Draft. This document is a template under legal review and is not yet in force. Highlighted fields are still to be filled in.

Data Processing Agreement and GDPR guide

This document has three parts:

  • Part A explains who is responsible for what when you use TellMyShop together with Claude. It is information only and does not constitute contract terms.
  • Part B is a data processing agreement within the meaning of art. 28 GDPR. It applies only when we process personal data on your behalf, mainly in the course of support.
  • Part C is a practical checklist for using TellMyShop in line with the GDPR, with a template entry for the record of processing activities.

"GDPR" means Regulation (EU) 2016/679. "Merchant" or "you" means the store owner (or the agency acting on the store owner's behalf) who uses the TellMyShop module. "We" means SEMownia Szymon Sanecznik, ul. Twarda 44, 00-831 Warszawa, tax ID (NIP) 6422931698.


Part A. Roles: who is responsible for what

A.1. You are the controller of your store's data

This agreement and guide apply equally to a PrestaShop store and to a WordPress site (with or without WooCommerce); here, "store" and "module" also mean the WordPress site and the TellMyShop plugin for WordPress.

The store holds personal data of customers, newsletter subscribers and employees, and a WordPress site also of users, comment authors and people who submit forms. You decide on the purposes and means of processing that data, so you are its controller (art. 4(7) GDPR). That does not change when you start managing the store with Claude.

A.2. How data flows when Claude uses the module

  1. You ask Claude to do a task in your store.
  2. Claude calls a tool of the TellMyShop module, which runs on your server.
  3. The module reads or changes data in the store and returns the result to Claude.
  4. The result is processed by Anthropic within your own Claude account.

Data goes from the store to your Claude account, and nowhere else. TellMyShop servers do not take part in this flow and, in normal operation, do not receive product, order or customer data.

Access to your customers' personal data (for example names, email addresses, phone numbers and addresses) is set in the module at one of three levels: no access (default), pseudonymisation (personal data is masked before it is passed to Claude) or full access only temporarily, for 1 to 24 hours, with a stated purpose and a log entry, after which the module returns to the previous level automatically. The module detects tables with personal data, including tables of modules from other vendors, and blocks files that typically contain personal data (logs, customer files, database dumps, .git). The change history and all file copies are encrypted with a key stored in a file outside the database. Erasure and export requests handled with the PrestaShop GDPR module (psgdpr) also cover the module's history. TBC: E1, whether the WordPress plugin supports the WordPress privacy tools (export and erasure of personal data). In WordPress, the "no access" level covers the WooCommerce customer and order tables (including in HPOS mode), user accounts and form entries (WPForms, Gravity Forms, Elementor), and the email addresses and IP addresses of comment authors are always masked (checked in the plugin code 0.1.0, src/Privacy/PersonalData.php). With pseudonymisation, the same customer has the same alias for one day, and the alias changes every day. An audit log (who enabled full access, the write switches or the licence, and when) can be downloaded as CSV and cannot be cleared from the panel. The change history is deleted after 180 days by default (a setting in the module). LAWYER: check this wording once confirmed in 2.6.0. Claude connects directly to the module on your server using a token generated in the module; TellMyShop servers do not issue or check this token. TBC: plugin code: confirm before each release.

The module automatically creates a copy of the store's database on your server, so that data can be restored if a problem occurs. The copy is encrypted, the module keeps the 2 most recent copies, they do not reach us or the AI provider, and the module deletes them when the connection is disabled and when the module is uninstalled.

A.3. Anthropic processes data under your agreement with Anthropic

The data that reaches Claude is processed by Anthropic under your agreement with Anthropic for your Claude plan. We are not a party to that agreement.

Anthropic offers individual plans and business plans under different terms. Before you let Claude see personal data from your store:

  • read Anthropic's current terms and privacy policy, and for business plans also its data processing addendum, and check what role Anthropic takes in your plan;
  • for business use involving personal data, we recommend a Claude business account (for example Team or Enterprise) whose terms include a data processing agreement;
  • check the data-use settings in your Claude account (for example whether conversations may be used to improve models) and set them in line with your privacy policy;
  • check where Anthropic processes data and which transfer mechanism applies.

We do not describe the details of Anthropic's terms here, because they can change and differ by plan. LAWYER: verify this part against Anthropic's terms in force on the date of publication.

A.4. TellMyShop is not a processor in normal operation

We license software that you install and run yourself. In normal operation we do not access, receive, store or otherwise process personal data from your store, so we are not a processor of that data on your behalf.

We are the controller of our own customer data (account, orders, invoices, licence verification data), as described in the Privacy Policy.

We become a processor only when we process personal data from your store on your behalf. This happens mainly in support, when you:

  • send us logs, screenshots or exports that contain personal data;
  • send us a database dump or a copy of the store;
  • give us temporary access to your back office, server or database.

