This DPA takes effect for a merchant when incorporated into the Master Services Agreement at installation.
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Master Services Agreement ("MSA") between the parties. It governs the Processing of Shopper Personal Data by OBSESSION ECOMMERCE DATA TOOLS LTD on behalf of the Merchant in connection with the OB Session Personalization Shopify application. Capitalised terms not defined here have the meaning given in the MSA.
Parties
(1) Processor: OBSESSION ECOMMERCE DATA TOOLS LTD, a company registered in Cyprus with registration number HE 496073, registered office at Nikola Tsadioti, Pearl Park Block 6, Apartment 115, 8035 Paphos, Cyprus ("Processor", "OB Session", "we"); and
(2) Controller: the merchant that installs the OB Session application ("Merchant", "Controller", "you"), identified in the MSA / order form.
Effective Date: the date the Merchant installs the App or the MSA effective date, whichever is earlier.
Background
A. The Merchant operates one or more Shopify storefronts and has installed the OB Session application (the "Service") — a behavioural recommendation engine that personalizes product recommendations, provides analytics and A/B testing, and attributes resulting orders.
B. In providing the Service, OB Session Processes Personal Data relating to visitors and shoppers on the Merchant's storefront(s) ("Shoppers") on the Merchant's behalf.
C. In respect of that Shopper Personal Data, the Merchant is the Controller and OB Session is the Processor. This DPA sets out the terms required by Article 28(3) GDPR.
D. This DPA does not govern OB Session's Processing of the Merchant's own account-contact data (e.g. the shop owner's name and email received on install), for which OB Session is an independent controller under its Privacy Policy.
1. Definitions
- "Applicable Data Protection Law" — all laws applicable to the Processing, including the EU GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, and US state privacy laws including the CCPA/CPRA.
- "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", "Supervisory Authority" — as defined in the GDPR.
- "Special Category Data" — the special categories of personal data under Article 9 GDPR: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership; and genetic data, biometric data used to uniquely identify a person, data concerning health, and data concerning a person's sex life or sexual orientation. Comparable data is treated as "sensitive personal information" or "sensitive data" under US state privacy laws (e.g. CCPA/CPRA).
- "EU SCCs" — the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914.
- "Restricted Transfer" — a transfer of Personal Data to a country without an adequacy decision under Applicable Data Protection Law.
- "Shopper Personal Data" — the Personal Data of Shoppers Processed by OB Session on the Merchant's behalf, as described in Annex 1.
- "Sub-processor" — a third party engaged by OB Session to Process Shopper Personal Data.
- "UK Addendum" — the ICO's International Data Transfer Addendum to the EU SCCs (version B1.0).
The Annexes form part of this DPA.
2. Roles and scope
2.1 In respect of Shopper Personal Data, the Merchant is the Controller and OB Session is the Processor. Each party complies with its obligations under Applicable Data Protection Law.
2.2 The subject-matter, duration, nature and purpose of the Processing, the categories of Data Subjects, and the types of Personal Data are set out in Annex 1.
2.3 Pseudonymous, minimised. The Service is designed to Process only pseudonymous Personal Data. It does not Process directly-identifying information (names, emails, phone numbers, addresses), payment or credential data, or Special Category Data by design, and never joins its identifiers to the Merchant's customer records. The categories Processed and not Processed are in Annex 1.
3. Processing instructions
3.1 Documented instructions. OB Session Processes Shopper Personal Data only on the Merchant's documented instructions — constituted by the MSA, this DPA, and the configuration the Merchant selects within the Service (including the identifier tier, Annex 1) — unless required to Process by law (in which case OB Session informs the Merchant first, unless legally prohibited).
3.2 Merchant responsibilities. The Merchant warrants that: (a) it has a valid lawful basis and has provided all notices and obtained all consents required for the Processing — including any consent required for the Service to set or read identifiers on a Shopper's device, configured through the Merchant's consent framework; (b) its instructions comply with Applicable Data Protection Law; and (c) it is responsible for the accuracy and legality of the data and the means by which it was obtained.
3.3 Unlawful instructions. OB Session informs the Merchant without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected Processing until the instruction is confirmed or amended.
3.4 Consent gating. No Shopper Personal Data is collected before the Shopper grants consent through Shopify's Customer Privacy API and the Merchant's consent framework; collection respects the store's regional consent configuration, and the stricter of the Merchant's chosen configuration and the Shopper's region/consent always applies.
4. Confidentiality
OB Session ensures that persons authorised to Process Shopper Personal Data are bound by confidentiality and that access is limited, on a least-privilege basis, to personnel who require it.
5. Security
Taking into account the state of the art and the risk, OB Session implements and maintains the technical and organisational measures in Annex 2 (Article 32 GDPR). OB Session may update those measures provided the overall level of security is not materially reduced.
