Data Processing Addendum
This Addendum governs how Seny processes personal data on your behalf when you install the app. It takes effect on installation.
Effective on installation of the Seny app. Version 1.0 — September 8, 2026. Questions? support@seny.app
Home/DPA
Introduction
This Addendum forms part of the agreement between MB Klero ("Processor", "we") and the merchant installing Seny ("Controller", "you"). Where it conflicts with the Terms of Service, this Addendum governs for personal data.
Definitions
"Personal Data", "processing", "controller", "processor", "data subject" and "supervisory authority" carry the meanings given in the EU General Data Protection Regulation (2016/679) ("GDPR"). "Data Protection Law" means the GDPR, the UK GDPR, the Swiss FADP, the California Consumer Privacy Act as amended ("CCPA"), and any other law applicable to processing under this Addendum.
Roles
You are the controller of personal data relating to your customers and store visitors. We process it only as your processor. You are responsible for having a lawful basis for the processing you instruct, and for the notices and consents your storefront gives.
For CCPA purposes we are a "service provider". We do not sell or share personal data, and we do not retain, use or disclose it for any purpose other than performing the services.
Subject matter, duration, nature and purpose
Subject matter: provision of the Seny app. Duration: while the app is installed, plus the retention periods in Section 8. Nature and purpose: generating and running storefront features, attributing revenue to them, and reporting their performance.
Categories of data subjects: your customers and store visitors; your staff who use the app.
Categories of personal data:
| Category | Detail |
|---|---|
| Order data | Amounts, line items, discounts, cart attributes, Shopify order id |
| Customer identifiers | First name and city/region — only if you enable sales notifications; held in memory for up to 5 minutes, never stored |
| Online identifiers | A pseudonymous session identifier and page path, collected only with the visitor's consent |
| Shopper submissions | Whatever your app's forms collect (e.g. email, review text) |
| Staff data | Name and email from Shopify OAuth |
No special categories of data under Article 9 GDPR are processed.
Our obligations
We will:
- a. process personal data only on your documented instructions, which this Addendum, the Terms and your use of the app constitute — including for international transfers — unless required otherwise by law, in which case we will tell you first unless the law forbids it;
- b. ensure everyone authorised to process it is under a duty of confidentiality;
- c. implement the technical and organisational measures in Annex A;
- d. respect the conditions in Section 5 for engaging subprocessors;
- e. assist you, by appropriate measures and taking account of the nature of the processing, in responding to data subject requests (Section 6);
- f. assist you with security, breach notification, data protection impact assessments and prior consultation, taking account of the information available to us;
- g. delete or return personal data at the end of the services (Section 8);
- h. make available the information needed to demonstrate compliance and allow for audits (Section 9).
Subprocessors
You give general authorisation for the subprocessors in Annex B. We impose data protection obligations on each of them no less protective than this Addendum, and remain fully liable for their performance.
We will give at least 30 days' notice before adding or replacing a subprocessor, by email to your account address and in the app. You may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, you may terminate the affected services without penalty.
Data subject requests
Shopify's customers/data_request and customers/redact webhooks are honoured automatically: a redaction request anonymises the shopper's identity in data we hold while preserving content that belongs to you, such as a published review's rating and text.
If a data subject contacts us directly we will refer them to you and not respond substantively, except to confirm the referral. We will assist you with any request you cannot fulfil yourself.
Personal data breach
We will notify you without undue delay and no later than 48 hours after becoming aware of a personal data breach affecting your personal data, with the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken. We will not notify a supervisory authority or data subjects on your behalf unless you instruct us to.
Retention and deletion
We apply these periods automatically:
| Data | Period |
|---|---|
| Storefront analytics events | 395 days from collection |
| Session identifiers within attributed orders | Removed after 395 days; financial amounts retained |
| Staff sessions | Deleted 7 days after expiry |
| Shopper submissions | Retained while the relevant feature exists |
On uninstall, Shopify sends a shop/redact request and we delete your apps, files, builder history, analytics and shopper submissions. Billing records are retained as accounting records, stripped of shop identity. You may request earlier deletion at any time.
Audit
On reasonable written notice, and no more than once a year unless a supervisory authority or a breach requires otherwise, we will make available the information necessary to demonstrate compliance with this Addendum, and will cooperate with audits conducted by you or an independent auditor you appoint, subject to confidentiality and our other customers' security.
International transfers
Personal data is hosted in the United States. We are established in Lithuania, so processing under this Addendum involves a transfer outside the European Economic Area, as do our other subprocessors in Annex B. Each such transfer is made under an adequacy decision or the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor) where applicable, which are incorporated here by reference with Annexes A and B supplying their Annexes I–III and the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) as the competent supervisory authority.
Liability
Each party's liability under this Addendum is subject to the limitations in the Terms of Service, except where Data Protection Law does not permit that limitation.
Annex A — Technical and organisational measures
Encryption. TLS 1.2 or higher for all data in transit, including to Shopify and every subprocessor. Database backups are encrypted with GPG in the pipe, so an unencrypted copy is never written to disk. The database volume is encrypted at rest.
Access control. The database is on a private network with no public ports. Production access is limited to personnel who require it, over authenticated channels. Shopify access tokens are held only for as long as the app is installed and are erased on uninstall.
Integrity. All Shopify webhooks are HMAC-verified before processing. Internal scheduled endpoints are protected by constant-time secret comparison. Generated storefront code is scanned against a safety contract that forbids eval, injected external scripts, and cookies.
Resilience. Nightly encrypted database backups with 14-day rotation, and a documented restore procedure.
Data minimisation by design. Order queries request money and attribution fields only. Customer name and location are fetched only when the merchant enables that feature, are held in memory for at most five minutes, and are never persisted. Storefront analytics do not use cookies and do not record IP addresses or user agents.
Consent. Storefront analytics are gated on Shopify's Customer Privacy API: no transmission and no identifier creation before consent is confirmed for that visitor.
Deletion. Automated retention sweeps run daily; Shopify erasure webhooks are honoured automatically.
Annex B — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Shopify Inc. | Platform and data source | Global |
| Hostinger | Application servers and database | United States (Boston) |
| Cloudflare, Inc. | CDN, TLS termination, edge caching | Global |
| Anthropic PBC | Code generation. No shopper or order data | United States |
| OpenAI, L.L.C. | Code generation. No shopper or order data | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | United States |
Our in-app feedback and roadmap tool, Klero, is operated by MB Klero itself and is therefore not a subprocessor.
MB Klero — V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania — support@seny.app
Accepted by the Controller on installation of the Seny app.