Data Processing Addendum
Draft v1 — Last updated 2026-05-28. Pending counsel review.
StoreWiz is operated by its parent company, currently in formation. The operating entity, jurisdiction of incorporation, and governing-law clauses will be finalized prior to general availability. For current corporate status, contact
legal@storewiz.ai.
This Data Processing Addendum ("DPA") forms part of the Terms of Service (or other written agreement) between the customer that subscribes to the StoreWiz Services ("Customer", "you") and StoreWiz ("StoreWiz", "we", "us") (together, the "Parties"). It governs the Processing of Personal Data by StoreWiz on Customer's behalf in connection with the Services.
This DPA is effective on the later of (a) the date you accept the Terms of Service, and (b) the date Customer signs this DPA via the in-product acceptance flow (see §17) or via a separately executed copy. To the extent of any conflict between the Terms of Service and this DPA in respect of Personal Data Processing, this DPA prevails.
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms of Service or the Privacy Policy.
- "Applicable Data Protection Law" means all data-protection and privacy laws applicable to the Processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK Data Protection Act 2018 and UK GDPR ("UK GDPR"), the Swiss Federal Act on Data Protection (revised 2023) ("Swiss FADP"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), other US state comprehensive privacy laws, Canada's PIPEDA and Quebec's Law 25, Brazil's LGPD, and other applicable laws as they apply to the Processing.
- "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Sub-processor" have the meanings given in the GDPR (with equivalents under other Applicable Data Protection Law).
- "Customer Personal Data" means Personal Data Processed by StoreWiz on Customer's behalf in connection with the Services. This includes Personal Data of Customer's customers, employees, suppliers, leads, and other Data Subjects.
- "EU SCCs" means the Standard Contractual Clauses for the transfer of Personal Data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (in force from 21 March 2022).
- "Restricted Transfer" means a transfer of Customer Personal Data to a country, territory, or international organization not recognized by the relevant supervisory authority as providing an adequate level of protection.
- "Annex I", "Annex II", "Annex III" mean the annexes to this DPA (and, where used in the EU SCCs, the corresponding annexes of the SCCs).
2. Roles and scope
2.1 Roles
In respect of Customer Personal Data:
- Customer is the Controller (and where Customer Processes data on behalf of its own customers as a Processor, Customer is the Processor and StoreWiz is the Sub-processor — see §2.2 below);
- StoreWiz is the Processor.
In respect of Account Data (the Personal Data Customer provides to register and maintain the StoreWiz account itself — e.g., admin user names and emails, billing contact data, OKR / Pillars configuration), StoreWiz is the Controller and the Privacy Policy governs.
2.2 Two-hat scenarios
If Customer Processes Personal Data of its own customers, employees, or other Data Subjects as a Processor on behalf of another Controller, and Customer in turn instructs StoreWiz to Process that Personal Data, then for the purposes of that Personal Data StoreWiz is a Sub-processor and Customer warrants that it has authority to engage StoreWiz on those terms.
2.3 Subject matter, nature, purpose, duration, categories
See Annex I for the description of Processing.
2.4 Customer instructions
StoreWiz Processes Customer Personal Data only on Customer's documented instructions. Customer's instructions are deemed given by:
- These Terms of Service, the Order Form (if any), and this DPA;
- Customer's configuration of the Services via the Admin Console (including Autonomy Tier choices per skill, data-residency selection, retention configuration, sub-processor opt-outs where applicable);
- Customer's use of the APIs;
- Written instructions from Customer to StoreWiz (e.g., support tickets, emails to
privacy@storewiz.ai).
If StoreWiz reasonably believes an instruction would violate Applicable Data Protection Law, StoreWiz will inform Customer without undue delay and may pause the affected Processing until clarified.
2.5 Processing in accordance with law
Each Party will comply with Applicable Data Protection Law in performing its obligations under this DPA. Customer represents that it has, and will maintain, a lawful basis for the Processing of Customer Personal Data and has provided all required notices and obtained all required consents from Data Subjects.
