StoreAgent

Data Processing Addendum

Last updated: 1 September 2026

This Data Processing Addendum (“DPA”) forms part of the StoreAgent Terms of Service (the “Agreement”) between Rymera Web Co Pty Ltd (ABN 51 604 474 213) trading as StoreAgent (“StoreAgent”, “we”, “us”) and the customer agreeing to the Agreement (“Customer”, “you”). It applies where StoreAgent processes Customer Personal Data on your behalf in the course of providing the Services.

If there is any conflict between this DPA and the rest of the Agreement in relation to the processing of Customer Personal Data, this DPA prevails.

1. Definitions

“Applicable Data Protection Law” means all laws relating to data protection and privacy that apply to a party’s processing under this DPA, including the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles; Regulation (EU) 2016/679 (the “GDPR”); the GDPR as incorporated into UK law by the Data Protection Act 2018 (the “UK GDPR”); and the California Consumer Privacy Act as amended by the CPRA (the “CCPA”).

“Customer Personal Data” means personal data or personal information within Store Data that StoreAgent processes on your behalf under the Agreement, as further described in Annex I.

“Store Data” has the meaning given in the StoreAgent Privacy Policy.

“Sub-processor” means a third party engaged by StoreAgent to process Customer Personal Data.

“Controller”, “processor”, “data subject”, “personal data”, “processing” and “personal data breach” have the meanings given in the GDPR. “Business”, “service provider”, “sell” and “share” have the meanings given in the CCPA.

2. Roles of the Parties

You are the controller of Customer Personal Data and StoreAgent is your processor. In respect of the CCPA, you are the business and StoreAgent is your service provider.

StoreAgent is an independent controller in respect of data it processes for its own purposes, including your account and billing records, Traffic Data, and the aggregated Usage Data described in the Agreement. That processing is governed by the StoreAgent Privacy Policy, not this DPA.

3. Scope of Processing

StoreAgent will process Customer Personal Data only:

(a) to provide, maintain, secure and support the Services in accordance with the Agreement and your documented instructions, including the instructions given through your configuration of the Services;
(b) as otherwise agreed in writing; or
(c) where required by law, in which case StoreAgent will inform you of that requirement before processing unless the law prohibits it.

StoreAgent will inform you if, in its opinion, an instruction infringes Applicable Data Protection Law.

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.

Model training. StoreAgent will not use Customer Personal Data to train, fine-tune or improve any AI model, and will not permit any Sub-processor to do so.

4. Connected AI Assistants

Where you enable Model Context Protocol access under §6.3 of the Agreement, requests pass through StoreAgent’s service on their way to your store. That is processing on your behalf and this DPA applies to it in full. StoreAgent records the connection, tool, outcome and time of each call, and does not record or retain the content of a request or its result.

The assistant you connect is a separate matter. You select that provider and hold the account with it, and it receives data under your agreement with it. That provider is not a StoreAgent Sub-processor and this DPA does not extend to what it does with that data. You are the controller of that disclosure and responsible for its lawfulness. The same applies to abilities registered by software other than StoreAgent: StoreAgent does not control what they do or what data they return, and you decide which to expose.

5. Your Obligations

You warrant that:

(a) you have a lawful basis for the processing you instruct StoreAgent to carry out, and have given all notices and obtained all consents required for it;
(b) the Customer Personal Data you provide, and your instructions, comply with Applicable Data Protection Law; and
(c) you will not use the Services to process special categories of personal data (as defined in Article 9 GDPR), government identifiers, payment card numbers, or health or financial data. You will also take reasonable steps to discourage your customers from submitting such data through the chat widget. StoreAgent’s Services are not designed for such data, and StoreAgent’s obligations under this DPA are calibrated accordingly.

6. Confidentiality

StoreAgent will ensure that every person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, and will limit access to those personnel who need it to provide the Services.

7. Security

StoreAgent will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. In doing so, StoreAgent will have regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing. Those measures are described in Annex II.

StoreAgent may update those measures from time to time provided the level of protection is not materially reduced.

8. Sub-processors

You give StoreAgent general authorisation to engage Sub-processors to process Customer Personal Data, including to add, replace and remove them from time to time as the Services develop. Annex III sets out the categories of Sub-processor StoreAgent currently engages. StoreAgent will identify the specific Sub-processor within each category, in writing, on request.

StoreAgent will:

(a) impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA;
(b) remain fully liable to you for each Sub-processor’s performance; and
(c) where it adds or replaces a Sub-processor that processes Customer Personal Data, give you at least ten (10) days’ notice by posting a notice in your StoreAgent account.

