Automated Commerce

Data Processing Agreement

Version 1. Effective 28 September 2026.

This Data Processing Agreement ("DPA") is entered into between the business customer using the Service ("Controller") and Automated Commerce B.V. ("AC", "Processor"), a private limited company registered with the Dutch Chamber of Commerce under number 98684213, with its registered office at Herengracht 451, 1017 BS Amsterdam, the Netherlands. AC's privacy contact is business@automatedcommerce.ai.

1. Formation, scope and roles

Formation. This DPA forms part of AC's Terms of Service and applies automatically from the moment the Controller accepts those Terms. No separate signature is required. The current version is published at automatedcommerce.ai/policies/data-processing-agreement. Where this DPA conflicts with the Terms of Service on a data-protection matter, this DPA controls.

Scope. This DPA covers all personal data AC processes on the Controller's behalf when providing the Service. Schedule 1 describes the platform processing. Schedule 2 describes the attribution collection plane, which applies only when the Controller activates attribution collection. It does not cover personal data for which AC is itself the controller, such as the account, login and billing data of the Controller's users, which AC's Privacy Policy covers.

Roles. The Controller determines the purposes and lawful bases, provides the notices required toward data subjects, obtains any required consent, handles data-subject requests, and issues documented instructions. AC, as processor, processes only on those lawful instructions and keeps every obligation that applicable data-protection law imposes on processors. Nothing in the agreement changes the parties' roles where the facts require a different classification, and this DPA does not state or imply that AC is free of obligations under applicable data-protection law.

2. Instructions

AC processes personal data only on the Controller's documented instructions, which consist of: (a) this DPA and its Schedules, (b) the Terms of Service and any order form, (c) the Controller's configuration choices in the Service (including connected channels and integrations, consent-management platform wiring, retention selections within the offered range, activation of attribution collection, and activation of any advertising-platform destination), and (d) any further written instruction the Controller gives through AC's designated support channel. AC will not process personal data for any purpose outside these instructions.

If AC believes an instruction infringes the GDPR or another applicable data-protection law, AC will promptly inform the Controller and may suspend performance of that instruction pending resolution.

3. Confidentiality

AC ensures that any person authorized to process personal data under this DPA is bound by an appropriate obligation of confidentiality, whether contractual or statutory, and has received training appropriate to their role before being granted access.

4. Security (Article 32)

AC implements and maintains technical and organisational measures appropriate to the risk, including:

  • Tenant isolation: every read of a Controller's data is scoped to that Controller's organization, and data is shared with another organization only through a connection the Controller sets up (for example a supplier or retailer partnership).
  • Access control: access to personal data is limited to the Controller's own users and to AC personnel who need it to operate or support the Service.
  • Encryption of personal data in transit and, where supported by the underlying storage service, at rest.
  • Defined retention and working deletion pathways (Section 8) rather than manual, ad hoc deletion.
  • Logging and monitoring sufficient to detect and respond to a personal data breach without undue delay.

Schedule 2 lists the additional controls of the attribution collection plane.

5. Personal data breaches

AC will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller's personal data, and will provide the information reasonably necessary for the Controller to meet its own Article 33 and 34 obligations.

6. Subprocessors

The Controller authorizes AC to engage the subprocessors listed in AC's subprocessor register at automatedcommerce.ai/policies/subprocessors. AC will:

  • Notify the Controller at least 30 days in advance, by email or in-Service notice, of any intended addition or replacement of a subprocessor.
  • Give the Controller the opportunity to object on reasonable, documented data-protection grounds before the change takes effect. If AC cannot reasonably accommodate the objection, the Controller may terminate the affected part of the Service before the change takes effect, with a pro-rata refund of prepaid fees.
  • Impose on each subprocessor, by contract or equivalent legal act, the data-protection obligations Article 28(4) GDPR requires.
  • Remain fully liable to the Controller for a subprocessor's performance of its data-protection obligations.

7. Assistance to the Controller

Taking into account the nature of processing and the information available to AC, AC will assist the Controller, at the Controller's reasonable request and cost where the assistance is not already built into the Service:

  • With responding to data-subject requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection), including through the Service's export and deletion tooling.
  • With the Controller's Article 32 security obligations.
  • With the Controller's Article 33 and 34 breach-notification obligations.
  • With the Controller's Article 35 DPIA and, where applicable, Article 36 prior-consultation obligations, including by providing the DPIA Technical Annex for the attribution collection plane.

