← Terms of Service

Data Processing Addendum

1. Parties & Roles

This Addendum forms part of the Agreement between PERSONAIZER LLC (“Processor”) and the customer (“Controller”). For end-user personal data processed through the Controller's personas/assistants, the Controller is the data controller and PERSONAIZER is the data processor. For PERSONAIZER's own account, billing, and security data, PERSONAIZER is the controller (governed by its Privacy Policy, not this Addendum).

2. Subject Matter, Duration, Nature & Purpose

PERSONAIZER processes end-user personal data solely to provide the Service — operating AI personas/assistants, delivering replies, enabling human-agent takeover, and retaining conversation history as configured — for the duration of the Agreement, and only on the Controller's documented instructions (the Agreement, this Addendum, and the Controller's configuration of the Service constitute those instructions).

3. Categories of Data & Data Subjects

  • Data subjects: the Controller's end users (website/app visitors; shoppers on the Controller's Shopify store or WordPress site; people who message the Controller's connected Facebook Page or Instagram account).
  • Personal data: conversation content (free text, transcribed speech); messaging-platform sender identifiers (PSID/IGSID) and timestamps; contact details an end user provides (name, email, phone); technical data (IP address, device/usage) where applicable; for a signed-in shopper or site user, the name, email and phone the Controller's own store or site passes to the widget, when the Controller has turned that on. No special-category data is intentionally processed, and the Controller agrees not to configure personas to solicit it.

4. Processor Obligations (Art. 28(3))

PERSONAIZER shall: (a) process only on the Controller's documented instructions, including for international transfers; (b) ensure personnel are bound by confidentiality; (c) implement the technical and organizational measures in Annex II; (d) respect the sub-processor conditions in §5; (e) assist the Controller, taking into account the nature of processing, in responding to data-subject-rights requests (§6); (f) assist with security, breach notification, and DPIAs (§7–8); (g) at the Controller's choice, delete or return end-user personal data at the end of the Agreement (§9); and (h) make available information necessary to demonstrate compliance and allow for audits (§10).

Where the Controller connects a Shopify store and turns on “Save chat contacts as Shopify customers”, PERSONAIZER writes contact details an end user leaves in the chat to that store's customer list — the Controller's own system, on the Controller's instruction; Shopify is not a PERSONAIZER sub-processor for this.

5. Sub-processors

The Controller provides general authorization for PERSONAIZER to engage the sub-processors listed in Annex III. PERSONAIZER imposes data-protection obligations on each sub-processor no less protective than this Addendum, and remains liable for their performance. PERSONAIZER will give at least 30 days' notice of any new or replacement sub-processor (via a sub-processors page or email), during which the Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected Service.

6. Data-Subject Rights

PERSONAIZER provides functionality enabling the Controller to access, export, correct, and delete an end user's data (including an operator action that erases a specific visitor's data, and deletion by the end user's provided contact details), and assists with requests PERSONAIZER receives directly by acting on the Controller's instructions.

7. Personal-Data Breach

PERSONAIZER notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's end-user data, with the information the Controller reasonably needs to meet its Art. 33–34 obligations, and reasonable assistance with investigation and mitigation.

8. DPIA Assistance

PERSONAIZER provides reasonable assistance with the Controller's data-protection impact assessments and prior consultations, given the information available to PERSONAIZER.

9. Deletion / Return on Termination

On termination, PERSONAIZER deletes or (at the Controller's election) returns the end-user personal data, and deletes existing copies unless retention is required by law. Conversation transcripts are in any case deleted within 90 days in the ordinary course; backups age out within their cycle.

10. Audit

PERSONAIZER makes available information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, by the Controller or an auditor it mandates, on reasonable notice and subject to confidentiality (responding to security questionnaires and providing available reports/certifications satisfies routine requests).

11. International Transfers

Primary processing is in the EEA. Where data is transferred to a third country (the US sub-processors in Annex III, and access from Georgia), the parties rely on the EU Standard Contractual Clauses (incorporated by reference, with PERSONAIZER as data importer/processor) or another valid Art. 46 mechanism.

12. General

This Addendum is governed by the laws of Georgia, and the courts of Tbilisi have exclusive jurisdiction over any dispute arising from it — except that the Standard Contractual Clauses are governed by the law of Ireland and disputes under them are resolved by the courts of Ireland, as those Clauses require. Each party's liability under this Addendum is subject to the limitations of liability in the Agreement. The Controller accepts this Addendum by accepting the Terms. In case of conflict on data protection, this Addendum prevails over the Agreement.

Annex I — Processing Details

As described in §2–3 above.

Annex II — Technical & Organizational Measures

EEA data residency (Azure Sweden Central); encryption at rest (AES-256) and in transit (TLS 1.2+); role-based access control and managed-identity infrastructure auth; tenant isolation; 90-day conversation-transcript retention with automated purge; per-visitor and per-account deletion capability; IP-masked telemetry (90-day retention); a breach runbook and data-loss-prevention measures.

Annex III — Approved Sub-processors

  • Microsoft Azure (Azure OpenAI, Speech, AI Search, Vision; infrastructure) — Sweden Central, EEA
  • Google Cloud (Vertex AI / Gemini, Cloud Speech) — Netherlands, EEA
  • Brave Search — US
  • Cohere — US
  • Freepik — EU
  • OpenAI (image generation) — US
  • Meta Platforms (Messenger/Instagram delivery) — US
  • Google (authentication) — US
  • Flitt / TBC Bank (billing) — Georgia

Contact

For questions about this Addendum, please contact us at legal@personaizer.com

Version 1.0 · Last updated: 2026-09-29