Data Processing Addendum
Version 2026-10 • Last updated: October 2026
1. About this Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between ChatFirm (“Processor”) and the merchant who installs the ChatFirm app on their Shopify store (“Merchant” or “Controller”) under the Terms of Service (the “Agreement”). It applies when ChatFirm processes Personal Data of the Merchant's customers on the Merchant's behalf. The Merchant accepts it in the ChatFirm dashboard (Settings → Data processing agreement); acceptance is recorded with a date and version.
“Personal Data,” “process,” “controller,” “processor” and “data subject” have the meanings they have in applicable data-protection law, including, where it applies, the EU/UK GDPR and Pakistan's data-protection and e-commerce laws (“Data Protection Law”).
2. Roles
The Merchant is the Controller of Customer Personal Data; ChatFirm is the Processor. ChatFirm is an independent controller of the limited Merchant account information it holds for its own purposes (billing, security, support), which is governed by the Privacy Policy.
3. Subject matter, duration and purpose
ChatFirm processes Customer Personal Data only to provide the ChatFirm service to the Merchant as described in the Agreement: WhatsApp order confirmation and follow-up, address verification, payment-proof handling, courier booking and tracking, review requests, abandoned-checkout reminders to opted-in customers, and alerts to the Merchant's admins. Processing lasts for the term of the Agreement and then as set out in section 12. The categories of data and data subjects are in Annex I.
4. Merchant instructions
- ChatFirm processes Customer Personal Data only on the Merchant's documented instructions: the Agreement, this DPA, the settings the Merchant chooses in the dashboard, and the Merchant's use of the features.
- ChatFirm will tell the Merchant if it believes an instruction infringes Data Protection Law. ChatFirm will not use Customer Personal Data for its own purposes, sell it, or combine it across merchants.
- The Merchant is responsible for having a lawful basis and the necessary notices and consents for the messages it sends through ChatFirm, and for using its WhatsApp account in line with WhatsApp's terms. ChatFirm sends abandoned-checkout reminders only to customers who ticked Shopify's marketing opt-in, and honours STOP replies.
5. Confidentiality
ChatFirm ensures that everyone it authorises to process Customer Personal Data is bound by a duty of confidentiality and receives access only as far as their role requires.
6. Security
ChatFirm maintains the technical and organisational measures in Annex II and will not materially reduce the protection they give. They include, among others:
- Encryption in transit (TLS) and at rest, and additional application-level encryption of Shopify access tokens and courier credentials.
- Private storage of payment screenshots, shown only through short-lived links.
- Access to production data limited to authorised personnel using strong passwords and multi-factor authentication; an access log of views and exports of customer data.
- Separation of test and production data; encrypted backups; a written incident-response plan.
- Automatic enforcement of the retention periods in Annex IV.
7. Subprocessors
The Merchant gives ChatFirm general authorisation to use the subprocessors listed in Annex III. ChatFirm will bind each subprocessor to data-protection obligations no less protective than this DPA and remains responsible for its performance. ChatFirm will give Merchants at least 30 days' notice of a new or replacement subprocessor (by notice in the dashboard and an update to the Subprocessors page). A Merchant who reasonably objects on data-protection grounds may uninstall the app within that period, and ChatFirm will then erase the store's data under section 12.
8. International transfers
Customer Personal Data may be processed outside the country where the Merchant or the data subject is located, including in Australia (database and storage) and the United States (AI address checking) and by Shopify in its own infrastructure. ChatFirm will use appropriate safeguards where Data Protection Law requires them and will make the relevant terms available on request.
9. Data subject requests and Shopify privacy requests
- ChatFirm will help the Merchant respond to data subjects who exercise their rights (access, correction, erasure, restriction, objection), using the tools in the dashboard (data export, privacy requests) and by email to the address below.
- Shopify's mandatory privacy requests are handled automatically: for customers/data_request ChatFirm prepares the customer's stored data for the Merchant within the 30 days Shopify allows; for customers/redact ChatFirm removes the customer's personal details within 30 days of Shopify sending the request; for shop/redact ChatFirm erases the store's data when Shopify sends it, 48 hours after the app is uninstalled.
- If a data subject contacts ChatFirm directly about Merchant data, ChatFirm will refer them to the Merchant unless the law requires otherwise.
10. Personal data breaches
ChatFirm will notify the Merchant without undue delay, and within 72 hours, after confirming a personal data breach affecting the Merchant's Customer Personal Data. The notice will describe what is known about the nature of the breach, the data and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed, and ChatFirm will keep the Merchant updated and cooperate in any notification to authorities or data subjects.
11. Assistance and audits
ChatFirm will give the Merchant reasonable help with data-protection impact assessments and consultations with authorities where they relate to ChatFirm's processing, and will make available the information reasonably needed to show compliance with this DPA, including answers to a written security questionnaire once a year. On-site audits are limited to what is reasonably required by law or by a competent authority, on reasonable notice, during business hours, and subject to confidentiality.
12. Return and deletion
While the Agreement is in force the Merchant can export its data from the dashboard (Settings). When the Merchant uninstalls the app, Shopify sends ChatFirm a shop-erasure request 48 hours later and ChatFirm then erases the store's Customer Personal Data (orders, checkouts, settings, connections, logs, payment screenshots and the WhatsApp session). Backups are overwritten as part of the provider's normal backup cycle. ChatFirm keeps only the minimal merchant and billing record needed for accounting, which contains no Customer Personal Data, and anything the law requires it to keep.
13. Liability, governing law and order of precedence
Each party's liability under this DPA is subject to the limitations in the Agreement. This DPA is governed by the law and jurisdiction stated in the Agreement. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails.
