Data Processing Agreement: Control AI Agents: AI Traffic

Version: 1.0
Effective date: September 29, 2026

This Data Processing Agreement ("DPA") is a standalone agreement between:

  • Control AI Agents ("Provider"), and
  • the merchant that installs or uses the Shopify app Control AI Agents: AI Traffic (the "App") on its Shopify store ("Merchant").

It applies to Personal Data that Provider processes on Merchant's behalf through the App. Merchant accepts it by clicking Accept the agreement in the App, and Provider records the date and the version accepted.

1. Definitions

  • Data Protection Laws: all privacy and data protection laws that apply to the processing. These may include the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), other US state privacy laws, and Canada's PIPEDA.
  • Personal Data: any information about an identified or identifiable natural person that Provider processes on Merchant's behalf through the App, as described in Annex 1.
  • Processing: has the meaning given in the Data Protection Laws. "Process" and "processed" have matching meanings.
  • Data Subject: the person the Personal Data is about.
  • Subprocessor: a third party Provider engages to process Personal Data.
  • Security Incident: a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
  • "Controller", "processor", "business" and "service provider" have the meanings given in the Data Protection Laws.

2. Roles

  1. Merchant is the controller (and, under the CCPA, the business) for the Personal Data. Provider is a processor (and service provider) acting on Merchant's behalf.
  2. Provider is an independent controller only for Merchant's own account data, such as the store contact email and billing status. That data is covered by Provider's Privacy Policy, not by this DPA.
  3. Merchant is responsible for having a lawful basis for the processing. This includes its own storefront privacy notice and consent settings, since the App's web pixel runs only when a visitor grants the permissions it declares through Shopify's customer privacy settings.

3. Instructions

  1. Provider processes Personal Data only on Merchant's documented instructions. These are this DPA and Merchant's configuration and use of the App (for example, approving pages, applying product copy, or uploading reviews). The exception is where law requires otherwise, in which case Provider tells Merchant first unless the law forbids it.

  2. Provider tells Merchant if it believes an instruction breaks the Data Protection Laws.

  3. Provider doesn't:

    • sell or share Personal Data (as those terms are defined in the CCPA);
    • retain, use or disclose it for any purpose other than providing the App, or outside the direct business relationship with Merchant;
    • combine it with personal data from other sources, except as the CCPA permits for service providers.

    Provider certifies that it understands these restrictions.

  4. Provider may create aggregated, de-identified data from the Personal Data, and use it to improve the App and publish general statistics. Provider takes reasonable measures so that this data can't be linked to Merchant or a Data Subject. It publicly commits not to try to re-identify it, and requires any recipient to make the same commitment.

4. Confidentiality

Provider makes sure that anyone it authorizes to process Personal Data is bound by confidentiality obligations, and has access only as needed to provide the App.

5. Security

Provider keeps in place the technical and organizational measures in Annex 2. They protect Personal Data at a level suited to the risk, and include encryption in transit and at rest. Provider may update the measures, as long as it doesn't lower the overall level of protection.

6. Subprocessors

  1. Merchant gives Provider general authorization to engage the Subprocessors listed in Annex 3.
  2. Provider tells Merchant at least 30 days before it adds or replaces a Subprocessor, by email to the store contact email and by publishing a new version of this DPA with the updated Annex 3, which the App shows to Merchant. Merchant may object on reasonable data protection grounds within that period. If the parties can't resolve the objection, Merchant may stop using the App by uninstalling it. That ends the processing, and Merchant owes no further fees for the period after uninstall.
  3. Provider puts data protection terms in place with each Subprocessor that are at least as protective as this DPA. Provider remains responsible for its Subprocessors' performance.