3. StoreWiz obligations as Processor
StoreWiz will:
a. Process only on documented instructions. Process Customer Personal Data only on Customer's documented instructions as set out in §2.4 (and any further documented instructions Customer provides), except where Processing is required by law to which StoreWiz is subject (in which case StoreWiz will inform Customer in advance unless law prohibits this on important grounds of public interest);
b. Confidentiality of personnel. Ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations or are subject to a statutory duty of confidence;
c. Security measures. Implement and maintain the technical and organizational measures set out in Annex II to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure;
d. Sub-processor engagement. Engage Sub-processors only in accordance with §5;
e. Assistance with Data Subject rights. Assist Customer by appropriate technical and organizational measures to respond to Data Subject requests as described in §6;
f. Assistance with DPIAs and prior consultation. Provide reasonable assistance to Customer with Data Protection Impact Assessments (Art. 35 GDPR) and prior consultations with supervisory authorities (Art. 36 GDPR);
g. Breach notification. Notify Customer of any Personal Data Breach affecting Customer Personal Data as described in §7;
h. Return or deletion. At the end of the provision of the Services, return or delete Customer Personal Data as described in §8;
i. Records of Processing. Maintain records of Processing activities as Processor under Art. 30(2) GDPR and make them available to Customer on reasonable request;
j. Make available necessary information. Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Art. 28 GDPR, subject to the audit provisions in §9;
k. Cooperate with supervisory authorities. Cooperate, on reasonable request, with supervisory authorities exercising their powers under Applicable Data Protection Law.
4. Customer obligations as Controller
Customer will:
a. Comply with its obligations as Controller under Applicable Data Protection Law, including providing all required notices to and obtaining all required consents from Data Subjects;
b. Ensure that its instructions to StoreWiz comply with Applicable Data Protection Law;
c. Decide on the Autonomy Tier per skill, the spend caps, the data-residency configuration, the retention configuration, and the scope of OAuth permissions granted to StoreWiz;
d. Be solely responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired it;
e. Notify StoreWiz of any Data Subject request or supervisory-authority inquiry directed at Customer that requires StoreWiz's assistance;
f. Comply with the Acceptable Use Policy.
5. Sub-processors
5.1 General authorization
Customer provides general authorization for StoreWiz to engage Sub-processors to assist in providing the Services. The current list of authorized Sub-processors is set out in Annex III and published at storewiz.ai/legal/sub-processors.
5.2 Sub-processor obligations
StoreWiz will:
- Enter into a written agreement with each Sub-processor imposing data-protection obligations no less protective than this DPA (insofar as applicable to the nature of the Sub-processor's services);
- Remain fully responsible to Customer for the performance of Sub-processors' obligations;
- Cause each Sub-processor to comply with the same restrictions on cross-border transfers as apply to StoreWiz under this DPA (see §10).
5.3 Notification of changes
StoreWiz will give Customer at least 30 days' prior written notice (by email to the Customer's primary contact and by updating the canonical Sub-processor URL) before engaging any new Sub-processor or making a material change to the role of an existing one. Notice may be shortened in cases of emergency replacement (e.g., a Sub-processor security incident or sudden vendor outage); StoreWiz will document the rationale in the audit log and provide the underlying detail on request.
5.4 Right to object
Customer may object in writing to a new or changed Sub-processor on reasonable data-protection grounds within 14 days of notice. The Parties will work together in good faith to resolve the objection. If StoreWiz cannot, with reasonable efforts, make available an alternative or accommodate Customer's objection, Customer may terminate the affected portion of the Services for cause and receive a pro-rata refund of pre-paid unused fees for that portion.
6. Data Subject rights
6.1 Customer-side handling
Customer is responsible for responding to Data Subject requests under Applicable Data Protection Law.
6.2 StoreWiz assistance
StoreWiz will provide reasonable assistance through appropriate technical and organizational measures, including:
- Self-service Customer-Personal-Data export from the Admin Console (available from Module M3);
- Self-service deletion of identifiable Customer Personal Data from the Admin Console;
- Manual assistance via
privacy@storewiz.aiwhere the self-service tools are not yet sufficient; - Where the request is forwarded by StoreWiz to a Sub-processor, coordination with that Sub-processor's response process.
6.3 Direct contact from Data Subjects
If a Data Subject contacts StoreWiz directly about Customer Personal Data, StoreWiz will (i) refer them to Customer where the Personal Data is Customer Personal Data, and (ii) promptly notify Customer of the contact.
6.4 Automated decision-making rights
Because the Services include automated decision-making (see Privacy Policy §5), the rights summarized in Privacy Policy §5.3 are exercisable through the Services and through privacy@storewiz.ai. StoreWiz will assist Customer in providing the meaningful-information disclosure that Article 22(3) GDPR contemplates, including by surfacing reasoning traces.
