Data Processing Agreement
Last updated: 25 September 2026
This Data Processing Agreement ("DPA"), version 1.0, forms part of the agreement under which Supportify AS, organisation number 936 919 634, Tordenskiolds gate 2, 0160 Oslo, Norway ("Supportify") provides the Supportify service (the "Service") to a merchant (the "Customer"). That agreement is our Terms of Service, or another written agreement between the Customer and Supportify (the "Agreement").
It applies whenever Supportify processes personal data on the Customer's behalf, and it is the agreement required by Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), which applies in Norway through the EEA Agreement and the Norwegian Personal Data Act (personopplysningsloven). A Norwegian version is published at /no/databehandleravtale.
1. Definitions
Terms such as "controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meaning given in the GDPR. In addition:
- Customer Personal Data means personal data that Supportify processes on the Customer's behalf in providing the Service, as described in Annex 1.
- End Customer means a customer or prospective customer of the Customer, or anyone else who contacts the Customer through a channel connected to the Service.
- Data Protection Law means the GDPR, the Norwegian Personal Data Act, and any other data protection law that applies to the processing, including the UK GDPR and the Swiss Federal Act on Data Protection where relevant.
- Sub-processor means a processor engaged by Supportify that processes Customer Personal Data.
- Standard Contractual Clauses means the clauses adopted by Commission Implementing Decision (EU) 2021/914.
- Customer-directed integration means a third-party service the Customer connects to its own account on the Service using its own credentials or authorisation, such as its e-commerce platform, mailbox, social media account, helpdesk, warehouse system or carrier account.
2. Roles and scope
2.1 The Customer is the controller of Customer Personal Data, and Supportify is its processor. Where the Customer is itself a processor acting for another controller, the Customer warrants that it is authorised to engage Supportify, and Supportify is then a sub-processor to that controller.
2.2 Supportify is a controller, not a processor, for the personal data it needs to run its own business: the Customer's account and its users, billing, product analytics about how the Service is used, and security and fraud logs. That processing is described in our Privacy Policy and is outside this DPA.
2.3 Annex 1 describes the subject matter, duration, nature and purpose of the processing and the categories of personal data and data subjects.
3. The Customer's instructions
3.1 Supportify processes Customer Personal Data only on the Customer's documented instructions, unless Union or EEA state law requires otherwise, in which case Supportify tells the Customer before processing unless that law prohibits it. The Customer's instructions are this DPA, the Agreement, the settings the Customer chooses in the Service (for example which channels and integrations it connects, which features it switches on and how long conversations are kept), and any further written instruction that is consistent with the Agreement.
3.2 Supportify tells the Customer promptly if, in its opinion, an instruction infringes Data Protection Law.
3.3 The Customer is responsible for having a lawful basis for the processing, for informing End Customers about it (including, where the law requires, that they are communicating with an AI system; the Service has a setting for this), and for the accuracy and lawfulness of the data and instructions it provides. The Service is not designed for special categories of personal data, and the Customer should not configure it to request them.
4. Supportify's obligations
Supportify shall:
- ensure that everyone it authorises to process Customer Personal Data is bound by confidentiality, and that access is limited to those who need it to provide, secure or support the Service;
- implement the technical and organisational measures described in Annex 2 (Article 32 GDPR);
- not sell Customer Personal Data, and not use it for any purpose of its own other than providing, securing and supporting the Service for the Customer. Supportify may compile aggregated statistics about the use and performance of the Service that identify no person and no Customer, and use them to improve the Service and describe how it performs;
- not use Customer Personal Data to train artificial intelligence models, and not permit its Sub-processors to do so;
- assist the Customer, taking into account the nature of the processing and the information available to Supportify, with the Customer's obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation);
- keep a record of processing activities carried out on the Customer's behalf (Article 30(2) GDPR).
5. Sub-processors
5.1 The Customer gives Supportify general written authorisation to engage Sub-processors. The current list, with each Sub-processor's purpose, the data it receives, where it processes it and the transfer mechanism relied on, is published at /subprocessors and forms Annex 3.
