Data Processing Agreement
Last updated: 2026-09-19
These are the processor terms required by Article 28(3) GDPR. They form part of the Terms of Service and take effect when you install the app — you do not need to sign or return anything. If your organisation requires a countersigned copy, email gimbernat13@gmail.com and we will provide one.
1. The parties
Controller: you, the merchant that installed the app.
Processor: Capyo, operated by an individual developer.
Operator legal name and address: see the Privacy Policy.
Shopify is a separate processor for you, under Shopify's own data processing addendum, which governs the Shopify-to-merchant relationship and is unaffected by this document. Store data we process reaches us through Shopify; the query set is sent onward to OpenAI and Perplexity by us, through the app's own API access, as described in section 8.
2. Subject matter, duration, nature and purpose
- Subject matter: providing the Capyo: AI Visibility & GEO Shopify app — the llms.txt template, the six validator checks, AI referral counting through the Web Pixel, the query set, the weekly runs on OpenAI search and Perplexity, the report and the alerts.
- Duration: from installation until the app is uninstalled and the deletion in section 11 completes.
- Nature of processing: collection from Shopify's API and from your storefront's Web Pixel, storage, structured retrieval, transmission of the query set to the two engines, report generation, and erasure.
- Purpose: solely to deliver the app to you and keep it secure. Never for our own marketing, never for profiling, never for sale.
3. Types of personal data
Most of what the app stores is store configuration, template state, query and answer data, and referral counts rather than personal data about an identifiable person. Where it is personal data, it is one of these kinds:
- Business-contact and account data about you and your staff: the shop's
.myshopify.comdomain, the Shopify OAuth access token, the merchant email address, and store configuration (plan, domains, locales, vendor names, the weekly schedule, template state and checksums). - Query and answer data about your store: the query texts, and the answers returned — engine, outcome, matched URL, citation URLs and titles, and an excerpt of at most 500 characters. These describe your products and your store; they do not identify your customers.
- AI referral counts: per day and assistant, visits, orders and revenue; a dedupe row per visit holding only the day and a random id the pixel mints for it; and one row per referred order with the order id, assistant, value and currency. None of this identifies a customer as a person.
Excluded by design: customer name, email address, postal address, phone number or customer id; IP addresses and user agents; page URLs; payment or card data; full AI answers beyond the 500-character excerpt; merchant API keys — the app requests none, because it asks the engines with its own API access.
Transient IP handling. The Web Pixel sends no IP address or user agent; the
/collect endpoint sees the request's IP address the way any web request does, uses it
only to apply its rate limit, holds it in memory for that request, and never writes it to disk or
to the database.
4. Categories of data subjects
The merchant and the merchant's staff and collaborators who use the app. Storefront visitors appear only in day-level referral counts keyed by a random per-visit id that identifies no one; no record is kept that identifies a visitor. The engines' answers are about your store, not about a person.
5. Your instructions
We process personal data only on your documented instructions. Installing the app, writing or removing the template, saving a query set, and choosing a paid plan are those instructions; the Privacy Policy describes their scope. Sending your query set to OpenAI and Perplexity is part of the weekly report you enable on Growth and Pro; the app asks through its own API access, and no credentials of yours are involved. You can change the instruction at any time by editing or removing queries, downgrading, or uninstalling. Further or different instructions can be sent to gimbernat13@gmail.com; if one would require disproportionate effort or a change to the service, we will say so rather than silently not do it.
If EU or member-state law obliges us to process beyond your instructions, we will tell you before doing so, unless that law forbids telling you. If we believe an instruction infringes the GDPR, we will inform you.
6. Confidentiality
Access is limited to the operator, who is bound by a duty of confidentiality that survives the end of this agreement. There are no other staff. Should that change, anyone given access will be bound by an equivalent written obligation before receiving it.
7. Security measures (Art. 32)
- TLS on every connection to the app and to this website; no plaintext endpoint exists.
- The database is closed to the public internet: it accepts PostgreSQL connections only from the application server, over password authentication (scram).
- Shopify access tokens are stored only in that database and are never logged or displayed.
- Administrative access to server and database is limited to the operator, over SSH with key authentication.
- Shopify webhooks are verified by HMAC signature before any action is taken.
- Minimum scopes:
read_products,read_themes,write_themesand the Web Pixel. Noread_ordersand no protected customer data. - The Web Pixel sends no IP address or user agent;
/collectuses an IP only to apply its rate limit, in memory, and stores none of it.
