Unformed Data Processing Agreement
Version 1.3 — Effective date: 31 July 2026
> Aligned with the actual implementation. The articles on liability and audits > deserve legal review before this agreement is presented to merchants.
Parties
Controller *(The fields below are completed per merchant at signing.)* Organisation name: [MERCHANT: NAME] · Registered address: [MERCHANT: ADDRESS] · Company number: [MERCHANT: COMPANY NUMBER] Hereinafter: the "Merchant".
Processor Legal name: D.E. DIGITAL (sole proprietorship) · Trading name: Unformed / Unformed AI Registered address: Pacayastraat 2 B17, 1105 BT Amsterdam, Netherlands · Dutch Chamber of Commerce number: 73677671 Hereinafter: "Unformed".
Article 1 — Subject matter and scope
- This Data Processing Agreement applies to every processing of personal data that Unformed carries out on behalf of the Merchant.
- It forms part of the agreement under which Unformed provides its services, hereinafter the "Main Agreement".
- In the event of conflict, this Data Processing Agreement prevails insofar as the protection of personal data is concerned.
- Terms have the meaning given to them by the GDPR.
Article 2 — Roles and instructions
- The Merchant is the controller for personal data made available to Unformed through Shopify and for data collected through feedback flows.
- Unformed processes only on documented instructions, for the performance of the Main Agreement, insofar as necessary to provide and secure the platform, or where legally required.
- The Main Agreement, this agreement, and the settings the Merchant configures in the platform together constitute documented instructions.
- Unformed informs the Merchant where, in its reasonable judgement, an instruction conflicts with data protection law.
- The Merchant is responsible for lawfulness, purposes and legal bases, informing data subjects, configuring appropriate questions and retention periods, obtaining any consent, honouring unsubscribes, and preventing the collection of unnecessary or sensitive data.
Article 3 — Nature and purpose of the processing
Unformed processes personal data in order to connect a Shopify store, receive relevant order events, determine when an invitation should be sent, send invitations on behalf of the Merchant, make feedback flows available, generate questions and follow-up questions, store answers, generate summaries and insights, present results, maintain and secure the service, execute privacy requests and investigate incidents.
Processing is automated and continuous for as long as the Merchant uses the service.
Article 4 — Categories of data subjects
Customers of the Merchant, visitors to the webshop, people who have placed an order, recipients of an invitation, respondents who complete a flow, contacts and staff of the Merchant, and other individuals whose data the Merchant enters.
Article 5 — Categories of personal data
Identification and contact
Email address, first name, Shopify customer ID, respondent ID, and technical or pseudonymised identifiers.
Customer profile
Language and locale setting, communication preference and unsubscribe status.
Order data
Shopify order ID, order number, order date, fulfilment, payment and cancellation status as a status value, product and variant IDs, product titles and quantities.
Rewards
The recipient's email address linked to the discount code they received, and the time of assignment.
The code stock itself contains no personal data: only the code, the store domain, the expiry date and whether it has been issued. The link to a person only comes into being at the moment of issue.
Feedback and conversation
Answers, open text responses, ratings and scores, conversation content, AI-generated follow-up questions, summaries, analyses and insights, and the times and status of the conversation.
Technical
IP addresses, session data, browser and device data, audit logs, access logs, error messages and security information.
Catalogue data (not personal data)
Product title, handle, product type, vendor, image, status and product IDs. Listed here because Unformed stores it, not because it is personal data. Prices and inventory levels are not retrieved.
What is expressly not processed
For this functionality Unformed does not process last name, phone number, home address, billing address, payment details, card details or monetary amounts.
This is technically enforced: the system rejects payloads containing amounts with an error. Changing this would require an amendment to this agreement, a demonstrable necessity, and additional approval from Shopify.
What Unformed writes to the store
Unformed does not only read from the Merchant's store; it also writes one type of object to it: discounts and the codes beneath them, and only where the Merchant has configured that feature.
