Data Processing Addendum
Last updated: 2026-07-12
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service between Resolvas Customer Service LLC, a Kansas limited liability company (“Resolvas,” “we,” “us”) and the merchant that installs or uses the Resolvas application (“Merchant,” “you”). It governs Resolvas's processing of Personal Data on the Merchant's behalf and reflects the requirements of the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the California Consumer Privacy Act (“CCPA/CPRA”), as applicable.
1. Roles of the parties
For Personal Data of the Merchant's end customers processed through the Service, the Merchant is the data controller (or, under CCPA, the “business”) and Resolvas is the data processor (or “service provider”). Resolvas processes such Personal Data only on the Merchant's documented instructions, as set out in this DPA and the Terms of Service. Shopify acts as the platform through which the Merchant's store and customer records are maintained.
2. Definitions
“Personal Data,” “processing,” “controller,” “processor,” “data subject,” and “personal data breach” have the meanings given in the GDPR. “Sub-processor” means any third party engaged by Resolvas to process Personal Data on the Merchant's behalf. “Service” means the Resolvas application and related services.
3. Subject matter, nature, and purpose of processing
Resolvas processes Personal Data solely to provide the Service: to triage incoming customer-support requests, identify the relevant customer and order, evaluate proposed actions against the Merchant's configured policies, execute approved actions (refunds, order edits, returns, store credit, replacements, and discount codes) through Shopify's Admin API, generate responses to customers, maintain an audit log, and bill the Merchant accurately. The duration of processing is the term of the Merchant's subscription, subject to the retention and deletion obligations in Section 9.
Automated decision-making. The Service applies AI to support requests and, within the limits the Merchant configures, executes actions (refunds, store credit, returns, replacements, discount codes, and order edits) without a human reviewing each one. A proposed action by the AI is authorized by a deterministic policy engine against the Merchant's rules (dollar caps, windows, exclusions, and fraud checks) before it executes; an action outside policy, over a cap, lacking required evidence, or flagged as higher-risk is not executed autonomously but is deferred to the Merchant's team or declined. Autonomous money actions execute only after the Merchant has accepted the current Terms and this DPA; until that consent is recorded, every action defers to a human. The Merchant, as controller, decides whether and how to inform its end customers about automated decision-making and remains responsible for handling any request by a data subject for human review of a decision; Resolvas provides the audit log and the ability to correct or counteract actions to support this.
4. Categories of data subjects and Personal Data
Data subjects: the Merchant's end customers who contact support, and the Merchant's own staff users.
Categories of Personal Data:
- Customer name, email address, and (where present in the order) shipping/billing address and phone number;
- The content of support messages and any photos a customer submits as evidence;
- Order, fulfillment, and refund history retrieved from Shopify;
- Merchant staff identifiers and access tokens (for app authentication).
Resolvas does not intentionally process special categories of data. Customers may incidentally include such data in free-text messages or photos; the Merchant instructs Resolvas to process whatever a customer voluntarily submits solely to resolve the ticket.
5. Merchant instructions
Resolvas processes Personal Data only on the Merchant's documented instructions, including with regard to international transfers, unless required by law (in which case Resolvas will inform the Merchant unless legally prohibited). The Terms of Service, this DPA, and the Merchant's in-app configuration constitute the Merchant's complete and final instructions. Resolvas will inform the Merchant if, in its opinion, an instruction infringes applicable data-protection law.
6. Confidentiality and data minimization
Resolvas ensures that persons authorized to process Personal Data are bound by confidentiality. As a core design principle, Resolvas redacts direct identifiers (name, email, address, phone) and sensitive values that appear in the message body (payment card numbers and U.S. Social Security numbers) to placeholders before any message text is sent to a large-language-model provider; identifiers are re-associated only within Resolvas's own systems when an action is executed. Support-message bodies are stored with these identifiers already redacted. Photos that a customer submits as evidence are an exception: text redaction does not apply to images, so a submitted photo is sent to the LLM provider's vision model in full for verification and may contain incidental Personal Data visible in the picture. The original is stored encrypted at rest (Section 7).
7. Security measures
Resolvas maintains technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2+) and at rest, including per-store AES-256-GCM envelope encryption of customer Personal Data, message bodies, submitted photos, and access tokens; the master key that wraps each per-store data-encryption key is held in a managed key-management service (AWS KMS);
- Email addresses indexed via a one-way keyed hash so equality lookups never require the plaintext;
- Redaction of direct and sensitive identifiers before any third-party AI processing (Section 6);
- Least-privilege, role-based access controls and multi-factor authentication for staff;
- Database access restricted by Row-Level Security on all tables (no grants to any anonymous or public role) plus account-level MFA, with no anonymous database key exposed to any client;
- A complete audit log of every action taken on the Merchant's behalf;
- Separation of development and production environments;
- A documented security incident-response process.