Changes that require no notice. No notice is required where StoreAgent changes a Sub-processor that does not process Customer Personal Data, replaces a Sub-processor with a service StoreAgent operates itself (which is not a Sub-processor), or removes a Sub-processor without replacement.

Urgent changes. Where a change must be made without delay — for example to maintain the security, integrity or continuity of the Services, or because a Sub-processor ceases to be available or acceptable — StoreAgent may make the change immediately and will notify you as soon as reasonably practicable afterwards.

Objection. If you are subject to the GDPR or UK GDPR, you may object to a new Sub-processor on reasonable data protection grounds by notifying StoreAgent in writing within ten (10) days of notice. The parties will discuss the objection in good faith. If StoreAgent cannot offer a reasonable alternative, your sole remedy is to terminate the affected Services and receive a pro-rata refund of prepaid fees for the unused term.

9. International Transfers

StoreAgent is established in Australia. Customer Personal Data is stored in the United States, and may transit its Sub-processors’ global networks in the course of being routed and served, as set out in Annex III.

Where StoreAgent transfers Customer Personal Data from the EEA, the United Kingdom or Switzerland to a country not subject to an adequacy decision, that transfer is governed by:

(a) the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this DPA by reference and completed as set out in Annex I and Annex III;
(b) for UK transfers, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, incorporated by reference; and
(c) for Swiss transfers, the SCCs with references to the GDPR read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as the competent authority.

For the purposes of the SCCs: the docking clause applies; the optional redress clause is not selected; the governing law and forum are those of Ireland; and the periodic audit interval in Clause 8.9 is as set out in §12 of this DPA.

Where StoreAgent discloses Customer Personal Data outside Australia, it will take steps reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles, as required by APP 8.

10. Assistance with Data Subject Rights

Taking into account the nature of the processing, StoreAgent will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests from data subjects exercising their rights under Applicable Data Protection Law.

The Services provide functionality allowing you to access, export, correct and delete Store Data directly. Where you cannot fulfil a request using that functionality, StoreAgent will provide reasonable assistance on request.

If StoreAgent receives a request directly from one of your customers, it will not respond to it substantively, and will promptly refer the individual to you.

11. Personal Data Breach

StoreAgent will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

StoreAgent will provide reasonable assistance with your own notification obligations, including under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth) and Articles 33 and 34 GDPR.

StoreAgent’s notification is not an acknowledgement of fault or liability.

12. Audits and Information

StoreAgent will make available to you the information reasonably necessary to demonstrate compliance with this DPA.

You may audit StoreAgent’s compliance no more than once in any twelve (12) month period, on at least thirty (30) days’ written notice, during business hours, subject to confidentiality obligations, and in a manner that does not unreasonably disrupt StoreAgent’s business. You may audit more frequently if required by a supervisory authority or following a personal data breach affecting your Customer Personal Data.

StoreAgent may satisfy an audit request by providing written responses to a reasonable security questionnaire, a description of the measures in Annex II as then implemented, and any third-party audit report or certification StoreAgent holds at the time of the request.

You will bear the cost of any audit unless it reveals a material breach of this DPA.

13. Data Protection Impact Assessments

StoreAgent will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority that you are required to carry out. That assistance is limited to matters relating to StoreAgent’s processing, and takes into account the information available to StoreAgent.

14. Deletion and Return

On termination or expiry of the Agreement, StoreAgent will delete or de-identify all Customer Personal Data within 90 days, except to the extent it is required by law to retain it. On written request made before the end of that period, StoreAgent will make Customer Personal Data available for export in a commonly used format.

Where StoreAgent retains Customer Personal Data because the law requires it, StoreAgent will isolate it, protect it from further processing, and delete it when the retention obligation ends.

Where Customer Personal Data persists in routine backup copies after it has been deleted from active systems, those copies are isolated from further processing, remain subject to this DPA, and are overwritten in the ordinary course of StoreAgent’s backup cycle.

15. California

In respect of personal information subject to the CCPA, StoreAgent acts as your service provider. StoreAgent:

(a) will not sell or share that personal information;
(b) will not retain, use or disclose it for any purpose other than the business purposes specified in the Agreement, including not for its own commercial purposes;
(c) will not retain, use or disclose it outside the direct business relationship between StoreAgent and you;
(d) will not combine it with personal information received from another source, except as permitted by the CCPA; and
(e) certifies that it understands and will comply with these restrictions.

16. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law, including a data subject’s rights under the Standard Contractual Clauses.

17. Term

This DPA takes effect when you accept the Agreement and continues until StoreAgent has deleted all Customer Personal Data in accordance with §14.


Annex I — Details of Processing

Roles. Customer is the controller; StoreAgent is the processor. For the purposes of the Standard Contractual Clauses, Customer is the data exporter and StoreAgent is the data importer.

