Legal
Data Processing Addendum
Effective 8 September 2026.
This Addendum forms part of the Terms of Service between the merchant ("Controller") and Siddesh Patil ("Processor"). It applies where the Processor processes personal data on the Controller's behalf, and gives effect to Article 28 of the UK and EU GDPR. It takes effect on installation; no signature is required, though we will countersign a copy on request to siddesh@citelift.app.
1. Roles
The Controller determines the purposes and means of processing personal data in its Shopify store. The Processor processes that data only to provide the service. Where the Processor decides purposes of its own — its own marketing, its own billing records — it acts as an independent controller under its Privacy Policy, and this Addendum does not apply.
2. Processing on documented instructions (Art. 28(3)(a))
The Processor processes personal data only on the Controller's documented instructions, which comprise this Addendum, the Terms, and the settings the Controller configures in the app. The Processor will tell the Controller if an instruction appears to infringe data protection law, and will not process data for its own purposes or to train its own models.
Personal data is not used to train any model. Every large language model call is made through OpenRouter as our contracting party; the editorial and video-relevance judgments described on the Subprocessors page are made by TypeSafe, which we contract with directly. Requests to Claude — article generation and the quality gates — are served by the endpoint OpenRouter selects for that model, which may be Anthropic itself or a cloud host of the same model such as Google Vertex AI or Amazon Bedrock; the AI-visibility probes reach the ChatGPT models on purpose, because measuring what that assistant answers is what the probe is for. Every request carries our instruction that the provider must not collect the data. OpenRouter's training on paid endpoints is disabled on our account.
Zero-data-retention routing is not yet enabled on that account. We would rather say so than claim a control we have not turned on. When it is enabled, this paragraph will say so and give the date it was turned on. Any vendor reached directly is used under its no-training API terms.
3. Confidentiality (Art. 28(3)(b))
Everyone the Processor authorises to process the data is bound by a written duty of confidentiality that survives the end of their engagement.
4. Security (Art. 28(3)(c), Art. 32)
The Processor implements the technical and organisational measures in Annex II, and will not reduce them below that standard.
5. Subprocessors (Art. 28(2), 28(3)(d))
The Controller gives general authorisation for the subprocessors listed at /subprocessors. The Processor will give at least 30 days' notice before adding or replacing one, by updating that page and emailing the Controller. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected part of the service and receive a pro-rata refund.
Each subprocessor is engaged under a written contract imposing obligations no less protective than this Addendum, and the Processor remains liable for their performance.
6. Data subject rights (Art. 28(3)(e))
Taking into account the nature of the processing, the Processor assists the Controller with requests from data subjects. In practice: Shopify's customers/data_request, customers/redact and shop/redact webhooks are implemented and acted on automatically, and each is recorded in an audit log the Controller may request. Because no customer names, emails, phone numbers or addresses are stored, a data request usually resolves as "no personal data held".
7. Assistance with Articles 32–36 (Art. 28(3)(f))
The Processor assists the Controller with security, breach notification, data protection impact assessments and prior consultation, to the extent the information is available to the Processor.
8. Personal data breach
The Processor notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data, with the nature of the breach, the categories and approximate number of records, the likely consequences, and the measures taken.
9. Deletion or return (Art. 28(3)(g))
On uninstall, the Processor erases the Controller's data within 30 days, which is the period Shopify requires. Reinstalling inside that window cancels the erasure. The Controller may ask for erasure at any time in the app's settings or through Shopify's shop/redact webhook, and that is carried out immediately. Articles already published remain on the Controller's own store and are unaffected. Backups age out on their own cycle, within 35 days.
10. Audit (Art. 28(3)(h))
The Processor makes available the information needed to demonstrate compliance and allows audits by the Controller or an auditor it mandates, on 30 days' notice, no more than once a year (or after a breach), during business hours, subject to confidentiality, and without access to other customers' data. Where a current third-party report or questionnaire answers the question, the Processor may provide that instead.
11. International transfers
Where the Processor transfers personal data out of the UK or EEA, the transfer is made under the European Commission's Standard Contractual Clauses (2021/914), Module Two (controller to processor), with the Controller as data exporter and the Processor as data importer, and for UK transfers the UK International Data Transfer Addendum (IDTA) version B1.0 to those Clauses. The Swiss FADP amendments apply where Swiss law governs the transfer. Docking clause 7 applies. The annexes below serve as Annexes I and II to those Clauses.
12. Liability and precedence
The liability limits in the Terms apply to this Addendum. Where this Addendum conflicts with the Terms on data protection, this Addendum prevails; where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
Annex I — Details of processing
| Subject matter | Provision of the Citelift app: planning, generating and publishing articles to the Controller's Shopify blog, and attributing orders to them |
| Duration | For as long as the app is installed, plus the retention periods in the Privacy Policy |
| Nature and purpose | Collection, storage, structuring, use, transmission and erasure, to generate content and produce attribution and visibility reporting |
| Categories of data subject | The Controller's staff who use the app; the Controller's customers, to the limited extent below |
| Categories of personal data | Store and account identifiers (shop domain, staff email held by Shopify's session, access tokens). Order journey fields: order id, total, currency, landing page, referrer, UTM parameters. No customer name, email address, telephone number or postal address is read or stored. |
| Special category data | None. The Controller must not configure the app to process it |
| Frequency | Continuous, driven by Shopify webhooks and scheduled jobs |
| Retention | As stated in the Privacy Policy: order journey fields 90 days; visibility runs 180 days; everything for an uninstalled store erased 30 days after uninstall |
| Competent supervisory authority | That of the Controller's own establishment |
Annex II — Technical and organisational security measures
- Encryption at rest. All application data is stored in Neon Postgres, encrypted at rest with AES-256.
- Application-layer encryption. Shopify access tokens and Google refresh tokens are additionally encrypted with AES-256-GCM using a key held only in the runtime environment, so a database copy alone does not yield a usable credential.
- Encryption in transit. TLS 1.2 or better on every connection — browser, Shopify, database and every subprocessor API.
- Access control. Production access is limited to named personnel through the Vercel and Neon consoles, each requiring two-factor authentication. There is no shared administrative account and no direct database access from developer machines. Access is reviewed when anyone joins or leaves.
- Secrets management. Secrets live in the hosting platform's encrypted environment store, never in the repository. Keys are rotatable without downtime through a documented dual-key procedure.
- Logging and redaction. Application logs are written through a logging helper that masks secret-shaped keys —
token,secret,key,password,authorization— at any depth of a payload, so a credential is not written to an application log. - Tenant isolation. Every query is scoped by store; no cross-store read path exists in the application.
- Data minimisation. The app requests Shopify protected customer data at Level 1 only and reads order journey fields; customer identity fields are never requested.
- Webhook authenticity. Every inbound webhook is HMAC-verified before it is acted on.
- Automated erasure. A nightly job enforces every published retention period and records what it deleted.
- Backups. Encrypted daily database backups, retained 30 days, with a tested restore: the backup was restored into an isolated database on 7 September 2026 and the restored schema and row counts were checked against live. In addition, point-in-time recovery as configured by our database provider.
- Vulnerability management. Dependencies are monitored and patched; the application is built and deployed from version control with no manual edits in production.
- Incident response. A documented procedure with a 72-hour controller notification commitment (clause 8).
Annex III — Subprocessors
See /subprocessors, which forms part of this Addendum.