5.2 Supportify gives at least 30 days' notice before a new Sub-processor starts processing Customer Personal Data, by e-mail to the Customer's account owner and by updating the list. The Customer may object on reasonable data protection grounds within 14 days of the notice. The parties will then discuss the objection in good faith. If Supportify cannot reasonably accommodate it, for example by not using the new Sub-processor for the Customer, the Customer may terminate the affected part of the Service without penalty before the change takes effect.
5.3 Where a Sub-processor must be replaced urgently to keep the Service secure or available, Supportify may make the change first and give notice as soon as possible afterwards; the right to object in 5.2 applies from that notice.
5.4 Supportify imposes on each Sub-processor, by written contract, data protection obligations that offer at least the level of protection of this DPA, and remains responsible to the Customer for its Sub-processors.
5.5 A Customer-directed integration is not a Sub-processor. When the Customer connects one, Supportify sends and receives data through it on the Customer's instruction, and the Customer's own agreement with that provider governs how the provider handles the data. The list at /subprocessors names the Customer-directed integrations the Service offers, for transparency.
6. International transfers
6.1 Supportify's servers, database and cache run in the EEA. Some Sub-processors, notably the providers of the AI models that read and write messages, process Customer Personal Data outside the EEA, mainly in the United States. The list in Annex 3 states, for each, where it processes data and the transfer mechanism relied on.
6.2 Supportify transfers Customer Personal Data outside the EEA only where Chapter V GDPR is complied with: to a country covered by an adequacy decision (including, for certified recipients, the EU-U.S. Data Privacy Framework), or under the Standard Contractual Clauses (Module 3, processor to processor) or another appropriate safeguard, together with supplementary measures where a transfer impact assessment calls for them.
6.3 The Customer authorises the transfers described in Annex 3. Where the Customer is established outside the EEA, Supportify's processing in the EEA does not itself amount to a restricted transfer by the Customer.
7. Personal data breaches
7.1 Supportify notifies the Customer without undue delay, and no later than 48 hours after becoming aware, of a personal data breach affecting Customer Personal Data.
7.2 The notice describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Supportify provides further information as it becomes available, takes reasonable steps to contain the breach, and cooperates with the Customer's notifications to the supervisory authority and to data subjects.
7.3 Supportify does not notify supervisory authorities or data subjects on the Customer's behalf unless the Customer instructs it to or the law requires it. A notice under this section is not an admission of fault.
8. Data subject requests
8.1 Supportify assists the Customer, by appropriate technical and organisational measures, in responding to requests from data subjects to exercise their rights under Chapter III GDPR.
8.2 For Shopify stores, requests made through Shopify are processed automatically. A data request produces an export of the End Customer's conversations and tickets in the Customer's store, which the Customer can download from the Service for 30 days. An erasure request anonymises the End Customer in the Customer's conversations, messages and tickets. For other platforms, or anything the automatic handling does not cover, the Customer can send the request to support@supportify.no and Supportify will carry it out without undue delay, and in any case in time for the Customer to answer within the deadline in Article 12(3) GDPR.
8.3 If a data subject contacts Supportify directly about Customer Personal Data, Supportify will not answer the request itself, other than to refer the data subject to the Customer, and will forward it to the Customer without undue delay.
9. Retention, deletion and return
9.1 During the Agreement, Customer Personal Data is kept as follows:
- Conversations (chat sessions and their messages, on every channel) are deleted automatically when they have been inactive for longer than the store's retention period. The period is 90 days unless the Customer has agreed a different one with Supportify (between 7 days and 10 years).
- Files attached to conversations follow the conversation's retention period. Photos uploaded for virtual try-on, and the images generated from them, are deleted after 24 hours.
- Support tickets and their messages are kept for as long as the Customer's account exists, because they are the Customer's case history, unless an erasure request under section 8 removes an End Customer from them. Files attached to tickets are deleted after 90 days.