6. Sub-processors
6.1 General authorisation. The Merchant authorises OB Session to engage the Sub-processors listed in Annex 3.
6.2 Flow-down and liability. OB Session imposes data-protection obligations on each Sub-processor no less protective than this DPA, and remains fully liable to the Merchant for each Sub-processor's performance.
6.3 Changes. OB Session gives the Merchant at least 30 days' prior notice of any intended addition or replacement of a Sub-processor (by email and/or a sub-processor page). The Merchant may object on reasonable, documented data-protection grounds; if the parties cannot resolve the objection, the Merchant may, as its sole remedy, terminate the affected part of the Service without penalty.
7. International transfers
7.1 OB Session is EEA-established. OB Session is established in the European Economic Area (Cyprus). The Merchant's engagement of OB Session as Processor does not, of itself, involve a transfer of Personal Data to a third country.
7.2 Hosting and the AWS transfer. The Service is hosted on Amazon Web Services, in AWS regions in the United States and/or the European Union. Where OB Session transfers Shopper Personal Data to AWS in the United States, that transfer is made under AWS's certification to the EU-US Data Privacy Framework (and, for UK Data Subjects, the UK Extension to it) and/or the EU SCCs (Module Three, Processor-to-Processor) and the UK Addendum, as incorporated into OB Session's agreement with AWS (Annex 5). OB Session remains liable to the Merchant for AWS's Processing under Clause 6.
7.3 EU/EEA residency. Where Shopper Personal Data is hosted in an AWS region in the EU, no transfer to a third country occurs.
8. Data subject rights assistance
8.1 Taking into account the nature of the Processing, OB Session assists the Merchant, by appropriate measures and insofar as possible, in responding to Shopper requests under Chapter III GDPR. If OB Session receives a request directly from a Shopper, it forwards it to the Merchant and does not respond itself (beyond confirming the Merchant is the Controller).
8.2 Mandatory Shopify webhooks. OB Session subscribes to and honours the mandatory compliance webhooks:
shop/redact— within 30 days of app uninstallation, OB Session deletes all of the Merchant's data across all systems;customers/redact— OB Session deletes the order records identified by the order IDs in the request; Shopper behavioural data is pseudonymous, cannot be associated with the customer, and expires under the retention schedule (Annex 4);customers/data_request— OB Session responds within the timeframe Shopify requires; because it holds no customer-identifying fields, it cannot link behavioural data to a named individual, and where the request identifies specific orders it returns the order-level records it holds for those order IDs (Clause 8.3).
8.3 Limitation where identification is not possible (Article 11 GDPR). OB Session Processes Shopper Personal Data in pseudonymous form and is not in a position to identify a Shopper. It is not obliged to acquire, maintain or Process additional information solely to identify a Data Subject to comply with this DPA. Behavioural data that cannot be linked to an identifiable Shopper expires automatically under the retention schedule; the only records OB Session can locate for a specific person are order records, by the order IDs Shopify provides.
9. Assistance with security, breach and impact assessments
Taking into account the nature of Processing and the information available to it, OB Session assists the Merchant in complying with its obligations under Articles 32 to 36 GDPR (security, breach notification and communication, data protection impact assessments, and prior consultation).
10. Personal Data Breach
10.1 OB Session notifies the Merchant without undue delay, and no later than 72 hours, after becoming aware of a Personal Data Breach affecting Shopper Personal Data.
10.2 The notification describes, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. OB Session cooperates so the Merchant can meet its Article 33/34 obligations. Notification is not an admission of fault.
11. Audits
11.1 OB Session makes available all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, and allows for and contributes to audits, subject to this Clause.
11.2 Documentation-first, remote. OB Session is a fully remote organisation operating no premises at which Shopper Personal Data is hosted; all Processing runs on Amazon Web Services infrastructure, the physical security of which is covered by AWS's independent certifications (SOC 2, ISO 27001, PCI DSS). OB Session satisfies its audit obligations by providing security-questionnaire responses, its policies and a description of its measures (Annex 2), and the relevant AWS certifications.
11.3 If that documentation is insufficient, the Merchant may request a remote audit (video/screen-share/interview), no more than once per 12 months (except following a Personal Data Breach or where a Supervisory Authority requires it), on 30 days' notice, under confidentiality, and at the Merchant's cost unless a material non-compliance is found. Nothing limits a Supervisory Authority's rights.
12. Retention, deletion and return
12.1 During the term. Shopper Personal Data is retained per the schedule in Annex 4. Retention follows the Merchant's chosen identifier tier where indicated, and shorter privacy configurations carry shorter retention.
12.2 On termination. On expiry or termination, OB Session, at the Merchant's choice, deletes or returns all Shopper Personal Data and deletes existing copies within 30 days, unless retention is required by law. Uninstalling the App triggers shop/redact (Clause 8.2).
