Skip to main content
Private betaThe Shopify app that makes your products readable and verifiable by AI.Shopify app: be readable by AII want in

Data Processing Agreement

Last updated : August 8, 2026

This agreement applies automatically whenever Verity Score processes personal data on behalf of a customer, in particular through the Shopify app. It forms an integral part of the terms of service. The French version prevails in the event of a discrepancy.

1. Parties and purpose

This agreement (the "Agreement") is entered into between:

The Customer, the merchant subscribing to the Service, acting as controller within the meaning of Article 4(7) GDPR,

and

  • Company name : Verity Score
  • Legal form : Société par actions simplifiée (French simplified joint-stock company)
  • Share capital : EUR 500
  • Registered office : 138 avenue Victor Hugo, 75016 Paris, France
  • Company registration : Paris Trade and Companies Register (RCS) 108 480 583
  • SIREN number : 108 480 583
  • EU VAT number : FR68108480583
  • European identifier (EUID) : FR7501.108480583
  • President : Kamil Kaderbay
  • Email : [email protected]

acting as processor within the meaning of Article 4(8) GDPR.

The Agreement sets out the conditions under which Verity Score processes personal data on behalf of the Customer in the context of the Service. It applies automatically to any subscription and prevails, for such processing, over any contrary provision.

2. Allocation of roles

Verity Score acts as processor for personal data originating from the Customer's store: order data, customer events, and any personal data contained in store content.

Verity Score acts as a separate controller for data relating to the commercial relationship with the Customer: account, billing, support, security and technical logs. That processing is governed by the privacy policy.

3. Description of the processing

Subject matter. Provision of the Service for auditing and improving the store's visibility to AI engines and agents.

Nature of operations. Collection, consultation, structuring, automated analysis, storage, transmission to the sub-processors listed in section 7, and erasure.

Purpose. Performance of the subscribed Service, to the exclusion of any purpose of Verity Score's own. No Customer data is used to train models, nor sold, rented or exploited for third-party marketing.

Duration. Processing lasts for the term of the subscription, plus the erasure period set out in section 11.

Categories of data subjects.

  • customers and prospects of the Customer's store
  • visitors to the Customer's store
  • Customer staff with access to the Service

Categories of data.

CategoryDetailCondition
Pseudonymized customer identifiersHashes of customer id, email and phoneread_orders scope granted
Order dataAmounts, currencies, dates, acquisition channel, landing pageread_orders scope granted
Browsing eventsPage views, traffic source, user agentread_customer_events scope granted
Customer user accountsFirst name, last name, email addressAlways
Incidental personal dataAny data appearing in store content (product pages, reviews, pages)Always

No special categories of data within the meaning of Article 9 GDPR are knowingly processed. The Customer refrains from introducing such data into the fields processed by the Service.

The read_orders and read_customer_events scopes are optional and requested separately after installation. Without them, no end-customer personal data is processed.

4. Documented instructions

Verity Score processes the data only on documented instructions from the Customer. The following constitute documented instructions: this Agreement, the terms of service, the scopes granted at installation, and the actions performed by the Customer in the Service interface.

Verity Score informs the Customer if, in its opinion, an instruction infringes the GDPR or another data protection provision.

Where a legal obligation requires Verity Score to process beyond the Customer's instructions, it informs the Customer before processing, unless that information is prohibited by law.

5. Confidentiality

Verity Score ensures that persons authorized to process the data are subject to a contractual confidentiality obligation, are trained in data protection, and access only the data strictly necessary for their role.

Access to production environments is individually attributed, logged and revoked without delay at the end of the assignment.

6. Security of processing

In accordance with Article 32 GDPR, Verity Score implements the following measures:

  • encryption of data in transit (TLS 1.3) and encryption at rest for databases
  • pseudonymization by hashing of end-customer identifiers, never stored in clear text
  • strong authentication and segregation of access to production environments
  • database access restricted by IP allow-list
  • logging of access and write operations
  • regular backups and a tested restoration procedure
  • protection against requests to internal resources, strict input validation, rate limiting
  • dependency review and application of security patches
  • logical segregation of data by store

These measures may evolve, provided the overall level of security is not reduced.

7. Sub-processors

The Customer grants Verity Score a general authorization to use the sub-processors listed below.