Categories of data subjects

  • Visitors to and customers of the Customer’s online store who interact with the StoreAgent chat widget.
  • Authors of product reviews published on the Customer’s store.
  • The Customer’s own personnel who use the Services.

Categories of personal data

  • Chat conversation content — free-text messages from store visitors and the responses returned. Because the field is free text, a message may contain any personal data the visitor chooses to type, such as a name, email address, telephone number, postal address or order number. StoreAgent neither requires nor extracts these.
  • Session data — session identifier, the store’s domain, timestamps, and a store-side account number where the visitor is signed in. IP addresses and browser details are not stored as part of a conversation.
  • Order details retrieved during a chat — where a visitor supplies an order number: order, payment and delivery details, the delivery area, any note the customer left at checkout, and the store’s internal customer account number. Customer name, email address, telephone number and street address are excluded by design and never retrieved.
  • Connected assistant call records — where MCP access is enabled, a record of each call identifying the connection, the tool, the outcome and the time. These do not contain the content of a request or its result.
  • Store content processed into AI memory — product, page and post content and product reviews. Mostly not personal data, though review content and author names may be.
  • Customer account data — name, email address and account details of the Customer’s own personnel.

Special categories of personal data. None. Customer is instructed not to submit special category data (§5(c)).

Frequency of processing. Continuous, for the duration of the Agreement.

Nature and purpose of processing. Collection, storage, transmission, retrieval, generation of AI responses and content, semantic indexing and search, and deletion — all for the purpose of providing the Services described in the Agreement.

Duration of processing. For the term of the Agreement, plus the retention periods set out in the Privacy Policy and §14 of this DPA.

Competent supervisory authority (SCCs Clause 13). Where the Customer is established in an EU Member State, the competent supervisory authority is the supervisory authority of that Member State. Where the Customer is not established in the EU but is subject to the GDPR under Article 3(2) and has appointed a representative under Article 27, it is the supervisory authority of the Member State in which that representative is established. Where the Customer is not established in the EU, is subject to the GDPR under Article 3(2) and has not appointed a representative, it is the supervisory authority of the Member State in which the data subjects whose personal data is transferred are located.

For transfers subject to the UK International Data Transfer Addendum, the competent authority is the UK Information Commissioner’s Office. For transfers subject to the Swiss FADP, it is the Swiss Federal Data Protection and Information Commissioner.


Annex II — Technical and Organisational Measures

StoreAgent maintains the following technical and organisational measures to protect Customer Personal Data.

Encryption. Data in transit is encrypted using TLS 1.2 or above. All personal data is stored on managed platforms that encrypt data at rest using AES-256 or equivalent.

Access control and confidentiality. Access to production systems is role-based and granted on a least-privilege basis, reassessed when a person’s role changes, and revoked when their engagement ends. Multi-factor authentication is required for administrative access to the application platform and the database. Everyone authorised to process personal data is bound by a written confidentiality obligation.

Integrity and isolation. All API requests are authenticated and every privileged operation is subject to a permission check. Each customer’s data is isolated from every other customer’s. Production, staging and development environments are separated.

Availability and resilience. Production systems run on established managed cloud platforms with network-level protection, denial-of-service mitigation and rate limiting. Automated encrypted backups allow timely restoration of availability and access to personal data after an incident.

Testing and review. Changes are reviewed before release through an automated build and test pipeline. Third-party dependencies are automatically monitored for published vulnerabilities. The security of the Services is reviewed internally on an ongoing basis.

Incident response. StoreAgent maintains a process for identifying, containing, assessing and remediating personal data breaches, and for notifying affected customers as set out in §11 of this DPA.

Sub-processors. StoreAgent has written data protection terms with every Sub-processor and reviews a Sub-processor’s security posture before engaging it.


Annex III — Sub-processors

Category of Sub-processorPurposeLocation of processing
AI model providerGenerating chat responses, product content, summaries and embeddingsUnited States
Cloud infrastructure and hostingApplication compute, database, object storage, network security and DDoS mitigationUnited States and global edge network
Transactional emailAccount, billing and support email deliveryUnited States
Payment processingBilling information only — not Customer Personal DataUnited States

StoreAgent will identify the specific Sub-processor within each category, in writing, on request by a Customer, and will give notice of changes as set out in §8 of this DPA.

StoreAgent

PO BOX 4362
Gumdale QLD 4154
Australia

Our Brands

© 2026 Rymera Web Co Pty Ltd. All Rights Reserved. ABN 51 604 474 213. Privacy Policy · Terms of Service · Data Processing Addendum · Affiliate Disclosure