12.3 Aggregated/anonymised data. Data rendered aggregated or anonymous such that it can no longer be linked to any device or Shopper is not Personal Data and may be retained and used to develop, maintain, and improve the Service. OB Session does not attempt to re-identify such data.
13. US state law — service provider
In respect of Shopper Personal Data relating to US residents, OB Session acts as a "service provider" under the CCPA/CPRA (and an equivalent role under comparable state laws). OB Session: (a) Processes the data only for the business purposes set out in this DPA and the MSA, and not for its own commercial purposes; (b) does not "sell" or "share" the data; (c) does not retain, use, or disclose the data outside the direct business relationship with the Merchant; and (d) certifies that it understands and will comply with these restrictions. OB Session may retain and use de-identified data in accordance with Clause 12.3; it does not attempt to re-identify de-identified data.
14. Special Category Data
The Service is not designed to Process Special Category Data. The Merchant warrants it will not configure or deploy the Service on any page or placement where the data Processed (including the products or collections a Shopper views) would reveal Special Category Data, and is solely responsible for determining whether such data is in scope and for establishing any condition required under Article 9 GDPR (including, where applicable, explicit consent). On becoming aware that Special Category Data is being Processed, OB Session may suspend the affected Processing and notify the Merchant.
15. Liability
15.1 Each party's liability under this DPA is subject to the exclusions and limitations of liability in the MSA. If, when a liability arises, no MSA containing an aggregate liability cap is in force, each party's aggregate liability under this DPA shall not exceed the fees paid or payable for the Service in the 12 months preceding the event giving rise to the liability.
15.2 Nothing limits liability that cannot be limited under Applicable Data Protection Law, including liability to Data Subjects under Article 82 GDPR.
16. Term
This DPA takes effect on the Effective Date and continues while OB Session Processes Shopper Personal Data on the Merchant's behalf. Clauses that by their nature should survive (including Clauses 12, 13 and 15) survive termination.
17. Order of precedence
In a conflict between this DPA and the MSA, this DPA prevails on the Processing of Shopper Personal Data. The cross-border-transfer safeguards for the AWS transfer are those in OB Session's agreement with AWS (Clause 7 / Annex 5).
18. Governing law
This DPA is governed by the laws of the Republic of Cyprus, and the courts of Cyprus have exclusive jurisdiction, save where Applicable Data Protection Law or the EU SCCs require otherwise.
19. Notices
Data-protection notices to OB Session — including legal and DPA correspondence, security and sub-processor inquiries, and data-subject and privacy matters — go to legal@ob-session.com. Notices to the Merchant: the contact in the MSA / Partner record.
20. General
20.1 This DPA, with the MSA and its Annexes, is the entire agreement on the Processing of Shopper Personal Data.
20.2 This DPA may be executed electronically (including by click-acceptance on installation) and in counterparts.
Acceptance
This DPA requires no signature. It is incorporated into the Master Services Agreement and is accepted by the Merchant electronically, together with the MSA, when the Merchant accepts those agreements in the OB Session app (Clause 20.2). OB Session accepts by making the Service available to the Merchant.
OB Session records the accepting Merchant, the version of this DPA accepted, and the date and time of acceptance; that record is available to the Merchant in the app admin and is the evidence of execution for the purposes of this DPA.
Annex 1 — Details of the Processing
Subject matter: provision of the OB Session behavioural recommendation Service on the Merchant's storefront(s), including training the Merchant-specific machine-learning model, generating and serving personalized recommendations, attributing resulting orders, and measuring performance through analytics and A/B testing.
Duration: the term of the Merchant's use of the Service, plus the deletion periods in Clause 12 / Annex 4.
Nature and purpose: automated collection and analysis of pseudonymous behavioural signals to train and operate the Merchant-specific machine-learning model, generate and serve personalized recommendations, and then measure their performance through analytics and A/B testing; and the derivation of aggregated, de-identified statistics that are no longer Personal Data (Clause 12.3). No automated decision-making producing legal or similarly significant effects (Article 22 GDPR) is performed.
Categories of Data Subjects: visitors to, and shoppers on, the Merchant's storefront(s) who have granted consent.
Categories of Shopper Personal Data:
- Pseudonymous identifiers — randomly generated identifiers distinguishing the visitor, the session, and the parts of the page involved in an interaction; never linked to a customer account; scoped to a single store.
- Interaction and behavioral signals — page/product views, clicks, hovers, scrolling, cursor movement, product-card visibility, viewport dimensions, add-to-cart/remove actions.
- Content and commerce context — products/collections viewed, cart contents and amounts, the placement where a recommendation was shown (e.g. a widget or the product-listing grid), and attributes of the merchant's catalog elements (titles, prices, labels).
- Navigation and traffic context — page type, navigation path (path-only URLs; query strings are discarded, apart from pagination and filter state), referrer, campaign (UTM) parameters.