6.5 Time to assist
StoreWiz will provide assistance within a reasonable time to allow Customer to meet its statutory deadlines under Applicable Data Protection Law (typically within 5 business days of a written request, with longer turnaround for complex requests, with an interim acknowledgement).
7. Personal Data Breach
7.1 Notification by StoreWiz
StoreWiz will notify Customer without undue delay, and where feasible no later than 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will be made to the Customer's primary technical and security contacts on record (or, where none are designated, to the Customer's account-administrator email).
7.2 Content of notification
To the extent then known, the notification will describe:
- The nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records affected;
- The likely consequences of the breach;
- The measures taken or proposed to address the breach and to mitigate its possible adverse effects;
- A point of contact at StoreWiz for further information.
StoreWiz will supplement the initial notification with additional information as it becomes available.
7.3 No determination of obligation
A notification of, or response to, a Personal Data Breach under this §7 is not an acknowledgment by StoreWiz of fault or liability.
7.4 Assistance
StoreWiz will provide reasonable assistance to Customer in fulfilling Customer's obligation to notify supervisory authorities and affected Data Subjects under Applicable Data Protection Law.
8. Return or deletion of Customer Personal Data
8.1 End of Services
At the end of the provision of the Services (whether by termination, expiration, or completion), StoreWiz will, at Customer's choice:
- Return Customer Personal Data to Customer in a structured, commonly-used, machine-readable format; or
- Delete Customer Personal Data;
within 30 days following the end of the Services, except to the extent retention is required by Applicable Data Protection Law or where set out below.
8.2 Backups
Deletion is applied first as a soft delete (the record is marked inactive and excluded from queries). Hard deletion follows within 30 days. Backups in the Neon point-in-time recovery window (currently 14 days) may continue to contain the data until the backup ages out. We will not restore deleted data from backup; if a database restore is genuinely required within the backup window, we will re-run the deletion as soon as the restore completes.
8.3 Legally-required retention
StoreWiz may retain Customer Personal Data to the extent required by Applicable Data Protection Law or other applicable law (e.g., billing records for tax purposes). Retained Personal Data continues to be protected under this DPA.
8.4 Shopify-mandated retention
If Customer uninstalls the StoreWiz Shopify app (Module M6+), StoreWiz honors Shopify's mandatory privacy webhooks (customers/redact, shop/redact, customers/data_request) and deletes the relevant data within the timelines required by Shopify (typically 30 days).
8.5 Confirmation
On Customer's request, StoreWiz will provide written confirmation of deletion.
9. Audits and information rights
9.1 Records
StoreWiz makes available to Customer all information reasonably necessary to demonstrate compliance with this DPA, including (without limitation) summaries of relevant policies, certifications when obtained, the records of Processing required by Art. 30(2) GDPR, and the records of Sub-processor engagements.
9.2 Audit on reasonable notice
Customer may, no more than once per twelve months (unless triggered by a Personal Data Breach affecting Customer Personal Data or by a supervisory-authority order), audit StoreWiz's compliance with this DPA on at least 30 days' written notice, subject to:
- The audit being conducted during normal business hours;
- The auditor (Customer or an independent third-party auditor reasonably acceptable to StoreWiz) signing an NDA with StoreWiz;
- The scope being limited to compliance with this DPA (and not including access to source code, raw production data, or information of other tenants);
- The audit not unreasonably interfering with StoreWiz's operations or the data security of other tenants;
- Customer bearing its own audit costs unless the audit identifies a material breach of this DPA.
9.3 Reports in lieu of on-site audit
To the extent StoreWiz holds independent third-party audit reports (such as SOC 2 Type II, ISO 27001) and provides them to Customer under NDA, those reports will satisfy Customer's audit rights in respect of the matters covered. StoreWiz does not currently hold such reports and will publish a roadmap target when one is in flight.
10. International data transfers
10.1 General
StoreWiz operates primarily on US-based infrastructure. Customer Personal Data may be transferred to and Processed in the United States and other jurisdictions as required for the Services and as described in Annex III.
