Legal
Data Processing Addendum
Version 1.2 · Last updated: July 2026
1. Parties, subject matter and duration
This Data Processing Addendum (“DPA”) supplements the Terms of Service for the ReplyHop app for Shopify and is concluded between the Merchant (the “Controller”) and ReplyHop, Philip Ladendorf, Stralauer Allee 17B, 10245 Berlin, Germany (the “Processor”). It governs the processing of personal data that the Processor carries out on behalf of the Controller pursuant to Art. 28 GDPR. The duration of this DPA corresponds to the duration of the Terms of Service; it ends when the app is uninstalled and the data has been deleted in accordance with Section 9.
2. Nature and purpose of the processing
The Processor operates a customer support ticketing service embedded in the Shopify admin. On the Controller’s behalf, the Processor receives customer support emails, stores and organises them as support tickets, retrieves and caches customer and order context from the Controller’s Shopify store to display alongside tickets, sends the Controller’s replies to customers by email, and delivers related notifications to the Controller’s staff.
3. Categories of data subjects and personal data
Data subjects concerned by the processing:
(a) customers and prospective customers of the Controller’s store who contact the Controller’s support address or are the subject of a support ticket; and
(b) staff members of the Controller who use the app.
Categories of personal data processed:
(a) identification and contact data (name, email address);
(b) the content of support communication, including email subject, message bodies and file attachments;
(c) Shopify customer and order context (customer ID, order history metadata such as order numbers, totals, fulfilment status, city/region/country of the default address, customer tags and notes);
(d) for staff members: name, email address and actions performed in the app (audit trail).
Special categories of personal data within the meaning of Art. 9 GDPR are not intended to be processed; the Controller shall not direct such data to the Service.
4. Instructions
The Processor processes personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law. The functionality of the Service as configured and used by the Controller, together with the Terms of Service and this DPA, constitutes the Controller’s complete instructions. The Processor shall inform the Controller immediately if, in its opinion, an instruction infringes applicable data protection law.
5. Confidentiality and security
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality. The Processor implements appropriate technical and organisational measures pursuant to Art. 32 GDPR, including as a minimum: encryption of data in transit (TLS) and at rest; strict per-store tenant isolation enforced at the data layer; authenticated access via Shopify’s session token mechanism; role-limited administrative access to production systems protected by strong authentication; logging of processing operations and an audit trail of staff actions within the app; separation of test and production environments; and encrypted, managed backups.
6. Subprocessors
The Controller grants a general authorisation for the engagement of subprocessors. The Processor has concluded data processing agreements with each subprocessor imposing data protection obligations equivalent to those in this DPA. The subprocessors currently engaged are:
(a) Convex, Inc., 444 De Haro St, San Francisco, CA, USA — application database and backend (data stored in the EU, eu-west-1);
(b) Resend, Inc., 2261 Market Street #5039, San Francisco, CA, USA — inbound and outbound email processing;
(c) Railway Corp., 548 Market St, San Francisco, CA, USA — application server hosting;
(d) BunnyWay d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia — storage of email attachments;
(e) Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA — AI gateway that routes draft-reply generation requests to the model provider;
(f) Fireworks AI, Inc., 2317 Broadway St, Redwood City, CA 94063, USA — hosting and inference of the language model (an open-weights DeepSeek model operated on Fireworks infrastructure) for AI-drafted reply suggestions, processing ticket message content and related order context. Requests are routed exclusively to Fireworks; no data is transmitted to DeepSeek. Fireworks processes draft-generation content with zero data retention and does not use it to train models.
The Processor will inform the Controller of intended changes concerning the addition or replacement of subprocessors by updating this page and giving notice through the app or by email, giving the Controller the opportunity to object on reasonable data protection grounds. If an objection cannot be resolved, the Controller may terminate the agreement by uninstalling the app.
7. International transfers
Where subprocessors are located in the USA or another third country, the transfer is safeguarded by the EU Standard Contractual Clauses pursuant to Art. 46 (2) (c) GDPR, and where applicable by an adequacy decision (such as the EU-U.S. Data Privacy Framework where the subprocessor is certified), together with supplementary measures where required.
8. Assistance and personal data breaches
Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organisational measures in fulfilling the Controller’s obligations to respond to requests from data subjects (Art. 12–23 GDPR) — including through Shopify’s mandatory data request and redaction mechanisms, which the Service implements — and in ensuring compliance with the obligations pursuant to Art. 32–36 GDPR. The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, providing the information required by Art. 33 (3) GDPR insofar as it is available.
9. Deletion and return of data
Upon termination of the agreement — in particular when the Controller uninstalls the app — the Processor deletes the personal data processed on the Controller’s behalf in accordance with Shopify’s app data deletion process, unless Union or Member State law requires storage. Individual customer data is additionally redacted upon receipt of a customer redaction request relayed by Shopify. The Controller can export ticket data prior to uninstallation.
10. Audit rights
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR. The Controller’s audit rights are primarily satisfied by the provision of meaningful documentation, including descriptions of the technical and organisational measures and relevant attestations of subprocessors (such as SOC 2 reports). Where this is not sufficient in an individual case, the Controller may conduct an audit upon reasonable advance notice during normal business hours, no more than once per year unless a personal data breach gives cause for an additional audit.
11. Final provisions
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with regard to the processing of personal data. The law of the Federal Republic of Germany applies. Should individual provisions of this DPA be or become invalid, the validity of the remaining provisions remains unaffected.