In these cases Part B applies.

A.5. Agencies

If you are an agency or freelancer using TellMyShop in a client's store, the client is usually the controller and you are their processor. If you work in the client's store through your own Claude account, Anthropic acts under your agreement with Anthropic, so it may be your sub-processor. Make sure your data processing agreement with the client covers this. If you involve us in support for a client's store, we act as your sub-processor under Part B.


Part B. Data Processing Agreement (art. 28 GDPR)

B.1. Parties, conclusion and precedence

  1. This data processing agreement ("DPA") is concluded between the Merchant as controller (or as processor acting on behalf of its client) and SEMownia Szymon Sanecznik as processor (or sub-processor) ("Processor").
  2. The DPA forms part of the Terms of Sale and the EULA. It is concluded in electronic form upon acceptance of those documents, and in any case upon the first sharing of personal data with us in support or the granting of access to the store (art. 28(9) GDPR allows electronic form). LAWYER: confirm the conclusion mechanism, including for Audit edition users.
  3. If the DPA conflicts with other agreements between the parties on the protection of personal data, the DPA prevails.

B.2. Subject matter and scope of application

The DPA applies when the Processor processes personal data of which the Merchant is the controller (or processor), in connection with:

  1. technical support and handling complaints;
  2. analysing logs, screenshots, exports or database dumps provided by the Merchant;
  3. working in the Merchant's back office, server or database through temporary access granted;
  4. any other service agreed by the parties in documentary form that involves such data.

The DPA does not apply to licence verification data or account data, which we process as controller.

B.3. Duration

The DPA applies for as long as the Processor stores or has access to the data within the scope set out in section B.2, and in any case until that data is deleted or returned under section B.11.

B.4. Nature and purpose of processing

Nature: receiving, storing, viewing, searching, analysing, reproducing errors on a test copy, and deleting. Purpose: diagnosing and fixing problems with the module, answering the Merchant's support requests and handling complaints.

B.5. Data subjects and categories of data

Data subjectsCategories of personal data
store customersidentification and contact data (name, email, phone, delivery and billing addresses), customer account data (including password hashes in database dumps), order and payment status data (no full card numbers), IP addresses, messages
newsletter subscribersemail, consent data
WordPress site users and comment authorsusername, name, email, website address, IP address, content of comments
people who submit forms on the sitedata entered in the form, IP address
employees and back-office users of the storename, email, role, login data, log entries
other persons whose data is stored in the storedata contained in the store's content and logs

No processing of special categories of data (art. 9 GDPR) is expected. The Merchant does not send such data unless strictly necessary and agreed in advance.

B.6. Processor's obligations

The Processor:

  1. processes personal data only on the Merchant's documented instructions, which are the DPA and the Merchant's support requests, unless processing is required by EU or Polish law; in that case it informs the Merchant before processing begins, unless the law forbids it;
  2. informs the Merchant immediately if, in its opinion, an instruction infringes the GDPR or other data protection law;
  3. ensures that persons authorised to process the data have committed to confidentiality;
  4. takes the technical and organisational measures required by art. 32 GDPR, at least those in Annex B1;
  5. uses sub-processors only in accordance with section B.7;
  6. taking into account the nature of processing, assists the Merchant in responding to data subject requests (chapter III GDPR), and forwards to the Merchant any request it receives directly, without answering it;
  7. assists the Merchant in meeting the obligations under art. 32 to 36 GDPR (security, breach notification, data protection impact assessment, prior consultation), taking into account the information available to it;
  8. notifies personal data breaches in accordance with section B.9;
  9. deletes or returns data in accordance with section B.11;
  10. makes available the information necessary to demonstrate compliance and allows audits in accordance with section B.10;
  11. does not use the data for any other purpose, in particular for training AI models, marketing or analytics;
  12. does not transfer the data outside the EEA, except in the cases in section B.8.

B.7. Sub-processors

  1. The Merchant gives a general authorisation to use the sub-processors listed in Annex B2.
  2. The Processor informs the Merchant by email (or by a notice in the account and on this page) about any intended addition or replacement of a sub-processor at least 14 days in advance. Within that period the Merchant may raise a reasoned objection on grounds related to data protection. If the parties cannot reach agreement, the Merchant may stop sharing data and request deletion of the data already shared.
  3. The Processor imposes on each sub-processor data protection obligations corresponding to the DPA and is liable to the Merchant for their performance.

B.8. Transfers outside the EEA

The Processor transfers personal data outside the EEA only to countries covered by an adequacy decision (including US companies certified under the EU-US Data Privacy Framework) or on the basis of standard contractual clauses, as indicated in Annex B2.

