Unformed Data Processing Agreement

Version 1.4 — Effective date: 31 July 2026

> Aligned with the actual implementation. The articles on information and audits > (14) and liability (16) have been legally revised.


Parties

Controller *(The fields below are completed per merchant at signing.)* Organisation name: [MERCHANT: NAME] · Registered address: [MERCHANT: ADDRESS] · Company number: [MERCHANT: COMPANY NUMBER] Hereinafter: the "Merchant".

Processor Legal name: DWE Labs (V.O.F.) · Trading name: Unformed / Unformed AI Registered address: Pacayastraat 2 B17, 1105 BT Amsterdam, Netherlands · Dutch Chamber of Commerce number: 42149791 Hereinafter: "Unformed".


Article 1 — Subject matter and scope

  1. This Data Processing Agreement applies to every processing of personal data that Unformed carries out on behalf of the Merchant.
  2. It forms part of the agreement under which Unformed provides its services, hereinafter the "Main Agreement".
  3. In the event of conflict, this Data Processing Agreement prevails insofar as the protection of personal data is concerned.
  4. Terms have the meaning given to them by the GDPR.

Article 2 — Roles and instructions

  1. The Merchant is the controller for personal data made available to Unformed through Shopify and for data collected through feedback flows.
  2. Unformed processes only on documented instructions, for the performance of the Main Agreement, insofar as necessary to provide and secure the platform, or where legally required.
  3. The Main Agreement, this agreement, and the settings the Merchant configures in the platform together constitute documented instructions.
  4. Unformed informs the Merchant where, in its reasonable judgement, an instruction conflicts with data protection law.
  5. The Merchant is responsible for lawfulness, purposes and legal bases, informing data subjects, configuring appropriate questions and retention periods, obtaining any consent, honouring unsubscribes, and preventing the collection of unnecessary or sensitive data.

Article 3 — Nature and purpose of the processing

Unformed processes personal data in order to connect a Shopify store, receive relevant order events, determine when an invitation should be sent, send invitations on behalf of the Merchant, make feedback flows available, generate questions and follow-up questions, store answers, generate summaries and insights, present results, maintain and secure the service, execute privacy requests and investigate incidents.

Processing is automated and continuous for as long as the Merchant uses the service.

Article 4 — Categories of data subjects

Customers of the Merchant, visitors to the webshop, people who have placed an order, recipients of an invitation, respondents who complete a flow, contacts and staff of the Merchant, and other individuals whose data the Merchant enters.

Article 5 — Categories of personal data

Identification and contact

Email address, first name, Shopify customer ID, respondent ID, and technical or pseudonymised identifiers.

Customer profile

Language and locale setting, communication preference and unsubscribe status.

Order data

Shopify order ID, order number, order date, fulfilment, payment and cancellation status as a status value, product and variant IDs, product titles and quantities.

Rewards

The recipient's email address linked to the discount code they received, and the time of assignment.

The code stock itself contains no personal data: only the code, the store domain, the expiry date and whether it has been issued. The link to a person only comes into being at the moment of issue.

Feedback and conversation

Answers, open text responses, ratings and scores, conversation content, AI-generated follow-up questions, summaries, analyses and insights, and the times and status of the conversation.

Technical

IP addresses, session data, browser and device data, audit logs, access logs, error messages and security information.

Catalogue data (not personal data)

Product title, handle, product type, vendor, image, status and product IDs. Listed here because Unformed stores it, not because it is personal data. Prices and inventory levels are not retrieved.

What is expressly not processed

For this functionality Unformed does not process last name, phone number, home address, billing address, payment details, card details or monetary amounts.

This is technically enforced: the system rejects payloads containing amounts with an error. Changing this would require an amendment to this agreement, a demonstrable necessity, and additional approval from Shopify.

What Unformed writes to the store

Unformed does not only read from the Merchant's store; it also writes one type of object to it: discounts and the codes beneath them, and only where the Merchant has configured that feature.

Products, orders, customers and other store data are never modified or created. The access rights used are limited to exactly that: reading orders, products and customers, and writing discounts.

Special categories of personal data

The platform is not intended for collecting special categories of personal data, unless expressly agreed in advance.

Article 6 — Confidentiality

  1. Unformed ensures that persons with access to personal data are given that access only where necessary, are bound by confidentiality, receive instructions on secure processing, and process only in accordance with the Merchant's instructions.
  2. Access is granted through individual accounts. Shared accounts are not permitted for access to production data.
  3. The confidentiality obligation survives termination.

Article 7 — Security measures

Unformed has implemented the following measures:

Encryption TLS for all traffic; encryption of stored data by the database provider; additional encryption of per-store API keys with AES-256-GCM, with the encryption key held outside the database.

