Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller", "Merchant") and Avery ("Processor", "we", "us") for the use of Avery’s conversion rate optimisation service.

1. Definitions

2. Scope and roles

You are the Controller of your store data. We are the Processor. We process Personal Data only on your documented instructions, which are the service features you activate (connecting your store, running analysis, requesting code suggestions, installing the web pixel).

3. Categories of data processed

CategoryData subjectsRetention
Store owner email and domainMerchantUntil disconnection + Shopify erasure
Product catalogue metadataNot personal data (business data)Until disconnection + Shopify erasure
Web pixel events (browser-scoped visitor ID, page URLs, viewport, referrer, order value)Store visitors (pseudonymised)90 days
Aggregated daily funnel and order metricsNo individual dataIndefinite

4. Subprocessors

We use the following subprocessors. We will notify you before adding a new subprocessor or materially changing one.

SubprocessorLocationPurpose
Neon Inc.United StatesPostgreSQL database hosting (encrypted at rest)
Fly.io Inc.United StatesApplication hosting and secret management
Anthropic PBCUnited StatesAI analysis and code generation (receives store domain, performance scores, product metadata, finding summaries, and theme file contents; does not receive access tokens, shopper data, or order details)
Google LLCUnited StatesPageSpeed Insights API (receives public storefront URLs)
Stripe, Inc.United StatesSubscription billing (receives store owner email and an account identifier; payment details are entered directly with Stripe)
Resend, Inc.United StatesTransactional and digest email delivery (receives store owner email, store domain, and email contents)
Functional Software, Inc. (Sentry)United StatesError monitoring (receives error reports with store domain and record identifiers; any report containing an access token is dropped before sending)

5. Security measures

6. Data subject rights

We will assist you in responding to data subject requests. The mechanisms available:

7. Data breach notification

We will notify you without undue delay, and in any case within 72 hours, of becoming aware of a Personal Data breach affecting your data. Notification will include the nature of the breach, categories of data affected, and measures taken.

8. International transfers

Our subprocessors are located in the United States. For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission, incorporated by reference into our agreements with each subprocessor.

9. Audit rights

You may audit our compliance with this DPA by requesting a summary of our security practices, subprocessor list, and data handling procedures. We will respond within 30 days.

10. Term and termination

This DPA applies for as long as we process your Personal Data. On termination of the service, we delete all Personal Data within the retention periods stated above, or immediately on your request.