Skip to content

Legal

Data processing agreement

This DPA applies automatically to every AskMerra account. Need a countersigned copy? Write to [email protected].

Last updated: 1 October 2026

Parties and scope

This agreement is between the business that uses AskMerra (“you”, the controller) and [Company legal name], [Registered address], registration number [Registration number] (“AskMerra”, “we”, the processor). It governs the personal data we process on your behalf when we provide the service under the terms of service, in accordance with Article 28 GDPR. It does not cover data we process as a controller, such as your account and billing data, which our privacy policy describes.

Processing details

Subject matterOperation of an AI shopping assistant (chat widget) on your website and the related dashboard features
DurationFor as long as you use the service, plus the deletion periods below
Nature of processingHosting and storage, generating answers with an AI model, product search, delivering escalation emails to your team, aggregated analytics, linking purchases to chats when the shopper consented (sales measurement), and deletion
PurposeAnswering shoppers’ questions, recommending your products, passing contact requests to your team, and giving you conversation history, analytics and the sales made after a chat
Data subjectsVisitors of your website who use the assistant; your staff named in escalation settings
Categories of dataPseudonymous visitor id, chat messages and answers, page URLs, language, approximate country, product interactions and feedback; name, email and message when a shopper uses the contact form in the chat; name and email of logged-in customers only if you enable identification; order number, amount, currency and products of purchases made within 7 days after a chat, only with the shopper’s analytics consent
Special categoriesNot intended. The assistant is instructed not to ask for health or other sensitive data, and you must not configure it to collect such data
RetentionConversations, events, purchases linked to chats and visitors are deleted automatically after the retention period you choose (30, 90 or 365 days)

Your responsibilities

  • You decide the purposes of the processing and make sure you have a legal basis for it.
  • If you keep sales measurement on, you collect the shoppers’ analytics consent with your cookie banner (Google Consent Mode or AskMerra.setConsent()). Without it, the widget sends no purchases.
  • You inform your shoppers: link your privacy policy in the widget settings (it is shown next to the AI notice and in the contact form) and describe the chat there. You can copy the widget’s storage table from our cookie policy.
  • You only use visitor identification (AskMerra.identify()) when you have a legal basis to link chats to customer accounts.
  • You only call AskMerra.open() or sendMessage() in response to a shopper’s action, so the widget stores nothing before the shopper uses it.
  • You answer your shoppers’ data protection requests; the dashboard lets you find and delete a shopper’s data by email address or visitor id.

Our obligations

  • We process personal data only on your documented instructions, including with regard to transfers outside the EEA. Your configuration of the service and these terms are your instructions. If we believe an instruction infringes data protection law, we tell you.
  • Everyone at AskMerra who can access the data is bound by confidentiality.
  • We take the security measures described below (Article 32 GDPR) and keep them up to date.
  • We never use your data to train AI models, and our sub-processors are contractually prohibited from doing so. We never sell it or use it for our own marketing.
  • We engage sub-processors only as described below.
  • We help you answer data subject requests (Articles 12 to 23 GDPR), mainly through the deletion tools in the dashboard and the widget’s AskMerra.forget() function.
  • We help you meet your obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to us.
  • The widget always tells shoppers they are talking to an AI assistant (Article 50 of the EU AI Act). This notice cannot be turned off.

Security measures

  • Encryption in transit (TLS 1.2+); encrypted storage at the hosting provider; data and backups hosted in the EU.
  • Logical tenant isolation enforced on every database query and verified by automated tests.
  • Credentials hashed (argon2id), API keys stored as SHA-256 hashes, encrypted two-factor secrets, two-factor sign-in, least-privilege team roles, audit log.
  • No storage of raw IP addresses; pseudonymous visitor identifiers; the widget stores nothing in the shopper’s browser before the shopper uses the chat.
  • Configurable retention with automatic daily deletion; backups kept for no more than 30 days.
  • Abuse protection and rate limiting on all public endpoints; monitoring and error alerting without personal data in error reports.

Sub-processors

You give us general authorization to engage the sub-processors below. We tell you about any new or replacement sub-processor at least 30 days in advance (by email or in the dashboard), and you may object on reasonable data protection grounds; if we can’t resolve the objection, you may end the service before the change takes effect. Each sub-processor is bound by a written contract with data protection obligations at least as protective as this DPA, and we remain responsible to you for its performance.

Sub-processorPurposeLocation
[Hosting provider name]Application, database, file and backup hostingEU
Anthropic, PBCAI model inference (chat answers, catalog enrichment)USA (SCCs / Data Privacy Framework)
Voyage AIText embeddings for semantic searchUSA (SCCs / Data Privacy Framework)
[Email provider name]Delivery of escalation emails to your team[Location]

Stripe processes your billing data with AskMerra as controller and receives no shopper data, so it is not a sub-processor under this DPA.

International transfers

Transfers to countries without an adequacy decision rely on the EU-U.S. Data Privacy Framework where the recipient is certified, and otherwise on the European Commission’s Standard Contractual Clauses (Decision 2021/914, module 3 for processor-to-processor transfers), with supplementary measures where required.

Assistance & audits

We make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, by you or an auditor you mandate who is bound by confidentiality, with reasonable notice and no more than once a year unless a breach or an authority requires it. We first offer our documentation, security information and existing certifications or reports.

Personal data breaches

We notify you without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting your data. The notice describes, as far as known, the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures taken or proposed. We add information as it becomes available.

Return and deletion

You can export your conversations from the dashboard at any time. When you delete a shop, its data is purged right away; conversations are also deleted on a rolling basis according to your retention setting. When the service ends, we delete the remaining data within 30 days, unless the law requires us to keep it. Copies in backups disappear within 30 days.

General

This DPA forms part of the terms of service. If they conflict on data protection, this DPA prevails. Questions: [email protected].