ShopifyShopifyKlaviyoKanalInflateTrendtrackInfinite FulfillmentAddingwellBoostEcom AgencyThe DeployerStork MarketingTheme Copilot AIPandectesTheme FullStackCookiebotTriple WhaleRechargeIntelligemsHotjarDatafastTrustMRRPageBuilder.storeTaap.itShopifyShopifyKlaviyoKanalInflateTrendtrackInfinite FulfillmentAddingwellBoostEcom AgencyThe DeployerStork MarketingTheme Copilot AIPandectesTheme FullStackCookiebotTriple WhaleRechargeIntelligemsHotjarDatafastTrustMRRPageBuilder.storeTaap.it
ShopifyShopifyKlaviyoKanalInflateTrendtrackInfinite FulfillmentAddingwellBoostEcom AgencyThe DeployerStork MarketingTheme Copilot AIPandectesTheme FullStackCookiebotTriple WhaleRechargeIntelligemsHotjarDatafastTrustMRRPageBuilder.storeTaap.itShopifyShopifyKlaviyoKanalInflateTrendtrackInfinite FulfillmentAddingwellBoostEcom AgencyThe DeployerStork MarketingTheme Copilot AIPandectesTheme FullStackCookiebotTriple WhaleRechargeIntelligemsHotjarDatafastTrustMRRPageBuilder.storeTaap.it
Legal

Data Processing Agreement

This agreement applies whenever BoostEcom processes personal data on your behalf: the customers, orders and contacts inside a store you connect. It forms part of the Terms of Use and takes effect when you connect your first store. Where it conflicts with the Privacy Policy about processor-side data, this agreement wins.

1. Roles

You are the controller of the data in your connected stores. BoostEcom is the processor. For your own account data (your email, your subscription, your conversations with the assistant) BoostEcom is the controller and the Privacy Policy applies instead.

2. Subject matter and duration

Processing lasts as long as the connection exists. It covers the categories of data a connected commerce platform exposes: customer identity and contact details, order and fulfilment records, cart and browsing events, and content you supply for analysis or generation.

3. Documented instructions

We process this data only to provide the services you have enabled, and on your documented instructions, which the product's own configuration constitutes. We will tell you if an instruction appears to breach applicable data protection law. We do not sell this data, and we do not use it to train models.

4. Confidentiality

Access is limited to personnel who need it to operate the service, bound by confidentiality obligations that survive the end of their engagement.

5. Security measures

We maintain the technical and organisational measures described on the security page, including encryption in transit and at rest, tenant isolation enforced at the query layer, role-based access control, and an append-only audit log of security and billing events.

6. Sub-processors

You give general authorisation for the sub-processors published on the sub-processors page. That page is generated from the codebase, so it cannot fall behind what is deployed. New additions are published there in advance, and you may object within 30 days of publication.

7. Data subject requests

Where one of your customers exercises a right against you, the platform gives you the tools to answer without our involvement: export and deletion are available per store and per organisation. Shopify's mandatory erasure and data-request webhooks are received and drained by a scheduled job, and a request is only marked complete once every affected store (vectors, customer links, attribution, archived payloads) has been processed. Anything a request leaves for a human is named explicitly rather than silently dropped.

8. Personal data breach

We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the nature of the breach, the categories and approximate volume of records concerned, the likely consequences and the measures taken.

9. Audit

On reasonable notice and no more than once a year, we will provide the information needed to demonstrate compliance with this agreement, including our sub-processor list, our security measures and our retention schedule, all of which are already published.

10. Return and deletion

On termination, you may export your data from the platform at any time before the account is deleted. Deleting an account removes its data, its stored files and its vector namespaces. Retention periods that outlive the account are limited to accounting records under legal obligation, and are listed in the Privacy Policy.

11. International transfers

Transfers outside the EEA rely on the European Commission's standard contractual clauses, and on the EU-U.S. Data Privacy Framework where the provider is certified. Each provider's region is published on the sub-processors page.

12. Acceptance

Connecting a store constitutes acceptance of this agreement. If your organisation needs a countersigned copy on its own paper, write to contact@boostecom.app.

Last updated September 12, 2026