10.2 EU SCCs
For Restricted Transfers of Customer Personal Data from the EEA to a country not recognized by the European Commission as providing an adequate level of protection, the Parties incorporate by reference the EU Standard Contractual Clauses (Module 2: Controller-to-Processor). Where Customer is itself a Processor and StoreWiz is therefore a Sub-processor, the Parties incorporate the EU SCCs Module 3 (Processor-to-Sub-processor).
- The optional Clause 7 (docking clause) is excluded.
- The optional language in Clause 11(a) (independent dispute resolution body) is excluded; Customer's choice of independent dispute resolution body is reserved.
- Clause 17 (governing law): the law of the EU Member State that grants third-party-beneficiary rights to Data Subjects governs the SCCs (default: the law of Ireland).
[TODO[entity-pending]: confirm chosen Member State law]. - Clause 18 (forum): the courts of the EU Member State whose law governs under Clause 17 have jurisdiction.
[TODO[entity-pending]]. - Annexes I, II, III to the SCCs are populated by the Annexes to this DPA.
10.3 UK Addendum
For Restricted Transfers from the United Kingdom, the Parties incorporate the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0, in force 21 March 2022, as may be updated). Tables 1–4 of the UK Addendum are populated as follows: Table 1 — names and contact details per Annex I.A; Table 2 — the EU SCCs Module(s) as set out in §10.2; Table 3 — the Annexes to this DPA; Table 4 — both Parties may end the Addendum on the conditions in clause 19.
10.4 Swiss FADP
For Restricted Transfers from Switzerland, the EU SCCs apply with the following modifications: references to "GDPR" are read as including the Swiss FADP; references to "Member State" are read as including Switzerland; the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority for Swiss transfers.
10.5 Transfer Impact Assessment
StoreWiz has conducted a Transfer Impact Assessment ("TIA") covering its US-based Sub-processors. The TIA considers the likelihood of US public-authority access under FISA 702, EO 12333, and similar provisions, and the supplementary technical and organizational measures StoreWiz has in place. A redacted summary of the TIA is available to Customer on request to privacy@storewiz.ai.
10.6 Data Privacy Framework
[TODO[founder-decide]: confirm whether StoreWiz will certify under the EU-US Data Privacy Framework. The DPA assumes SCCs as primary mechanism until certification is in place.]
11. CCPA / CPRA specific provisions
To the extent Customer Personal Data includes "Personal Information" of California residents and StoreWiz processes that Personal Information as a "Service Provider" within the meaning of the CCPA/CPRA:
a. StoreWiz will Process such Personal Information only for the limited and specified purposes of providing the Services (a "Business Purpose" under the CCPA/CPRA);
b. StoreWiz will not "sell" or "share" the Personal Information within the meaning of the CCPA/CPRA;
c. StoreWiz will not retain, use, or disclose the Personal Information for any purpose other than the Business Purposes specified in this DPA or as permitted by Applicable Data Protection Law;
d. StoreWiz will not combine the Personal Information that StoreWiz receives from or on behalf of Customer with Personal Information that StoreWiz receives from or on behalf of another person, or that StoreWiz collects from its own interactions with consumers, except for the Business Purposes permitted by the CCPA Regulations;
e. StoreWiz will notify Customer if it can no longer meet its obligations under the CCPA/CPRA;
f. Customer may take reasonable and appropriate steps to ensure StoreWiz uses the Personal Information consistent with Customer's obligations under the CCPA/CPRA, and to stop and remediate unauthorized use.
12. AI Sub-processor specific provisions
Because the Services include automated decision-making and forward sanitized prompts to AI providers, the following additional provisions apply:
a. No model training on Customer Personal Data. StoreWiz will not use Customer Personal Data to train, fine-tune, or otherwise adapt the weights of any foundation model. StoreWiz contractually requires the same restriction from its AI Sub-processors (Anthropic via Vercel AI Gateway BYOK).
b. Honest disclosure on retention. Anthropic, under standard paid-API terms, retains API content for approximately 30 days for abuse and safety review, then deletes it. Zero Data Retention ("ZDR") is not currently provisioned. StoreWiz will evaluate provisioning ZDR with Anthropic as real tenant data starts flowing (Modules M2/M3) and will update this DPA when the configuration changes.
c. Cross-tenant pattern learning. StoreWiz may derive statistical patterns from outcomes across many tenants, subject to k-anonymity ≥ 10 and no PII (see Privacy Policy §6.4). Customer may opt the tenant out of contributing to cross-tenant patterns from the Admin Console.
d. Reasoning trace access. StoreWiz stores reasoning traces sufficient to provide meaningful information about automated-decision logic under Art. 22(3) GDPR / Law 25 Art. 12.1. Reasoning traces are accessible to Customer via the Admin Console (from Module M3) and on request to privacy@storewiz.ai.
e. Sanitization. Customer-provided and Customer-customer-provided content (emails, reviews, support tickets, social DMs) is sanitized before being forwarded to AI Sub-processors.
f. Tool whitelisting and scope enforcement. Agents are scope-limited via tool whitelists; out-of-scope tool calls are blocked and logged.
