Data Processing Agreement
Last updated: June 24, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Telltale AI Ltd. Co. ("Telltale", "Processor") and the merchant that installs or uses Telltale ("Merchant", "Controller"). It governs Telltale's processing of personal data on the Merchant's behalf.
1. Roles
The Merchant is the Controller of its customers' personal data. Telltale is the Processor, processing such data only to provide the service and only on the Merchant's documented instructions (including via the Merchant's use of the service and connected integrations).
2. Scope and purpose of processing
- Subject matter: provision of retention analytics and campaign generation.
- Duration: for the term of the Merchant's use of Telltale, plus deletion windows in §8.
- Nature/purpose: ingesting commerce data, computing retention analytics, building campaign audiences, pushing audiences to the Merchant's connected email/SMS provider, and measuring performance.
- Categories of data subjects: the Merchant's customers and prospective customers.
- Categories of personal data: name; email; phone; shipping address (city, region, ZIP); order history and totals; fulfillment/shipping events; abandoned checkouts; product interest; email/SMS engagement events from connected providers; and, where the Merchant enables Telltale's Shopify Web Pixel, consent-gated on-site behavioral events (pages/products viewed, on-site searches, cart events, dwell time) tied to a first-party visitor identifier. No special-category data; no payment card numbers; no raw IP addresses stored.
3. Processor obligations
Telltale will: (a) process personal data only on the Controller's instructions; (b) ensure persons authorized to process it are bound by confidentiality; (c) implement the technical and organizational security measures in Annex A; (d) respect the conditions in §4 for engaging sub-processors; (e) assist the Controller, taking into account the nature of processing, in responding to data subject requests and in meeting security, breach-notification, and data-protection-impact-assessment obligations; (f) at the Controller's choice, delete or return personal data at the end of the service (§8); and (g) make available information necessary to demonstrate compliance and allow for reasonable audits.
4. Sub-processors
The Controller authorizes Telltale to engage the sub-processors listed at telltale.pro/pages/subprocessors, including the Merchant's own connected email/SMS providers. Telltale will impose data-protection terms on each sub-processor no less protective than this DPA and remains responsible for their performance. Telltale will give notice of intended changes and the Controller may object on reasonable data-protection grounds.
5. Data subject rights
Telltale will, to the extent the Controller cannot do so through the service, assist the Controller in fulfilling data subject requests. Telltale implements Shopify's customers/data_request (export) and customers/redact (erasure) flows so the Merchant can satisfy access and deletion requests.
6. Security
Telltale implements the measures in Annex A, including encryption in transit and at rest, access controls with audit logging, environment separation, encrypted backups, and incident response.
7. Personal data breach
Telltale will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, with the information reasonably available to help the Controller meet its obligations.
8. Deletion / return
On customers/redact Telltale erases the identified customer's data. On uninstall, Shopify sends shop/redact ~48h later and Telltale erases the Merchant's data across its systems. The Merchant may also request deletion by contacting owl@telltale.pro.
9. International transfers
Where the DPA covers transfers of EEA/UK/Swiss personal data to the United States or other countries, the parties agree the applicable Standard Contractual Clauses (and UK/Swiss addenda) are incorporated by reference, with Telltale as "data importer".
10. General
This DPA prevails over conflicting terms regarding processing of personal data. Governing law and liability follow the main agreement; governing law: State of Utah, United States.
Annex A — Technical & organizational measures
- Encryption in transit: TLS for all connections; database connections require SSL.
- Encryption at rest: database and object storage encrypted at rest; field-level AES encryption of stored customer email and phone; OAuth/provider credentials stored encrypted (AES). Emails are additionally salted-SHA-256 hashed for matching; plaintext customer email is not retained where a hash suffices.
- Access control: least-privilege staff access to production data; authentication via an identity provider; access to protected customer data is limited and logged.
- Environment separation: test/development data is kept separate from production.
- Backups: backups are encrypted.
- Resilience & monitoring: error monitoring with PII scrubbing; data-loss prevention controls.
- Incident response: documented security incident-response process with defined roles and merchant-notification steps.
- Data minimization & retention: only the minimum Shopify scopes are requested; data is retained only as long as needed and deleted per §8; raw webhook payloads are pruned on a rolling 90-day schedule; raw on-site behavioral events (Web Pixel) are retained for up to 90 days, after which only derived aggregate browsing signals persist.