Annex I: details of processing
| Item | Detail |
|---|---|
| Data subjects | Customers of the Merchant's Shopify store who place an order, or start a checkout and opt in to marketing. |
| Categories of Personal Data | Name, phone number, delivery address, order details (order number, items, total, payment method and status), replies sent on WhatsApp (YES / NO / ADVANCE / STOP, address corrections, cancellation reasons), payment screenshots, courier consignment and delivery status, and technical event records. No customer email addresses are collected. |
| Special categories | None are intended. Free-text replies and screenshots could incidentally contain other information; ChatFirm does not analyse them for it. |
| Nature and purpose | Storage, organisation, transmission and deletion in order to run the automations described in section 3. |
| Frequency | Continuous, while the Merchant's store is active. |
| Retention | As set out in Annex IV. |
Annex II: technical and organisational measures
| Area | Measure |
|---|---|
| Encryption | TLS for all traffic. Database and file storage encrypted at rest by the provider. Shopify access tokens and courier credentials additionally encrypted with AES-256-GCM before storage. STOP opt-outs stored as a keyed hash, not as phone numbers. |
| Access control | Production data accessible only to authorised personnel, on a least-privilege basis; the database service key is held only in the server environment; strong passwords and multi-factor authentication on every account that can reach production data; access removed promptly when a person leaves. |
| Storage of screenshots | Private bucket; short-lived signed links only. |
| Logging | Application-level access log of every view or export of customer data through the dashboard and of every privacy action (counts, not content); retained 12 months. |
| Separation | Production and test data are kept in separate environments. |
| Backups and resilience | Provider-managed, encrypted backups of the production database. |
| Minimisation | Only name, phone and address are requested from Shopify; email is not collected; checkouts are stored only for opted-in customers; raw order copies are cut down after 30 days. |
| Retention | Automatic daily enforcement of Annex IV, and automatic handling of Shopify's privacy requests. |
| Incident response | Written plan covering detection, containment, assessment, notification (Merchants within 72 hours of confirmation; Shopify as required) and review. |
| Personnel | Confidentiality obligations; security and privacy briefing before access is granted. |
Annex III: subprocessors
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Shopify Inc. | Platform on which ChatFirm is installed. Delivers order and checkout events to ChatFirm and receives the changes ChatFirm makes (for example order tags and notes). | Store details; orders and checkouts of the Merchant's own store. | Canada / United States (Shopify's infrastructure) |
| Supabase Inc. | Database and file storage for ChatFirm: merchant settings, orders, abandoned checkouts, privacy-request records, logs and payment screenshots. Data is encrypted at rest and in transit. | All data described in the Privacy Policy, except message content held only inside WhatsApp. | Sydney, Australia (AWS ap-southeast-2) |
| Groq, Inc. | AI language model that judges whether a customer's free-text address reply is a complete delivery address. | The text of the customer's address reply only. No name, phone number or order number is sent. Groq does not train on it and, with ChatFirm's zero-data-retention setting, does not keep it. | United States |
| Railway Corp. | Hosts the shared OpenWA service, an open-source, unofficial WhatsApp Web integration through which messages are sent and received on the Merchant's own WhatsApp account. | WhatsApp session credentials needed to stay connected, and a copy of the messages the session sends and receives (including customers' replies), which the service deletes automatically after 30 days. | As configured for ChatFirm's Railway project (confirmed in the subprocessor register before launch) |
| Vercel Inc. | Hosts the ChatFirm web application and receives the order and checkout events sent by Shopify. | Customer name, phone number, address and order details while they are processed; request logs are kept for a short period. | United States (ChatFirm's functions run in Sydney, Australia) |
| ngrok Inc. | A tunnel that carries ChatFirm's internal requests to its workflow engine until the engine moves to its own server. | Order and customer details in transit, encrypted; ngrok does not store the content. | United States |
| Server hosting provider (ChatFirm application and workflow automation) | Runs the ChatFirm web application and the workflow engine (n8n) that carries out the automations. | Data in transit between Shopify, WhatsApp, the courier and the database; transient processing only. | Named here when production hosting goes live; this page is updated and merchants are notified before any new subprocessor handles customer data |
Annex IV: retention
| Data | Kept for | Then |
|---|---|---|
| Orders (customer name, phone, delivery address, replies) | 12 months from the order date | Personal details are removed. The order's stage, totals and dates remain so billing counts and order history stay accurate. |
| Message copies held by the WhatsApp gateway (OpenWA), including customers' replies | 30 days | Deleted automatically by the gateway. A customer erasure request removes the customer's details from ChatFirm immediately; their messages in the gateway age out within these 30 days. |
| Raw copy of the Shopify order | 30 days | Cut down to the product lines (product, quantity, price); everything else is deleted. |
| Abandoned checkouts (only customers who opted in to marketing) | 30 days | Deleted. |
| Technical logs | 90 days | Deleted. |
| Payment screenshots | 12 months | Deleted from storage. |
| Customer data exports prepared for a Shopify data request | 30 days | Deleted. |
| Access log (who viewed or exported customer data) | 12 months | Deleted. |
| WhatsApp STOP opt-outs | Kept while the store is a ChatFirm customer | Stored only as a one-way keyed hash, never the phone number, so a customer who opted out is never messaged again. Deleted with the store's data when the store is erased. |
| Website waitlist (name, email, store URL) | Until ChatFirm opens to you or you ask us to delete it | Deleted on request. |
| Billing history and the merchant record (no customer personal data) | As required for accounting | Kept after a store is erased. |
Contact
Data-protection questions and requests under this DPA: privacy@chatfirm.tech. Legal notices: legal@chatfirm.tech.