13. Liability
The Parties' liability under this DPA is governed by, and limited in accordance with, the limitations of liability set out in the Terms of Service (including the aggregate cap), subject to any provisions of Applicable Data Protection Law that cannot be excluded by contract. To the extent the EU SCCs apply, nothing in this section limits a Data Subject's rights as third-party beneficiary under the SCCs.
14. Term, termination, and survival
This DPA is effective for the duration of the Services and any further period during which StoreWiz Processes Customer Personal Data. The provisions intended to survive termination (including §6 (assistance with Data Subject rights), §7 (breach notification for Processing that occurred during the term), §8 (return / deletion), §9 (audits), §10 (transfers, for transfers occurring during the term), §11 (CCPA/CPRA), §12 (AI sub-processors), §13 (liability)) survive.
15. General
15.1 Order of precedence
In case of conflict between this DPA and the Terms of Service in respect of Personal Data Processing, this DPA prevails. In case of conflict between this DPA and the EU SCCs (where they apply), the EU SCCs prevail to the extent of the conflict.
15.2 Notices
Notices under this DPA may be sent to: Customer — the email address on the account; StoreWiz — privacy@storewiz.ai with a copy to legal@storewiz.ai.
15.3 Amendments
We may update this DPA from time to time to reflect changes in Applicable Data Protection Law, changes to our Sub-processor list, or otherwise. For material changes, we will give at least 30 days' advance notice in the Admin Console and by email. If Customer reasonably objects to a material change on data-protection grounds, the Parties will work together to resolve; failing resolution, Customer may terminate the affected Services for cause and receive a pro-rata refund.
15.4 Severability
If any provision of this DPA is held unenforceable, the rest remains in effect and the unenforceable provision will be reformed to the minimum extent necessary to make it enforceable.
15.5 Counterparts and electronic acceptance
This DPA may be executed in counterparts and by electronic means.
16. Governing law
This DPA is governed by, and construed in accordance with, the law governing the Terms of Service, except that (a) the EU SCCs, UK Addendum, and Swiss supplement are governed by the laws stated within them; (b) Applicable Data Protection Law continues to apply on a mandatory basis. [TODO[entity-pending]: governing law of the main agreement].
17. Acceptance
This DPA is deemed accepted by Customer on the earlier of:
a. Customer's affirmative acceptance via the in-product flow at Settings → Privacy → Data Processing Addendum (available from Module M3); or
b. Customer's continued use of the Services after StoreWiz has notified Customer of this DPA being available; or
c. Execution of a counterpart of this DPA by both Parties (e.g., signed PDF returned to legal@storewiz.ai).
Electronic acceptance creates an auditable record including timestamp and IP address.
Annex I — Description of Processing
I.A — List of Parties
Data Exporter (Controller, except where Customer is itself a Processor as Sub-processor under §2.2):
- Name: the Customer entity that has agreed to the Terms of Service and this DPA.
- Address: as set out in the Customer's account.
- Contact for data-protection matters: as set out in the Customer's account.
- Activities relevant to the data transferred: subscription to the StoreWiz Services for the operation of the Customer's e-commerce store.
Data Importer (Processor):
- Name: StoreWiz (operating entity in formation; see banner at the top of this DPA).
- Address:
[TODO[entity-pending]: registered office address]. - Contact for data-protection matters:
privacy@storewiz.ai/dpo@storewiz.ai. - Activities relevant to the data transferred: provision of the StoreWiz Services (autonomous AI platform that operates the Customer's e-commerce store).