- Search signals — store search terms.
- Device and locale characteristics — user agent, language, time zone, platform, screen size.
From the above, the Service derives behavioural signals and product-recommendation inferences; its internal feature set is not itemised in this Agreement.
Order data (billing and attribution): order ID, date, currency, amounts, line items (with product/variant references and attribution flags), and a test flag. No customer fields (name, email, phone, address, or Shopify customer ID) are processed.
Configuration recorded per Merchant (selected at onboarding):
- Identifier tier: Tier 1 (persistent, up to 365 days) · Tier 2 (session, localStorage) · Tier 3 (session, per-tab) — as selected by the Merchant at onboarding and recorded in the App admin
Special Category Data: none (see Clause 14).
Frequency of transfer: continuous, for the duration of the Service.
Annex 2 — Technical and organisational measures
(Summary; the full posture is published at ob-session.com/security.)
- Consent gating — no data collected before the Shopper grants consent via Shopify's Customer Privacy API; regional consent respected.
- Pseudonymisation and minimisation by design — randomly generated identifiers; no customer-identifying fields requested; order queries restricted to financial/attribution fields.
- Encryption — in transit (TLS) on all public endpoints and the event pipeline; at rest (AES-256) for databases, storage and backups.
- Access control — least-privilege access restricted to personnel who require it; secrets managed via a managed secrets store; access events logged.
- Tenant isolation — all data keyed by store; the model trained for one Merchant is never applied to another; shop-level purge deletes across all tables.
- Resilience / fail-safe — if a recommendation cannot be served within the time limit, the Merchant's default content is served, so a Service interruption cannot break a page or checkout.
- Operational security — environment separation between development and production; dependency management and patching.
- Retention enforcement — deletion on a defined schedule per Annex 4.
- Breach management — procedures to detect, investigate, mitigate and notify Personal Data Breaches per Clause 10.
Annex 3 — Sub-processors
| Sub-processor | Role / Service | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Sole cloud-infrastructure provider — all OB Session Processing runs on AWS-native services (compute, storage, database, and managed services). No other sub-processor is used. | AWS regions in the United States and/or the European Union | EU SCCs + EU-US Data Privacy Framework certification (for US hosting) |
Shopify is the platform on which the App runs and is an independent party with its own agreement with the Merchant; it is not a Sub-processor of OB Session. Individual AWS services are components of a single Sub-processor and are not listed separately. The current list is available at legal@ob-session.com; material changes are notified under Clause 6.3.
Annex 4 — Retention schedule
Maximum periods. The Merchant's chosen identifier tier may shorten them; the periods applying to the Merchant's own configuration are recorded in the App admin (or an Order Form where used).
| Data | Retention |
|---|---|
| Recommendation state (a pseudonymous record used to personalize the visit, and the current cart) | Follows the identifier tier: up to 365 days in Tier 1; session-scoped (~60 minutes) in Tier 2; per-tab in Tier 3 |
| Behavioural event data and A/B measurements | Up to 12 months (rolling) |
| Order-level records (billing/attribution; no customer fields) | Up to 24 months, or earlier on a customers/redact request |
| On-device identifiers (cookie / localStorage / sessionStorage) | Per the identifier tier (session, or up to 365 days in Tier 1) |
| Infrastructure access logs (may contain IPs) | Up to 30 days |
| Merchant catalog/config and model artefacts (not personal data) | While installed; deleted on shop/redact |
All Merchant data is deleted on shop/redact following uninstallation. Aggregated/anonymised data may be retained (Clause 12.3).
Annex 5 — Cross-border transfers
OB Session is established in the EEA (Cyprus), so the Merchant's engagement of OB Session as Processor is not itself a Restricted Transfer (EDPB Guidelines 05/2021). OB Session's Sub-processor, Amazon Web Services EMEA SARL, is also established in the EEA (Luxembourg), so the engagement of that Sub-processor is likewise not a Restricted Transfer.
A Restricted Transfer arises where Shopper Personal Data is hosted on AWS infrastructure in the United States — an onward transfer from Amazon Web Services EMEA SARL to Amazon Web Services, Inc. (Clause 7). That transfer is governed by OB Session's data processing agreement with AWS and relies on:
- AWS's certification to the EU-US Data Privacy Framework — and the UK Extension for UK Data Subjects (AWS is also certified to the Swiss-US DPF); and/or
- the EU SCCs (Commission Implementing Decision (EU) 2021/914), Module Three (Processor-to-Processor), with the UK Addendum (B1.0) where UK Data Subjects are in scope, as incorporated into the AWS agreement.
OB Session remains fully liable to the Merchant for this transfer (Clause 6.2). Where Shopper Personal Data is hosted in an AWS region in the EU (Clause 7.3), no such transfer occurs.