# Data Processing Agreement

> Data processing agreement entered into under Article 28 GDPR between the merchant, as controller, and Verity Score, as processor. Nature of processing, security, sub-processors, transfers and data subject rights.

- Canonical HTML: https://verityscore.io/en/dpa/
- Markdown alternate: https://verityscore.io/en/dpa.md
- Language: en
- Content type: trust/compliance
- Updated: 2026-08-08
- Robots: noindex on HTML; Markdown exists for trust verification and agent ingestion

This agreement applies automatically whenever Verity Score processes personal data on behalf of a customer, in particular through the Shopify app. It forms an integral part of the terms of service. The French version prevails in the event of a discrepancy.

## 1. Parties and purpose

This agreement (the "Agreement") is entered into between:

**The Customer**, the merchant subscribing to the Service, acting as **controller** within the meaning of Article 4(7) GDPR,

and

- **Company name** : Verity Score
- **Legal form** : Société par actions simplifiée (French simplified joint-stock company)
- **Share capital** : EUR 500
- **Registered office** : 138 avenue Victor Hugo, 75016 Paris, France
- **Company registration** : Paris Trade and Companies Register (RCS) 108 480 583
- **SIREN number** : 108 480 583
- **EU VAT number** : FR68108480583
- **European identifier (EUID)** : FR7501.108480583
- **President** : Kamil Kaderbay
- **Email** : hello@verityscore.io

acting as **processor** within the meaning of Article 4(8) GDPR.

The Agreement sets out the conditions under which Verity Score processes personal data on behalf of the Customer in the context of the Service. It applies automatically to any subscription and prevails, for such processing, over any contrary provision.

## 2. Allocation of roles

Verity Score acts as **processor** for personal data originating from the Customer's store: order data, customer events, and any personal data contained in store content.

Verity Score acts as a separate **controller** for data relating to the commercial relationship with the Customer: account, billing, support, security and technical logs. That processing is governed by the [privacy policy](https://verityscore.io/en/privacy/).

## 3. Description of the processing

**Subject matter.** Provision of the Service for auditing and improving the store's visibility to AI engines and agents.

**Nature of operations.** Collection, consultation, structuring, automated analysis, storage, transmission to the sub-processors listed in section 7, and erasure.

**Purpose.** Performance of the subscribed Service, to the exclusion of any purpose of Verity Score's own. No Customer data is used to train models, nor sold, rented or exploited for third-party marketing.

**Duration.** Processing lasts for the term of the subscription, plus the erasure period set out in section 11.

**Categories of data subjects.**

- customers and prospects of the Customer's store
- visitors to the Customer's store
- Customer staff with access to the Service

**Categories of data.**

| Category | Detail | Condition |
| --- | --- | --- |
| Pseudonymized customer identifiers | Hashes of customer id, email and phone | `read_orders` scope granted |
| Order data | Amounts, currencies, dates, acquisition channel, landing page | `read_orders` scope granted |
| Browsing events | Page views, traffic source, user agent | `read_customer_events` scope granted |
| Customer user accounts | First name, last name, email address | Always |
| Incidental personal data | Any data appearing in store content (product pages, reviews, pages) | Always |

**No special categories of data** within the meaning of Article 9 GDPR are knowingly processed. The Customer refrains from introducing such data into the fields processed by the Service.

The `read_orders` and `read_customer_events` scopes are **optional** and requested separately after installation. Without them, no end-customer personal data is processed.

## 4. Documented instructions

Verity Score processes the data only on **documented instructions** from the Customer. The following constitute documented instructions: this Agreement, the terms of service, the scopes granted at installation, and the actions performed by the Customer in the Service interface.

Verity Score informs the Customer if, in its opinion, an instruction infringes the GDPR or another data protection provision.

Where a legal obligation requires Verity Score to process beyond the Customer's instructions, it informs the Customer before processing, unless that information is prohibited by law.

## 5. Confidentiality

Verity Score ensures that persons authorized to process the data are subject to a contractual confidentiality obligation, are trained in data protection, and access only the data strictly necessary for their role.

Access to production environments is individually attributed, logged and revoked without delay at the end of the assignment.

## 6. Security of processing

In accordance with Article 32 GDPR, Verity Score implements the following measures:

- encryption of data in transit (TLS 1.3) and encryption at rest for databases
- pseudonymization by hashing of end-customer identifiers, never stored in clear text
- strong authentication and segregation of access to production environments
- database access restricted by IP allow-list
- logging of access and write operations
- regular backups and a tested restoration procedure
- protection against requests to internal resources, strict input validation, rate limiting
- dependency review and application of security patches
- logical segregation of data by store

These measures may evolve, provided the overall level of security is not reduced.