- Records of the Service's own actions that name an End Customer, such as the log of which order data the AI looked up and a record of emails the spam filter set aside, are kept for up to 90 days.
- Anything else the Customer stores in the Service, such as its knowledge base, settings and saved replies, is kept until the Customer deletes it or the Agreement ends.
9.2 Before the Agreement ends, the Customer may ask Supportify for an export of its conversations and tickets in a machine-readable format. Within 30 days after the Agreement ends, Supportify deletes Customer Personal Data, unless Union or EEA state law requires it to be kept. Copies in backups are deleted as the backups expire in their normal cycle and are not restored into use in the meantime.
10. Information and audits
10.1 Supportify makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the sub-processor list, the description of security measures in Annex 2, and reasonable answers to written security and privacy questionnaires.
10.2 Where that information is not sufficient, or a supervisory authority requires it, the Customer may carry out an audit, including an inspection, itself or through an independent auditor bound by confidentiality. The Customer gives at least 30 days' written notice, audits no more than once in any twelve months unless a personal data breach or an authority requires it, and bears its own costs. Audits are conducted during business hours and so as not to disrupt the Service or compromise the data of Supportify's other customers.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Law does not permit such a limitation.
12. Term, precedence and changes
12.1 This DPA applies for as long as Supportify processes Customer Personal Data, and survives the end of the Agreement until that data has been deleted.
12.2 If this DPA conflicts with the Agreement, this DPA prevails as regards the processing of personal data. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail. If the English and Norwegian versions of this DPA differ, the English version prevails.
12.3 Supportify may update this DPA to reflect changes in law or in the Service. It will give at least 30 days' notice of a change that materially reduces the protection given to Customer Personal Data, and the Customer may terminate the Agreement before the change takes effect if it does not accept it.
13. Governing law and jurisdiction
This DPA is governed by Norwegian law. Disputes are subject to the jurisdiction of the Oslo District Court (Oslo tingrett), without prejudice to the rights of data subjects and supervisory authorities under Data Protection Law.
Annex 1: Details of the processing
Subject matter and duration
The provision of the Service under the Agreement, for the term of the Agreement and until the data is deleted under section 9.
Nature and purpose
Collection, storage, organisation, retrieval, analysis, transmission and deletion of personal data in order to answer and manage the Customer's customer service: generating replies and drafts with AI models, classifying and routing messages (including filtering spam and tagging cases), looking up and acting on orders, returns, shipments and subscriptions in the Customer's connected systems, handling tickets, notifying the Customer's team, and reporting to the Customer on its support.
Categories of data subjects
- End Customers who contact the Customer through a channel connected to the Service (chat widget, e-mail, Instagram, Messenger, WhatsApp, phone, SMS or the ticket portal);
- Other people who write to a mailbox or account the Customer has connected;
- The Customer's staff and contractors who use the Service, to the extent their data appears in conversations, tickets, notes and audit records.
Categories of personal data
- Identity and contact details: name, e-mail address, phone number, postal and delivery addresses;
- The content of communications: chat messages, e-mails (sender, recipients, subject, body and attachments), direct messages, and, where the Customer enables the phone channel, call audio and transcripts;
- Images and files an End Customer sends, including photos uploaded to features such as virtual try-on where the Customer enables them;
- Order and account data from the Customer's connected systems: orders, items, prices, payment and fulfilment status, shipments and tracking, returns and their reasons, subscriptions and loyalty balances. The Service does not receive full payment card numbers;
- Technical data about a chat session: IP address, browser and device type, the page being viewed, language and country;
- Data derived by the Service: summaries, tags, categories, detected language, and whether a message was classified as spam.
Special categories of personal data
None are intended. End Customers may nonetheless volunteer them in free text, for example health information in a question about a product. Such data is processed only as part of the message it arrives in, under the same measures and retention as the rest of the conversation. Photos uploaded for virtual try-on show the person in them; the Service uses them only to generate the requested image, never to identify anyone, and deletes them after 24 hours.
