Tillie Data Processing Agreement
Between: the Shopify merchant that installs Tillie ("Merchant", the controller)
and: Clarity Insights Imaging Pty Ltd (ABN 92 696 493 740), [Company number], 8/10 Lower River Terrace, South Brisbane QLD 4101 ("Tillie", "we", the processor)
This agreement ("DPA") forms part of the Terms of Service. It applies automatically when the Merchant installs Tillie. It covers personal information that we process for the Merchant: data about the Merchant's customers, callers and emailers ("Customer Personal Data").
It is written to meet: the Privacy Act 2020 (NZ); the Privacy Act 1988 (Cth) and the Australian Privacy Principles; the EU and UK GDPR (Article 28); the California Consumer Privacy Act (service provider terms); and Shopify's protected customer data requirements.
1. Roles
- The Merchant is the controller (or "agency" / "APP entity") for Customer Personal Data. It decides why the data is processed.
- We are the processor (or "service provider"). We process Customer Personal Data only for the Merchant and only to provide the service.
- For New Zealand law, we hold Customer Personal Data as the Merchant's agent (Privacy Act 2020, s 11).
- Each party complies with the privacy law that applies to it.
2. Instructions
- We process Customer Personal Data only on the Merchant's documented instructions. These are: the Terms of Service, this DPA, and the settings the Merchant chooses in the app (for example recording, retention periods, help-desk connection and automatic sending).
- We tell the Merchant if we believe an instruction breaks the law.
- We will not:
- sell or "share" Customer Personal Data (as California law defines these terms);
- use it for our own purposes, including marketing or advertising;
- combine it with data from other stores;
- use it to create, train, fine-tune or improve any AI or machine-learning model;
- keep, use or disclose it outside our direct business relationship with the Merchant.
- We may process data in other ways only where the law requires it. We will tell the Merchant first unless the law forbids that.
3. Confidentiality
Everyone we allow to access Customer Personal Data is bound by a duty of confidence. Our staff have no standing access to call or email content. Emergency access needs a recorded reason and approval, expires after 24 hours, and is logged.
4. Security measures
We keep the technical and organisational measures in Annex 2. They are designed to meet Shopify's Level 1 and Level 2 protected customer data requirements. We may improve them over time but will not reduce overall protection.
5. Subprocessors
- The Merchant gives general authorisation for us to use the subprocessors in Annex 3.
- We have a written contract with each subprocessor with data protection terms no less protective than this DPA.
- We give at least 30 days' notice before adding or replacing a subprocessor, in the app or by email, and on https://hellotillie.com/privacy#8-who-receives-the-information-subprocessors.
- The Merchant may object on reasonable data protection grounds within 14 days of the notice. We will try to find a fix. If we cannot, the Merchant may end the service by uninstalling, and will not be charged the plan fee for the period after the change.
- We remain responsible for our subprocessors' performance.
- Help desks and mailboxes the Merchant connects (Gorgias, Zendesk, Re:amaze, Gmail, Microsoft 365) are the Merchant's own providers, not our subprocessors.
6. Help with requests from individuals
- Shopify sends us customer data requests and deletion requests on the Merchant's behalf (the
customers/data_requestandcustomers/redactwebhooks). We act on each within 30 days of receipt:- data request: we find calls, messages, follow-ups and email records linked to the customer (by Shopify customer ID, phone and order numbers) and make an encrypted export available to the Merchant in the app. The Merchant sends it to the customer;
- deletion: we delete recordings, transcripts, messages, follow-ups and email copies linked to the customer. We keep only billing facts (call length and minutes) with no personal content.
- If an individual contacts us directly, we pass the request to the Merchant within 5 business days and do not answer it ourselves unless the Merchant asks us to.
- We give reasonable help with the Merchant's privacy impact assessments and with regulator enquiries, to the extent they concern our service.
7. Security incidents
- We notify the Merchant within 48 hours of becoming aware of a security incident that affects the Merchant's Customer Personal Data.
- The notice will say, as far as known at the time: what happened; the kinds and rough number of records and people affected; likely effects; what we have done and will do; and a contact person. We send more details as we learn them.
