This Data Processing Agreement (the "DPA") is entered into between:
This DPA forms part of, and is subject to, the agreement between the parties for the provision of the Sellena services (the "Agreement"). Where this DPA conflicts with the Agreement on the subject of personal data protection, this DPA prevails.
Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Sub-processor", "Supervisory Authority", and "Personal Data Breach" have the meanings given in the applicable data protection law (including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, and, where applicable, the California Consumer Privacy Act as amended ("CCPA/CPRA")) — collectively "Data Protection Law".
"Customer Personal Data" means Personal Data that Sellena Processes on behalf of the Customer under the Agreement (see Annex 1).
"Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission (or the UK equivalent) for the transfer of Personal Data to processors in third countries.
2.1 As between the parties, the Customer is the Controller and Sellena is the Processor of the Customer Personal Data. The Customer's own end-customers and storefront visitors are the Data Subjects.
2.2 Sellena is the controller of merchant account data (store contact details, billing, app usage); that data is governed by the Privacy Policy, not by this DPA.
2.3 Each party will comply with its obligations under Data Protection Law.
The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.
Sellena will:
(a) Documented instructions. Process Customer Personal Data only on the Customer's documented instructions — including as set out in the Agreement, this DPA, and the configuration of the app — including for international transfers, unless required to do otherwise by law (in which case Sellena will inform the Customer, unless legally prohibited).
(b) Confidentiality. Ensure that persons authorised to Process Customer Personal Data are bound by confidentiality.
(c) Security. Implement and maintain the technical and organisational measures in Annex 2 (Article 32 GDPR).
(d) Sub-processors. Only engage Sub-processors in accordance with Section 6.
(e) Data-subject requests. Taking into account the nature of the Processing,
assist the Customer by appropriate measures to respond to Data Subjects
exercising their rights. Because Sellena is a Shopify app, these are supported
through Shopify's customers/data_request, customers/redact, and shop/redact
flows; Sellena will forward or act on such requests it receives.
(f) Assistance. Assist the Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the Processing and the information available to Sellena.
(g) Deletion or return. At the Customer's choice, delete or return all Customer Personal Data at the end of the provision of the services, and delete existing copies, unless retention is required by law (see Section 9).
(h) Records and audits. Make available to the Customer the information necessary to demonstrate compliance with this Section and allow for and contribute to audits in accordance with Section 8.
(i) Notice of unlawful instruction. Immediately inform the Customer if, in Sellena's opinion, an instruction infringes Data Protection Law.
Sellena will not sell Customer Personal Data, use it for its own advertising, or use it to train shared or foundation AI models, and will keep each Customer's data logically separated.
Sellena will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, by email to the store's contact address in Shopify, and will provide the Customer with the information reasonably available to it (nature of the breach, categories and approximate number of Data Subjects and records, likely consequences, measures taken) to assist the Customer in meeting its own notification obligations.
6.1 The Customer provides a general authorisation for Sellena to engage Sub-processors, provided that Sellena: (a) imposes data-protection obligations substantially the same as those in this DPA; and (b) remains liable for the acts and omissions of its Sub-processors.
6.2 The current Sub-processors are listed in Annex 3. Sellena will give the Customer reasonable prior notice of the addition or replacement of a Sub-processor (e.g. by updating the list or by email), and the Customer may object on reasonable data-protection grounds; the parties will work in good faith to resolve the objection.
Where Sellena transfers Customer Personal Data outside the EEA, UK, or Switzerland (for example, to its AI Sub-processor in the United States), it will ensure an appropriate transfer mechanism is in place, such as the Standard Contractual Clauses (and the UK Addendum / Swiss adaptations where applicable), or another lawful mechanism.
Sellena will, on reasonable prior written request and no more than once per year (unless required by a Supervisory Authority or following a Personal Data Breach), make available information reasonably necessary to demonstrate compliance, including relevant certifications, security summaries, or completed questionnaires. On-site audits, where strictly necessary, will be at reasonable times, subject to confidentiality, and not unreasonably disrupt Sellena's operations.
On termination or expiry of the Agreement, or on the Customer's request, Sellena
will delete or return Customer Personal Data. In practice: uninstalling the app
triggers Shopify's shop/redact (48 hours later), on which Sellena erases the
shop's data across its systems, including the support inbox and stored sessions;
order-attribution records are also subject to Sellena's retention limits.
Operational logs and LLM traces, which can contain chat content, are retained
for 30 days and deleted automatically; they are not purged earlier on
shop/redact, so Customer Personal Data may persist there for up to 30 days
after erasure from the application. Back-ups are overwritten in the ordinary
cycle.
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement.
This DPA is governed by the governing law of the Agreement — under Sellena's Terms of Service, the laws of Georgia — without prejudice to the mandatory provisions of Data Protection Law that apply to the Customer.
customers/redact and
shop/redact compliance flows; sessions purged on uninstall.| Sub-processor | Purpose | Location | Notes |
|---|---|---|---|
| OpenAI, L.L.C. | AI processing of chat message content to generate replies | United States | API data not used to train models; transfers under SCCs |
| Hetzner Online GmbH | Hosting of the application, its database, the self-hosted conversation system (Chatwoot), the catalog service, and the logging and tracing systems | Germany and Finland (EU) | No transfer outside the EEA |
| Shopify | Platform, OAuth, billing and the compliance webhooks that carry data-subject requests | Under Shopify's own terms | Independent controller for its platform |
A current sub-processor list is available on request at help@sellena.co.