Data Processing Agreement

Sellena · Version 1.1 · Last updated: 2026-09-17

Parties

This Data Processing Agreement (the "DPA") is entered into between:

This DPA forms part of, and is subject to, the agreement between the parties for the provision of the Sellena services (the "Agreement"). Where this DPA conflicts with the Agreement on the subject of personal data protection, this DPA prevails.

1. Definitions

Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Sub-processor", "Supervisory Authority", and "Personal Data Breach" have the meanings given in the applicable data protection law (including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, and, where applicable, the California Consumer Privacy Act as amended ("CCPA/CPRA")) — collectively "Data Protection Law".

"Customer Personal Data" means Personal Data that Sellena Processes on behalf of the Customer under the Agreement (see Annex 1).

"Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission (or the UK equivalent) for the transfer of Personal Data to processors in third countries.

2. Roles and scope

2.1 As between the parties, the Customer is the Controller and Sellena is the Processor of the Customer Personal Data. The Customer's own end-customers and storefront visitors are the Data Subjects.

2.2 Sellena is the controller of merchant account data (store contact details, billing, app usage); that data is governed by the Privacy Policy, not by this DPA.

2.3 Each party will comply with its obligations under Data Protection Law.

3. Processing details

The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.

4. Processor obligations (Article 28 GDPR)

Sellena will:

(a) Documented instructions. Process Customer Personal Data only on the Customer's documented instructions — including as set out in the Agreement, this DPA, and the configuration of the app — including for international transfers, unless required to do otherwise by law (in which case Sellena will inform the Customer, unless legally prohibited).

(b) Confidentiality. Ensure that persons authorised to Process Customer Personal Data are bound by confidentiality.

(c) Security. Implement and maintain the technical and organisational measures in Annex 2 (Article 32 GDPR).

(d) Sub-processors. Only engage Sub-processors in accordance with Section 6.

(e) Data-subject requests. Taking into account the nature of the Processing, assist the Customer by appropriate measures to respond to Data Subjects exercising their rights. Because Sellena is a Shopify app, these are supported through Shopify's customers/data_request, customers/redact, and shop/redact flows; Sellena will forward or act on such requests it receives.

(f) Assistance. Assist the Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the Processing and the information available to Sellena.

(g) Deletion or return. At the Customer's choice, delete or return all Customer Personal Data at the end of the provision of the services, and delete existing copies, unless retention is required by law (see Section 9).

(h) Records and audits. Make available to the Customer the information necessary to demonstrate compliance with this Section and allow for and contribute to audits in accordance with Section 8.

(i) Notice of unlawful instruction. Immediately inform the Customer if, in Sellena's opinion, an instruction infringes Data Protection Law.

Sellena will not sell Customer Personal Data, use it for its own advertising, or use it to train shared or foundation AI models, and will keep each Customer's data logically separated.

5. Personal Data Breach

Sellena will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, by email to the store's contact address in Shopify, and will provide the Customer with the information reasonably available to it (nature of the breach, categories and approximate number of Data Subjects and records, likely consequences, measures taken) to assist the Customer in meeting its own notification obligations.

6. Sub-processors

6.1 The Customer provides a general authorisation for Sellena to engage Sub-processors, provided that Sellena: (a) imposes data-protection obligations substantially the same as those in this DPA; and (b) remains liable for the acts and omissions of its Sub-processors.

6.2 The current Sub-processors are listed in Annex 3. Sellena will give the Customer reasonable prior notice of the addition or replacement of a Sub-processor (e.g. by updating the list or by email), and the Customer may object on reasonable data-protection grounds; the parties will work in good faith to resolve the objection.

7. International transfers

Where Sellena transfers Customer Personal Data outside the EEA, UK, or Switzerland (for example, to its AI Sub-processor in the United States), it will ensure an appropriate transfer mechanism is in place, such as the Standard Contractual Clauses (and the UK Addendum / Swiss adaptations where applicable), or another lawful mechanism.

8. Audits

Sellena will, on reasonable prior written request and no more than once per year (unless required by a Supervisory Authority or following a Personal Data Breach), make available information reasonably necessary to demonstrate compliance, including relevant certifications, security summaries, or completed questionnaires. On-site audits, where strictly necessary, will be at reasonable times, subject to confidentiality, and not unreasonably disrupt Sellena's operations.

9. Return and deletion

On termination or expiry of the Agreement, or on the Customer's request, Sellena will delete or return Customer Personal Data. In practice: uninstalling the app triggers Shopify's shop/redact (48 hours later), on which Sellena erases the shop's data across its systems, including the support inbox and stored sessions; order-attribution records are also subject to Sellena's retention limits. Operational logs and LLM traces, which can contain chat content, are retained for 30 days and deleted automatically; they are not purged earlier on shop/redact, so Customer Personal Data may persist there for up to 30 days after erasure from the application. Back-ups are overwritten in the ordinary cycle.

10. Liability

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement.

11. Governing law

This DPA is governed by the governing law of the Agreement — under Sellena's Terms of Service, the laws of Georgia — without prejudice to the mandatory provisions of Data Protection Law that apply to the Customer.


Annex 1 — Details of Processing

Annex 2 — Technical and Organisational Measures (Article 32)

Annex 3 — Sub-processors

Sub-processor Purpose Location Notes
OpenAI, L.L.C. AI processing of chat message content to generate replies United States API data not used to train models; transfers under SCCs
Hetzner Online GmbH Hosting of the application, its database, the self-hosted conversation system (Chatwoot), the catalog service, and the logging and tracing systems Germany and Finland (EU) No transfer outside the EEA
Shopify Platform, OAuth, billing and the compliance webhooks that carry data-subject requests Under Shopify's own terms Independent controller for its platform

A current sub-processor list is available on request at help@sellena.co.