7. Data Subject requests

  1. Shopify delivers Data Subject access and deletion requests for a store to the App through the customers/data_request, customers/redact and shop/redact webhooks. Provider acts on each one within 30 days of receipt, which is Shopify's deadline:
    • Access: Provider compiles the Personal Data it holds for the orders listed in the request, emails Merchant's store contact email that it's ready, and makes it available to download in the App (Settings > Customer data requests), for Merchant to send to the Data Subject. The file stays available for 60 days. After that it's cleared, and only a record of the request remains.
    • Deletion: Provider deletes the order records listed in the request, with their line items and returns, and the facts and quotes taken from those return notes. It also erases them from earlier data request files and from page idea evidence.
  2. If a Data Subject contacts Provider directly, Provider passes the request to Merchant without undue delay and doesn't respond itself, except to direct the person to Merchant.
  3. Provider gives Merchant reasonable help with other requests, and with data protection impact assessments and consultations with authorities, as far as they relate to the App.

8. Security Incidents

  1. Provider notifies Merchant without undue delay, and no later than 72 hours, after it becomes aware of a Security Incident affecting Merchant's Personal Data.

  2. The notice describes, as far as is known:

    • the nature of the incident;
    • the categories and approximate number of Data Subjects and records affected;
    • the likely consequences;
    • the measures taken or proposed;
    • a contact point.

    Provider sends further details as they become available.

  3. Provider takes reasonable steps to contain the incident and limit its effects. Notice of an incident isn't an admission of fault.

9. Retention, return and deletion

  1. Provider keeps Personal Data only as long as needed to provide the App. Visit-level data from the web pixel is deleted after 90 days, after which only daily totals remain, with no visitor identifiers. Compiled data request files are cleared after 60 days (section 7).
  2. When Merchant uninstalls the App, Provider stops processing Merchant's Personal Data. Shopify sends a shop/redact request 48 hours after uninstall. Provider then deletes all of Merchant's data, and it leaves Provider's backups within 7 days, when the automated backups roll over.
  3. Before uninstalling, Merchant may ask Provider for an export of its data.
  4. Pages that Merchant published through the App are stored in Merchant's own Shopify store and aren't affected by deletion.

10. Audits and information

  1. Provider makes available the information reasonably needed to show compliance with this DPA, including answers to a reasonable written security questionnaire, once a year.

  2. If the Data Protection Laws require more, Merchant may carry out an audit, or have one carried out by an independent auditor bound by confidentiality. The conditions are:

    • at least 30 days' notice;
    • during business hours;
    • no more than once in any 12 months, unless there has been a Security Incident;
    • at Merchant's cost.

    The audit must not give access to other merchants' data.

11. International transfers

Provider and its Subprocessors process Personal Data in the United States.

  • For transfers of Personal Data from the European Economic Area or Switzerland, the parties agree to the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module Two (controller to processor), which are incorporated by reference.
  • For the United Kingdom, they agree to the UK International Data Transfer Addendum.
  • The details required by those clauses are in Annexes 1 to 3.

12. Term and updates

  1. This DPA stays in effect for as long as Provider processes Personal Data on Merchant's behalf.
  2. Provider may update this DPA by publishing a new version at https://controlaiagents.com/dpa. The App then shows Merchant the change and asks Merchant to accept the new version. An update doesn't lower the protection of Personal Data (section 5).

