Data Processing Agreement
Last updated : August 8, 2026
This agreement applies automatically whenever Verity Score processes personal data on behalf of a customer, in particular through the Shopify app. It forms an integral part of the terms of service. The French version prevails in the event of a discrepancy.
1. Parties and purpose
This agreement (the "Agreement") is entered into between:
The Customer, the merchant subscribing to the Service, acting as controller within the meaning of Article 4(7) GDPR,
and
- Company name : Verity Score
- Legal form : Société par actions simplifiée (French simplified joint-stock company)
- Share capital : EUR 500
- Registered office : 138 avenue Victor Hugo, 75016 Paris, France
- Company registration : Paris Trade and Companies Register (RCS) 108 480 583
- SIREN number : 108 480 583
- EU VAT number : FR68108480583
- European identifier (EUID) : FR7501.108480583
- President : Kamil Kaderbay
- Email : [email protected]
acting as processor within the meaning of Article 4(8) GDPR.
The Agreement sets out the conditions under which Verity Score processes personal data on behalf of the Customer in the context of the Service. It applies automatically to any subscription and prevails, for such processing, over any contrary provision.
2. Allocation of roles
Verity Score acts as processor for personal data originating from the Customer's store: order data, customer events, and any personal data contained in store content.
Verity Score acts as a separate controller for data relating to the commercial relationship with the Customer: account, billing, support, security and technical logs. That processing is governed by the privacy policy.
3. Description of the processing
Subject matter. Provision of the Service for auditing and improving the store's visibility to AI engines and agents.
Nature of operations. Collection, consultation, structuring, automated analysis, storage, transmission to the sub-processors listed in section 7, and erasure.
Purpose. Performance of the subscribed Service, to the exclusion of any purpose of Verity Score's own. No Customer data is used to train models, nor sold, rented or exploited for third-party marketing.
Duration. Processing lasts for the term of the subscription, plus the erasure period set out in section 11.
Categories of data subjects.
- customers and prospects of the Customer's store
- visitors to the Customer's store
- Customer staff with access to the Service
Categories of data.
| Category | Detail | Condition |
|---|---|---|
| Pseudonymized customer identifiers | Hashes of customer id, email and phone | read_orders scope granted |
| Order data | Amounts, currencies, dates, acquisition channel, landing page | read_orders scope granted |
| Browsing events | Page views, traffic source, user agent | read_customer_events scope granted |
| Customer user accounts | First name, last name, email address | Always |
| Incidental personal data | Any data appearing in store content (product pages, reviews, pages) | Always |
No special categories of data within the meaning of Article 9 GDPR are knowingly processed. The Customer refrains from introducing such data into the fields processed by the Service.
The read_orders and read_customer_events scopes are optional and requested separately after installation. Without them, no end-customer personal data is processed.
4. Documented instructions
Verity Score processes the data only on documented instructions from the Customer. The following constitute documented instructions: this Agreement, the terms of service, the scopes granted at installation, and the actions performed by the Customer in the Service interface.
Verity Score informs the Customer if, in its opinion, an instruction infringes the GDPR or another data protection provision.
Where a legal obligation requires Verity Score to process beyond the Customer's instructions, it informs the Customer before processing, unless that information is prohibited by law.
5. Confidentiality
Verity Score ensures that persons authorized to process the data are subject to a contractual confidentiality obligation, are trained in data protection, and access only the data strictly necessary for their role.
Access to production environments is individually attributed, logged and revoked without delay at the end of the assignment.
6. Security of processing
In accordance with Article 32 GDPR, Verity Score implements the following measures:
- encryption of data in transit (TLS 1.3) and encryption at rest for databases
- pseudonymization by hashing of end-customer identifiers, never stored in clear text
- strong authentication and segregation of access to production environments
- database access restricted by IP allow-list
- logging of access and write operations
- regular backups and a tested restoration procedure
- protection against requests to internal resources, strict input validation, rate limiting
- dependency review and application of security patches
- logical segregation of data by store
These measures may evolve, provided the overall level of security is not reduced.
