Draft. This document is a template under legal review and is not yet in force. Highlighted fields are still to be filled in.

Data Processing Agreement and GDPR guide

This document has three parts:

  • Part A explains who is responsible for what when you use TellMyShop with Claude. It is information, not contract terms.
  • Part B is a data processing agreement under art. 28 GDPR. It applies only when we process personal data on your behalf, mainly during support.
  • Part C is a practical checklist for using TellMyShop in line with the GDPR, with a template entry for your record of processing activities.

"GDPR" means Regulation (EU) 2016/679. "Merchant" or "you" means the store owner (or the agency acting for the store owner) who uses the TellMyShop module. "We" means SEMownia Szymon Sanecznik, ul. Twarda 44, 00-831 Warszawa, tax ID (NIP) 6422931698.


Part A. Roles: who is responsible for what

A.1. You are the controller of your store's data

Your store holds personal data of your customers, newsletter subscribers and employees. You decide why and how that data is processed, so you are its controller (art. 4(7) GDPR). That does not change when you start using Claude to manage the store.

A.2. How data flows when Claude uses the module

  1. You ask Claude to do something in your store.
  2. Claude calls a tool of the TellMyShop module, which runs on your server.
  3. The module reads or changes data in your store and returns the result to Claude.
  4. The result is processed by Anthropic within your own Claude account.

Data goes from your store to your Claude account, and nowhere else. TellMyShop servers are not part of this flow and do not receive product, order or customer data in normal operation. Claude connects directly to the module on your server with an access token generated in the module; the token is not issued or checked by TellMyShop servers.

Your customers' personal data (for example names, email addresses, phone numbers and addresses) is masked before it is passed to Claude. Customer data is controlled by a separate switch, independent of the Blocks. For Service mode (Block 5), customer tables are excluded from SQL queries by default. TBC: plugin code: which fields and tools are masked, where the switch is and how the SQL exclusion works; the 0.3.0 code review found no tools returning customer data and confirmed masking of emails and phones in logs. LAWYER: check this wording once the code is confirmed.

A.3. Anthropic processes data under your agreement with Anthropic

The data that reaches Claude is processed by Anthropic under your agreement with Anthropic for your Claude plan. We are not a party to that agreement.

Anthropic offers individual plans and business plans under different terms. Before you let Claude see personal data from your store:

  • read Anthropic's current terms, privacy policy and, for business plans, its data processing addendum, and check what role Anthropic takes for your plan;
  • for business use involving personal data, we recommend a Claude business plan (for example Team or Enterprise) whose terms include a data processing agreement;
  • check the data-use settings in your Claude account (for example whether conversations may be used to improve models) and set them to match your privacy policy;
  • check where Anthropic processes data and which transfer mechanism applies.

We do not describe Anthropic's terms here because they can change and differ by plan. LAWYER: verify this section against Anthropic's terms at the time of publication.

A.4. TellMyShop is not your processor in normal operation

We license software that you install and run yourself. In normal operation we do not access, receive, store or otherwise process personal data from your store, so we are not your processor for that data.

We are the controller of our own customer data (your account, orders, invoices, licence check data), as described in the Privacy Policy.

We become your processor only when we process personal data from your store on your behalf. This happens mainly in support, when you:

  • send us logs, screenshots or exports that contain personal data;
  • send us a database dump or a copy of the store;
  • give us temporary access to your back office, server or database.

For these cases Part B applies.

A.5. Agencies

If you are an agency or freelancer using TellMyShop on a client's store, the client is usually the controller and you are their processor. If you use your own Claude account to work on the client's store, Anthropic acts under your agreement with Anthropic, so it may be your sub-processor. Make sure your data processing agreement with the client covers this. If you involve us in support for a client's store, we act as your sub-processor under Part B.


