Tillie Data Processing Agreement

Draft — under legal review. This document may change before it takes effect.

Last updated: 26 September 2026

Between: the Shopify merchant that installs Tillie ("Merchant", the controller)
and: Clarity Insights Imaging Pty Ltd (ABN 92 696 493 740), [Company number], 8/10 Lower River Terrace, South Brisbane QLD 4101 ("Tillie", "we", the processor)

This agreement ("DPA") forms part of the Terms of Service. It applies automatically when the Merchant installs Tillie. It covers personal information that we process for the Merchant: data about the Merchant's customers, callers and emailers ("Customer Personal Data").

It is written to meet: the Privacy Act 2020 (NZ); the Privacy Act 1988 (Cth) and the Australian Privacy Principles; the EU and UK GDPR (Article 28); the California Consumer Privacy Act (service provider terms); and Shopify's protected customer data requirements.

1. Roles

  1. The Merchant is the controller (or "agency" / "APP entity") for Customer Personal Data. It decides why the data is processed.
  2. We are the processor (or "service provider"). We process Customer Personal Data only for the Merchant and only to provide the service.
  3. For New Zealand law, we hold Customer Personal Data as the Merchant's agent (Privacy Act 2020, s 11).
  4. Each party complies with the privacy law that applies to it.

2. Instructions

  1. We process Customer Personal Data only on the Merchant's documented instructions. These are: the Terms of Service, this DPA, and the settings the Merchant chooses in the app (for example recording, retention periods, help-desk connection and automatic sending).
  2. We tell the Merchant if we believe an instruction breaks the law.
  3. We will not:
    • sell or "share" Customer Personal Data (as California law defines these terms);
    • use it for our own purposes, including marketing or advertising;
    • combine it with data from other stores;
    • use it to create, train, fine-tune or improve any AI or machine-learning model;
    • keep, use or disclose it outside our direct business relationship with the Merchant.
  4. We may process data in other ways only where the law requires it. We will tell the Merchant first unless the law forbids that.

3. Confidentiality

Everyone we allow to access Customer Personal Data is bound by a duty of confidence. Our staff have no standing access to call or email content. Emergency access needs a recorded reason and approval, expires after 24 hours, and is logged.

4. Security measures

We keep the technical and organisational measures in Annex 2. They are designed to meet Shopify's Level 1 and Level 2 protected customer data requirements. We may improve them over time but will not reduce overall protection.

5. Subprocessors

  1. The Merchant gives general authorisation for us to use the subprocessors in Annex 3.
  2. We have a written contract with each subprocessor with data protection terms no less protective than this DPA.
  3. We give at least 30 days' notice before adding or replacing a subprocessor, in the app or by email, and on https://hellotillie.com/privacy#8-who-receives-the-information-subprocessors.
  4. The Merchant may object on reasonable data protection grounds within 14 days of the notice. We will try to find a fix. If we cannot, the Merchant may end the service by uninstalling, and will not be charged the plan fee for the period after the change.
  5. We remain responsible for our subprocessors' performance.
  6. Help desks and mailboxes the Merchant connects (Gorgias, Zendesk, Re:amaze, Gmail, Microsoft 365) are the Merchant's own providers, not our subprocessors.

6. Help with requests from individuals

  1. Shopify sends us customer data requests and deletion requests on the Merchant's behalf (the customers/data_request and customers/redact webhooks). We act on each within 30 days of receipt:
    • data request: we find calls, messages, follow-ups and email records linked to the customer (by Shopify customer ID, phone and order numbers) and make an encrypted export available to the Merchant in the app. The Merchant sends it to the customer;
    • deletion: we delete recordings, transcripts, messages, follow-ups and email copies linked to the customer. We keep only billing facts (call length and minutes) with no personal content.
  2. If an individual contacts us directly, we pass the request to the Merchant within 5 business days and do not answer it ourselves unless the Merchant asks us to.
  3. We give reasonable help with the Merchant's privacy impact assessments and with regulator enquiries, to the extent they concern our service.

