SC
StoreWizData Processing Agreement
Version 1.0 — Effective March 1, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller", "Customer") and StoreWiz ("Processor") for the provision of the StoreWiz platform services.
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on Personal Data (collection, storage, use, disclosure, erasure).
- Data Subject: The individual to whom Personal Data relates.
- Sub-processor: A third party engaged by StoreWiz to process Personal Data.
- GDPR: General Data Protection Regulation (EU) 2016/679.
2. Scope of Processing
StoreWiz processes the following categories of Personal Data on behalf of the Customer:
- Customer Data: Names, email addresses, order history, browsing behavior from connected stores
- Communication Data: Email contents, chat messages processed via integrated accounts
- Analytics Data: Aggregated KPIs, revenue metrics, campaign performance
- Account Data: Team member names, emails, roles, login metadata
Processing purposes: Providing AI ecommerce analytics, campaign management, content generation, and business intelligence as described in the service agreement.
3. Obligations of the Processor
StoreWiz shall:
- Process Personal Data only on documented instructions from the Customer
- Ensure persons authorized to process data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Not engage another processor without prior written authorization from the Customer
- Assist the Customer in responding to Data Subject requests
- Delete or return all Personal Data upon termination of the agreement
- Make available all information necessary to demonstrate compliance
4. Security Measures
StoreWiz implements the following technical and organizational measures:
- Encryption at Rest: AES-256-GCM for sensitive data (OAuth tokens, credentials)
- Encryption in Transit: TLS 1.3 for all API communications
- Access Control: JWT-based authentication with httpOnly cookies, role-based access
- Data Isolation: Row-level security with tenant-scoped queries
- Audit Logging: Cross-tenant query audit trail for administrative access
- Data Retention: Configurable per-category retention policies with automated enforcement
- Backup: Daily encrypted backups with point-in-time recovery
5. Sub-processors
The Customer authorizes StoreWiz to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|
| Anthropic | AI model inference (Claude) | United States |
| Neon | PostgreSQL database hosting | US / EU (configurable) |
| Fly.io | Application hosting | US / EU (configurable) |
| Upstash | Redis (queue & cache) | US / EU (configurable) |
| Resend | Transactional email delivery | United States |
| LemonSqueezy | Payment processing | United States |
| Replicate / Fal.ai | Image generation | United States |
StoreWiz will notify the Customer of any intended changes to sub-processors at least 30 days before the change takes effect.
6. Data Subject Rights
StoreWiz provides tools to assist with Data Subject requests:
- Right of Access: Full data export available via Settings > Privacy > Export Data
- Right to Rectification: Data can be updated through the platform interface or API
- Right to Erasure: Account deletion with 30-day grace period via Settings > Privacy
- Right to Data Portability: JSON export of all data categories
- Right to Restrict Processing: Consent toggles for marketing, analytics, AI processing
- Right to Object: Consent management with full audit trail
7. Data Breach Notification
In the event of a Personal Data breach, StoreWiz shall:
- Notify the Customer without undue delay and no later than 72 hours after becoming aware
- Provide details of the breach: nature, categories and approximate number of Data Subjects affected
- Describe likely consequences and measures taken or proposed to address the breach
- Assist the Customer in fulfilling its obligation to notify supervisory authorities
8. International Data Transfers
Where Personal Data is transferred outside the EEA, StoreWiz ensures adequate safeguards through:
- Standard Contractual Clauses (SCCs) as approved by the European Commission
- Data residency options (US East, EU West, Asia Pacific) configurable per tenant
- Transfer Impact Assessments for high-risk transfers
9. Data Retention & Deletion
Upon termination of the agreement, StoreWiz will:
- Provide a 30-day window for the Customer to export all data
- Delete all Personal Data within 90 days of termination
- Provide written confirmation of deletion upon request
- Retain only data required by applicable law (e.g., billing records)
10. Audit Rights
The Customer has the right to audit StoreWiz's compliance with this DPA. Audits may be conducted by the Customer or an independent third-party auditor, subject to reasonable notice and during normal business hours. StoreWiz will provide reasonable cooperation and access to relevant records.
11. Term & Termination
This DPA remains in effect for the duration of the service agreement and as long as StoreWiz processes Personal Data on behalf of the Customer. Provisions relating to data deletion and confidentiality survive termination.
12. Governing Law
This DPA is governed by the laws applicable to the main service agreement. For EEA customers, the GDPR and applicable member state laws apply to data processing matters.
13. Acceptance
Customers can accept this DPA electronically through the StoreWiz platform at Settings > Privacy > Data Processing Agreement. Electronic acceptance is legally binding and creates an auditable record including timestamp and IP address.