Part B. Data Processing Agreement (art. 28 GDPR)

B.1. Parties, conclusion and precedence

  1. This Data Processing Agreement ("DPA") is between the Merchant as controller (or as processor acting for its client) and SEMownia Szymon Sanecznik as processor (or sub-processor) ("Processor").
  2. The DPA forms part of the Terms of Sale and the EULA. It is concluded electronically when you accept those documents, and in any case when you first share personal data with us in support or give us access to your store (art. 28(9) GDPR allows electronic form). LAWYER: confirm conclusion mechanism, including for Audit edition users.
  3. If this DPA conflicts with other agreements between the parties on the protection of personal data, this DPA prevails.

B.2. Subject matter and when the DPA applies

The DPA applies when the Processor processes personal data of which the Merchant is the controller (or processor), in the course of:

a) technical support and handling complaints; b) analysing logs, screenshots, exports or database dumps provided by the Merchant; c) working in the Merchant's back office, server or database through temporary access granted by the Merchant; d) any other service the parties agree in writing that involves such data.

It does not apply to the licence check data or account data, which we process as controller.

B.3. Duration

The DPA applies for as long as the Processor holds or has access to personal data under section B.2, and in any case until that data is deleted or returned under section B.11.

B.4. Nature and purpose of processing

Nature: receiving, storing, viewing, searching, analysing, reproducing errors on a test copy, and deleting. Purpose: diagnosing and fixing problems with the module, answering the Merchant's support requests and handling complaints.

B.5. Data subjects and categories of data

Data subjectsCategories of personal data
customers of the Merchant's storeidentification and contact data (name, email, phone, delivery and billing addresses), customer account data (including password hashes in database dumps), order and payment status data (no full card numbers), IP addresses, messages
newsletter subscribersemail, consent data
employees and back-office users of the storename, email, role, login data, log entries
other persons whose data is stored in the storedata contained in the store's content and logs

No special categories of data (art. 9 GDPR) are expected. The Merchant must not send them unless strictly necessary and agreed in advance.

B.6. Processor's obligations

The Processor:

  1. processes personal data only on the Merchant's documented instructions, which are this DPA and the Merchant's support requests, unless EU or Polish law requires otherwise; in that case it informs the Merchant before processing unless the law forbids it;
  2. informs the Merchant immediately if, in its opinion, an instruction infringes the GDPR or other data protection law;
  3. ensures that persons authorised to process the data have committed to confidentiality;
  4. takes the technical and organisational measures required by art. 32 GDPR, at least those in Annex B1;
  5. uses sub-processors only under section B.7;
  6. taking into account the nature of processing, assists the Merchant in responding to data subject requests (chapter III GDPR) and forwards to the Merchant any request it receives directly, without answering it;
  7. assists the Merchant in meeting the obligations under art. 32 to 36 GDPR (security, breach notification, DPIA, prior consultation), taking into account the information available to it;
  8. notifies personal data breaches under section B.9;
  9. deletes or returns data under section B.11;
  10. makes available the information needed to demonstrate compliance and allows audits under section B.10;
  11. does not use the data for any other purpose, in particular not for training AI models, marketing or analytics;
  12. does not transfer the data outside the EEA except under section B.8.

B.7. Sub-processors

  1. The Merchant gives a general authorisation to use the sub-processors listed in Annex B2.
  2. The Processor informs the Merchant by email (or by a notice in the account and on this page) about any intended addition or replacement of a sub-processor at least 14 days in advance. The Merchant may object on reasonable data protection grounds within that period. If the parties cannot agree, the Merchant may stop sharing data with the Processor and ask for deletion of data already shared.
  3. The Processor imposes on each sub-processor data protection obligations equivalent to this DPA and remains liable to the Merchant for its sub-processors.

B.8. Transfers outside the EEA

The Processor transfers personal data outside the EEA only to countries with an adequacy decision (including US companies certified under the EU-US Data Privacy Framework) or under Standard Contractual Clauses, as indicated in Annex B2.

