Data Processing Addendum
Between: Syntheum AI, Inc. (“Processor”, “Syntheum”) and the merchant that installs Syntheum Lite (“Controller”, “Merchant”). This DPA forms part of, and is subject to, the agreement between the parties governing use of the App (“Agreement”).
1. Roles and scope
1.1 For personal data relating to the Merchant's customers, prospective customers, and storefront visitors (“Customer Data”) processed through the App, the Merchant is the controller and Syntheum is the processor. Where a sub-processor is engaged, Syntheum remains responsible for its processing under this DPA.
1.2 Syntheum processes Customer Data only to provide the App and only on the Merchant's documented instructions, which are given by the Merchant's configuration and use of the App and by this DPA. Syntheum will not process Customer Data for its own purposes, and will not sell it or use it for advertising or cross-merchant profiling.
2. Subject matter, nature, and duration
2.1 Nature and purpose of processing: providing AI-powered storefront search and a conversational shopping assistant, and measuring search-to-purchase attribution for the Merchant. See the Privacy Policy for the full purpose description.
2.2 Duration: for the term of the installation, subject to the deletion and retention terms in Section 8.
3. Categories of data subjects and personal data
3.1 Data subjects: the Merchant's storefront shoppers and visitors.
3.2 Categories of Customer Data processed:
- Storefront search query text and associated operational signals (result count, search confidence score, response time, widget surface).
- Search-to-purchase attribution events: order identifier (used solely as a de-duplication key), order and line totals, currency, purchased product/variant identifiers, quantities, storefront consent state, and an internal search identifier (“qid”).
3.3 Excluded data: the App does not process customer names, email addresses, phone numbers, or physical/postal addresses. Data minimization is enforced in the Web Pixel and ingestion code.
4. Sub-processors
4.1 The Merchant authorizes Syntheum to engage the sub-processors listed below. Syntheum imposes data protection obligations on each sub-processor no less protective than this DPA.
| Sub-processor | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, compute, storage (D1/KV), vector search, AI gateway | US / global edge |
| Anthropic, PBC (via Cloudflare AI Gateway) | Conversational AI response generation | US |
4.2 Syntheum will give the Merchant prior notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object on reasonable data protection grounds.
5. Consent
The App honors the storefront customer-privacy/consent signal exposed by Shopify: where a shopper has not permitted analytics processing, the attribution pixel does not capture the event. The Merchant is responsible for obtaining and configuring lawful consent (e.g. its cookie/consent banner and regional settings) as controller.
6. Security measures (technical and organizational)
Syntheum maintains at least the following measures:
- Encryption of Customer Data in transit (TLS) and at rest.
- Access control on a least-privilege basis; production access limited to authorized personnel and authenticated via the platform provider's IAM.
- Tenant isolation: Customer Data is scoped and queried by merchant identifier.
- Secret management: credentials and API tokens held as platform secrets, never in source control.
- Data minimization: only the fields in Section 3.2 are collected; direct identifiers are excluded at the point of collection.
- Logging and monitoring of service health and abuse, without storing excluded identifiers.
7. Assistance to the Controller
7.1 Data subject requests. Taking into account the nature of the
processing, Syntheum will assist the Merchant by appropriate technical and organizational
measures, insofar as possible, to respond to data subject requests. The App implements
Shopify's customers/data_request, customers/redact, and
shop/redact webhooks for this purpose.
7.2 Personal data breach. Syntheum will notify the Merchant without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably necessary for the Merchant to meet its notification obligations.
7.3 Syntheum will assist the Merchant with data protection impact assessments and prior consultations to the extent applicable and reasonable.
8. Retention and deletion
8.1 Retention. Customer Data (search queries and attribution/conversion records) is retained for a maximum of 90 days and then automatically deleted. Prior to deletion, Syntheum derives anonymized, aggregated statistics (monthly counts/sums, containing no qid, order identifier, order total, or per-event timestamp), which are not Customer Data and may be retained to preserve long-term insights.
8.2 Deletion on request/termination. On the Merchant's request, on app
uninstall, or on a verified shop/redact event, Syntheum will delete Customer
Data associated with the Merchant, except anonymized aggregates and any data Syntheum is
legally required to retain.
9. International transfers
Where processing of Customer Data involves a transfer from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree the applicable Standard Contractual Clauses (and UK/Swiss addenda) are incorporated by reference, with Syntheum as data importer.
10. Audit
Syntheum will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor mandated by the Merchant, subject to reasonable confidentiality and frequency limits.
11. Liability, precedence, and individually negotiated agreements
11.1 This DPA is subject to the liability provisions of the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of Customer Data, this DPA prevails.
11.2 Individually negotiated agreements prevail. This DPA is Syntheum's standard data processing addendum for self-serve merchants. Where the Merchant and Syntheum have entered into a separately negotiated and signed data processing agreement, enterprise agreement, or equivalent instrument covering the same subject matter (for example, under an enterprise or partner-led engagement), that instrument supersedes this DPA to the extent of any conflict, and this DPA does not apply to processing governed by that instrument.
12. Governing law
12.1 This DPA is governed by and construed in accordance with the laws of the Commonwealth of Massachusetts, without regard to its conflict-of-laws principles, and the parties submit to the exclusive jurisdiction of the state and federal courts located in Middlesex County, Massachusetts. If the Agreement specifies a governing law and forum, that governing law and forum control and apply to this DPA in place of this Section.
12.2 Nothing in this Section limits or overrides the application of any mandatory data protection law (including, where applicable, the EU GDPR, the UK GDPR, and US state privacy laws) that applies to the processing of Customer Data irrespective of the governing law chosen here.
Syntheum AI, Inc., 432 Salem Street, Woburn, MA 01801 · privacy@syntheum.ai