8. Deletion and return

On termination, the Controller may export its data for 60 days as set out in the Terms of Service. AC then deletes or fully anonymises the personal data processed under this DPA within a further 90 days, and backup overwrite cycles complete within 180 days of the start of deletion. At the Controller's written request, AC will instead return the data or delete it earlier. These obligations do not apply to the extent applicable law requires AC to retain data, in which case AC continues to protect the retained data under this DPA for the duration of that retention. On request, AC will certify the deletion in writing.

During the term, erasure requests for the attribution collection plane are executed through AC's tenant erasure tooling (Schedule 2).

9. Audit and information rights

AC will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, on reasonable notice and no more than once per year absent a documented incident or regulatory inquiry. AC may satisfy an audit request in the first instance by providing a current independent audit report or certification covering the relevant controls, where one exists and reasonably addresses the Controller's request.

10. International transfers

Where AC or a subprocessor transfers personal data outside the European Economic Area, AC will ensure the transfer is covered by a valid Chapter V GDPR transfer mechanism, in the first instance the European Commission's 2021 Standard Contractual Clauses (Controller-to-Processor and, where relevant, Processor-to-Processor modules) incorporated by reference into this DPA, or an applicable adequacy decision. AC will identify the actual recipient and transfer path on request and will implement supplementary safeguards where the transfer-impact assessment for that path requires them.

11. Changes to this DPA

AC will not change this DPA by publishing a new version alone. AC will notify the Controller of any proposed change directly, by email and in-Service notice, at least 30 days before it takes effect, and will publish each version with its version number and effective date. A change that adds a category of personal data, a purpose, or a type of recipient takes effect for the Controller only once the Controller confirms it in the Service; until then, AC continues under the previous version and may pause the part of the Service the change concerns. For any other change, the Controller may object during the notice period and, if AC cannot reasonably accommodate the objection, terminate the affected subscription before the change takes effect, with a pro-rata refund of prepaid fees.

12. Order of precedence

If any provision of this DPA conflicts with the Terms of Service on a data-protection matter, this DPA controls. If any provision of this DPA conflicts with a mandatory provision of applicable data-protection law, that law controls.

Schedule 1: Platform processing

Subject matter and purpose. Operating the Service for the Controller: product catalog management, synchronisation with connected sales channels and marketplaces, import of orders from those channels, supplier and retailer collaboration, the website analytics dashboard, AI-assisted content generation, and related support.

Duration. The term of the Terms of Service, followed by the deletion periods in Section 8.

Categories of data subjects.

  • The Controller's customers whose orders AC imports from a connected sales channel.
  • Visitors to the Controller's storefront, where the Controller installs AC's website analytics.
  • Business contacts of the Controller, such as people at suppliers, retailers or partners, whose details the Controller or its trading partners enter, invite or import.

Categories of personal data.

  • Order data from connected sales channels: order and line details, amounts and currency, the channel's customer identifier and email address, and, where the channel supplies them, the customer's name, phone number, and billing and shipping address.
  • Website analytics: page URL and query string, referrer, UTM and advertising click identifiers, browser, operating system, device type, screen size, language, country, region and city, and a session identifier. IP addresses are not stored.
  • Business contact data: names, email addresses and roles of business contacts, and the content of documents the Controller uploads for import (for example supplier order sheets), which may include business contact details printed on them.

AI processing. Product content, and documents the Controller uploads for import, are processed by the AI providers listed in the subprocessor register to generate or extract content. The Service does not send order data of the Controller's customers or website analytics data to AI providers.

Special categories. The Service is not designed to process special categories of personal data (Article 9 GDPR), and the Controller must not enter them into it.

Schedule 2: Attribution collection plane

This Schedule applies only when the Controller activates attribution collection.

1. Subject matter, nature and purpose

Subject matter. AC processes personal data on the Controller's behalf to collect, stitch and attribute storefront visitor and order journeys to marketing campaigns, and to compute per-tenant campaign and channel credit for the Controller's own budget-steering decisions.

Nature of processing. Collection of browser-emitted events and Shopify-sourced order fields; pseudonymous identity stitching across visitor, session, cart, checkout, order and customer keys; storage in a tenant-scoped analytics store; computation of attribution credit with rule-based and statistical models (including a data-driven model that may redistribute credit using campaign-level view-through totals reported by the Controller's advertising platforms); classification of orders as first or repeat purchases; where the Controller activates it, delivery of conversion events to its advertising platforms (part 6); retention management and erasure execution.