B.9. Personal data breaches

  1. The Processor notifies the Merchant of a personal data breach affecting data processed under this DPA without undue delay and in any case within 48 hours of becoming aware of it, by email to the Merchant's account address.
  2. The notification includes, as far as known at the time: the nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed, and a contact person. Information may be provided in stages.
  3. The Processor does not notify supervisory authorities or data subjects on the Merchant's behalf unless the Merchant asks it to.

B.10. Information and audits

  1. The Processor provides, on request, the information needed to demonstrate compliance with art. 28 GDPR, in particular a description of the measures in Annex B1.
  2. If that information is not sufficient, the Merchant may carry out an audit, itself or through an independent auditor bound by confidentiality, no more than once in 12 months (and additionally after a breach), with at least 30 days' notice, during business hours and without disrupting the Processor's business. Audits are carried out remotely by default, through questionnaires and documents. Each party bears its own costs. LAWYER: confirm cost allocation.

B.11. Deletion after support

  1. The Processor deletes personal data received under this DPA (logs, screenshots, dumps, copies of the store) no later than 30 days after the support case is closed, unless the Merchant asks for return before that date or the law requires retention.
  2. Temporary access credentials (back office, server, database) are not stored after the work is completed. The Merchant should disable or delete the temporary account; the Processor confirms in the support thread when it no longer needs access.
  3. Copies in backups are deleted when the backups are overwritten in the normal cycle (BACKUP_ROTATION_DAYS days) and are not restored in the meantime except to recover from a failure.
  4. On request, the Processor confirms deletion by email.

B.12. Merchant's obligations

The Merchant:

  1. ensures it has a legal basis for the processing and that sharing the data with the Processor is lawful;
  2. shares only the data needed to solve the problem, masked or pseudonymised where possible (for example a staging copy with anonymised customers);
  3. uses the secure channel agreed with support for files containing personal data, never public links;
  4. creates dedicated temporary accounts with minimal permissions for any access and removes them after the case is closed.

B.13. Liability

Each party is liable towards data subjects under art. 82 GDPR. Between the parties, liability under this DPA is governed by the liability provisions of the EULA (section 16), to the extent permitted by law. LAWYER: confirm whether the B2B liability cap should apply to data protection claims between the parties.

B.14. Final provisions

The DPA is governed by Polish law. Changes required by law or by a change in sub-processors are made under section B.7 or by publishing an updated version with 30 days' notice.

Annex B1. Technical and organisational measures

AreaMeasures
Access controlaccess to support data limited to named persons who need it; individual accounts; two-factor authentication on email, file storage and admin accounts; password manager; access removed when no longer needed
EncryptionHTTPS/TLS for all transfers; encrypted storage for files containing personal data; full-disk encryption on laptops and workstations
Data minimisationwe ask for masked data and anonymised copies first; we work on a local test copy rather than the live store where possible
Separationsupport data stored separately from our own customer database; never used for other purposes
Temporary accessonly accounts created by the Merchant, with minimal permissions; no copying of credentials into tickets or chat; confirmation when access is no longer needed
Logginglog of who accessed support files and when (LOGGING_TOOL) TBC
Deletiondeletion within 30 days after the case is closed; backups overwritten in a BACKUP_ROTATION_DAYS-day cycle
Devicesup-to-date operating systems and software, screen lock, antivirus where appropriate
Peoplewritten confidentiality commitments; instructions on handling support data
Incidentsincident procedure with 48-hour notification to the Merchant
Resilienceregular backups of our systems; providers with security certifications (e.g. ISO 27001 or SOC 2) where available

Annex B2. Sub-processors

Sub-processorPurposeLocationTransfer safeguard
MAILBOX_PROVIDER (e.g. Google Workspace)support mailbox and attachmentsLOCATIONSAFEGUARD
Cloudflare R2secure transfer and storage of larger files (dumps, store copies)LOCATIONSAFEGUARD
HELPDESK_PROVIDER (if used)support ticket systemLOCATIONSAFEGUARD
PASSWORD_MANAGER (if temporary credentials are shared)secure sharing of credentialsLOCATIONSAFEGUARD

TBC: final list. Note: if support staff use an AI assistant to analyse logs or dumps, that provider must be added here as a sub-processor, or such use must be excluded.


