Skip to content
In private rollout: onboarded personally, usually live within 24 hours.
Legal

Data Processing Agreement

How Cervito processes personal data on your behalf.

Last updated
Entity
The Growth Locker FZC · SPC Freezone, Sharjah, United Arab Emirates

Interim policy, pending final legal review. This is a good-faith interim version. Questions: [email protected]

1. The agreement (binding by incorporation)

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between you (the "Controller", the merchant operating a connected store) and The Growth Locker FZC, operator of Cervito (the "Processor"). By connecting a store to Cervito, or by accepting the Terms of Service, you agree to this DPA in respect of personal data relating to your storefront visitors that Cervito processes on your behalf. A counter-signed copy for your records is available on request at [email protected].

2. Roles and scope

Cervito acts as processor of storefront-visitor personal data on the Controller's behalf and processes it only to provide the service and on the Controller's documented instructions (these terms and the Controller's use of the dashboard being such instructions). The subject-matter is the operation of an AI shopping associate; the duration is the term of the Controller's subscription plus the deletion windows below.

3. Categories of data and data subjects

  • Data subjects: the Controller's storefront visitors and shoppers.
  • Categories: conversation messages and any details a visitor types (which may include a name); anonymous session/visitor identifiers; email and optional phone where a visitor provides one; order and catalog metadata; attribution/interaction events.

4. Sub-processors

We engage the sub-processors below. This list reflects production today.

Sub-processorPurposeProcessing location
RailwayApplication + database hosting (production)European Union (Netherlands)
AnthropicLLM inference for the associate's replies. Visitor-typed first names may be included in the conversation text sent for inference (email, phone, and card numbers are removed first).United States
OpenAIText-embedding generation for catalog/product search (your catalog text, not visitor identifiers)United States
ResendTransactional email: verification links, data-export deliveries, and notifications. Receives visitor email addresses and exported personal-data files.United States
CloudflareDNS, edge delivery, network security, and privacy-preserving (cookieless) analytics for our marketing websiteGlobal edge network
GoogleBusiness email (Google Workspace; e.g. [email protected]); the appointment scheduler embedded on our marketing site's /book page; and Google Meet for the 30-minute demo video call a prospect books, together receiving the booking and meeting details they choose to submitUnited States / EU
ShopifyYour connected store platform: catalog, orders, and customer data for stores you connectPer Shopify's terms

The Google appointment-scheduler and Google Meet entries cover demo bookings on our marketing site, where we (The Growth Locker FZC) are the controller of the prospect's own data, and are listed here for transparency, not as processing carried out on your behalf as Controller.

Changes to sub-processors. We will give at least 30 days' notice before a new sub-processor begins processing your visitors' personal data (by email to your account contact and/or an update to this page). You may object on reasonable data-protection grounds within that period ([email protected]); if we cannot address your objection, you may terminate the affected service for the unused portion of any prepaid term.

5. International transfers

Some sub-processors are outside the EU/EEA (notably the United States, see section 4). Where personal data is transferred to them, we rely on the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, with additional safeguards. We are finalizing the formal transfer documentation with legal counsel and will make the relevant clauses available on request.

6. Connected-platform data terms (Shopify Protected Customer Data)

When you connect a store, your platform's data-protection terms apply in addition to this DPA. For Shopify stores, Cervito accesses customer data under Shopify's Protected Customer Data requirements; we limit the customer fields we request to those needed to operate the associate (product, order, and customer-identity data), honor the mandatory Shopify GDPR webhooks (section 7), and bind our sub-processors to data-protection terms at least as protective as those we owe you here.

Platform differences. The automatic GDPR webhooks are a Shopify feature. Other platforms differ. For example, Magento does not provide native deletion webhooks, so for a connected Magento store, erasure is handled through the self-service visitor portal and your written request to us, not by a platform webhook. We will tell you which mechanisms apply for each platform you connect.

7. Assistance with data-subject requests

Taking into account the nature of processing, we assist you in meeting your obligations to data subjects:

  • Self-service visitor portal. A shopper can request a copy of, or the erasure of, their data directly after verifying control of their email address. Exports are delivered to the shopper; erasure is executed across the Cervito-powered stores that hold their data. This is the only path that delivers an export directly to a shopper.
  • Shopify GDPR webhooks. For Shopify stores we honor all three mandatory webhooks: customers/redact and shop/redact automatically delete the relevant data; customers/data_request compiles the export and forwards it to you, the merchant, to deliver to the shopper. You remain responsible for delivering that export within the statutory deadline.

8. Erasure and the retained order record

On an erasure request we delete the visitor's conversation transcripts, conversation analyses, attribution touches, and contact records, and we anonymize the visitor profile. We retain a minimized order record (an order reference, amount, and date, with name, email, phone, address, and any gift/engraving/recipient details removed) only where you, as controller, instruct us to or are legally required to keep it (for example, your own financial-record obligations). We do not assert an independent legal obligation of our own to retain it.

9. Deletion or return on termination; audit

On termination you may elect to have us delete or return your storefront-visitor personal data. Unless you instruct return, we delete it within 30 days of termination, except (a) the minimized order record above and (b) data we are legally required to keep. Before deletion you may request an export. Data not affected by termination continues to be deleted automatically on the Privacy Policy retention windows.

Audit. We will make available the information reasonably necessary to demonstrate compliance, including, on request, a description of our technical and organizational measures and responses to a reasonable security questionnaire (no more than once per 12 months). Where a documented review is insufficient and an on-site or third-party audit is genuinely required, it will be on at least 30 days' written notice, during business hours, under a confidentiality agreement, limited to systems relevant to your data, conducted so as not to disrupt our operations or compromise other customers' confidentiality, and at your cost.

10. Personal data breach

If we become aware of a personal data breach affecting your storefront visitors' personal data, we will notify you without undue delay at your account contact and, to the extent then known, describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. We will reasonably assist you in meeting your own notification obligations. The deadline to notify a supervisory authority is the controller's obligation; our commitment is prompt notice and assistance.

11. Cookies and consent (merchant responsibility)

The associate may set cookies or similar storage on your storefront. Where the law of your shoppers' location requires consent for non-essential storage (e.g. EU ePrivacy, UK PECR), you, the merchant, are responsible for obtaining that consent, including running a consent platform if needed. Cervito reads consent signals from common consent platforms; where you enable consent gating, the associate restricts non-essential storage accordingly.

12. Security

We apply technical and organizational measures appropriate to the risk, including: encryption of platform credentials at rest (AES-256-GCM); tenant isolation at the database layer; sealed, rotating session binding; audit logging; and removal of email/phone/card numbers from conversation text before AI inference. We require our sub-processors to maintain appropriate measures.

13. Contact

DPA and data-protection matters: [email protected].