B.9. Personal data breaches

  1. The Processor notifies the Merchant of a breach of personal data processed under the DPA without undue delay and no later than within 48 hours of becoming aware of it, by email to the address assigned to the Merchant's account.
  2. The notification includes, as far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, the measures taken or proposed, and a contact person. Information may be provided in stages.
  3. The Processor does not notify the supervisory authority or data subjects of the breach on the Merchant's behalf unless the Merchant asks it to.

B.10. Information and audits

  1. The Processor makes available, on request, the information necessary to demonstrate compliance with the obligations under art. 28 GDPR, in particular a description of the measures in Annex B1.
  2. If that information is not sufficient, the Merchant may carry out an audit, itself or through an independent auditor bound by confidentiality, no more than once in 12 months (and additionally after a breach), with at least 30 days' notice, during business hours and without disrupting the Processor's business. Audits are carried out remotely as a rule, by means of questionnaires and documents. Each party bears its own costs. LAWYER: confirm the cost allocation.

B.11. Deletion of data after support

  1. The Processor deletes personal data received under the DPA (logs, screenshots, database dumps, copies of the store) no later than 30 days after the support case is closed, unless the Merchant has requested its return earlier or the law requires it to be retained.
  2. Temporary access credentials (back office, server, database) are not stored after the work is completed. The Merchant should disable or delete the temporary account; the Processor confirms in the support thread that access is no longer needed.
  3. Copies in backups are deleted when the backups are overwritten in the normal cycle (BACKUP_ROTATION_DAYS days) and are not restored in the meantime, except to recover from a failure.
  4. On request, the Processor confirms the deletion of data by email.

B.12. Merchant's obligations

The Merchant:

  1. ensures a legal basis for the processing and the lawfulness of sharing the data with the Processor;
  2. shares only the data necessary to solve the problem, masked or pseudonymised where possible (for example a staging copy with anonymised customers);
  3. sends files containing personal data through the agreed secure channel, never through public links;
  4. creates separate temporary accounts with minimal permissions for the purposes of access, and deletes them after the support case is closed.

B.13. Liability

Each party is liable towards data subjects under art. 82 GDPR. Between the parties, liability under the DPA is governed by § 16 of the EULA, to the extent permitted by law. LAWYER: confirm whether the B2B liability cap should cover the parties' claims related to data protection.

B.14. Final provisions

The DPA is governed by Polish law. Changes required by law or by a change of sub-processors are made in accordance with section B.7 or by publishing a new version with 30 days' notice.

Annex B1. Technical and organisational measures

AreaMeasures
Access controlaccess to support data only for named persons who need it; individual accounts; two-factor authentication on email, file storage and administrator accounts; password manager; access removed when it is no longer needed
EncryptionHTTPS/TLS for every transfer; encrypted storage of files containing personal data; disk encryption on laptops and workstations
Data minimisationwe ask for masked data and anonymised copies first; where possible, we work on a local test copy instead of the live store
Separationsupport data stored separately from our customer database; never used for other purposes
Temporary accessonly accounts created by the Merchant, with minimal permissions; no copying of credentials into tickets or chats; confirmation when access is no longer needed
Logginglog of access to support files (LOGGING_TOOL) TBC
Deletiondeletion within 30 days after the support case is closed; backups overwritten in a BACKUP_ROTATION_DAYS-day cycle
Devicesup-to-date operating systems and software, screen lock, antivirus protection where appropriate
Peoplewritten confidentiality commitments; instructions on handling support data
Incidentsincident handling procedure with notification to the Merchant within 48 hours
Resilienceregular backups of our systems; providers with security certifications (for example ISO 27001 or SOC 2) where available
Integrity of store datathe module supports the integrity of the Merchant's data with an automatic local copy of the database on the Merchant's server: the copy is encrypted, the module keeps the 2 most recent copies, the copies are not sent to the Licensor (the Processor) or to the AI provider, and they are deleted when the connection is disabled and when the module is uninstalled; this mechanism does not change the scope of processing entrusted under section B.2

Annex B2. Sub-processors

Sub-processorPurposeLocationTransfer safeguard
MAILBOX_PROVIDER (for example Google Workspace)support mailbox and attachmentsLOCATIONSAFEGUARD
Cloudflare R2secure transfer and storage of larger files (database dumps, store copies)LOCATIONSAFEGUARD
HELPDESK_PROVIDER (if used)support ticket systemLOCATIONSAFEGUARD
PASSWORD_MANAGER (when temporary credentials are shared)secure sharing of credentialsLOCATIONSAFEGUARD

TBC: final list. Note: if support staff analyse logs or database dumps with the help of an AI assistant, its provider must be added as a sub-processor, or such use must be excluded.