Purpose. Per-tenant marketing attribution and campaign budget measurement for the Controller's own storefront. AC does not process this data for any purpose of its own, including cross-tenant benchmarking, generalized model training, advertising or resale (part 5).

2. Categories of data subjects

  • Storefront visitors, including those who have not created an account or completed a purchase.
  • Customers who complete a checkout or place an order through the Controller's Shopify store.
  • Individuals who arrived at the storefront through an advertising or email-marketing link that carried a click identifier (part 3).

3. Categories of personal data

  • Browser journey lane: pseudonymous client and session identifiers (on headless storefronts, a first-party visitor cookie ac_vid, HTTP-only, lifetime up to 400 days, set only with a consented event); page and referrer URLs, product/variant/collection identifiers viewed, cart/checkout/order correlation tokens, consent state at time of capture, and campaign attribution signals from the landing URL: UTM parameters and advertising click identifiers (Google gclid, gbraid, wbraid; Meta fbclid; TikTok ttclid; Pinterest epik; Microsoft msclkid; oppref). For Klaviyo email links AC records only that a _kx token was present, never the token itself. AC does not store IP addresses, user-agent strings or device fingerprints from this lane.
  • Shopify order-journey lane: order and refund identifiers, order revision and amount/currency, checkout token, Shopify customer identifier, and, where the Controller's Shopify configuration supplies them, SHA-256-hashed email and phone identifiers used solely for identity stitching. AC does not receive or store the customer's plaintext email or phone number through this lane.
  • Derived data: pseudonymous identity links between visitor, session, cart, checkout, order and customer keys; canonicalized journey/touch records; first-or-repeat purchase classification per order; per-campaign and per-channel attribution credit. Pseudonymous keys remain personal data for as long as AC or the Controller can single out the individual they relate to, directly or in combination with other information reasonably available to either party.
  • AC does not intentionally collect special-category data (Article 9 GDPR) through this collection plane and the Controller must not configure fields to carry it.

4. Additional security controls

  • Fail-closed collection: no attribution event or identifier is accepted or materialized for a tenant unless a current privacy-readiness approval is on file for that tenant; the gate defaults to blocking, not permitting.
  • Per-event consent enforcement at admission, keyed to the consent snapshot captured with the event, not a later or looser state.
  • Prohibited-field validation that rejects payloads carrying data the product does not collect for this purpose (for example plaintext payment-card data).
  • Retention horizons computed at admission, as set out in the DPIA Technical Annex.
  • Tenant erasure tooling that removes personal data from the collection plane's live stores and deletes the associated raw event ledger, for erasure and consent-withdrawal requests during the term.

5. No cross-tenant use

AC does not use identifiable or pseudonymous journey or attribution data from more than one tenant together, for benchmarking, model training, calibration or any other purpose. Any future cross-tenant use requires a separate, documented role, purpose and legal-basis review, and, where it would make AC a controller or joint controller for that use, a separate agreement covering that role. This DPA does not authorize that use.

6. Optional delivery to advertising platforms

Delivery is off by default. It runs only for a platform the Controller explicitly activates and connects to its own advertising account, and only after AC has recorded the Controller's approval of an advertising legal basis. Each event is delivered only if the consent snapshot captured with that event granted marketing consent and the visitor has not withdrawn marketing consent since; an event captured without marketing consent is never delivered, regardless of later consent or configuration changes.

When activated, AC transmits conversion events on the Controller's instruction to:

  • Meta (Conversions API): event name, time, value and currency, SHA-256-hashed email and hashed pseudonymous customer identifier, and the Meta click identifiers (fbc, fbp) where present.
  • Google Ads (Data Manager API): conversion time, value and currency, SHA-256-hashed email and phone, and gclid, gbraid or wbraid where present.
  • Pinterest (Conversions API): event name, time, value and currency, SHA-256-hashed email, and the Pinterest click identifier where present.
  • TikTok (Events API): event name, time, value and currency, SHA-256-hashed email and phone, and ttclid where present.

Each platform processes the delivered data under the Controller's own agreement with that platform, which governs the platform's role and any transfer outside the European Economic Area. AC keeps delivery evidence (what was sent, when, and the delivery outcome) for the retention period in the DPIA Annex, and the Controller can deactivate a destination at any time, which stops further delivery.

Stay Ahead: Newsletter

Get the latest insights from the AI-industry and updates on new platform features