Legal

Data Processing Agreement

Effective
6 August 2026
Version
1.0
Controller
RETAIL COMMERCE AI F.Z.E

These terms govern personal data that Retail Commerce AI processes on behalf of merchants using the platform. They form part of the terms of service and apply from the moment a merchant installs or subscribes.

01

Parties and roles

Processor: RETAIL COMMERCE AI F.Z.E, a Free Zone Establishment registered in Ajman Free Zone, United Arab Emirates (licence 56607), B.C. 1304575, Ajman Free Zone C1 Building, AJMAN, UAE (“RCAI”, “we”, “us”).

Controller:the merchant that installs or subscribes to the RCAI platform (“Merchant”, “you”), as identified in the applicable order, subscription or app installation.

The Merchant is the controller of shopper personal data. RCAI is the processor, acting only on the Merchant’s documented instructions. Where RCAI processes data about the Merchant’s own staff in order to administer their account, RCAI acts as controller for that limited purpose, governed by its privacy policy rather than by this agreement.

This agreement forms part of, and is subject to, the terms of service. Where this agreement and those terms conflict on the processing of personal data, this agreement prevails. It takes effect when the Merchant first installs or subscribes to the platform, and continues for as long as RCAI processes personal data on the Merchant’s behalf.

02

Subject matter, duration, nature and purpose

RCAI provides a shared customer support inbox. Shopper messages sent to the Merchant’s Instagram Business account, Facebook Page or website chat widget are delivered into that inbox, where an AI assistant drafts replies and the Merchant’s agents read, edit and send them. Where the Merchant connects a Shopify store, RCAI reads catalogue and recent order data so that replies can answer product and order questions.

Processing continues for the duration of the Merchant’s subscription and thereafter only as set out in clause 10. A full description is at Annex I.

03

Instructions

RCAI processes personal data only on the Merchant’s documented instructions, which comprise this agreement, the terms of service, and the Merchant’s own use of the platform’s features.

RCAI will inform the Merchant if, in its opinion, an instruction infringes applicable data protection law, and may suspend processing of that instruction until the matter is resolved.

RCAI will not sell personal data. RCAI will not use shopper personal data to train its own models, and does not permit its sub-processors to use it to train theirs; message content is sent to the AI sub-processors named in Annex III solely to generate a reply for the Merchant, under API terms that exclude training on submitted content.

04

Confidentiality

Personnel authorised to process personal data are bound by written confidentiality obligations and have access limited to what their role requires. Access rights are reviewed at least annually and are removed on role change or departure.

05

Security

RCAI implements the technical and organisational measures set out at Annex II, having regard to the state of the art, the costs of implementation, and the risks to data subjects.

Annex II describes the measures in place at the version date and separately identifies measures that are planned but not yet implemented. RCAI will update Annex II as measures change and will not represent a planned measure as an existing one.

06

Sub-processors

The Merchant gives RCAI general authorisation to engage sub-processors. The current list is at retailcommerceai.com/subprocessors and at Annex III.

RCAI will give the Merchant at least thirty (30) days’notice before adding or replacing a sub-processor, by email to the Merchant’s registered contact address. The Merchant may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Merchant may terminate the affected part of the service, and RCAI will refund any fees paid in advance for the unused remainder of the then-current term.

RCAI imposes on each sub-processor data protection obligations no less protective than those in this agreement, and remains fully liable to the Merchant for the performance of each sub-processor’s obligations.

07

Data subject rights

RCAI will, taking into account the nature of the processing, assist the Merchant by appropriate technical and organisational measures in fulfilling the Merchant’s obligation to respond to requests from data subjects. The platform implements:

  • Deletion of a shopper’s data on request, tenant-scoped, matched on email and phone.
  • The Shopify compliance webhooks — customers/data_request, customers/redact and shop/redact. The latter two are automated; customers/data_request is fulfilled by RCAI manually within thirty (30) days of receipt.
  • The Meta data deletion callback, which deletes a shopper’s conversations and messages and reports honestly where nothing matched.

If a data subject contacts RCAI directly, RCAI will not respond substantively but will refer them to the Merchant and inform the Merchant without undue delay.

