1. Roles and subject matter
When you use supportif.ai for your shop, you (the merchant) act as data controller for the personal data of your customers, and supportif.ai — Manuel Sampl acts as your data processor within the meaning of Art. 28 GDPR. This agreement supplements our Terms of Service and governs that processing. Subject matter: automation of customer support communication, including receipt, analysis and answering of support emails, ticket management, knowledge extraction and preparation of shop actions subject to your approval.
2. Categories of data and data subjects
- Data subjects: your shop's customers, your staff members, you as merchant.
- Data categories: contact data (names, email addresses), communication content (support emails and attachments metadata), order and transaction data from your Shopify shop, and configuration data.
3. Our obligations as processor
- We process data only on your documented instructions — expressed through your use and configuration of the app — and only for providing the Service.
- Persons authorized to process data are bound to confidentiality.
- We support you in responding to data subject requests (access, deletion, rectification) concerning data held in the Service.
- We notify you without undue delay of any personal data breach affecting your data.
- Upon termination (uninstall), we delete your data as described in the Privacy Policy.
4. Sub-processors
You authorize the sub-processors listed in the Privacy Policy (AI providers OpenAI and Anthropic — only for the models you select, hosting via Vercel and database infrastructure, Telegram — only if you connect a bot). We will inform you of intended changes to sub-processors, giving you the opportunity to object. Transfers outside the EEA are safeguarded by EU Standard Contractual Clauses or equivalent mechanisms. Note: if you configure a local LLM, no email content is sent to AI sub-processors for inference.
5. Technical and organizational measures (TOMs)
- Encryption: TLS for all data in transit; AES-256-GCM encryption of credentials and tokens at rest; infrastructure-level database encryption.
- Access controls: production access restricted to the minimum necessary personnel, protected by strong authentication; role-based access within the app (merchant, staff).
- Data minimization: AI calls include only the data required for the specific task.
- Retention: configurable retention (default 365 days) with automated deletion; full deletion on uninstall.
- Action gating: no write operation on your shop is executed without explicit merchant approval, providing an auditable human control point.
- Logging: executed actions are logged per ticket (what, when, approved by whom).
6. Audits
We provide the information reasonably necessary to demonstrate compliance with this agreement and, where legally required, enable audits — primarily through documentation and written responses to your inquiries at support@supportif.ai.
7. Duration
This agreement applies for as long as you use the Service and ends automatically when you uninstall the app and your data has been deleted.