Skip to content

Data Processing Addendum (DPA)

Version 2026-08-18 — this version applies from 18 August 2026.

This Data Processing Addendum under Art. 28 GDPR governs the processing of personal data that AIProCraft carries out on behalf of its customers (the “controller”) when providing services that analyse data from connected store systems — currently the Revenue Recovery service for Shopify stores. It applies in addition to our Terms; in case of conflict regarding commissioned processing, this Addendum prevails. The Addendum is concluded electronically: before a store is connected, the controller accepts this Addendum through the dedicated function in the customer portal; the acceptance is recorded server-side with account, accepting user, timestamp, and Addendum version. The German version is authoritative; translations are provided for convenience.

Parties and roles

The customer using the service is the controller within the meaning of Art. 4(7) GDPR. M. Amin Sayegh, trading as AIProCraft, Paul-Bertz-Str. 38, 09120 Chemnitz, Germany, is the processor within the meaning of Art. 4(8) GDPR. The processor processes the personal data covered by this Addendum exclusively on behalf of and for the purposes of the controller.

Subject matter and duration

The subject matter of the processing is the analysis of commerce data from the controller's connected store systems to identify revenue-leakage patterns and provide evidence-backed findings (Revenue Recovery). Processing begins when a store is connected and ends when the connection is disconnected or the app is uninstalled; remaining derived results are deleted under the periods set out in the section “Deletion and return”.

Nature and purpose of the processing

Read-only retrieval of commerce data via the store platform's API (for Shopify: scopes read_products, read_orders, read_all_orders), transient in-memory analysis of this data by detection logic, and storage of derived scan results and findings. No data is written back to the store system; personal data is not used for advertising, for profiling of data subjects, or for any purpose other than providing the service to the controller.

Categories of personal data

Order, refund and fulfilment records retrieved from the connected store: order identifiers, dates, amounts, discount codes, line items, and the platform's internal customer reference number. Customer names, email addresses, telephone numbers, and postal addresses are not retrieved. Persisted derived results contain at most order/refund reference identifiers as evidence.

Categories of data subjects

Customers (buyers) of the controller's store whose orders are contained in the retrieved commerce data.

Documented instructions

The processor processes personal data only on documented instructions from the controller — including with regard to transfers of personal data to a third country or an international organisation — unless required to do so by Union or Member State law to which the processor is subject; in that case, the processor informs the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a) GDPR). Connecting a store, triggering or scheduling scans, disconnecting the connection, and uninstalling the app constitute instructions given through the service; further instructions may be given in text form. The processor informs the controller without undue delay if, in its opinion, an instruction infringes applicable data protection law.

Confidentiality

Persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).

Technical and organisational measures (Art. 32 GDPR)

Transport encryption (HTTPS/TLS) for all connections to the store platform, the application, and the database infrastructure; encrypted storage on the database infrastructure; additional application-level AES-256-GCM encryption of store access credentials with a separately managed key; strict tenant isolation via database row-level security; exclusively server-side processing with least-privilege access boundaries; no persistence of raw order or customer records; automatic deletion under fixed retention periods. The measures are kept up to date with the state of the art without falling below the agreed level of protection.

Subprocessors

The controller grants general authorisation for the subprocessors used to operate the service; the subprocessors currently engaged are listed in the section “Subprocessor register”. The processor announces intended additions or replacements at least 30 days before they take effect, in text form (by email to the address registered for the account), and updates the register on this page, so the controller can object on justified grounds (Art. 28(2) GDPR). The processor imposes on each subprocessor, by way of a contract, the same data protection obligations as set out in this Addendum, in particular providing sufficient guarantees to implement appropriate technical and organisational measures; where a subprocessor fails to fulfil its data protection obligations, the processor remains fully liable to the controller for the performance of that subprocessor's obligations (Art. 28(4) GDPR).

Subprocessor register

As of 18 August 2026, the following subprocessors are engaged for the Revenue Recovery service:

SubprocessorFunctionProcessing locationTransfer basis
SupabaseDatabase and authentication infrastructure; storage of the persisted Revenue Recovery dataAWS region eu-central-1 (Frankfurt, Germany)Supabase Data Processing Addendum (incorporated into its terms of service), including the EU Standard Contractual Clauses where applicable
VercelApplication hosting and server-side processing (serverless functions)currently includes the region iad1 (USA)Vercel Pro Data Processing Addendum including the EU Standard Contractual Clauses (2021)

Assistance with data-subject rights

Taking into account the nature of the processing, the processor assists the controller with appropriate technical and organisational measures in responding to requests from data subjects (Art. 12–23 GDPR). For Shopify stores, deletion and access requests forwarded through Shopify's privacy webhooks (customers/data_request, customers/redact, shop/redact) are processed automatically.

Deletion and return

Raw order and customer records are not stored and therefore require no deletion or return. The free returns cost check additionally stores no result — neither scan results nor findings — so there is nothing to delete or return for it; the retention periods below apply only to the derived results of Product Intelligence checks and Revenue Recovery scans. Derived scan results are deleted automatically: scan history after 180 days at the latest; findings no longer confirmed by newer scans after 90 days at the latest; after disconnection or uninstallation, all remaining results after 30 days at the latest, with encrypted access credentials removed immediately. After the end of the provision of the processing services, the processor will — at the choice of the controller — either delete the personal data still stored (the derived scan results and findings) or return it to the controller in a common, machine-readable format and then delete existing copies, unless Union or Member State law requires further storage (Art. 28(3)(g) GDPR). If the controller does not exercise this choice within the periods stated above, the data is deleted.

Information and audit rights

The processor makes available to the controller all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits — including inspections — conducted by the controller or an auditor mandated by the controller, at reasonable intervals and upon reasonable notice (Art. 28(3)(h) GDPR).

Personal data breaches

The processor notifies the controller without undue delay after becoming aware of a personal data breach concerning the commissioned processing and assists the controller in complying with Art. 33 and 34 GDPR, taking into account the nature of the processing and the information available to the processor.

Assistance of the controller (Art. 32–36 GDPR)

Taking into account the nature of the processing and the information available to it, the processor assists the controller in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR (Art. 28(3)(f) GDPR): with the security of processing (Art. 32), with the notification and communication obligations for personal data breaches (Art. 33 and 34 — see the section “Personal data breaches”), with data protection impact assessments (Art. 35), and with prior consultation of the supervisory authority (Art. 36), in particular by providing the information described in this Addendum about the nature, scope, and security measures of the processing.

International transfers

Processing takes place within the infrastructure of the providers listed in the subprocessor register. Persistent storage of the Revenue Recovery data takes place with Supabase in the AWS region eu-central-1 (Frankfurt, Germany). Server-side processing by the application runs on Vercel's infrastructure and currently includes the region iad1 (USA); to that extent a transfer to a third country takes place, based on the Vercel Pro Data Processing Addendum including the EU Standard Contractual Clauses (2021). Beyond that, personal data is transferred to a third country only where the requirements of Chapter V GDPR are met, in particular on the basis of an adequacy decision or standard contractual clauses.

Responsibilities of the controller

The controller is responsible for the lawfulness of the processing, for informing its own customers, and for an appropriate legal basis for the store data made accessible to the processor. The controller connects only stores it is entitled to connect.