Skip to content

New: Multi-store management is here — connect up to 3 stores on Growth.

Ship your first AI conversation in under 5 minutes.

Get 30% off your first 3 months — limited time.

Data Processing Agreement

Last updated: 2026-07-18

This Data Processing Agreement ("DPA") supplements the Terms of Service between Any Store AI ("Processor") and the merchant ("Controller") whenever the Controller's use of the Service involves personal data of individuals in the EU/EEA or UK ("Data Subjects"), consistent with Article 28 GDPR / UK GDPR. It is a standard starting template, not a countersigned legal instrument on its own. Email the contact address below to countersign a copy.

1. Subject matter and duration

Processor processes personal data on Controller's behalf for the duration of the underlying Terms of Service, solely to provide the chat widget, product search, and cart/checkout assistance features of the Service.

2. Nature and purpose of processing

Processing consists of: receiving customer chat messages, querying the Controller's store catalog, generating AI responses, and creating carts/checkout links on the Controller's behalf. Categories of Data Subjects: the Controller's end customers who interact with the chat widget. Categories of data: chat message content, and any contact details (e.g. email) a customer voluntarily provides mid-conversation.

3. Sub-processors

Controller authorizes Processor's use of the sub-processors listed in the Subprocessor List, which Processor will keep current. Processor remains liable for each sub-processor's compliance with the obligations of this DPA.

4. Processor obligations

  • Process personal data only on documented instructions from the Controller, including regarding international transfers.
  • Ensure personnel with data access are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (encryption at rest for store credentials, encrypted off-site backups, access-restricted production systems).
  • Assist the Controller in responding to Data Subject requests (access, deletion, portability) via the deletion/export process described in the Privacy Policy.
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting their data.
  • Delete or return all personal data at the end of the Terms, except where retention is required by law.

5. Data Subject rights

Processor will assist Controller in fulfilling Data Subject access, rectification, erasure, and portability requests to the extent the Service's own tooling allows, at no additional charge for reasonable requests.

6. International transfers

Where personal data is transferred outside the EEA/UK, Processor relies on its sub-processors' own Standard Contractual Clauses or equivalent safeguards.

7. Audit rights

Processor will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality.

8. Contact

To countersign this DPA or ask questions, contact [email protected].