- We notify Shopify within 24 hours of becoming aware of an actual or suspected breach of Merchant Data, as Shopify's terms require.
- We help the Merchant decide whether the incident is a notifiable privacy breach (NZ) or an eligible data breach (Australia), or needs notice under GDPR Article 33 (72 hours for controllers). We provide the facts and a draft of the notice.
- Unless the law requires, we will not notify regulators or individuals about the Merchant's Customer Personal Data without first consulting the Merchant. Where the incident also affects our own data (for example merchant account data), we notify regulators ourselves.
- Our Incident Response Plan sets out how we handle incidents.
8. Deletion and return
- The Merchant can export and delete call data in the app at any time, and set retention periods (Annex 1).
- When the Merchant uninstalls, Shopify sends us a
shop/redactrequest 48 hours later. We then delete all Customer Personal Data for that store and destroy the store's encryption key, so any remaining encrypted copies (including backups) cannot be read. We complete this within 30 days of uninstall. - We keep billing records (plan, minutes, charges) for 7 years for tax law. They contain no Customer Personal Data.
- Provider backups expire on their own schedule (for example Cloudflare D1 point-in-time recovery). Because of step 2, they hold only unreadable ciphertext for call content.
9. Audits
- We keep records needed to show we meet this DPA, including the access log (kept 2 years).
- Once a year, on 30 days' written notice, the Merchant may ask for a written answer to a reasonable security questionnaire and a summary of our controls. We may rely on our subprocessors' certifications (for example Cloudflare ISO 27001, Twilio and OpenAI SOC 2) for their parts.
- If the law or a regulator requires more, or after a security incident, the Merchant (or an independent auditor bound by confidentiality) may carry out a reasonable audit at the Merchant's cost, during business hours, without access to other stores' data.
10. International transfers
- Customer Personal Data is processed in the United States and other countries where our subprocessors operate (Annex 3).
- For New Zealand (IPP 12) and Australia (APP 8), we use subprocessors bound by contract to comparable safeguards, and remain accountable for them.
- For personal data from the EEA, UK or Switzerland, the parties agree to the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), [Module 2 (controller to processor) and/or Module 3 (processor to processor) — lawyer to confirm], with the UK Addendum and Swiss amendments, incorporated by reference. [Placeholder: SCC annex elections, clause 7 docking, clause 9 option, clause 11 option, clause 13 supervisory authority, clauses 17–18 governing law and forum.]
- Our subprocessors rely on their own transfer tools (SCCs, the EU-US Data Privacy Framework, or Global CBPR) as described in their DPAs.
11. Term and liability
This DPA lasts as long as we process Customer Personal Data for the Merchant. The liability limits in the Terms of Service apply, except where the law does not allow them to. If this DPA conflicts with the Terms, this DPA wins on data protection matters.
Annex 1. Processing details
| Item | Details |
|---|---|
| Subject matter | Answering the Merchant's phone calls and drafting and sending replies to the Merchant's customer emails and help-desk tickets. |
| Duration | While the app is installed, plus up to 30 days after uninstall for deletion. |
| Nature of processing | Receiving and streaming call audio; speech recognition and speech output by AI; recording (if on); transcription; reading store and order data from Shopify; identity checks; sending text messages at the caller's request; reading and replying to emails and tickets; AI drafting and review; summaries; storage; export; deletion. |
| Purpose | To answer customers' questions for the Merchant, take messages and callbacks, and help staff reply to email. |
| Individuals | Callers; people who email or message the Merchant; customers whose orders are looked up. |
| Personal data | Phone numbers; call audio; transcripts; names; order numbers; postcodes; order contents, status and shipping; delivery city; name, phone, email and address on an order (read, not spoken in full); email addresses; email and ticket text; messages and callback details; texts sent. |
| Sensitive data | Not intended. Callers or emailers may volunteer sensitive information; it is handled as ordinary call content and deleted on the same schedule. |
| Retention (defaults; Merchant can change within limits) | Recordings 30 days (0–365); transcripts 90 days (1–730); call records 400 days (30–1,095); messages and callbacks 90 days (1–365); email records [90 days — confirm]; exports 30 days; access log 2 years; live call memory 2 hours. Backstop: call files older than 800 days are deleted. |
| Frequency | Continuous while the app is installed. |
Annex 2. Security measures
Mapped to Shopify's protected customer data requirements.
