1. Scope and roles
This DPA applies to personal data BRDG processes on Customer's behalf in providing BRDG (“Customer Personal Data”). Customer is the controller and BRDG is the processor. If Customer is itself a processor for another controller, BRDG acts as Customer's subprocessor. Each party will comply with the data-protection laws applicable to its role.
Capitalized terms not defined here have the meaning in the agreement. “Data Protection Law” includes applicable privacy and data-protection law governing the processing, such as the GDPR, UK GDPR, and U.S. state privacy laws where applicable.
2. Customer instructions
BRDG will process Customer Personal Data only to provide, secure, support, and improve the service in accordance with the agreement, Customer's documented configuration and commands, and applicable law. The agreement, enabled Shopify scopes, approved tool manifests, integration configuration, support requests, and authorized API calls are documented instructions.
BRDG will notify Customer if, in our reasonable opinion, an instruction violates applicable Data Protection Law, unless law prohibits notice. We may suspend the affected processing while the parties resolve the issue. Customer is responsible for the lawfulness, accuracy, quality, and minimization of its instructions and Customer Personal Data.
3. Processing details
| Subject matter | Shopify commerce context, governed storefront decisions, experiments and deployments, outcome measurement, identity linkage, submissions, integrations, and support. |
|---|---|
| Duration | The term of the service plus the limited period needed for deletion, protected backups, security, dispute resolution, and legal retention. |
| Data subjects | Customer personnel and agents; storefront visitors, shoppers, leads, customers, and recipients selected by Customer. |
| Data categories | Account and contact details; pseudonymous identifiers; device, page, consent, and interaction data; catalog, order, and attribution data; declared submission fields; support and audit records. |
| Operations | Collection, validation, encryption, organization, storage, retrieval, analysis, transmission, attribution, restriction, deletion, and de-identification. |
| Sensitive data | Not intentionally required. Customer must not provide special-category, precise health, government identifier, financial-account, or similarly sensitive data unless BRDG has expressly agreed in writing and appropriate safeguards are configured. |
4. Confidentiality and personnel
BRDG will limit access to personnel and contractors who need Customer Personal Data to perform the service. Those people are bound by confidentiality obligations and receive appropriate privacy and security guidance. BRDG remains responsible for their compliance with this DPA.
5. Security measures
BRDG maintains measures appropriate to the risk, including as applicable:
- encryption in transit and encryption of designated secrets and contact fields at rest;
- shop-scoped authorization, least-privilege credentials, role and scope enforcement, and separation of raw shopper PII from agent-facing interfaces;
- audit logs, input and contract validation, deterministic safety gates, rate limits, and operational monitoring;
- backups, queue recovery, change control, vulnerability remediation, and incident-response procedures appropriate to the service; and
- consent-aware storefront storage, redaction workflows, deletion controls, and vendor due diligence.
Customer is responsible for secure endpoint configuration, credential management, user and agent permissions, lawful storefront notices and consent, and the security of Customer's own themes, tools, integrations, and systems.
6. Subprocessors
Customer authorizes BRDG to use the providers listed on our Subprocessors page. BRDG will impose data-protection obligations appropriate to the services each subprocessor performs and remains responsible for their performance to the extent required by Data Protection Law.
We will keep the current list publicly available and provide additional notice of a new subprocessor where the agreement or applicable law requires it. Customer may object on reasonable data-protection grounds by contacting us promptly. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may end the affected feature or service as the agreement permits.
7. Data-subject requests
Taking into account the nature of processing, BRDG will provide reasonable assistance for access, correction, deletion, portability, objection, or restriction requests. Shopify's customer-data request, customer-redaction, and shop-redaction webhooks are part of this workflow. If BRDG receives a request about Customer Personal Data directly, we will refer it to Customer unless law permits or requires us to respond.
8. Assistance and personal-data incidents
BRDG will provide reasonable information and assistance for Customer's data-protection impact assessments, regulator consultations, and compliance duties, considering the nature of the processing and information available to us.
BRDG will notify Customer without undue delay after confirming a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a “Personal Data Breach”). Notice will include available information reasonably needed for Customer's obligations and does not constitute an admission of fault. Customer is responsible for notifications relating to Customer's systems, credentials, tools, or instructions.
9. Return and deletion
During the service, Customer may use available export and deletion features or contact us for assistance. At termination or on a lawful instruction, BRDG will delete or return Customer Personal Data, unless applicable law requires retention. Deletion from protected backups may occur through the ordinary backup lifecycle; retained data remains protected and isolated from routine use.
10. Audits
On reasonable written request, BRDG will provide information necessary to demonstrate compliance with this DPA. If that information is insufficient and Data Protection Law gives Customer an audit right, Customer may conduct an audit no more than once annually, unless a confirmed incident or regulator requires more, with reasonable notice, confidentiality, minimal operational disruption, and reimbursement of reasonable costs. Audits may not expose another customer's data, security-sensitive information, or third-party confidential material.
11. International transfers
BRDG may process Customer Personal Data in countries outside its origin. Where a restricted transfer requires a mechanism, the applicable European Commission Standard Contractual Clauses or UK transfer addendum are incorporated as required, with Customer as data exporter and BRDG as data importer. The processor modules apply according to the parties' roles, and this DPA supplies the processing description and safeguards. BRDG will use supplementary measures where reasonably necessary.
12. CCPA/CPRA service-provider terms
For personal information subject to the CCPA/CPRA, BRDG acts as a service provider or contractor. We will not sell or share Customer Personal Data, retain, use, or disclose it outside the business purposes in the agreement, or combine it with personal information from another source except as permitted by law. BRDG will notify Customer if we determine we can no longer meet these obligations, and Customer may take reasonable steps to stop and remediate unauthorized use.
13. Order of precedence and contact
If this DPA conflicts with the agreement on processing Customer Personal Data, this DPA controls. Standard Contractual Clauses control over conflicting terms where they apply. All other agreement terms, including liability limits, remain in effect. DPA and privacy questions can be sent to hello@getbrdg.ai.