Skip to content

Data Processing Addendum

Last updated: July 22, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Dorothy Thomas, doing business as Suvenna ("Suvenna", the "Processor") and the merchant that installs or uses the Suvenna product (the "Merchant", the "Controller"). It governs Suvenna's processing of the Merchant's customers' ("Shoppers'") personal data. It is incorporated by reference into our Terms of Service and applies automatically when the Merchant uses the product.

1. Roles and subject matter

The Merchant is the controller of its Shoppers' personal data. Suvenna processes that data solely as a processor, on the Merchant's documented instructions (including the configuration and settings the Merchant chooses in the app), to provide the Suvenna support service. The details of processing are described in Annex A.

2. Processor obligations

Suvenna will:

  • Process personal data only on the Merchant's documented instructions, unless required by law.
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Annex B).
  • Respect the conditions for engaging sub-processors (section 3).
  • Assist the Merchant, insofar as possible, in responding to data-subject requests.
  • Assist the Merchant with security, breach notification, and, where applicable, data-protection impact assessments.
  • At the Merchant's choice, delete or return the personal data at the end of the service, and delete existing copies unless retention is legally required, per the retention terms in our Privacy Policy.
  • Make available information necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and security conditions.

3. Sub-processors

The Merchant authorizes Suvenna to engage the sub-processors listed in Annex C. Suvenna imposes data protection obligations on each sub-processor no less protective than this DPA and remains liable for their performance. Suvenna will give 30 days' notice of any intended addition or replacement of a sub-processor (by updating this page and notifying Merchants), allowing the Merchant to object on reasonable data-protection grounds.

4. Data-subject rights

Taking into account the nature of the processing, Suvenna will assist the Merchant by appropriate technical and organizational measures, including the deletion and export mechanisms exposed via Shopify's customer data request, customer redaction, and shop redaction webhooks, to fulfill the Merchant's obligation to respond to data-subject requests.

5. Personal data breach

Suvenna will notify the Merchant without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting the Merchant's data, with the information reasonably available: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken or proposed.

6. International transfers

Personal data is processed in the United States. Where a transfer from the EU, UK, or another jurisdiction requiring a transfer mechanism applies, the parties rely on the EU Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated by reference with Suvenna as data importer and the Merchant as data exporter.

7. Deletion and return

On termination or the Merchant's request, Suvenna deletes the Merchant's Shoppers' personal data per the retention schedule in the Privacy Policy, and on Shopify's shop redaction request erases the shop's Shopper data. The Merchant may export data before termination using the app's tools.

8. Governing law

This DPA is governed by the laws of the State of Texas, USA, consistent with the Terms of Service.

Annex A: Description of processing

  • Nature and purpose: providing AI-assisted customer support (answering Shopper questions; drafting and sending replies; organizing tickets; and, only if the Merchant enables it, executing Shopper-requested refunds, cancellations, or returns on the Shopper's own order).
  • Duration: for the term of the Merchant's use, subject to the retention schedule.
  • Types of personal data: Shopper email (identity binding); order data read live from Shopify; support message content and attachments, which may contain personal data the Shopper provides.
  • Categories of data subjects: the Merchant's customers who contact support.

Annex B: Security measures

Encryption in transit (HTTPS) and at rest (platform disk encryption, with OAuth tokens additionally encrypted at the application layer using AES-256-GCM); row-level tenant isolation; least-privilege access; append-only audit logging of side-effecting actions; two-factor authentication availability; automated retention and deletion; and the incident response process described in section 5.

Annex C: Approved sub-processors

  • Anthropic (United States): AI reply drafting. Shopper messages and order details, transient, under commercial terms that do not use the data for model training and apply zero or short-term retention.
  • Supabase (United States): database, authentication, and storage. Support records, encrypted tokens, attachments.
  • Vercel (United States): hosting and compute. Data in transit.
  • Mailgun (United States): email transport. Inbound and outbound email content.
  • Google and Microsoft (United States): connected Merchant mailboxes. Email content in mailboxes the Merchant owns and connects.
  • Stripe (United States): billing for direct customers. Merchant billing data only, no Shopper personal data.

Contact

Questions about this DPA go to Suvenna at admin@suvenna.com or through our contact page.