Sub-processorPurposeLocationOutside EU
Railway Corp.Hosting of the audit engine, the Shopify app, the MCP server and application databasesUnited StatesYes
Cloudflare, Inc.Site delivery (CDN), DNS, TLS termination and abuse protectionUnited States and global edge networkYes
MongoDB, Inc. (MongoDB Atlas)Storage of audit results, contact requests and MCP server logsEuropean Union (Frankfurt region)No
Shopify International Ltd.App installation platform, merchant authentication and subscription billingIreland (Shopify Inc. group, Canada)No
OpenAI, L.L.C.Audit findings generation, assisted content drafting and AI purchase simulationsUnited StatesYes
Anthropic PBCAI purchase simulations and generative engine response testingUnited StatesYes
Google LLC (Gemini API)AI purchase simulations and generative engine response testingUnited States and European UnionYes
Perplexity AI, Inc.AI purchase simulations and generative engine response testingUnited StatesYes
Sendinblue SAS (Brevo)Transactional email delivery (audit report, service notifications)FranceNo
Notion Labs, Inc.Pseudonymized internal tracking board (audited domain, tool called, status). No IP address or emailUnited StatesYes

Verity Score contractually imposes on each sub-processor protection obligations equivalent to those of this Agreement and remains fully liable to the Customer for their performance.

Where a sub-processor is added or replaced, Verity Score informs the Customer by email at least thirty (30) days before implementation. The Customer may object on legitimate data protection grounds within that period. Failing a reasonable alternative, the Customer may terminate the subscription without penalty, with a pro-rata refund of the unused period.

8. Transfers outside the European Union

Some sub-processors are established in the United States. These transfers are governed by the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914, processor-to-processor module) and, where the provider is certified, by the EU-US Data Privacy Framework.

Verity Score applies supplementary technical measures: encryption in transit, minimization of transmitted data, pseudonymization of identifiers, and no transmission of raw order data to language model providers.

9. Assistance to the Customer

Data subject rights. Verity Score provides the Customer with the functions needed to respond to requests for access, rectification, erasure, restriction, portability and objection. Requests forwarded by Shopify under the compliance webhooks (customers/data_request, customers/redact, shop/redact) are handled automatically within the deadlines imposed by Shopify. If a data subject contacts Verity Score directly, Verity Score refers them to the Customer and informs the Customer without delay.

Impact assessment. Verity Score provides the Customer, on request, with the information needed to carry out a data protection impact assessment and, where applicable, prior consultation with the supervisory authority.

Security. Verity Score assists the Customer in complying with its obligations under Articles 32 to 36 GDPR.

10. Personal data breach

Verity Score notifies the Customer of any personal data breach without undue delay and at the latest seventy-two (72) hours after becoming aware of it, by email to the account contact address.

The notification states the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact point.

Verity Score documents each breach and cooperates with the Customer to enable it to meet its own notification obligations to the supervisory authority and, where applicable, to data subjects.

11. Fate of data at the end of the contract

At the end of the service, the Customer has thirty (30) days to export its data. On expiry of that period, Verity Score deletes all personal data processed on its behalf, including in backups according to their rotation cycle, which does not exceed ninety (90) days.

Uninstalling the Shopify app triggers the same process.

Verity Score may retain data whose retention is required by Union or national law, for the required period only and without further processing. A deletion certificate is provided on written request.

12. Audit and documentation

Verity Score makes available to the Customer the information necessary to demonstrate compliance with the obligations of Article 28 GDPR.

The Customer may, at most once a year and on thirty (30) days' notice, carry out a documentary audit or appoint an independent auditor bound by confidentiality and not a competitor of Verity Score. An additional audit is possible following a confirmed data breach.

Audits take place during business hours, without disrupting operations, and do not cover other customers' data. Audit costs are borne by the Customer, unless the audit reveals a material failure by Verity Score.

13. Liability and changes

Each party's liability under this Agreement is governed by Article 82 GDPR and, as regards contractual relations, by the limitations set out in the terms of service.

Verity Score may amend the Agreement to reflect legislative, regulatory or case-law developments, or a decision of the supervisory authority. Any material change is notified thirty (30) days before it takes effect.

The Agreement is governed by French law. The Tribunal des activités économiques de Paris has sole jurisdiction.