7. Sub-processors
The Customer grants Verity Score a general authorization to use the sub-processors listed below.
| Sub-processor | Purpose | Location | Outside EU |
|---|---|---|---|
| Railway Corp. | Hosting of the audit engine, the Shopify app, the MCP server and application databases | United States | Yes |
| Cloudflare, Inc. | Site delivery (CDN), DNS, TLS termination and abuse protection | United States and global edge network | Yes |
| MongoDB, Inc. (MongoDB Atlas) | Storage of audit results, contact requests and MCP server logs | European Union (Frankfurt region) | No |
| Shopify International Ltd. | App installation platform, merchant authentication and subscription billing | Ireland (Shopify Inc. group, Canada) | No |
| OpenAI, L.L.C. | Audit findings generation, assisted content drafting and AI purchase simulations | United States | Yes |
| Anthropic PBC | AI purchase simulations and generative engine response testing | United States | Yes |
| Google LLC (Gemini API) | AI purchase simulations and generative engine response testing | United States and European Union | Yes |
| Perplexity AI, Inc. | AI purchase simulations and generative engine response testing | United States | Yes |
| Sendinblue SAS (Brevo) | Transactional email delivery (audit report, service notifications) | France | No |
| Notion Labs, Inc. | Pseudonymized internal tracking board (audited domain, tool called, status). No IP address or email | United States | Yes |
Verity Score contractually imposes on each sub-processor protection obligations equivalent to those of this Agreement and remains fully liable to the Customer for their performance.
Where a sub-processor is added or replaced, Verity Score informs the Customer by email at least thirty (30) days before implementation. The Customer may object on legitimate data protection grounds within that period. Failing a reasonable alternative, the Customer may terminate the subscription without penalty, with a pro-rata refund of the unused period.
8. Transfers outside the European Union
Some sub-processors are established in the United States. These transfers are governed by the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914, processor-to-processor module) and, where the provider is certified, by the EU-US Data Privacy Framework.
Verity Score applies supplementary technical measures: encryption in transit, minimization of transmitted data, pseudonymization of identifiers, and no transmission of raw order data to language model providers.
9. Assistance to the Customer
Data subject rights. Verity Score provides the Customer with the functions needed to respond to requests for access, rectification, erasure, restriction, portability and objection. Requests forwarded by Shopify under the compliance webhooks (customers/data_request, customers/redact, shop/redact) are handled automatically within the deadlines imposed by Shopify. If a data subject contacts Verity Score directly, Verity Score refers them to the Customer and informs the Customer without delay.
Impact assessment. Verity Score provides the Customer, on request, with the information needed to carry out a data protection impact assessment and, where applicable, prior consultation with the supervisory authority.
Security. Verity Score assists the Customer in complying with its obligations under Articles 32 to 36 GDPR.
10. Personal data breach
Verity Score notifies the Customer of any personal data breach without undue delay and at the latest seventy-two (72) hours after becoming aware of it, by email to the account contact address.
The notification states the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact point.
Verity Score documents each breach and cooperates with the Customer to enable it to meet its own notification obligations to the supervisory authority and, where applicable, to data subjects.
11. Fate of data at the end of the contract
At the end of the service, the Customer has thirty (30) days to export its data. On expiry of that period, Verity Score deletes all personal data processed on its behalf, including in backups according to their rotation cycle, which does not exceed ninety (90) days.
Uninstalling the Shopify app triggers the same process.
Verity Score may retain data whose retention is required by Union or national law, for the required period only and without further processing. A deletion certificate is provided on written request.
12. Audit and documentation
Verity Score makes available to the Customer the information necessary to demonstrate compliance with the obligations of Article 28 GDPR.
The Customer may, at most once a year and on thirty (30) days' notice, carry out a documentary audit or appoint an independent auditor bound by confidentiality and not a competitor of Verity Score. An additional audit is possible following a confirmed data breach.
Audits take place during business hours, without disrupting operations, and do not cover other customers' data. Audit costs are borne by the Customer, unless the audit reveals a material failure by Verity Score.
13. Liability and changes
Each party's liability under this Agreement is governed by Article 82 GDPR and, as regards contractual relations, by the limitations set out in the terms of service.
Verity Score may amend the Agreement to reflect legislative, regulatory or case-law developments, or a decision of the supervisory authority. Any material change is notified thirty (30) days before it takes effect.
The Agreement is governed by French law. The Tribunal des activités économiques de Paris has sole jurisdiction.