SpeakingOf
Data Processing Agreement
The Article 28 terms under which SpeakingOf processes personal data on behalf of a merchant.
Last updated: 29 August 2026
1. Scope and acceptance
This Data Processing Agreement ("DPA") applies to every merchant that installs and uses the SpeakingOf Shopify app ("the App"), and forms part of the agreement between that merchant ("Merchant") and the operator of the App ("Operator"). It takes effect when the Merchant installs the App and remains in effect for as long as the App is installed.
It is entered into in electronic form, as permitted by Article 28(9) of the General Data Protection Regulation. No signature is required for it to apply. A Merchant who needs a countersigned copy, or who requires their own data processing terms, can request one at hello@speakingof.app, and the Operator's full legal name, country of establishment, and registered address will be provided as part of that document.
Where this DPA conflicts with any other terms between the parties, this DPA governs the processing of personal data.
2. Roles of the parties
For personal data processed through the App, the Merchant is the data controller and the Operator is the data processor. The Merchant determines which conversations exist on its storefront, which spaces are created, who may take part in them, and which features of the App are enabled. Shopify remains an independent party in its own right for the platform, authentication, and billing it provides.
3. Subject matter, nature, and purpose
The Operator processes personal data solely to provide the App: displaying and delivering storefront conversations, supporting the Merchant's team in the Inbox, moderating content, sending the notifications the Merchant enables, and producing the Merchant's own analytics and attribution reporting. Processing lasts for as long as the App is installed, plus the retention periods in section 7.
4. Categories of data subjects and personal data
Data subjects: the Merchant's customers and storefront visitors who take part in a conversation, and the Merchant's own staff who use the App.
Personal data:
- Read from Shopify: customer ID, display name, first and last name, email address, account state, tags, number of orders, and amount spent; and order context (order number and date, status, total, line item titles and quantities, fulfilment tracking details).
- Stored by the App: a participant record containing the Shopify customer ID, first name, display name, and email address; conversation content including messages, replies, reactions, poll votes, and image attachments; guest session records; and usage and attribution events.
- Provided by the Merchant: internal notes, saved replies, moderation decisions, a notification recipient email address, and configuration.
Order details are read from Shopify each time they are displayed and are not stored by the App. Customer tags, order count, and amount spent are cached for five minutes. No special categories of personal data are requested by the App.
5. Obligations of the Operator
- Instructions. The Operator processes personal data only on the Merchant's documented instructions, which include the Merchant's configuration of the App and this DPA, unless required otherwise by law.
- Confidentiality. Every person authorised to process the personal data is bound by confidentiality.
- Security. The Operator implements appropriate technical and organisational measures as described in section 8.
- Sub-processors. The Operator uses the sub-processors listed in section 6, imposes equivalent data protection obligations on them, and gives the Merchant notice before adding or replacing one, so that the Merchant may object.
- Data subject rights. The Operator assists the Merchant in responding to requests for access, correction, deletion, restriction, objection, and portability, including through Shopify's customer data request and redaction webhooks.
- Assistance. The Operator assists the Merchant with security obligations, breach notification, and data protection impact assessments, taking into account the nature of the processing and the information available.
- Deletion. On uninstallation, or on the Merchant's request, the Operator deletes the personal data as described in section 7.
- Audit. The Operator makes available the information necessary to demonstrate compliance with Article 28 and contributes to audits or inspections carried out by the Merchant or its auditor, on reasonable notice and no more than once a year unless required by a supervisory authority.
6. Sub-processors
- Amazon Web Services - application hosting, database, and image attachment storage, in the us-east-1 (United States) region.
- Resend - delivery of the notification and report emails a Merchant enables.
- Shopify - platform, authentication, billing, and the APIs the App reads.
The current list is maintained on this page. Merchants who wish to be notified by email of a change can ask to be added to that list at the contact address below.
7. Retention and deletion
- Messages, reactions, and poll votes - up to 24 months, then deleted.
- Image attachments - the retention window the Merchant selects, up to 180 days by default.
- Guest session tokens - 180 days from last use.
- Configuration, analytics, and attribution records - for the life of the Merchant's account.
The App implements Shopify's data request, customer redaction, and shop redaction webhooks. When the Merchant uninstalls the App, the store's conversations, configuration, and billing records are deleted. When Shopify sends a customer redaction request, that customer's conversation data and attachments are deleted.
8. Security measures
Personal data is encrypted in transit using TLS and encrypted at rest by the underlying AWS services. Access to production systems and to protected customer data is limited to the Operator and is logged. Production and test environments are kept separate. Image attachments are served only through short-lived authorised links rather than public URLs. The App applies rate limiting, spam protection, and the content moderation controls the Merchant configures.
9. Personal data breaches
The Operator notifies the Merchant without undue delay after becoming aware of a personal data breach affecting the Merchant's data, and provides the information the Merchant needs to meet its own notification obligations.
10. International transfers
The Operator is not established in the European Economic Area, and personal data is stored and processed in the United States as described above. Where the Merchant is established in the EEA, the United Kingdom, or Switzerland, the parties will enter into the European Commission's Standard Contractual Clauses, or the applicable UK or Swiss equivalent, on request at the contact address below.
11. Term and contact
This DPA remains in force while the App is installed and, for the obligations that survive it, until the personal data has been deleted. Questions, requests for a countersigned copy, requests for the Standard Contractual Clauses, and audit requests go to hello@speakingof.app.