We hold no ISO 27001 or SOC 2 certification and do not claim application-level encryption at rest beyond what the hosting providers apply to their own storage.
8. Sub-processors and the engines
You give general authorisation for the sub-processors below.
| Sub-processor | Company country | Purpose | Where the servers are |
|---|---|---|---|
| Shopify International Ltd | Ireland | Platform, source of all store data, and billing | Per Shopify's own DPA |
| OpenAI | United States | Runs the weekly query set through the app's own OpenAI API key and returns answers and citations — paid plans only | United States |
| Perplexity | United States | Runs the same query set through the app's own Perplexity search API key and returns answers and citations — paid plans only | United States |
| Resend | United States |
Weekly email digest to the merchant's own address — active only when email sending is
enabled (EMAIL_ENABLED=on); until then no email code path runs and it receives
nothing
| United States |
| Hostinger International Ltd | Cyprus | Application hosting (virtual server) | United States |
| netcup GmbH | Germany | Database hosting (PostgreSQL) | United States |
| GitHub, Inc. | United States | Hosting of this public website only; no app data reaches it | GitHub Pages infrastructure |
The engines run the queries through the app's own API access and return answers and citations; they receive the query text and the store's country code, never customer data. We remain fully liable to you for the performance of the sub-processors listed above that we do engage directly.
Changes. Before a new sub-processor starts processing, a listed one is replaced, or a hosting location moves — including the email digest being switched on — we update this table with a new date at the top of the page. You may object on reasonable data-protection grounds by writing to gimbernat13@gmail.com; if we cannot accommodate the objection, you may uninstall the app and stop paying, with a pro-rata refund of any prepaid period through Shopify.
9. International transfers (GDPR Chapter V)
Merchant data processed through the app is stored on servers located in the United States: the application server and the PostgreSQL database. The companies operating them are European (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing takes place outside the EEA.
Those transfers rely on the Standard Contractual Clauses included in the providers' data processing terms, together with the providers' technical and organisational security commitments and the measures in section 7. The query set sent to OpenAI and Perplexity, and any future email digest through Resend, likewise involve processing in the United States.
The app stores no end-customer personal data, so nothing about your shoppers crosses a border. The transferred data is the store configuration, template state, validator results, query set, answers and excerpts, referral counts and orders, usage counters and access token described in section 3.
Hosting locations may change. Any such change, or a new sub-processor, is announced on this page before it takes effect, under the notice rule in section 8. Shopify's own transfers are governed by its DPA and transfer mechanisms.
10. Assistance to you
- Data-subject requests. If a data subject contacts us directly about data we process for you, we forward it and do not answer on your behalf. We help you respond, taking into account the nature of the processing and the information available to us.
- Security incidents. We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with what we know: what happened, which categories of data, likely consequences, and the measures taken.
- DPIAs and prior consultation. We provide the information you reasonably need for an assessment under Art. 35 or a consultation under Art. 36.
11. Deletion at the end of the agreement
Sessions are deleted immediately on the app/uninstalled webhook, and queued jobs for
your shop are cancelled. All remaining data about your shop is deleted when Shopify sends the
shop/redact webhook, which deletes every row for the shop in every table, or earlier
if you ask us in writing. Referral dedupe rows older than 2 days and runs and answers older than
12 months are pruned daily while the app is installed.
The llms.txt template is not Capyo data; it lives in your theme. One click in the app removes it, and on uninstall the app makes one attempt to remove it — but Shopify normally revokes access before the uninstall webhook, so remove the template before uninstalling if you do not want it to stay. If left behind, it keeps working: it is plain Liquid with no connection to this app.
12. Audit
On written request we provide the information needed to demonstrate compliance with Article 28 — the current sub-processor list, the security measures in section 7, the data model, and answers to a reasonable security questionnaire — once per twelve months, or more often after a breach affecting your data or where a supervisory authority requires it. Because the service is small and single-tenant per shop, we do not host on-site audits; where a controller's law requires an inspection, we will agree a proportionate remote alternative in good faith.
13. Order of precedence
Where this document conflicts with the Terms of Service on a matter of personal-data processing, this document wins. The GDPR wins over both.
14. Contact
gimbernat13@gmail.com. See also the Privacy Policy and the Terms of Service.