Data Processing Addendum
Account Editor Chatbot for Shopify · Operated by ITGeeks · Effective: 19 July 2026
This Data Processing Addendum ("DPA") forms part of the agreement between ITGeeks
("Processor", "we") and the merchant who installs the Account Editor Chatbot app
("Controller", "you"). By installing or continuing to use the App, you agree to this DPA.
It applies to all personal data of your customers that the App processes on your behalf.
1. Roles and scope
- You are the data controller of your customers' personal data. We are your data processor.
- The subject matter, nature, purposes, categories of data, and retention periods of the
processing are described in our Privacy Policy,
which is incorporated into this DPA.
- We process personal data only to provide the App's features to you and your customers,
and on your documented instructions (which include your configuration of the App). We do
not sell personal data or process it for our own purposes.
2. Confidentiality and personnel
- Access to personal data is limited to personnel who need it to operate and support the
App, and who are bound by confidentiality obligations.
- Administrative access to production systems is restricted to authorized personnel and
protected by strong authentication.
3. Security
- We implement appropriate technical and organizational measures, including: encryption of
personal data in transit (TLS) and at rest (AES-256, including backups); strict per-store
data isolation; authenticated and HMAC-verified integrations; audit logging of automated
actions and deletion operations; and automatic expiry of transient data.
- We maintain a security incident response process. We will notify you without undue delay
after becoming aware of a personal data breach affecting your customers' data, and will
provide the information reasonably required for you to meet your own notification
obligations.
4. Sub-processors
- You authorize the sub-processors listed in the
Privacy Policy (hosting, database, language-model,
messaging, and email-delivery providers).
- We remain responsible for our sub-processors' performance and impose data protection
obligations on them consistent with this DPA.
- We will update the published sub-processor list before adding a new sub-processor. Your
continued use of the App after an update constitutes acceptance; if you object, your
remedy is to uninstall the App (which triggers deletion under section 6).
5. Data subject rights and assistance
- The App implements Shopify's mandatory privacy webhooks. Customer data access requests are
logged for you to fulfil; customer deletion requests are executed automatically across all
of our systems and audit-logged.
- Taking into account the nature of the processing, we will reasonably assist you in
responding to data subject requests and in meeting your security, breach-notification,
and impact-assessment obligations.
6. Retention and deletion
- Personal data is retained only as long as described in the Privacy Policy's retention
table; transient data expires automatically.
- When you uninstall the App, all data for your store — including all of your customers'
personal data — is deleted following Shopify's 48-hour uninstall grace period. Deletion
operations are recorded in an audit log that contains identifiers and counts only.
7. International transfers
- Processing takes place in the United States. Where personal data originates from
jurisdictions requiring transfer safeguards, the parties rely on the sub-processors'
recognized transfer mechanisms and, where required, the standard contractual clauses
referenced by the applicable data protection law.
8. Audits
- On written request (no more than once per year, under confidentiality), we will make
available information reasonably necessary to demonstrate compliance with this DPA,
including summaries of our deletion audit logs for your store.
9. Contact
Privacy and data protection inquiries:
support@accounteditor.com.