I.B — Description of Processing
| Topic | Detail |
|---|---|
| Categories of Data Subjects | (i) Customer's customers; (ii) Customer's prospective customers / leads; (iii) Customer's employees and authorized users; (iv) Customer's suppliers, vendors, and partners; (v) other Data Subjects whose Personal Data Customer connects to StoreWiz |
| Categories of Personal Data | See Privacy Policy §3 (Identifiers; contact details; order and transaction data; product and inventory; communications (emails, support tickets, reviews, social posts); marketing data; financial signals; usage data; device and connection data) |
| Special Category data (Art. 9 GDPR) | Not Processed as part of normal operations |
| Frequency of transfer | Continuous (real-time and batched), throughout the duration of the Services |
| Nature of the Processing | Storage; retrieval; analysis by AI agents; generation of Proposals; execution of approved Proposals against third-party platforms; reporting to Customer; safety and abuse review; backup; deletion |
| Purpose of the Processing | Provision of the StoreWiz Services as described in the Terms of Service and Privacy Policy |
| Period of retention | As set out in Privacy Policy §8 and §8 of this DPA |
| For transfers to Sub-processors | Subject matter, nature, duration of Processing as set out in Annex III |
I.C — Competent supervisory authority
For EU transfers under the EU SCCs: [TODO[entity-pending]: confirm chosen supervisory authority based on EU representative location — typically the supervisory authority of the EU representative's Member State, default Ireland]. For UK transfers under the UK Addendum: the UK Information Commissioner's Office. For Swiss transfers: the Federal Data Protection and Information Commissioner (FDPIC).
Annex II — Technical and organizational measures (TOMs)
This Annex describes the technical and organizational measures implemented by StoreWiz to ensure the security of Customer Personal Data appropriate to the risk (Art. 32 GDPR).
II.1 — Access control to premises and systems
- Cloud-hosted infrastructure with Sub-processors (Vercel, Neon, others) operating physical-access controls at their data centers (see Sub-processor security documentation referenced in Annex III).
- StoreWiz personnel access to production systems is restricted via SSO, MFA, and least-privilege role-based access controls. Quarterly access reviews are performed (as the team scales beyond solo-founder operation).
II.2 — Authentication and identity
- Multi-factor authentication for all administrative accounts.
- OAuth-based authentication for third-party platform integrations (Shopify, Klaviyo, Meta, Google, Plaid, support tools).
- Session management via Clerk (from Module M2) with short-lived sessions and secure session cookies.
II.3 — Encryption
- TLS 1.2 or higher for all external transport.
- AES-256 encryption at rest for the Neon database (per Neon's documentation).
- Application-layer encryption (AES-256-GCM) for sensitive at-rest secrets (OAuth tokens, credentials).
II.4 — Tenant isolation (defense in depth)
- Row-Level Security (RLS) at the database layer: every query against a tenant-scoped table is filtered by the verified tenant identity. RLS is the last line of defense — even an application-code bug cannot read cross-tenant.
- Application-layer scoped query wrapper that enforces tenant_id on all queries to tenant-scoped tables; lint rules block raw queries against those tables.
- Per-request tenant context that is set from the verified session before any query; throws if missing.
- Cross-tenant attack test suite that runs in CI on every code change.
- Recall-layer scoping (memsearch / vector queries) tenant-scoped via the same RLS.
II.5 — AI safety controls
- Input sanitization on user-provided content before forwarding to AI models.
- Structural prompt boundaries with explicit "untrusted user content" labeling.
- Output schema validation (BAML) that rejects out-of-shape or instruction-emitting responses.
- Per-agent tool whitelists; out-of-whitelist tool calls are blocked and logged.
- Confidence-threshold gating on sensitive actions; below-threshold actions escalate to human approval.
- Conversation drift detection on Wizzy chat.
- Step and token budget enforcement (max-step / max-token per agent tier) to prevent runaway thinking.
II.6 — Logging and monitoring
- Server-side error and performance monitoring via Sentry, with PII-scrubbing rules applied at capture.
- Internal safety audit log capturing guardrail trips (cross-tenant attack attempts, prompt-injection signals, scope violations, confidence-threshold escalations, hallucination-verification failures, step-budget exceeded events).
- Per-tenant tagging for cost, error rates, and other operational metrics.
- Synthetic uptime monitoring via Sentry uptime checks.
II.7 — Backup and recovery
- Neon point-in-time recovery (PITR) backups with a 14-day window.
- Backup data is encrypted and isolated.
- Disaster-recovery procedures are documented and tested at least annually as the team scales.
II.8 — Personnel
- Confidentiality and acceptable-use commitments from all personnel.
