Data Processing Agreement
Applies to every merchant using Reply Desks. Accepted when you create a workspace or connect a store.
1. Roles
You (the merchant) are the controllerof your customers' personal data. Reply Desks is the processor. We process personal data only on your documented instructions (in practice, delivering the support features you use) and never for our own purposes.
2. Subject matter and duration
We process customer support conversations and the Shopify order and customer data needed to answer them, for as long as your workspace is active. Processing ends when you disconnect the store, delete the workspace, or Shopify sends a redaction request.
3. Categories of data and data subjects
Data subjects: your customers, and your own staff who use the app.
Data: name, email address, phone number, shipping and billing address, order and fulfilment history, support messages and their attachments, and the actions your agents take on a ticket.
Data: name, email address, phone number, shipping and billing address, order and fulfilment history, support messages and their attachments, and the actions your agents take on a ticket.
4. Our obligations
- Process only on your instructions, and for no other purpose.
- Keep personal data confidential and limit access to people who need it to operate the service.
- Apply appropriate technical and organisational measures: encryption in transit and at rest, encrypted credentials, role-based access enforced server-side, tenant isolation, and logging of access to personal data.
- Never sell personal data, share it with advertisers, or use it to train AI models.
- Assist you in responding to data subject requests, and in meeting your own security and breach obligations.
5. Sub-processors
We use Railway (hosting and database), Cloudflare (DNS and edge), Resend (outbound email) and Anthropic (AI reply drafting, on plans that include it and only at an agent's request). Each is bound by equivalent obligations. We will give notice before adding a sub-processor that processes customer personal data, and you may object.
6. International transfers
Where personal data leaves the EEA or the UK, transfers rely on the Standard Contractual Clauses or an adequacy decision, as applicable to the sub-processor concerned.
7. Security incidents
We notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with what happened, which data was involved, what we have done, and what you should do. That timing is set so it supports your own notification duty rather than consuming it.
8. Retention and deletion
Closed tickets are deleted once they pass your workspace's retention window (default 24 months; set it in Settings → Preferences, or turn deletion off if you are under a legal hold). Open tickets are never deleted by retention. We honour Shopify's
customers/redact and shop/redact requests, and delete your data on request when you leave.9. Audit
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information needed to demonstrate compliance with this agreement.
10. Contact
Data protection queries and security reports: [email protected]. See also our privacy policy.