Access separation The Shopify app runs under its own database role with its own schema and no rights whatsoever on platform data. This is enforced by the database, not by agreement: an attempted access fails with a permission error.

Row-level security Row Level Security on all tables containing customer or order data, restricted to the owner's workspace. Unauthenticated access to these tables has been fully revoked.

Authentication of incoming traffic Signature verification on all Shopify webhooks. Server-to-server traffic uses API keys of which only a hash is stored, with rights granted per operation.

Connection procedure The connection between store and platform uses a single-use code that expires after sixty seconds. Redeeming it additionally requires a shared secret held only by the app, so that an intercepted code is worthless on its own. The API key does not pass through the merchant's browser.

Separated environments Development and production use separate database projects with their own keys and secrets. In the development environment the component that reads real customer data is not instantiated; only synthetic data on a domain that cannot exist is used there.

Logging Every access to protected customer data is recorded with store, key, operation, count and timestamp — without the data itself.

Other Multi-factor authentication for administrative access; a password manager; automated deletion procedures; backups and recovery procedures; error monitoring; periodic dependency updates; periodic review of access rights.

Unformed may adjust measures where technical developments warrant it, provided the level of protection is not materially reduced.

Article 8 — Sub-processors

  1. The Merchant grants general written authorisation for the engagement of sub-processors.
  2. The current list is published at https://unformed.ai/dpa/#current-sub-processors and available on request via privacy@unformed.ai.
  3. Unformed informs the Merchant at least 30 days before a material addition or replacement, by email or through the platform.
  4. Within that period the Merchant may object on reasoned grounds where there is a demonstrable material data protection risk.
  5. The parties will then jointly seek a reasonable solution. If none is found, the Merchant may terminate the affected component.
  6. Unformed imposes materially equivalent obligations on sub-processors and remains responsible towards the Merchant.

Current sub-processors

NameServiceRegion
SupabaseDatabase, authentication, storage, edge functionseu-west-1 (Ireland)
RailwayHosting of the Shopify appEU West
OpenAIProcessing of selected conversation contentUnited States
AnthropicProcessing of selected conversation contentUnited States
ResendSending and delivery of emaileu-west-1 (Ireland)
LangfuseMonitoring of AI interactionseu-west-1 (Ireland)

Article 9 — International transfers

  1. OpenAI and Anthropic process in the United States.
  2. For those transfers Unformed relies on the Standard Contractual Clauses, supplemented by the measures in Article 7.
  3. All other sub-processors process within the EEA: database, hosting, storage, email delivery and monitoring run in eu-west-1 (Ireland).
  4. The transfer concerns conversation content only. Contact details used to send an invitation do not leave the EEA.
  5. The Merchant authorises Unformed to carry out international transfers subject to this Article.

Article 10 — Rights of data subjects

  1. Where Unformed receives a request directly concerning data processed on behalf of the Merchant, Unformed forwards it to the Merchant.
  2. Unformed does not respond independently, unless the Merchant instructs it to do so in writing or Unformed is legally required to.
  3. Unformed provides reasonable assistance with requests for access, rectification, erasure, restriction, portability, objection and withdrawal of consent.
  4. The Merchant remains responsible for the substantive assessment and timely handling.

Article 11 — Shopify privacy requests

Unformed supports Shopify's mandatory processes:

RequestHow Unformed executes it
Access to customer dataRegistered automatically with a 30-day deadline, including a reference to the records involved and a notification to Unformed. Compiling and delivering the data is done manually.
Deletion of customer dataAutomatic: email address and name are replaced with an untraceable value and the invitation link is invalidated
Deletion of store dataAutomatic: all invitations, order events, product data, the connection and the access key are deleted or revoked

The authenticity of these requests is verified using the signature Shopify sends with them. A request without a valid signature is rejected.

For an individual customer deletion request, the personal data is made untraceable but the feedback itself is retained. The obligation attaches to the personal data; depriving the merchant of their feedback goes beyond that.

Article 12 — Personal data breaches and security incidents

  1. Unformed informs the Merchant without undue delay after becoming aware of a breach affecting personal data processed on behalf of the Merchant.
  2. Unformed aims to provide a first notification within 24 hours of confirmation.
  3. The notification includes, insofar as available: the nature of the incident, the systems affected, the categories of personal data, the estimated number of data subjects, the likely consequences, the measures taken and a point of contact.
  4. Information may be provided in phases.
  5. Unformed contains the incident, preserves evidence, investigates the cause, documents it, and supports the Merchant with any notification.
  6. The Merchant determines whether notification to a supervisory authority or to data subjects is required.
  7. Unformed makes no public statement naming the Merchant without prior consultation, unless legally required.