## 7. Sub-processors

The Customer grants Verity Score a **general authorization** to use the sub-processors listed below.

| Sub-processor | Purpose | Location | Outside EU |
| --- | --- | --- | --- |
| Railway Corp. | Hosting of the audit engine, the Shopify app, the MCP server and application databases | United States | Yes |
| Cloudflare, Inc. | Site delivery (CDN), DNS, TLS termination and abuse protection | United States and global edge network | Yes |
| MongoDB, Inc. (MongoDB Atlas) | Storage of audit results, contact requests and MCP server logs | European Union (Frankfurt region) | No |
| Shopify International Ltd. | App installation platform, merchant authentication and subscription billing | Ireland (Shopify Inc. group, Canada) | No |
| OpenAI, L.L.C. | Audit findings generation, assisted content drafting and AI purchase simulations | United States | Yes |
| Anthropic PBC | AI purchase simulations and generative engine response testing | United States | Yes |
| Google LLC (Gemini API) | AI purchase simulations and generative engine response testing | United States and European Union | Yes |
| Perplexity AI, Inc. | AI purchase simulations and generative engine response testing | United States | Yes |
| Sendinblue SAS (Brevo) | Transactional email delivery (audit report, service notifications) | France | No |
| Notion Labs, Inc. | Pseudonymized internal tracking board (audited domain, tool called, status). No IP address or email | United States | Yes |

Verity Score contractually imposes on each sub-processor protection obligations equivalent to those of this Agreement and remains fully liable to the Customer for their performance.

Where a sub-processor is added or replaced, Verity Score informs the Customer by email at least **thirty (30) days** before implementation. The Customer may object on legitimate data protection grounds within that period. Failing a reasonable alternative, the Customer may terminate the subscription without penalty, with a pro-rata refund of the unused period.

## 8. Transfers outside the European Union

Some sub-processors are established in the United States. These transfers are governed by the **Standard Contractual Clauses** adopted by the European Commission (Implementing Decision 2021/914, processor-to-processor module) and, where the provider is certified, by the **EU-US Data Privacy Framework**.

Verity Score applies supplementary technical measures: encryption in transit, minimization of transmitted data, pseudonymization of identifiers, and no transmission of raw order data to language model providers.

## 9. Assistance to the Customer

**Data subject rights.** Verity Score provides the Customer with the functions needed to respond to requests for access, rectification, erasure, restriction, portability and objection. Requests forwarded by Shopify under the compliance webhooks (`customers/data_request`, `customers/redact`, `shop/redact`) are handled automatically within the deadlines imposed by Shopify. If a data subject contacts Verity Score directly, Verity Score refers them to the Customer and informs the Customer without delay.

**Impact assessment.** Verity Score provides the Customer, on request, with the information needed to carry out a data protection impact assessment and, where applicable, prior consultation with the supervisory authority.

**Security.** Verity Score assists the Customer in complying with its obligations under Articles 32 to 36 GDPR.

## 10. Personal data breach

Verity Score notifies the Customer of any personal data breach **without undue delay and at the latest seventy-two (72) hours** after becoming aware of it, by email to the account contact address.

The notification states the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact point.

Verity Score documents each breach and cooperates with the Customer to enable it to meet its own notification obligations to the supervisory authority and, where applicable, to data subjects.

## 11. Fate of data at the end of the contract

At the end of the service, the Customer has **thirty (30) days** to export its data. On expiry of that period, Verity Score **deletes** all personal data processed on its behalf, including in backups according to their rotation cycle, which does not exceed ninety (90) days.

Uninstalling the Shopify app triggers the same process.

Verity Score may retain data whose retention is required by Union or national law, for the required period only and without further processing. A deletion certificate is provided on written request.

## 12. Audit and documentation

Verity Score makes available to the Customer the information necessary to demonstrate compliance with the obligations of Article 28 GDPR.

The Customer may, at most **once a year** and on thirty (30) days' notice, carry out a documentary audit or appoint an independent auditor bound by confidentiality and not a competitor of Verity Score. An additional audit is possible following a confirmed data breach.

Audits take place during business hours, without disrupting operations, and do not cover other customers' data. Audit costs are borne by the Customer, unless the audit reveals a material failure by Verity Score.

## 13. Liability and changes

Each party's liability under this Agreement is governed by Article 82 GDPR and, as regards contractual relations, by the limitations set out in the [terms of service](https://verityscore.io/en/terms/).

Verity Score may amend the Agreement to reflect legislative, regulatory or case-law developments, or a decision of the supervisory authority. Any material change is notified thirty (30) days before it takes effect.

The Agreement is governed by French law. The Tribunal des activités économiques de Paris has sole jurisdiction.