Products, orders, customers and other store data are never modified or created. The access rights used are limited to exactly that: reading orders, products and customers, and writing discounts.
Special categories of personal data
The platform is not intended for collecting special categories of personal data, unless expressly agreed in advance.
Article 6 — Confidentiality
- Unformed ensures that persons with access to personal data are given that access only where necessary, are bound by confidentiality, receive instructions on secure processing, and process only in accordance with the Merchant's instructions.
- Access is granted through individual accounts. Shared accounts are not permitted for access to production data.
- The confidentiality obligation survives termination.
Article 7 — Security measures
Unformed has implemented the following measures:
Encryption TLS for all traffic; encryption of stored data by the database provider; additional encryption of per-store API keys with AES-256-GCM, with the encryption key held outside the database.
Access separation The Shopify app runs under its own database role with its own schema and no rights whatsoever on platform data. This is enforced by the database, not by agreement: an attempted access fails with a permission error.
Row-level security Row Level Security on all tables containing customer or order data, restricted to the owner's workspace. Unauthenticated access to these tables has been fully revoked.
Authentication of incoming traffic Signature verification on all Shopify webhooks. Server-to-server traffic uses API keys of which only a hash is stored, with rights granted per operation.
Connection procedure The connection between store and platform uses a single-use code that expires after sixty seconds. Redeeming it additionally requires a shared secret held only by the app, so that an intercepted code is worthless on its own. The API key does not pass through the merchant's browser.
Separated environments Development and production use separate database projects with their own keys and secrets. In the development environment the component that reads real customer data is not instantiated; only synthetic data on a domain that cannot exist is used there.
Logging Every access to protected customer data is recorded with store, key, operation, count and timestamp — without the data itself.
Other Multi-factor authentication for administrative access; a password manager; automated deletion procedures; backups and recovery procedures; error monitoring; periodic dependency updates; periodic review of access rights.
Unformed may adjust measures where technical developments warrant it, provided the level of protection is not materially reduced.
Article 8 — Sub-processors
- The Merchant grants general written authorisation for the engagement of sub-processors.
- The current list is published at https://unformed.ai/dpa/#current-sub-processors and available on request via privacy@unformed.ai.
- Unformed informs the Merchant at least 30 days before a material addition or replacement, by email or through the platform.
- Within that period the Merchant may object on reasoned grounds where there is a demonstrable material data protection risk.
- The parties will then jointly seek a reasonable solution. If none is found, the Merchant may terminate the affected component.
- Unformed imposes materially equivalent obligations on sub-processors and remains responsible towards the Merchant.
Current sub-processors
| Name | Service | Region |
|---|---|---|
| Supabase | Database, authentication, storage, edge functions | eu-west-1 (Ireland) |
| Railway | Hosting of the Shopify app | EU West |
| OpenAI | Processing of selected conversation content | United States |
| Anthropic | Processing of selected conversation content | United States |
| Resend | Sending and delivery of email | eu-west-1 (Ireland) |
| Langfuse | Monitoring of AI interactions | eu-west-1 (Ireland) |
Article 9 — International transfers
- OpenAI and Anthropic process in the United States.
- For those transfers Unformed relies on the Standard Contractual Clauses, supplemented by the measures in Article 7.
- All other sub-processors process within the EEA: database, hosting, storage, email delivery and monitoring run in eu-west-1 (Ireland).
- The transfer concerns conversation content only. Contact details used to send an invitation do not leave the EEA.
- The Merchant authorises Unformed to carry out international transfers subject to this Article.
Article 10 — Rights of data subjects
- Where Unformed receives a request directly concerning data processed on behalf of the Merchant, Unformed forwards it to the Merchant.
- Unformed does not respond independently, unless the Merchant instructs it to do so in writing or Unformed is legally required to.
- Unformed provides reasonable assistance with requests for access, rectification, erasure, restriction, portability, objection and withdrawal of consent.
