) the Terms.
Annex I — Details of processing
Subject matter. Provision of the Chatoly AI chat, live chat, helpdesk, and messaging service to the Merchant.
Duration. For the term of the Merchant's use of the Service, plus the retention and deletion periods below.
Nature and purpose. Receiving, storing, displaying, analysing, and responding to communications between End Customers and the Merchant; retrieving order information to answer End Customer questions; and sending consent-gated messages on the Merchant's behalf.
Categories of data subject. End Customers and visitors to the Merchant's storefront and connected messaging channels.
Categories of Personal Data.
| Category | Detail | Source |
|---|---|---|
| Conversation content | Messages between the End Customer and the Merchant or the AI assistant, including anything the End Customer chooses to type | Widget, email, WhatsApp, Instagram, Messenger |
| Contact details | Email address; phone number and name where an End Customer provides them | Provided by the End Customer, or read from an order |
| Order data | Order number, status, line items, fulfilment and tracking information, order total, and the email address on the order | Shopify Admin API (read_orders) |
| Marketing consent status | Whether the End Customer has consented to marketing | Shopify order and customer records |
| Technical and behavioural data | Visitor identifier, pages viewed, cart and product context, approximate location (city/region/country/time zone), IP address, timestamps | Collected by the widget |
No special categories of Personal Data under GDPR Article 9 are requested by the Service. End Customers may volunteer such data in free-text messages; it is processed only as conversation content.
Purposes of processing protected customer data, as declared to Shopify: customer service, marketing or advertising (consent-gated recovery messaging), and analytics.
Retention. Enforced automatically by a daily job:
| Data | Window |
|---|---|
| Conversations and their messages | 365 days from the last message |
| Resolved and closed tickets | 365 days (open tickets are never deleted automatically) |
| Customer profiles | 365 days without activity |
| Widget coupon leads | 365 days |
| Recovery sends and events | 180 days |
| Raw inbound WhatsApp / Meta payloads | 90 days |
| Analytics events | 180 days |
| Visitor sessions, activity, and identities | 90 days |
| Protected-data access audit trail | 365 days |
Annex II — Technical and organisational measures
Encryption
- TLS for all data in transit, on certificates issued by Let's Encrypt.
- Shopify and messaging-channel access tokens encrypted at the application layer before storage.
- Database backups encrypted with AES-256; the key is stored outside the application environment and outside the backup location.
Resilience and recovery
- Automated nightly database backups, each verified as restorable immediately after it is written; an unreadable archive is discarded rather than retained.
- Restore rehearsals performed monthly into an isolated database.
- Backup retention: 14 daily, plus the first backup of each month retained for 12 months.
Access control
- Staff authentication is federated to Google; Chatoly stores no staff passwords.
- Merchant workspace access is role-scoped.
- Chatoly staff access to a Merchant workspace requires an explicit, time-limited, reasoned grant, recorded with actor, reason, expiry, and IP address.
Accountability and monitoring
- Every read of protected customer data is recorded with the actor, the data category, the declared purpose, and the outcome. The data subject is recorded as a salted fingerprint, so the audit trail does not itself hold contact details.
- Application and infrastructure logs are centralised and monitored.
- Automated enforcement of the retention windows in Annex I.
Organisational
- Documented Security Incident Response Policy with defined severities, a 72-hour merchant notification commitment, and post-incident review.
- Data minimisation: only the protected customer data fields required for the Service are requested from Shopify — currently order data and the email address on the order.
- Separation of production and non-production environments and data.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| OpenAI | AI generation of replies, summaries, and embeddings | United States |
| Vultr | Cloud infrastructure hosting and storage | United States |
| Resend | Transactional and recovery email delivery | United States |
| Meta Platforms | WhatsApp, Instagram, and Messenger message delivery | United States / Ireland |
| Staff and merchant authentication | United States | |
| Stripe | Subscription billing | United States |
| Expo | Mobile push notification delivery | United States |
This list is current as of the "Last updated" date above. Changes are notified under Section 6.
Contact
Data protection enquiries: support@chatoly.com