7. Security incidents

  1. We notify the Merchant within 48 hours of becoming aware of a security incident that affects the Merchant's Customer Personal Data.
  2. The notice will say, as far as known at the time: what happened; the kinds and rough number of records and people affected; likely effects; what we have done and will do; and a contact person. We send more details as we learn them.
  3. We notify Shopify within 24 hours of becoming aware of an actual or suspected breach of Merchant Data, as Shopify's terms require.
  4. We help the Merchant decide whether the incident is a notifiable privacy breach (NZ) or an eligible data breach (Australia), or needs notice under GDPR Article 33 (72 hours for controllers). We provide the facts and a draft of the notice.
  5. Unless the law requires, we will not notify regulators or individuals about the Merchant's Customer Personal Data without first consulting the Merchant. Where the incident also affects our own data (for example merchant account data), we notify regulators ourselves.
  6. Our Incident Response Plan sets out how we handle incidents.

8. Deletion and return

  1. The Merchant can export and delete call data in the app at any time, and set retention periods (Annex 1).
  2. When the Merchant uninstalls, Shopify sends us a shop/redact request 48 hours later. We then delete all Customer Personal Data for that store and destroy the store's encryption key, so any remaining encrypted copies (including backups) cannot be read. We complete this within 30 days of uninstall.
  3. We keep billing records (plan, minutes, charges) for 7 years for tax law. They contain no Customer Personal Data.
  4. Provider backups expire on their own schedule (for example Cloudflare D1 point-in-time recovery). Because of step 2, they hold only unreadable ciphertext for call content.

9. Audits

  1. We keep records needed to show we meet this DPA, including the access log (kept 2 years).
  2. Once a year, on 30 days' written notice, the Merchant may ask for a written answer to a reasonable security questionnaire and a summary of our controls. We may rely on our subprocessors' certifications (for example Cloudflare ISO 27001, Twilio and OpenAI SOC 2) for their parts.
  3. If the law or a regulator requires more, or after a security incident, the Merchant (or an independent auditor bound by confidentiality) may carry out a reasonable audit at the Merchant's cost, during business hours, without access to other stores' data.

10. International transfers

  1. Customer Personal Data is processed in the United States and other countries where our subprocessors operate (Annex 3).
  2. For New Zealand (IPP 12) and Australia (APP 8), we use subprocessors bound by contract to comparable safeguards, and remain accountable for them.
  3. For personal data from the EEA, UK or Switzerland, the parties agree to the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), [Module 2 (controller to processor) and/or Module 3 (processor to processor) — lawyer to confirm], with the UK Addendum and Swiss amendments, incorporated by reference. [Placeholder: SCC annex elections, clause 7 docking, clause 9 option, clause 11 option, clause 13 supervisory authority, clauses 17–18 governing law and forum.]
  4. Our subprocessors rely on their own transfer tools (SCCs, the EU-US Data Privacy Framework, or Global CBPR) as described in their DPAs.

11. Term and liability

This DPA lasts as long as we process Customer Personal Data for the Merchant. The liability limits in the Terms of Service apply, except where the law does not allow them to. If this DPA conflicts with the Terms, this DPA wins on data protection matters.


Annex 1. Processing details

ItemDetails
Subject matterAnswering the Merchant's phone calls and drafting and sending replies to the Merchant's customer emails and help-desk tickets.
DurationWhile the app is installed, plus up to 30 days after uninstall for deletion.
Nature of processingReceiving and streaming call audio; speech recognition and speech output by AI; recording (if on); transcription; reading store and order data from Shopify; identity checks; sending text messages at the caller's request; reading and replying to emails and tickets; AI drafting and review; summaries; storage; export; deletion.
PurposeTo answer customers' questions for the Merchant, take messages and callbacks, and help staff reply to email.
IndividualsCallers; people who email or message the Merchant; customers whose orders are looked up.
Personal dataPhone numbers; call audio; transcripts; names; order numbers; postcodes; order contents, status and shipping; delivery city; name, phone, email and address on an order (read, not spoken in full); email addresses; email and ticket text; messages and callback details; texts sent.
Sensitive dataNot intended. Callers or emailers may volunteer sensitive information; it is handled as ordinary call content and deleted on the same schedule.
Retention (defaults; Merchant can change within limits)Recordings 30 days (0–365); transcripts 90 days (1–730); call records 400 days (30–1,095); messages and callbacks 90 days (1–365); email records [90 days — confirm]; exports 30 days; access log 2 years; live call memory 2 hours. Backstop: call files older than 800 days are deleted.
FrequencyContinuous while the app is installed.