8. Sub-processors
The Merchant provides general authorization for Resolvas to engage the sub-processors listed below. Each is bound by data-protection obligations no less protective than those in this DPA, and receives only the data necessary for its function.
- Shopify: Commerce platform; order/customer source of truth. Processes all order & customer data (the Merchant's platform). Location: Global.
- Anthropic: AI reasoning & photo verification. Processes redacted message text; customer-submitted photos. Location: USA.
- Voyage AI: Knowledge-base embeddings. Processes Merchant documents at ingestion, plus redacted search queries derived from customer messages at answer time (direct identifiers removed first). Location: USA.
- Postmark: Inbound and outbound email processing. Processes inbound customer emails and outbound reply content, together with the customer email address (in transit). Location: USA.
- Supabase: Database hosting. Processes stored data at rest (Personal Data encrypted). Location: USA.
- Fly.io: Application hosting / compute. Processes in-memory data during requests. Location: USA.
- AWS (Amazon Web Services KMS): Encryption-key custody. Holds the master key that wraps each per-store data-encryption key; processes only wrapped key material, never customer content. Location: USA.
- Cloudflare: CDN, WAF, and bot protection for the public marketing site and API edge. Processes marketing-site/contact-form traffic (may include a submitter's IP and any details entered in a form). Location: Global.
- Gorgias: Helpdesk integration (only if connected by the Merchant). Processes support-ticket content. Location: USA.
- Sentry: Application error diagnostics. Processes error type, stack trace, route path, store domain, and ticket identifier. Message bodies, customer names, email addresses, phone numbers, and request payloads are stripped before transmission; identifiers found inside error text are redacted. Location: USA.
Resolvas will give the Merchant at least 30 days' notice before adding or replacing a sub-processor (by in-app notice or email). If the Merchant reasonably objects on data-protection grounds, the Merchant may terminate the Service before the change takes effect. Resolvas remains liable for its sub-processors' compliance with this DPA.
9. Retention, return, and deletion of data
Resolvas retains Personal Data only as long as needed to provide the Service, then purges it on a rolling schedule (our default windows; a Merchant may request shorter ones via support@resolvas.com): a resolved, escalated, or archived support ticket and its customer Personal Data are deleted 90 days after the ticket closes; audit logs are retained approximately 365 days; policy snapshots approximately 90 days. An active ticket (still open or awaiting a human) is never deleted on this schedule. Merchant configuration and knowledge-base content are retained for the term of the subscription.
On expiry or termination of the Service, Resolvas deletes Personal Data processed on the Merchant's behalf. When a Merchant uninstalls the Service, all of that store's data is purged following Shopify's shop/redact flow (which Shopify fires 48 hours after uninstall); the uninstall itself immediately clears the Merchant's authentication tokens. On request, the Merchant can also export or delete an individual customer's data on demand from within the app, or have Resolvas do so, ahead of these windows. Deletion is a hard delete, not anonymization.
10. Assistance to the Merchant
Taking into account the nature of processing, Resolvas assists the Merchant, by appropriate technical and organizational measures, in fulfilling the Merchant's obligations to respond to data-subject requests (access, erasure, rectification, portability, restriction, objection) and to ensure security, breach notification, and data-protection impact assessments. Resolvas implements Shopify's mandatory customers/data_request, customers/redact, and shop/redact webhooks, and provides an in-app tool for the Merchant to fulfill requests received directly.
11. Personal data breach notification
Resolvas will notify the Merchant without undue delay after becoming aware of a personal data breach affecting the Merchant's Personal Data, and will provide information reasonably necessary for the Merchant to meet its own notification obligations (which, under GDPR, may require notifying the supervisory authority within 72 hours).
12. International transfers
The Service is operated from data centers in the United States, and the sub-processors in Section 8 process data in the United States. Where Personal Data of EU/UK data subjects is transferred, the parties rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), which are incorporated into this DPA by reference, or another lawful transfer mechanism.
13. Audits
Resolvas will make available to the Merchant information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor mandated by the Merchant, no more than once per year and subject to reasonable confidentiality and scheduling, or as required by a supervisory authority.
14. CCPA service-provider terms
To the extent the CCPA/CPRA applies, Resolvas acts as a “service provider” and will not sell or share Personal Data, will not retain, use, or disclose it for any purpose other than providing the Service (or as permitted by the CCPA), and will not combine it with data from other sources except as permitted. Resolvas certifies it understands and will comply with these restrictions.
15. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA controls. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Clauses control.
16. Governing law
This DPA is governed by the same law as the Terms of Service, except where applicable data-protection law requires otherwise.
17. Contact
Data-protection inquiries, sub-processor-list requests, and notices under this DPA should be sent to support@resolvas.com.