Part C. Checklist: using TellMyShop in line with the GDPR

C.1. Module settings

  • Leave customer data access at "no access". If a task requires it, choose "pseudonymisation". Turn on full access only for a specific task that needs real data, for the shortest possible time (1 to 24 hours) and with a clearly stated purpose.
  • Turn on the write switches (Commerce, Theme, Plugins or Modules, Service) only for as long as you need them. Theme and Plugins turn themselves off after 24 hours, and Service after 3 hours. Commerce stays on until you turn it off, so turn it off when you finish working.
  • WordPress: keep the Commerce (WooCommerce) switch off if you do not need it, and when you add a form tool or a store to WordPress, check whether the plugin recognises its tables as personal data.
  • Claude should act as a separate employee with minimal permissions. For content and SEO work, such a profile does not need access to the Customers and Orders tabs.
  • When you only need audits and reports, use TellMyShop Free (free version, read-only).
  • Set a sensible hourly call limit.
  • Consider setting Claude to ask before each use of a tool, at least at the start.

C.2. Claude account

  • For business use with personal data, use a Claude business plan whose terms include a data processing agreement.
  • Check the data-use settings in your Claude account (for example model improvement) and choose what fits your privacy policy.
  • Check where Anthropic processes data and which transfer mechanism applies.
  • Decide who in your team may connect Claude to the store, and use named accounts.

C.3. Your documents

  • If unmasked customer data may reach Claude, update your store's privacy policy: state that you use an AI assistant provided by Anthropic to manage the store, which data may be processed, the legal basis (usually the legitimate interest in running the store efficiently) and any transfer outside the EEA.
  • Add an entry to your record of processing activities (template in section C.5).
  • Assess whether a data protection impact assessment (DPIA) is needed. With no access or pseudonymisation and work on the catalogue only, it usually is not; with broad access to unmasked customer data, carry out an analysis. LAWYER: confirm the guidance.
  • Agencies: make sure that your data processing agreement with each client covers the use of Claude and TellMyShop and, where appropriate, names Anthropic (your Claude account) as a sub-processor.

C.4. Support and incidents

  • When asking us for help, send masked logs, or reproduce the problem on a staging copy with anonymised customers.
  • For temporary access, create a separate employee account with minimal permissions and delete it when the work is finished.
  • If personal data is exposed (for example you share a conversation with someone after enabling full access), assess the event as a possible personal data breach: as controller, you may be obliged to notify it to the President of the Polish Personal Data Protection Office (Prezes UODO) within 72 hours (art. 33 GDPR).
  • Make regular backups of your store. The automatic database copy created by the module does not replace your full backup of the store.

C.5. Template entry for the record of processing activities

FieldExample entry (adapt it)
Name of processing activityManaging the online store with an AI assistant (Claude) through the TellMyShop module
ControllerYOUR_COMPANY, YOUR_ADDRESS, contact YOUR_PRIVACY_CONTACT
Purposeediting the content of products, categories and pages; SEO; store diagnostics; [if enabled: answering questions about orders and customers]
Legal basisart. 6(1)(f) GDPR: legitimate interest in running the store efficiently; [art. 6(1)(b) where the processing serves the performance of contracts with customers]
Data subjectsstore customers, newsletter subscribers, employees (only when the data is not masked or appears in logs)
Categories of databy default none (no access to customer data); with pseudonymisation, masked customer data; with time-limited full access: names, email addresses, phone numbers, addresses, order data; employee names in logs
RecipientsAnthropic as the provider of Claude under the terms of the YOUR_CLAUDE_PLAN plan; SEMownia Szymon Sanecznik only in support, under the TellMyShop data processing agreement; the store's hosting provider
Transfers outside the EEAAnthropic: TRANSFER_MECHANISM_FROM_ANTHROPIC_TERMS
Retention periodin the store: according to your existing rules; in Claude: according to your Claude account settings and Anthropic's terms; module change log: CHANGE_LOG_RETENTION TBC: plugin code
Security measuresthree levels of access to customers' personal data (none by default; pseudonymisation; full only time-limited with a stated purpose); detection of tables with personal data; encryption of the change history and file copies with a key outside the database; emails and phone numbers masked in logs; email notifications to the store owner when protective settings are relaxed; audit log (CSV) of enabling full access, the write switches and the licence, which cannot be cleared from the panel; Commerce, Theme, Plugins and Service write switches off by default, with Theme and Plugins turning themselves off after 24 hours and Service after 3 hours; permanent blocks (passwords, administrator accounts and roles, API keys, payment data, configuration files); HTTPS only; only a hash of the access token stored; Claude acts as an employee with limited permissions; preview and confirmation of each change; change log and undo; automatic encrypted database copy on the store's server (2 most recent copies, deleted when the connection is disabled and when the module is uninstalled); hourly call limit; TellMyShop Free read-only

PrestaShop is a registered trademark of PrestaShop SA. WordPress is a trademark of the WordPress Foundation. WooCommerce is a trademark of Automattic Inc. Claude is a trademark of Anthropic. TellMyShop is not affiliated with any of these entities.