Annex 1: Details of processing

Item Details
Subject matter Providing the App: reports on AI-referred traffic and on orders and visits from AI shopping agents (such as Meta Muse, ChatGPT agent, Perplexity Comet and Claude in Chrome), guide pages and product copy built from store data, and the split test that measures the effect
Duration While the App is installed, plus the deletion periods in section 9
Nature of processing Collection through Shopify's APIs and the App's web pixel, storage, removing personal details from free text, classification by AI models, aggregation, and deletion
Purposes (1) Count orders and visits from AI assistants and AI shopping agents. (2) Sort AI-referred visits, searches and orders into shopper needs. (3) Draft and check guide pages and product copy from reviews, returns and product data, and publish on approval. (4) Translate published guide pages into the languages Merchant chose (Scale plan). (5) Measure AI visits, AI orders and Google visits for tested and untouched products. (6) Send the weekly summary to Merchant. (7) Handle privacy requests, security and support.
Data Subjects Merchant's customers who placed orders (their orders are stored without a customer ID). Visitors to Merchant's storefront who granted the pixel's permissions. People who wrote reviews or return notes (text only; their names are not stored).
Categories of Personal Data Orders: order ID and number, date, totals, sales channel (including an AI shopping agent that placed the order), line items, and visit attribution (landing page URL, referrer URL, source, UTM tags). Visits: Shopify's random browser identifier, session key, event type and time, the page's domain, path and UTM tags (for checkout, order status and customer account pages, only the first word of the path, without the token), the referring site with at most the first word of its path, product viewed, on-site search text with personal details removed, and the name of an AI agent when the browser's user agent carries a token its vendor documents, such as Google-Agent or Meta-ExternalFetcher (not the user agent itself). Returns: reason, variant, quantity, and note with personal details removed. Reviews: rating, title and text with personal details removed (reviewer names are never stored).
Excluded data Customer IDs are not stored with orders or visits. The only customer ID kept is the one Shopify sends in a privacy request, as part of the record of that request and its compiled file. Customer names, email addresses, phone numbers and postal addresses (Shopify protected customer data Level 2) are not collected. No special categories of data are intended. Merchant must not upload them in review files.
Frequency Continuous while the App is installed

Annex 2: Technical and organizational measures

  1. Encryption in transit. HTTPS with TLS 1.2 or 1.3 for all traffic to the App. TLS is required for all database connections. TLS for all calls to Subprocessors.
  2. Encryption at rest.
    • Database storage, automated backups and snapshots are encrypted with AES-256 through AWS Key Management Service.
    • Secrets are stored in AWS Secrets Manager.
    • Review app API tokens are also encrypted with AES-256-GCM at the application level.
  3. Network isolation.
    • The database runs in private subnets, isn't publicly accessible, and accepts connections only from the App's web and worker services.
    • The web service accepts traffic only from the load balancer, which rate-limits web pixel requests from each IP address (AWS WAF, without request logs or samples).
    • The worker accepts no inbound traffic.
  4. Least privilege.
    • The App's runtime role may only call the Claude models on Amazon Bedrock and send email through Amazon SES from Provider's own domain.
    • Staff access to production is limited to authorized personnel and follows least privilege.
  5. Minimization.
    • Only the fields in Annex 1 are stored.
    • Personal details (such as emails and phone numbers) are removed from review text, return notes and search text before storage.
    • Reviewer names are dropped at import.
    • The web pixel records only for visitors who granted its permissions, and stops as soon as a visitor withdraws consent on the page.
    • Only product data, cleaned text and counts are sent to AI Subprocessors. No customer identifiers are sent.
  6. Retention. Visit-level data is deleted after 90 days by a daily job. Compiled data request files are cleared after 60 days. Store data is deleted on shop/redact. Backups roll over after 7 days. Logs are kept for 30 days and exclude shopper data.
  7. Merchant control.
    • Nothing is published or changed in the store without Merchant's approval, unless Merchant turns on auto-publish.
    • The original of every product description change is saved and can be restored.
  8. Integrity and availability. Automated daily database backups with point-in-time recovery, managed patching of the database engine, and deployments that roll back automatically on failure.
  9. Monitoring and response. Centralized logs; CloudWatch alarms that email the operator when a background job fails, an error is logged, the worker stops running, no web server is healthy, or server errors pass a threshold; and an incident process that meets the notice period in section 8.
  10. Vendor management. Each Subprocessor is bound by data protection terms, and the list is kept current in Annex 3.

Annex 3: Subprocessors

Subprocessor Service Purpose Location
Amazon Web Services, Inc. Amazon ECS, Amazon RDS, AWS Secrets Manager, Amazon CloudWatch, AWS WAF Hosting, database, backups, secrets, logs, rate limiting United States (us-east-1)
Amazon Web Services, Inc. Amazon Bedrock (Claude models) Writing pages and product copy, translating pages (Scale plan), and judgments when Jev is unavailable United States, and other AWS Regions through global cross-region inference
Amazon Web Services, Inc. Amazon SES The weekly email to Merchant United States
TypeSafe AI, Inc. Jev Sorting visits into shopper needs, labeling reviews and returns, checking claims United States