Data Processing Agreement
This agreement applies where we process personal data on a merchant’s behalf. It forms part of our Terms of Service and takes effect automatically when you use the service. You do not need to sign it separately, though we will sign a copy on request.
1. Roles
You are the controller of your customers’ personal data. We are your processor. Where the CCPA applies, we are a service provider: we do not sell or share personal data, and we do not retain, use or disclose it for any purpose other than performing the service for you.
For the accounts of your own agents who log in, we are an independent controller, and our Privacy Policy governs.
2. Subject matter, duration, nature and purpose
| Subject matter | Providing a customer-support inbox and related AI assistance |
|---|---|
| Duration | For as long as your workspace exists, plus any period needed to complete deletion. Conversation history is retained for the period your plan sets, which is one, two or three years from the last customer or agent message on a finished conversation (Starter, Growth, Scale), while the workspace is on a paid subscription, and deleted whole after that; see the Privacy Policy, section 8 |
| Nature | Receiving, storing, organising, displaying, analysing and transmitting messages and related commerce data |
| Purpose | Enabling you to answer your customers, with order context and AI-generated suggestions |
| Categories of data subject | Your customers and people who contact you |
Categories of personal data
- Identifiers. Name, email address, social handle, phone number
- Message content in both directions, and the raw provider payload including mail headers and recipient address
- Filenames and links for attachments. For email, we also store the attachment file itself, in our own private object storage, encrypted in transit and reachable only through short-lived signed links. For other channels the file stays with that channel’s provider and we keep only the link
- Satisfaction ratings and free-text survey comments
- AI-generated conversation summaries
- Commerce data. Order details and cached store customer records
- Links between identities we infer belong to one person
We do not require, and the service is not designed for, special categories of personal data (health, biometrics, and similar). Because your customers write freely to you, such data may appear in message content incidentally. You should not deliberately route it here.
3. Our obligations
- Instructions. We process personal data only on your documented instructions, which include your use of the service and its settings. We will tell you if we believe an instruction breaches applicable data protection law.
- Confidentiality. Personnel authorised to process your data are bound by confidentiality obligations.
- Security. We maintain the technical and organisational measures in §7.
- Assistance. We will assist you, taking into account the nature of the processing, with data subject requests, security obligations, breach notification and impact assessments.
4. Subprocessors
You give general authorisation for us to engage subprocessors. Each is bound by data protection terms no less protective than these, and we remain liable for their performance.
The current list is published at helpme.social/subprocessors and is maintained as part of this agreement. It is a separate page so that it can be kept accurate without amending these terms.
We will give you reasonable advance notice before adding or replacing a subprocessor. To be notified, email privacy@helpme.social and we will add you to the notification list. If you reasonably object on data protection grounds, tell us within that period; if we cannot offer a reasonable alternative, you may terminate the affected part of the service.
5. International transfers
Our infrastructure and subprocessors are in the United States. Where you are subject to UK or EU data protection law, transfers rely on the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), and the UK International Data Transfer Addendum where applicable. Those clauses are incorporated into this agreement by reference, with you as data exporter and us as data importer.
6. Data subject requests
If a data subject contacts us directly about data we process for you, we will refer them to you rather than respond on your behalf.
For Shopify merchants, Shopify’s privacy request tooling reaches us directly. A customer redaction request is carried out automatically. What that does, and what it does not do, is set out in §8.
7. Security measures
We take all measures required pursuant to Article 32 of the GDPR. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk.
We will provide a description of those measures on reasonable written request, so that you can satisfy your own obligations as controller.
8. Deletion and return
On your instruction, or on termination, we will delete personal data we process for you. A Shopify customer redaction request is executed automatically.
What deletion removes is the individual’s identity and their own content. That is their contact details, every channel identity, our cached copy of their store customer record, the content of inbound messages, attachments, survey comments, and the AI summary. Delivery details of outbound messages, including recipient address and mail headers, are cleared.
What remains is your operational record. That is, that a conversation occurred, its timestamps, status, tags, and the replies your agents wrote.
Two residuals we state rather than gloss:
- An agent reply that quoted the customer keeps that quoted text. It is your own message content and we do not rewrite it. Removing it would mean deleting your agents’ replies or running a matcher over prose; we chose neither.
- Email attachments we store ourselves are deleted with the record. For other channels the file lives with that channel’s provider: we delete our reference to it, but we cannot delete their copy.
Deletion does not reach backups immediately. We keep encrypted backups, and a backup taken before a deletion can still contain the deleted data until it ages out, which takes up to 30 days.
There is no self-service export today. If you want your data returned, ask before terminating.
9. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information we hold at that time, updated as we learn more. Notice goes to the email on your account, so keep it current.
10. Audit
On reasonable written request, no more than once a year (or after a breach affecting your data), we will provide the information reasonably necessary to demonstrate compliance with this agreement and respond to a reasonable security questionnaire. We do not currently hold third-party audit certifications, and we are not going to imply otherwise.
11. Precedence
Where this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails. Where it conflicts with the Standard Contractual Clauses, those clauses prevail.