- The Merchant remains responsible for the substantive assessment and timely handling.
Article 11 — Shopify privacy requests
Unformed supports Shopify's mandatory processes:
| Request | How Unformed executes it |
|---|---|
| Access to customer data | Registered automatically with a 30-day deadline, including a reference to the records involved and a notification to Unformed. Compiling and delivering the data is done manually. |
| Deletion of customer data | Automatic: email address and name are replaced with an untraceable value and the invitation link is invalidated |
| Deletion of store data | Automatic: all invitations, order events, product data, the connection and the access key are deleted or revoked |
The authenticity of these requests is verified using the signature Shopify sends with them. A request without a valid signature is rejected.
For an individual customer deletion request, the personal data is made untraceable but the feedback itself is retained. The obligation attaches to the personal data; depriving the merchant of their feedback goes beyond that.
Article 12 — Personal data breaches and security incidents
- Unformed informs the Merchant without undue delay after becoming aware of a breach affecting personal data processed on behalf of the Merchant.
- Unformed aims to provide a first notification within 24 hours of confirmation.
- The notification includes, insofar as available: the nature of the incident, the systems affected, the categories of personal data, the estimated number of data subjects, the likely consequences, the measures taken and a point of contact.
- Information may be provided in phases.
- Unformed contains the incident, preserves evidence, investigates the cause, documents it, and supports the Merchant with any notification.
- The Merchant determines whether notification to a supervisory authority or to data subjects is required.
- Unformed makes no public statement naming the Merchant without prior consultation, unless legally required.
Article 13 — Retention and deletion
- Unformed does not retain data longer than necessary or than instructed by the Merchant.
- The following periods are applied automatically by a daily clean-up job:
| Data | Period | Action |
|---|---|---|
| Order events | 180 days after recording | deleted |
| Email address and name on an invitation | 90 days after the (scheduled) send time | made untraceable |
| Access log | 24 months | deleted |
| Register of data subject requests | 24 months after handling | deleted |
- The link between an issued discount code and the recipient's email address is not deleted automatically. It is erased upon a customer deletion request, upon deletion of the store, and upon termination of the Main Agreement. Automation is planned.
- Feedback and conversation data is retained according to the Merchant's settings. This period is not currently enforced automatically; deletion takes place on request or upon termination.
- After termination of the Main Agreement, Unformed deletes or anonymises the personal data within 90 days, unless the Merchant requests earlier deletion or an export, a legal obligation requires otherwise, or data temporarily remains present in a backup.
- Data in backups disappears through the normal backup cycle and is not actively processed again, except where restoration is necessary.
- On request, Unformed confirms that deletion has been carried out.
Article 14 — Audits and information
- On reasonable request, Unformed makes available information demonstrating compliance, including an extract from the access log for the Merchant's store.
- The Merchant may request an audit at most once per calendar year, unless a supervisory authority requires an additional audit, there has been a confirmed serious incident, or there are concrete indications of non-compliance.
- Unformed may first make available existing documentation and written answers.
- An additional audit is announced at least 30 days in advance, takes place during working hours, is carried out by an independent expert bound by confidentiality, does not unnecessarily disrupt the service, and is limited to what is relevant to the Merchant.
- Reasonable costs are borne by the Merchant, unless the audit reveals a material shortcoming on the part of Unformed.
Article 15 — Assistance with compliance
Unformed provides reasonable assistance with security obligations, breach assessments, data protection impact assessments, consultation with a supervisory authority, responding to privacy requests, and demonstrating compliance.
Unformed may charge reasonable costs for extensive assistance falling outside normal service delivery.
Article 16 — Liability
Liability is governed by the Main Agreement, to the extent permitted under applicable law.
Signatures
Merchant: name, role, date, signature Unformed: name, role, date, signature
*This agreement is also available in Dutch at https://unformed.ai/nl/verwerkersovereenkomst/. In the event of any discrepancy between the two versions, the English version prevails.*