08

Personal data breach

RCAI will notify the Merchant without undue delay and in any event within seventy-two (72) hoursof becoming aware of a personal data breach affecting personal data processed on the Merchant’s behalf.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where that information is not all available at once, RCAI will provide it in phases without further undue delay rather than delaying the first notification.

RCAI maintains a written Security Incident Response Policy, available to the Merchant on request, which governs how it detects, contains, investigates and reports such incidents.

09

Audit

RCAI will make available to the Merchant the information necessary to demonstrate compliance with this agreement.

The Merchant may exercise this right once per calendar year by written questionnaire, to which RCAI will respond within thirty (30) days, together with any third-party certification or audit report RCAI then holds.

Where a supervisory authority requires it, or following a personal data breach affecting the Merchant’s data, the Merchant may additionally conduct or mandate an audit on thirty (30) days’ written notice. Such an audit takes place during business hours, causes no unreasonable disruption, is subject to confidentiality, and is at the Merchant’s cost unless it identifies a material breach of this agreement by RCAI.

RCAI holds no third-party security certification — no ISO 27001, no SOC 2 — at the version date. This is stated here rather than left to be discovered.

10

Deletion and return

On termination, RCAI will, at the Merchant’s choice, delete or return all personal data processed on the Merchant’s behalf and delete existing copies, within thirty (30) days, unless retention is required by applicable law. RCAI will confirm deletion in writing on request.

Two points of detail, because they differ from the simple case:

  • Uninstalling the Shopify app does not delete data.It stops processing and deactivates the widget. Merchants uninstall to pause, to change plan, or in error, and reinstalling restores their history. Erasure follows Shopify’s shop/redact, which arrives forty-eight hours later where erasure is genuinely intended, or a direct written request to RCAI.
  • Redaction removes personal data from order records while retaining the commercial record.An order’s number, total and status are the Merchant’s own business record; the shopper’s name, email and phone are nulled in place.

During the subscription, data is retained according to the periods in Annex I.

11

International transfers

RCAI is established in the United Arab Emirates. Personal data is stored in the Republic of Korea (Seoul, AWS ap-northeast-2) and processed by the sub-processors listed at Annex III in the regions stated there.

Where the Merchant or its shoppers are in the European Economic Area, the United Kingdom or Switzerland, and personal data is transferred outside those areas:

  • The EU Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), are incorporated into this agreement by reference and apply to that transfer. Annex I to this agreement serves as Annexes I.A and I.B to those Clauses; Annex II serves as Annex II; Annex III serves as the list of sub-processors. The docking clause (Clause 7) applies. For Clause 9, Option 2 (general written authorisation) applies, with the notice period at clause 6 above. For Clause 11, the optional independent dispute resolution body is not selected. For Clause 17, the Clauses are governed by the law of Ireland. For Clause 18(b), disputes are resolved before the courts of Ireland.
  • For transfers subject to UK law, the International Data Transfer Addendumto those Clauses issued by the UK Information Commissioner (version B1.0) is incorporated by reference, with this agreement supplying the Addendum’s Table 1–4 information, and neither party permitted to terminate under Section 19.
  • For transfers subject to Swiss law, references in the Clauses to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the competent authority is the Federal Data Protection and Information Commissioner.

Where the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies, RCAI processes personal data in accordance with it.

The Merchant may request that its data be stored in a different region. RCAI will confirm whether it can accommodate the request and on what terms.

12

Governing law, jurisdiction and liability

This agreement is governed by the laws of the United Arab Emirates as applied in the Emirate of Ajman, and the parties submit to the exclusive jurisdiction of the courts of Ajman — save that, where the Standard Contractual Clauses apply, clause 11 governs disputes arising under those Clauses.

Each party’s liability under this agreement is subject to the limitations and exclusions of liability set out in the terms of service, save that nothing in this agreement limits either party’s liability to the extent that such limitation is not permitted by applicable law.

13

Order of precedence

Where the Standard Contractual Clauses apply and conflict with the remainder of this agreement, the Clauses prevail. Otherwise, this agreement prevails over the terms of service on matters of personal data processing.

14

Annex I — Description of processing

Also serves as Annexes I.A and I.B to the Standard Contractual Clauses.

