Skip to content

Data Processing Agreement

Applies to every merchant using Reply Desks. Accepted when you create a workspace or connect a store.

1. Roles

You (the merchant) are the controllerof your customers' personal data. Reply Desks is the processor. We process personal data only on your documented instructions (in practice, delivering the support features you use) and never for our own purposes.

2. Subject matter and duration

We process customer support conversations and the Shopify order and customer data needed to answer them, for as long as your workspace is active. Processing ends when you disconnect the store, delete the workspace, or Shopify sends a redaction request.

3. Categories of data and data subjects

Data subjects: your customers, and your own staff who use the app.
Data: name, email address, phone number, shipping and billing address, order and fulfilment history, support messages and their attachments, and the actions your agents take on a ticket.

4. Our obligations

  • Process only on your instructions, and for no other purpose.
  • Keep personal data confidential and limit access to people who need it to operate the service.
  • Apply appropriate technical and organisational measures: encryption in transit and at rest, encrypted credentials, role-based access enforced server-side, tenant isolation, and logging of access to personal data.
  • Never sell personal data, share it with advertisers, or use it to train AI models.
  • Assist you in responding to data subject requests, and in meeting your own security and breach obligations.

5. Sub-processors

We use Railway (hosting and database), Cloudflare (DNS and edge), Resend (outbound email) and Anthropic (AI reply drafting, on plans that include it and only at an agent's request). Each is bound by equivalent obligations. We will give notice before adding a sub-processor that processes customer personal data, and you may object.

6. International transfers

Where personal data leaves the EEA or the UK, transfers rely on the Standard Contractual Clauses or an adequacy decision, as applicable to the sub-processor concerned.

7. Security incidents

We notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with what happened, which data was involved, what we have done, and what you should do. That timing is set so it supports your own notification duty rather than consuming it.

8. Retention and deletion

Closed tickets are deleted once they pass your workspace's retention window (default 24 months; set it in Settings → Preferences, or turn deletion off if you are under a legal hold). Open tickets are never deleted by retention. We honour Shopify's customers/redact and shop/redact requests, and delete your data on request when you leave.

9. Audit

On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information needed to demonstrate compliance with this agreement.

10. Contact

Data protection queries and security reports: [email protected]. See also our privacy policy.