Data Processing Addendum
Effective September 29, 2026
This Data Processing Addendum (“DPA”) is part of the Terms of Service between VEWO LLC (“VEWO”) and the Client. It applies whenever VEWO processes personal data on the Client's behalf, including data received from accounts the Client connects.
1. Roles
The Client is the controller (or “business”). VEWO is the processor (or “service provider”). VEWO processes Client personal data only on the Client's documented instructions, which are the Terms, the Client's order and the Client's use of the services.
2. What we process
| Purpose | Providing the services the Client bought: research and reports, ad creative, social analysis, content, schema and the client portal. |
|---|---|
| People | The Client's staff who use the portal. The Client's customers only to the extent their data appears in order line items or aggregate metrics. |
| Data | Names, work email addresses and roles of portal users. Order line items and totals, product and content data, advertising and email performance metrics. VEWO does not request customer names, email addresses, phone numbers or addresses from Shopify. |
| Sensitive data | None is required, and the Client agrees not to send it. |
| Duration | The term of the Client's order, plus up to 30 days for deletion. |
3. VEWO's commitments
- Process Client personal data only to provide the services, and tell the Client if we believe an instruction breaks the law.
- Make sure everyone who processes it is bound by confidentiality.
- Apply the security measures in section 7.
- Collect and keep only the minimum data needed, and use it only for the purposes above.
- Not sell or share Client personal data, not use it for targeted advertising, not retain or use it outside our business relationship with the Client, and not combine it with data from other sources except as the services require. We will notify the Client if we can no longer meet these obligations.
- Not use Client data to train AI models.
- Help the Client respond to requests from individuals exercising privacy rights, and with any required assessments.
4. Sub-processors
The Client authorizes VEWO to use the sub-processors on our sub-processor list. VEWO binds each one to data protection obligations at least as protective as this DPA and remains responsible for them. We will update the list at least 30 days before adding a sub-processor. The Client may object on reasonable data protection grounds, and if we can't resolve the objection, the Client may end the affected service.
5. Security incidents
If VEWO confirms a breach of security that affects Client personal data, we will notify the Client without undue delay, and within 72 hours of confirming it. We will describe what happened, the data involved and the steps taken, and we will revoke any affected access tokens.
6. Deletion and return
When the services end, or when the Client asks, VEWO deletes the Client's connected-account tokens immediately and deletes or returns Client personal data within 30 days, unless the law requires us to keep it. We also act on platform deletion requests, such as Shopify's customer and shop redaction requests, within 30 days.
7. Security measures
- Encryption in transit (TLS) and at rest.
- Access tokens and keys encrypted with AES-256-GCM in our application, with keys held separately from the database.
- Each client's data kept separate, with database access rules that deny access by default.
- Staff access limited to people who need it, with an audit log of credential use.
- Short-lived platform tokens where the platform supports them, and least-privilege permissions.
- Error monitoring, backups through our hosting and database providers, and a written incident response process.
8. Information and audits
On reasonable request, and no more than once a year unless required by a regulator or after an incident, VEWO will provide information that shows compliance with this DPA, such as a description of our security measures and completed security questionnaires.
9. International transfers
VEWO and its sub-processors process data in the United States. Where the law requires it for personal data from the EU, UK or Switzerland, the parties agree to the Standard Contractual Clauses (controller to processor), which are incorporated by reference.
10. Precedence
If this DPA conflicts with the Terms of Service about personal data, this DPA controls.
Contact
VEWO LLC · Phoenix, Arizona · hello@vewo.ai