Categories of data subjects

  • Shoppers who message the Merchant on Instagram, Facebook Messenger, WhatsApp or the Merchant’s website
  • Customers named on the Merchant’s Shopify orders
  • The Merchant’s own staff who use the platform

Categories of personal data

DataSource and notes
NameMeta profile, Shopify order
Platform-scoped user IDMeta. Instagram- or Page-scoped; not a global identifier
Email addressShopify order, staff account. Shopify Level 2 protected customer data
Phone numberShopify order, WhatsApp conversation. Shopify Level 2 protected customer data
Message contentThe shopper. Free text
Order number, status, total, tracking, expected deliveryShopify. Cached, not authoritative
Conversation metadataAssignment, status, timestamps, read state

Not collected: shipping or billing addresses, payment card data, government identifiers. RCAI does not store shopper addresses at all. The Shopify access request deliberately excluded address fields and did not request read_all_orders.

Special category data is not requested, not required, and not knowingly processed. Because message content is free text, a shopper may volunteer such data unprompted. RCAI does not use it, does not index on it, and it is deleted with the conversation.

Frequency: continuous, for the duration of the subscription.

Purposes:delivering shopper messages into the Merchant’s inbox; generating draft replies; sending the Merchant’s replies back to the shopper on the originating platform; answering product and order questions; and providing the Merchant with their conversation history.

Retention

DataPeriod
Conversations and messages730 days, purged daily
Cached order records180 days, purged daily
Catalogue recordsRefreshed each sync; removed when absent from a complete sync
Access log for protected customer data730 days
Compliance request log3 years. Stores a SHA-256 of the subject, never the payload
Shop record after redactionRetained as a tombstone recording the date of redaction

Competent supervisory authority for the Standard Contractual Clauses: the supervisory authority of the EEA member state in which the Merchant is established or, where the Merchant is not established in the EEA, the authority of the member state in which its EU representative is established.

15

Annex II — Technical and organisational measures

Also serves as Annex II to the Standard Contractual Clauses.

In place

  • Encryption in transit — TLS on all external connections.
  • Encryption at rest — provided by the database platform at storage level.
  • Credential isolation — third-party access tokens are held in an encrypted secrets vault, not in application tables or environment variables. Shopify tokens are short-lived, expire within approximately one hour, and are rotated automatically through a stored refresh token.
  • Tenant isolation enforced in the database, not only in application code — row-level security on tenant tables, and a dedicated database role for anonymous website visitors carrying column-level SELECT grants only, so that an ungranted column or any write is refused by the grant before row-level security is consulted. Verified by role impersonation against the live database.
  • Separation of development from production — development and testing run against a separate database containing no customer data.
  • Access logging for protected customer data — server-side access is recorded with the actor, the action, the record count and a SHA-256 of the subject, never the underlying values.
  • Webhook authenticity — HMAC signature verification over raw request bytes on both the Shopify and Meta webhook endpoints; requests failing verification are rejected before any processing.
  • Authentication — merchant sign-in is email and password with role-based access control. Facebook Login for Business is used only to connect business assets, never to authenticate people into the product.
  • Automated retention enforcement — see Annex I.
  • Secrets management— production secrets are held in the hosting provider’s encrypted environment configuration and are not committed to source control.
  • Written incident response policy — with defined severity levels, response times, containment procedure and notification obligations.

Planned, and not yet in place

Listed because this annex is a representation to the Merchant and must not overstate.

  • Database backups. Not currently in place. Planned: managed backups with point-in-time recovery.
  • Logging of panel reads.The access log above covers server-side paths. Reads performed by a Merchant’s own agents within the application interface occur in the browser under row-level security and are not individually logged. Planned: database-level audit logging.
  • Alerting on anomalous query volume or failed authentication.
  • Third-party certification. None held.
16

Annex III — Sub-processors

The maintained list, with change notifications under clause 6, is at retailcommerceai.com/subprocessors.

Retail Commerce AIRETAIL COMMERCE AI F.Z.E · Ajman Free Zone, United Arab EmiratesPrivacyTermsRefundsCancellationDelete your dataDPASub-processorshello@retailcommerceai.com+971 54 575 0708