Frequency
Continuous, for as long as the Customer uses the Service.
Annex 2: Technical and organisational measures
Supportify keeps these measures under review and may change them, provided the overall level of protection does not fall.
Hosting and encryption
- Servers, the PostgreSQL database and the cache run with Fly.io in Amsterdam, in the EU. Files End Customers send are kept in Tigris object storage in a private bucket and are served only through signed links that expire. The one exception is images generated by virtual try-on, which are served from an unguessable address and deleted after 24 hours.
- All traffic to the Service is encrypted with TLS, and plain HTTP is redirected to HTTPS. Data is encrypted in transit between our servers and the database.
- The database and file storage are encrypted at rest by the hosting providers.
- Credentials the Service holds for the Customer (e-commerce platform tokens, mailbox authorisations and integration API keys) are additionally encrypted field by field with AES-256-GCM, under a key that exists only as a production secret.
- Payment card numbers never reach the Service.
Access control
- The Customer controls who on its team can see and do what: owner, admin, agent and viewer roles, with per-person permissions such as seeing only assigned tickets.
- Passwords are hashed with bcrypt, and an account is locked for 30 minutes after five failed sign-ins. Users can sign in with Google or Shopify instead of a password.
- Access to production systems is limited to named Supportify personnel who need it to run and support the Service, and is used only for that.
- When Supportify support staff need to see what a Customer sees, they open a support session: it is granted to a single workspace, requires a written reason, lasts at most one hour and cannot be renewed, is read-only unless configuration access is specifically granted, can never send a message to an End Customer, does not add anyone to the Customer's team, and shows a banner on every screen while it lasts.
- End Customers must prove they own an e-mail address with a one-time code before the AI discloses order information in chat, with limits on how many codes are sent and how many wrong guesses are allowed.
- Sign-in and API endpoints are rate limited, and webhooks from Shopify and other platforms are verified by signature before they are processed.
Logging and audit
- Actions by Supportify administrators, including opening a conversation, are written to an append-only audit log. If the entry cannot be written, the action does not happen.
- Every support session is recorded, with who opened it, why and for how long, before access is granted, and every change made in one is recorded too.
- Changes to the Customer's configuration made through the in-product assistant are recorded with who applied them.
- Application logs mask e-mail addresses, phone numbers and postal addresses before they leave the server. Error reports are configured not to include users' default personal data.
Data minimisation and deletion
- Order and customer records are read from the Customer's own systems when a conversation needs them, not copied into a separate customer database.
- Retention is enforced by an automated nightly job. A separate check alerts Supportify if a run has not completed within 36 hours.
- Erasure requests reach every copy of the End Customer's data on a message, including e-mail headers and the results of order look-ups, and are retried until they succeed.
- Knowledge the Service learns from a Customer's answered cases is checked automatically for personal data, and anything containing it is discarded. Nothing is added to the knowledge base unless the Customer approves it.
- No Customer's data is used in another Customer's conversations.
AI safeguards
- AI providers receive only what a task needs: the conversation, and the order or product details looked up for it.
- The AI acts only through the accounts the Customer has connected, and within the actions the Customer has switched on. While a reply is a draft waiting for a person, the AI does not change orders.
- Customer Personal Data is not used to train AI models, by Supportify or by its AI providers (section 4).
Availability and resilience
- Each application runs on more than one machine. The database is a managed PostgreSQL service with backups several times a day and point-in-time restore.
- Scheduled jobs report to an external uptime monitor. If the main AI provider fails, the chat widget falls back to a standby provider so End Customers still get an answer.
Organisational measures
- Everyone at Supportify with access to Customer Personal Data is bound by confidentiality.
- Sub-processors are chosen for their security and data protection terms and are bound by written data processing agreements.
- Personal data breaches are handled under section 7, and the Customer is kept informed until each one is closed.
Annex 3: Sub-processors
The Sub-processors authorised under section 5, and the Customer-directed integrations described in section 5.5, are listed at /subprocessors.