Processor: the operator of Salestino, established in Poland — OWNER: legal name, address, NIP (“Salestino”).
Controller: the merchant who installs the Salestino app on a Shopify store (“Merchant”), wherever that shop is registered.
This addendum forms part of the Terms of Service. If they conflict on the processing of personal data, this addendum prevails.
Salestino provides an AI sales and support agent and a helpdesk for the Merchant’s Shopify store. In doing so Salestino processes personal data of the Merchant’s customers and of the Merchant’s staff on the Merchant’s documented instructions: the installation of the app, the configuration the Merchant saves (plans, action limits, appearance, mailboxes), and the messages those people send through the widget or email.
The Merchant is the controller of store-customer data. Salestino is the processor. Salestino is the controller of the waitlist on salestino.com and of the Merchant’s own account data; that processing is described in the privacy policy and is outside this addendum.
Salestino processes under GDPR because it is established in Poland (Art. 3(1)). That does not change if the Merchant is registered in the United States or elsewhere. The Merchant remains responsible for the law that applies to them as controller — GDPR if they are in the EEA, UK GDPR, US state privacy statutes, their own privacy policy and their Shopify obligations.
Salestino processes personal data only on the Merchant’s documented instructions, unless Union or Member State law requires otherwise. The Merchant’s instructions are: provide the features of the installed plan; look up orders the visitor has verified; prepare the write-actions the Merchant has enabled and present them to the Merchant’s staff for execution — Salestino does not carry any of them out on its own initiative; deliver helpdesk mail the Merchant sends; honour Shopify’s customers/data_request, customers/redact and shop/redact webhooks.
Salestino will inform the Merchant if an instruction, in its opinion, infringes GDPR or other applicable data-protection law, and will not follow that instruction until the Merchant confirms or amends it.
The product is not designed to collect special-category data. A customer may type it into a message. It is stored as message content and is subject to the same retention and erasure as any other message. The Merchant is responsible for their own policy on that.
Nature: storage, retrieval, disclosure to the Merchant’s staff, transmission to subprocessors listed below, generation of a suggested reply, and preparation of order actions for the Merchant’s own staff to execute. Salestino performs no order action automatically.
Purpose: provide the Salestino app to the Merchant. No other purpose. No sale. No cross-merchant profiling. No training of Salestino’s own model. Prompts sent to a model host carry an instruction that the host must not retain them for training.
Duration: for as long as the app is installed, then as in clause 11. Retention while installed is in the privacy policy (orders are not stored at all; conversations, threads and action records 24 months; verifications 90 days; visit beacons 90 days; access log 24 months; spam 30 days).
Salestino ensures that people authorised to process the data are bound to confidentiality. Dashboard seats are owner or agent. Only the owner can change plan, action limits, sending domain or storefront appearance. Reads of a customer’s thread or order history are written to an access log by identifier, not by copying the data. Production and test data are kept separate.
Taking into account the state of the art, the cost of implementation, and the nature of the data (support messages and order records of an SMB store), Salestino implements:
Backups of the production database, once production exists, will be encrypted. OWNER: name the backup product and the encryption guarantee after 8.8.
The Merchant authorises the subprocessors listed in the privacy policy’s processor table, as updated on that page. Salestino will give the Merchant prior notice of a replacement or addition (email to the shop contact, and this page) and a reasonable window to object. Objection that cannot be accommodated is resolved by the Merchant uninstalling the app, which stops the processing.
Each subprocessor is bound to data-protection obligations no less protective than this addendum, in particular as regards the purpose limitation and the training prohibition on model hosts.
The Processor is established in Poland. A disclosure of personal data to a subprocessor outside the EEA is a transfer under GDPR Chapter V. Several subprocessors listed in the privacy policy are in the United States. OWNER + legal: name the mechanism before production holds this data — standard contractual clauses, a Data Privacy Framework certification, or an adequacy decision. Do not claim any of those until the signed papers exist.
Salestino assists the Merchant, at the Merchant’s request and considering the nature of the processing, with:
The Merchant remains responsible for answering their customer and for notices they owe a supervisory authority.
On uninstall, Salestino stops processing and keeps the store’s data for 30 days so a reinstall is not a blank slate, then deletes it. Shopify’s shop/redact webhook (typically 48 hours after uninstall) deletes immediately, including files and the sending-domain claim. A customers/redact webhook anonymises that person’s content in place and deletes their files, their AI drafts and the visit rows keyed to their device.
A customers/data_request webhook is the return of the data: everything Salestino holds for that person, mailed to the shop owner as JSON for the Merchant to forward.
The access log survives a person-level redaction because it stores identifiers only; after redaction those identifiers no longer resolve to the person. It is deleted with the shop.
Salestino will make available the information necessary to demonstrate compliance with this addendum and will allow audits, including inspections, by the Merchant or an auditor mandated by the Merchant, no more than once per year unless a competent authority or a documented breach requires more, on reasonable notice, during business hours, and without access to other merchants’ data. OWNER: confirm you will actually host this.
OWNER + legal: liability allocation, caps, and the relationship to Shopify’s Partner terms. Do not invent a cap.
This addendum starts when the Merchant first installs the app and ends when Salestino has deleted the Merchant’s personal data under clause 11.
This addendum is governed by the law of Poland and by GDPR. Disputes go to the common courts of the Republic of Poland, without prejudice to a Merchant’s mandatory rights as a controller under the law of their own establishment, and without prejudice to PUODO or any other supervisory authority.