- Background checks for personnel with privileged access (as the team scales beyond solo-founder operation).
- Security-awareness training (as the team scales beyond solo-founder operation).
II.9 — Vendor management
- Sub-processors are engaged under written contracts with data-protection obligations no less protective than this DPA.
- Sub-processor security posture is reviewed before engagement and on material change.
II.10 — Incident response
- Internal incident response runbook covering detection, containment, eradication, recovery, and post-incident review.
- Personal Data Breach notification per §7 of this DPA.
II.11 — Continuous improvement
- We acknowledge the following limits and will close them under documented timelines:
- SOC 2 Type I: aspirational, targeted post-MVP launch.
- SOC 2 Type II: aspirational, targeted ~12 months after Type I.
- ISO 27001: post-MVP consideration.
- Pen-testing: commissioned as we approach SOC 2 Type I readiness and at least annually thereafter.
- Bug-bounty program: under evaluation; until launched, good-faith security research is welcomed under AUP §7.
II.12 — Encryption-in-transit between Sub-processors
Where Sub-processors transmit Customer Personal Data among themselves to provide the Services, the transmission is over TLS-encrypted channels.
Annex III — List of Sub-processors
The current list of authorized Sub-processors is maintained at storewiz.ai/legal/sub-processors. As of the date of this DPA:
| # | Sub-processor | Role | Region / data residency | DPA URL | Status |
|---|---|---|---|---|---|
| 1 | Vercel Inc. | Application hosting, CDN, Edge runtime, server-side logs | US / EU configurable from M2+ | https://vercel.com/legal/dpa | Active |
| 2 | Vercel Inc. (AI Gateway) | Routing of AI model calls (LLM, embeddings, image, video, voice) | US / global | https://vercel.com/legal/dpa + https://vercel.com/legal/ai-product-terms | Active |
| 3 | Anthropic, PBC (engaged via Vercel AI Gateway BYOK) | LLM provider for Wizzy + 17 specialist agents | US (~30-day standard abuse-review retention; ZDR not currently provisioned) | https://www.anthropic.com/legal/commercial-terms | Active |
| 4 | Neon Inc. | Primary Postgres database (tenant data, embeddings, PITR backups) | US default / EU configurable from M2+ | https://neon.com/dpa | Active |
| 5 | Upstash, Inc. | Redis cache and rate-limiting | Global edge (US/EU primary) | https://upstash.com/static/trust/dpa.pdf | Active |
| 6 | Inngest, Inc. | Durable background-job execution, event bus, webhook intake, cron | US (AWS + GCP) | https://www.inngest.com/security (DPA available on request) | Active |
| 7 | Functional Software, Inc. (Sentry) | Error and performance monitoring, uptime | US (EU optional) | https://sentry.io/legal/dpa/ | Active |
| 8 | Atlassian Pty Ltd. (Statuspage via Dogwood Labs, Inc.) | Public status page | US | https://www.atlassian.com/legal/data-processing-addendum | Active |
| 9 | Clerk Inc. | Authentication, session management, OAuth helper, organization management, 2FA | US (EU on Enterprise) | https://clerk.com/legal/dpa | Available from M2 |
| 10 | Resend, Inc. | Transactional email delivery | US | https://resend.com/legal/dpa | Available from M2 |
| 11 | Sold through Link, LLC (d/b/a Lemon Squeezy) | Merchant of Record for billing, invoicing, tax | US (processes globally) | https://www.lemonsqueezy.com/dpa | Available from M2 |
| 12 | Shopify Inc. | Source platform for Customer's e-commerce store data (read-only from M1 Free Audit; full integration from M6) | Shopify-hosted | https://www.shopify.com/legal/dpa | Available from M6 (read-only from M1) |
| 13 | Intuition Machines, Inc. (hCaptcha) | Anti-bot challenges on public forms | US (EU edge) | https://newassets.hcaptcha.com/dpa/IMI_Data_Processing_Addendum_4.20.2023.pdf | Active on public forms |
Sub-processors marked "Available from MN" are not currently engaged. We will not engage them until the relevant module launches, and we will follow the 30-day notice procedure under §5.3 (or rely on the fact that this Annex III pre-discloses them, at our option).
Contact. Privacy: privacy@storewiz.ai. DPO matters: dpo@storewiz.ai. Legal: legal@storewiz.ai.