Article 13 — Retention and deletion

  1. Unformed does not retain data longer than necessary or than instructed by the Merchant.
  2. The following periods are applied automatically by a daily clean-up job:
DataPeriodAction
Order events180 days after recordingdeleted
Email address and name on an invitation90 days after the (scheduled) send timemade untraceable
Access log24 monthsdeleted
Register of data subject requests24 months after handlingdeleted
  1. The link between an issued discount code and the recipient's email address is not deleted automatically. It is erased upon a customer deletion request, upon deletion of the store, and upon termination of the Main Agreement. Automation is planned.
  2. Feedback and conversation data is retained according to the Merchant's settings. This period is not currently enforced automatically; deletion takes place on request or upon termination.
  3. After termination of the Main Agreement, Unformed deletes or anonymises the personal data within 90 days, unless the Merchant requests earlier deletion or an export, a legal obligation requires otherwise, or data temporarily remains present in a backup.
  4. Data in backups disappears through the normal backup cycle and is not actively processed again, except where restoration is necessary.
  5. On request, Unformed confirms that deletion has been carried out.

Article 14 — Information and audits

14.1 Provision of information

Upon reasonable request, Unformed makes available to the Merchant all information that is reasonably necessary to demonstrate that Unformed complies with its obligations under this Data Processing Agreement and Article 28 GDPR.

To the extent relevant and available, this information may consist of:

  1. descriptions of the technical and organisational measures in place;
  2. applicable certifications, audit reports and security statements;
  3. written answers to reasonable questions from the Merchant; and
  4. relevant extracts from access or activity logs relating to the Merchant's store, account or data.

Unformed is not obliged to provide information that does not relate to the processing carried out on behalf of the Merchant, or the provision of which would reasonably jeopardise the security, confidentiality or rights of other customers or third parties. Where possible, Unformed will anonymise, aggregate or redact such information.

14.2 Use of existing documentation

Unformed may in the first instance make available current documentation, certifications, independent audit reports and written answers.

To the extent that this information is reasonably sufficient to demonstrate Unformed's compliance, the parties will take it into account when determining whether, and to what extent, an additional audit is necessary.

Providing existing documentation does not limit the Merchant's right to an additional audit where the information provided is reasonably insufficient to establish compliance with this Data Processing Agreement or applicable data protection law.

14.3 Frequency of audits

The Merchant may in principle carry out, or have carried out, an audit at most once per calendar year.

This limitation does not apply where:

  1. a competent supervisory authority requires an audit, inspection or additional review;
  2. there has been a confirmed security incident or a personal data breach;
  3. there are reasonable and concrete indications that Unformed is not complying with its obligations under this Data Processing Agreement or applicable data protection law;
  4. a previous audit revealed a material shortcoming and a follow-up audit is reasonably necessary; or
  5. an additional audit is reasonably necessary for the Merchant to comply with a legal obligation.

14.4 Conduct of an audit

An audit may be carried out by the Merchant itself or by an independent and sufficiently qualified auditor appointed by the Merchant.

The persons carrying out the audit:

  1. are bound by appropriate confidentiality obligations;
  2. comply with Unformed's reasonable security and access requirements;
  3. have sufficient knowledge and experience to carry out the audit; and
  4. are not in a situation involving a material conflict of interest.

Unformed may refuse a proposed auditor only on reasonable grounds, including demonstrable risks to confidentiality, security or independence. Unformed will not withhold or delay its consent without reasonable grounds.

14.5 Notice and scheduling

Except in urgent circumstances or where a competent supervisory authority requests otherwise, an audit is announced in writing at least thirty days in advance.

The notice states at least:

  1. the purpose and legal basis of the audit;
  2. the proposed date and duration;
  3. the identity and qualifications of the auditor;
  4. the systems, processing operations and subjects covered by the audit; and
  5. the information the Merchant wishes to receive prior to the audit.

The parties will reasonably coordinate the planning and conduct of the audit.

14.6 Scope and proportionality

An audit:

  1. takes place as far as possible during Unformed's normal working hours;
  2. is limited to the systems, processes, personal data and processing operations relevant to the services provided to the Merchant;
  3. is proportionate to the purpose of and reason for the audit;
  4. does not unnecessarily disrupt Unformed's business operations and services;
  5. is, where reasonably possible, first carried out remotely or by means of a documentary review; and
  6. does not give access to personal data, confidential information, trade secrets or systems of other customers or third parties, unless strictly necessary and lawful and appropriate safeguards are in place.

