Legal and trust

Data Processing Addendum

These data-processing terms apply when Hello Marky Chat processes personal data for a business customer.Last updated 30 August 2026

1. Parties and scope

This Data Processing Addendum forms part of the Terms of Service between the customer (“Controller” or “Merchant”) and Hello Marky Chat (“Processor”). It applies to personal data that the customer submits to Hello Marky Chat or directs us to obtain from connected services, including Shopify protected customer data.

2. Processing instructions and purpose

We process personal data only on documented instructions in the Terms, this Addendum, the customer’s product settings, and support requests. Processing is limited to providing and securing chat, lead capture, customer-requested support, enabled integrations, troubleshooting, privacy-request handling, and legal compliance. We will notify the customer if an instruction appears unlawful unless prohibited by law.

3. Data and people

Data may include customer and visitor identifiers, contact details, conversation content, marketing-preference evidence, order support details, technical records, and account-user information. Data subjects may include the customer’s shoppers, prospects, website visitors, channel users, staff, and contractors. The nature and duration of processing follow the enabled features and the retention periods in our Privacy Policy.

4. Confidentiality and security

We restrict personal-data access to authorised personnel with a business need and confidentiality obligations. We maintain technical and organisational safeguards appropriate to risk, including encrypted transport, provider encryption at rest and for backups, encrypted integration credentials and temporary order summaries, multi-factor staff authentication, role-based access, logging, rate limits, production/test separation, retention enforcement, and incident-response procedures.

5. Subprocessors and international transfers

The customer authorises subprocessors needed to operate the service, including hosting, database, storage, cache, AI, email, observability, payment, and customer-selected integration providers described in our Privacy Policy. We remain responsible for their processing to the extent required by applicable law and use appropriate contractual safeguards for international transfers.

6. Assistance and rights requests

Taking into account the nature of processing, we provide reasonable assistance with access, correction, deletion, restriction, portability, objection, consent withdrawal, security, impact assessments, and regulator consultations. Shopify privacy webhooks are authenticated and handled through a deadline-tracked workflow. Contact [email protected] for assistance.

7. Security incidents

We will notify the customer without undue delay after confirming a personal-data breach affecting customer data, provide available information needed for legal obligations, take reasonable containment and remediation steps, and preserve relevant evidence. Notification is not an admission of fault.

8. Return and deletion

On verified request or termination, we delete or return customer personal data unless retention is required by law. Production data is subject to automated retention limits; encrypted backup copies expire through the configured backup rotation. A customer should export required information before account deletion.

9. Demonstrating compliance

We make available information reasonably necessary to demonstrate compliance and will cooperate with a proportionate audit or assessment, subject to confidentiality, security, scope, and cost arrangements. Independent certifications are not claimed unless listed in writing.

10. Priority and contact

If this Addendum conflicts with the Terms on processing personal data, this Addendum controls. Privacy questions and requests may be sent to [email protected].