Part C. Checklist: using TellMyShop in line with the GDPR

C.1. Module settings

  • Keep customer data masking on. Switch it off only for a specific task that needs real customer data, and switch it back on afterwards. TBC: plugin code
  • Start in read-only mode and turn writes on only when you need them.
  • Keep the service connection and Blocks 3 to 5 off unless a developer needs them, and keep its IP allowlist short.
  • Keep Block 2 (commerce) off unless you need it.
  • Let Claude act as a dedicated employee account with minimal permissions. For content and SEO work, that profile does not need access to Customers or Orders.
  • Use read-only mode when you only need audits and reports.
  • Set a sensible hourly call limit.
  • In Claude, consider setting tools to ask before each call, at least at the start.

C.2. Claude account

  • For business use with personal data, use a Claude business plan whose terms include a data processing agreement.
  • Check the data-use settings in your Claude account (for example model improvement) and choose what fits your privacy policy.
  • Check where Anthropic processes data and the transfer mechanism.
  • Decide who in your team may connect Claude to the store, and use individual accounts.

C.3. Your documents

  • If unmasked customer data may reach Claude, update your privacy policy: say that you use an AI assistant provided by Anthropic to manage the store, which data may be processed, the legal basis (usually your legitimate interest in running the store efficiently), and any transfer outside the EEA.
  • Add an entry to your record of processing activities (template in C.5).
  • Assess whether a DPIA is needed. With masking on and catalogue work only, it is usually not; with large-scale access to unmasked customer data, assess it. LAWYER: confirm guidance.
  • Agencies: make sure your DPA with each client covers your use of Claude and TellMyShop, and lists Anthropic (your Claude account) as a sub-processor where relevant.

C.4. Support and incidents

  • When asking us for help, send masked logs, or reproduce the problem on a staging copy with anonymised customers.
  • For temporary access, create a separate employee account with minimal permissions and delete it afterwards.
  • If personal data is exposed (for example you switched masking off and shared a conversation), assess it as a possible personal data breach: as controller, you may need to notify the supervisory authority within 72 hours (art. 33 GDPR).
  • Keep regular backups of your store.

C.5. Template: record of processing activities entry

FieldExample entry (adapt it)
Name of processingManaging the online store with an AI assistant (Claude) through the TellMyShop module
ControllerYOUR_COMPANY, YOUR_ADDRESS, contact YOUR_PRIVACY_CONTACT
Purposeediting product, category and page content; SEO; store diagnostics; [if enabled: answering questions about orders and customers]
Legal basisart. 6(1)(f) GDPR: legitimate interest in running the store efficiently; [art. 6(1)(b) where the processing serves performance of contracts with customers]
Data subjectsstore customers, newsletter subscribers, employees (only if data is unmasked or in logs)
Categories of databy default masked customer data; if unmasked: names, email addresses, phone numbers, addresses, order data; employee names in logs
RecipientsAnthropic, as provider of Claude under YOUR_CLAUDE_PLAN terms; SEMownia Szymon Sanecznik only in support, under the TellMyShop DPA; hosting provider of the store
Transfers outside the EEAAnthropic: TRANSFER_MECHANISM_FROM_ANTHROPIC_TERMS
Retentionin the store: per your existing retention rules; in Claude: per your Claude account settings and Anthropic's terms; module change log: CHANGE_LOG_RETENTION TBC: plugin code
Security measurescustomer personal data masked before it reaches Claude TBC: plugin code; emails and phones masked in logs; read-only mode by default; service connection limited to allowlisted IPs; HTTPS only; only a hash of the access token stored; Claude acts as an employee with limited permissions; preview and confirmation of each change; change log and undo; hourly call limit; read-only mode available

PrestaShop is a registered trademark of PrestaShop SA. Claude is a trademark of Anthropic. TellMyShop is not affiliated with either.