The audit does not entitle the Merchant to carry out penetration tests, vulnerability scans, social engineering tests, load tests or other active security testing on Unformed's systems without Unformed's separate written consent.

14.7 Cooperation

Unformed provides the cooperation reasonably necessary to enable the audit. Unformed may require the Merchant and the auditor to follow reasonable instructions in advance to protect the security, confidentiality, continuity and integrity of the services.

Where Unformed considers that an instruction or audit request conflicts with the GDPR or other applicable law, Unformed informs the Merchant without undue delay.

14.8 Costs

Each party bears its own costs in connection with the audit as a matter of principle.

Reasonable and demonstrable additional costs incurred by Unformed as a result of an audit that goes beyond the customary provision of information and reasonable cooperation may be charged to the Merchant, provided Unformed supplies a reasonable cost estimate in advance.

These additional costs are borne by Unformed to the extent that the audit shows that:

  1. Unformed is materially failing to comply with this Data Processing Agreement or applicable data protection law; and
  2. that failure is attributable to Unformed.

14.9 Audit results

The Merchant treats the audit results and the information provided by Unformed as confidential, and uses them solely to assess or demonstrate compliance with this Data Processing Agreement and applicable data protection law.

The Merchant may share the results with its professional advisers and competent supervisory authorities, to the extent necessary or legally required and provided appropriate confidentiality is ensured.

The Merchant provides Unformed with a copy of the final audit report or, where the report also contains unrelated confidential information, a summary of the findings that relate to Unformed.

14.10 Remedial measures

Where an audit reveals a shortcoming attributable to Unformed, Unformed draws up a remediation plan within a reasonable period and takes appropriate measures to remedy the shortcoming.

The period and the measures are determined on the basis of the nature, severity and risks of the shortcoming identified.

Article 15 — Assistance with compliance

Unformed provides reasonable assistance with security obligations, breach assessments, data protection impact assessments, consultation with a supervisory authority, responding to privacy requests, and demonstrating compliance.

Unformed may charge reasonable costs for extensive assistance falling outside normal service delivery.

Article 16 — Liability

16.1 Responsibility of the parties

Each party is liable to the other party for damage resulting from an attributable failure to perform this Data Processing Agreement or its obligations under applicable data protection law, to the extent that the party concerned is responsible for the damage.

The Merchant is in particular responsible for:

  1. the lawfulness of the processing of the Personal Data;
  2. the existence of a valid legal basis for processing;
  3. informing Data Subjects; and
  4. the lawfulness, accuracy and completeness of the instructions given to Unformed.

Unformed is in particular responsible for:

  1. compliance with the legal obligations that apply specifically to Unformed as Processor; and
  2. processing Personal Data in accordance with the lawful, documented instructions of the Merchant.

16.2 Claims by Data Subjects and third parties

If a party is held liable by a Data Subject or a third party for damage resulting wholly or partly from a failure attributable to the other party, that other party is required to bear the portion of the damage, reasonable costs and awarded compensation that corresponds to its share of the responsibility.

The party against whom the claim is brought:

  1. notifies the other party without undue delay;
  2. provides the information reasonably required;
  3. gives the other party the opportunity to consult reasonably on the defence and handling of the claim; and
  4. does not, save where legally required or in an urgent situation, enter into a settlement acknowledging the other party's liability without prior consultation.

16.3 Limitations under the Main Agreement

The exclusions, limitations and liability caps set out in the Main Agreement apply to the parties' liability towards each other under this Data Processing Agreement, to the extent that their application does not conflict with mandatory applicable law.

Unless the Main Agreement expressly provides otherwise, liability under this Data Processing Agreement does not constitute a separate or additional liability cap. Claims under the Main Agreement and under this Data Processing Agreement are taken into account together for the purposes of applying a liability cap.

16.4 Administrative fines

Each party bears, as a matter of principle, the administrative fines and other public law sanctions imposed directly on it.

This is without prejudice to any right of recourse against the other party, to the extent that:

  1. such recourse is permitted under applicable law; and
  2. the fine or sanction results from a failure attributable to that other party.

16.5 Mandatory law

Nothing in this Data Processing Agreement limits or excludes:

  1. the statutory rights of Data Subjects, including the right to compensation under Article 82 GDPR;
  2. the powers of a competent supervisory authority; or
  3. liability that cannot validly be limited or excluded under mandatory applicable law.

Signatures

Merchant: name, role, date, signature Unformed: name, role, date, signature


*This agreement is also available in Dutch at https://unformed.ai/nl/verwerkersovereenkomst/. In the event of any discrepancy between the two versions, the English version prevails.*