Annex 2. Security measures

Mapped to Shopify's protected customer data requirements.

Shopify requirementOur measureStatus at draft date
L1.1 Minimum dataRead-only scopes. Only the order lookup tool reads protected fields. Only delivery city is spoken. The assistant never asks for an email address. Tool outputs are filtered to what an answer needs.In place
L1.2 Tell merchants what and whyPrivacy Policy, this DPA, and a "Data we keep" section in Settings.Settings section [to build]
L1.3 Limit to stated purposesData used only for the service; contract terms; no AI training (store: false on OpenAI calls).In place
L1.4 Respect consentTexts, callbacks, messages and transfers need the caller's consent. Recording always plays a notice. Per-store AI disclosure setting.In place
L1.5 Opt-out of saleNo sale or sharing of data.In place
L1.6 Automated decisionsNo decision with legal or similarly significant effect. Identity check only controls disclosure; a human callback is always offered. Auto-send is off by default and per question type.In place
L1.7 Agreements with merchantsTerms of Service and this DPA.This document
L1.8 Retention periodsPer-store retention settings with the defaults above; daily deletion job; storage lifecycle backstop.Deletion job [to build]
L1.9 Encryption in transit and at restTLS on all connections; Twilio and Shopify signature checks. Provider encryption at rest, plus our own per-store key (AES-256-GCM) for recordings, transcripts, caller numbers, tokens and help-desk keys. Identifiers stored as keyed hashes.Partly; gaps listed in APP_REVIEW_READINESS §2
L2.1 Encrypted backupsProvider backups are encrypted; our own ciphertext stays encrypted in any backup; exports encrypted. Destroying a store's key makes its backups unreadable.In place once L1.9 gaps are fixed
L2.2 Test and production separateSeparate Shopify app, Cloudflare resources, Twilio account and OpenAI project for test. Test uses made-up data only.Production environment [to create]
L2.3 Data loss preventionNo personal data in logs (invocation logs off; tool arguments redacted; events carry hashes). No public storage. Recordings play only through signed, short-lived links. Exports only through the admin.Admin logs [to switch off]
L2.4 Limit staff accessNo standing staff access. Break-glass grant with reason, approver and 24-hour expiry, behind single sign-on with multi-factor.[To build before real data]
L2.5 Strong passwordsPasskeys or multi-factor on Shopify Partner, Cloudflare, Twilio, OpenAI, Anthropic, GitHub and email accounts. Least-privilege API tokens.[Record evidence]
L2.6 Access logAppend-only log of transcript views, recording plays, order lookups, exports, deletes and staff access. Kept 2 years. Merchant can view their own log.Partly
L2.7 Incident response policyIncident Response Plan.This pack

Other measures: every database query is scoped to one store; tests run with two stores to catch leaks; customer email text is treated as data, never as instructions to the AI; links and attachments in emails are never opened.

Annex 3. Subprocessors

SubprocessorServiceLocationTransfer tool
Cloudflare, Inc.Hosting, database (D1), storage (R2), queues, networkGlobal; storage [region to confirm]SCCs, DPF, Global CBPR (Cloudflare DPA v6.4)
OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd)AI voice, summaries, email drafting and reviewUnited StatesSCCs (OpenAI DPA)
Twilio Inc.Phone numbers, call routing and audio, temporary recording, SMS, number registrationUnited States; numbers in AU and NZDPF, BCRs, SCCs (Twilio DPA, 9 April 2026)
Anthropic, PBC [only if used at launch]Email drafting or reviewUnited StatesSCCs (Anthropic DPA in Commercial Terms)
[Email provider — TBD]Summary and alert emails to merchants[Location][Tool]

Shopify is the platform the Merchant uses, not our subprocessor. It sends us store and order data and handles billing under the Merchant's own agreement with Shopify.