| Shopify requirement | Our measure | Status at draft date |
|---|---|---|
| L1.1 Minimum data | Read-only scopes. Only the order lookup tool reads protected fields. Only delivery city is spoken. The assistant never asks for an email address. Tool outputs are filtered to what an answer needs. | In place |
| L1.2 Tell merchants what and why | Privacy Policy, this DPA, and a "Data we keep" section in Settings. | Settings section [to build] |
| L1.3 Limit to stated purposes | Data used only for the service; contract terms; no AI training (store: false on OpenAI calls). | In place |
| L1.4 Respect consent | Texts, callbacks, messages and transfers need the caller's consent. Recording always plays a notice. Per-store AI disclosure setting. | In place |
| L1.5 Opt-out of sale | No sale or sharing of data. | In place |
| L1.6 Automated decisions | No decision with legal or similarly significant effect. Identity check only controls disclosure; a human callback is always offered. Auto-send is off by default and per question type. | In place |
| L1.7 Agreements with merchants | Terms of Service and this DPA. | This document |
| L1.8 Retention periods | Per-store retention settings with the defaults above; daily deletion job; storage lifecycle backstop. | Deletion job [to build] |
| L1.9 Encryption in transit and at rest | TLS on all connections; Twilio and Shopify signature checks. Provider encryption at rest, plus our own per-store key (AES-256-GCM) for recordings, transcripts, caller numbers, tokens and help-desk keys. Identifiers stored as keyed hashes. | Partly; gaps listed in APP_REVIEW_READINESS §2 |
| L2.1 Encrypted backups | Provider backups are encrypted; our own ciphertext stays encrypted in any backup; exports encrypted. Destroying a store's key makes its backups unreadable. | In place once L1.9 gaps are fixed |
| L2.2 Test and production separate | Separate Shopify app, Cloudflare resources, Twilio account and OpenAI project for test. Test uses made-up data only. | Production environment [to create] |
| L2.3 Data loss prevention | No personal data in logs (invocation logs off; tool arguments redacted; events carry hashes). No public storage. Recordings play only through signed, short-lived links. Exports only through the admin. | Admin logs [to switch off] |
| L2.4 Limit staff access | No standing staff access. Break-glass grant with reason, approver and 24-hour expiry, behind single sign-on with multi-factor. | [To build before real data] |
| L2.5 Strong passwords | Passkeys or multi-factor on Shopify Partner, Cloudflare, Twilio, OpenAI, Anthropic, GitHub and email accounts. Least-privilege API tokens. | [Record evidence] |
| L2.6 Access log | Append-only log of transcript views, recording plays, order lookups, exports, deletes and staff access. Kept 2 years. Merchant can view their own log. | Partly |
| L2.7 Incident response policy | Incident Response Plan. | This pack |
Other measures: every database query is scoped to one store; tests run with two stores to catch leaks; customer email text is treated as data, never as instructions to the AI; links and attachments in emails are never opened.
Annex 3. Subprocessors
| Subprocessor | Service | Location | Transfer tool |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, database (D1), storage (R2), queues, network | Global; storage [region to confirm] | SCCs, DPF, Global CBPR (Cloudflare DPA v6.4) |
| OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd) | AI voice, summaries, email drafting and review | United States | SCCs (OpenAI DPA) |
| Twilio Inc. | Phone numbers, call routing and audio, temporary recording, SMS, number registration | United States; numbers in AU and NZ | DPF, BCRs, SCCs (Twilio DPA, 9 April 2026) |
| Anthropic, PBC [only if used at launch] | Email drafting or review | United States | SCCs (Anthropic DPA in Commercial Terms) |
| [Email provider — TBD] | Summary and alert emails to merchants | [Location] | [Tool] |
Shopify is the platform the Merchant uses, not our subprocessor. It sends us store and order data and handles billing under the Merchant's own agreement with Shopify.