Truefold — Data Processing Agreement (Merchant DPA)
Version 1.0 — Effective 2026-08-27
Last updated: 2026-08-28
This Data Processing Agreement ("DPA") forms part of the Truefold Terms of Service (the "Agreement") between:
- Auke Vos, an individual (persona física) established in Mexico, doing business as Truefold (truefold.ai) ("Truefold", the "Processor"); and
- the merchant that has installed the Truefold application or otherwise subscribed to the Truefold service (the "Merchant", the "Controller").
It applies whenever Truefold processes Personal Data on the Merchant's behalf in the course of providing the Truefold service, and in particular whenever the Merchant connects its Shopify store, advertising accounts (Meta Ads, Google Ads), or Klaviyo account to Truefold. Where the Merchant is subject to the EU or UK General Data Protection Regulation, this DPA is intended to satisfy Article 28(3) GDPR. Where Mexican law applies, Truefold acts as encargado and the Merchant as responsable within the meaning of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares ("LFPDPPP"), and this DPA constitutes the processing mandate required by that law.
1. Definitions
"Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR"), or the equivalent concepts under the data protection law applicable to the Merchant ("Applicable Data Protection Law"). "Customer Data" means Personal Data relating to the Merchant's end customers that Truefold processes on the Merchant's behalf, including Protected Customer Data as defined by Shopify. "Sub-processor" means a third party engaged by Truefold to process Personal Data on the Merchant's behalf. "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
2. Roles and scope
2.1 The Merchant is the Controller of Customer Data and determines the purposes and means of its Processing. Truefold is the Processor and processes Customer Data only on the Merchant's behalf.
2.2 The subject matter, duration, nature and purpose of Processing, the categories of Personal Data and the categories of Data Subjects are set out in Annex I.
2.3 This DPA does not apply to data of which Truefold is itself the controller (the Merchant's own account data — the name, email address and login credentials of the Merchant's users — which Truefold processes to operate, secure and bill the service, as described in the Truefold Privacy Policy).
3. Instructions
3.1 Truefold shall process Customer Data only on the Merchant's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Truefold is subject; in that case Truefold shall inform the Merchant of that legal requirement before Processing, unless the law prohibits it.
3.2 The Merchant's complete and final documented instructions at the date of this DPA are: (a) the Agreement; (b) this DPA; (c) the configuration choices the Merchant makes in the Truefold application (which data sources to connect, which users to invite, which analyses to run); and (d) the Merchant's use of the service's features (dashboards, AI chat, alerts, the P&L module). Additional instructions require written agreement of both parties.
3.3 Truefold shall immediately inform the Merchant if, in its opinion, an instruction infringes Applicable Data Protection Law.
4. Confidentiality
Truefold shall ensure that every person it authorises to process Customer Data (currently: the operator personally) is bound by a contractual or statutory duty of confidentiality, and that access to Customer Data is limited to what is necessary to provide, maintain and secure the service.
5. Security
5.1 Truefold shall implement and maintain appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing. The measures in place at the date of this DPA are described in Annex II. Truefold may update them from time to time, provided the updates do not materially reduce the overall level of protection.
5.2 The measures in Annex II include, by design, data minimisation at ingestion: direct identifiers that the service does not need (customer names, street addresses, phone numbers, IP addresses, browser and session identifiers, payment-card metadata) are discarded before storage, and customer email addresses are replaced with a keyed one-way hash so that no plaintext customer email is retained at rest.
6. Sub-processing
6.1 The Merchant grants Truefold general written authorisation to engage the Sub-processors listed in the Truefold Sub-processor Register (Annex III, maintained at truefold.ai/legal/subprocessors), which forms part of this DPA.
6.2 Truefold shall give the Merchant at least 30 days' notice (by email to the Merchant's administrative contact, or by prominent notice in the application) before adding or replacing a Sub-processor that processes Customer Data. The Merchant may object on reasonable, data-protection-related grounds within that period; if the parties cannot resolve the objection, the Merchant may terminate the affected service and receive a pro-rata refund of prepaid fees.
6.3 Truefold shall impose on each Sub-processor, by way of contract, data-protection obligations materially equivalent to those in this DPA, and remains fully liable to the Merchant for the performance of each Sub-processor's obligations.
7. Assistance with Data Subject rights
7.1 Taking into account the nature of the Processing, Truefold shall assist the Merchant, by appropriate technical and organisational measures, in fulfilling the Merchant's obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection).
7.2 For Shopify stores, Truefold honours Shopify's mandatory privacy webhooks: on receipt of a customers/data_request Truefold shall compile and make available to the Merchant an export of the Customer Data it holds for that Data Subject; on receipt of a customers/redact Truefold shall delete that Data Subject's Customer Data; on receipt of a shop/redact Truefold shall delete the store's Customer Data. Erasure of a Data Subject is performed against the stored keyed email hash and platform identifiers, since Truefold retains no plaintext identifiers to match against.
7.3 If a Data Subject contacts Truefold directly, Truefold shall not respond substantively (except to direct the Data Subject to the Merchant) and shall forward the request to the Merchant without undue delay.
8. Personal Data Breach
8.1 Truefold shall notify the Merchant without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notification shall, to the extent then known, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — and shall be supplemented as further information becomes available. This timing is designed to leave the Merchant a reasonable margin within its own 72-hour notification obligation under Article 33 GDPR.
8.2 Truefold shall document all Personal Data Breaches and reasonably cooperate with the Merchant's own notification obligations to Supervisory Authorities and Data Subjects. Truefold's internal handling of incidents, including its parallel obligation to notify Shopify within 24 hours, is set out in the Truefold Incident Response Policy.
9. DPIA and prior consultation
Taking into account the nature of the Processing and the information available to it, Truefold shall provide reasonable assistance to the Merchant with data protection impact assessments and prior consultations with Supervisory Authorities, insofar as they relate to the Processing under this DPA.
10. Deletion and return
10.1 Upon termination of the Agreement, uninstallation of the Truefold app, or disconnection of a data source, Truefold shall delete the associated Customer Data within 30 days, unless retention is required by law. Receipt of a Shopify shop/redact webhook triggers deletion without waiting for that period. Residual copies in encrypted backups are overwritten in the ordinary course of the backup providers' rotation cycles.
10.2 Before deletion, the Merchant may request an export of its Customer Data in a commonly used, machine-readable format.
11. Audit and information
11.1 Truefold shall make available to the Merchant all information reasonably necessary to demonstrate compliance with this DPA, including the current versions of Annex II, the Sub-processor Register, the Data Residency & International Transfers statement, and the Incident Response Policy, and shall answer reasonable written security questionnaires at no charge no more than once per 12-month period.
11.2 Where the information under 11.1 is insufficient to demonstrate compliance, the Merchant (or an independent auditor mandated by it and bound by confidentiality) may conduct an audit, limited to the Processing under this DPA, on at least 30 days' written notice, no more than once per 12-month period (except following a Personal Data Breach or where required by a Supervisory Authority), during business hours, remotely by default, and without access to other merchants' data. Each party bears its own costs.
12. International transfers
12.1 Truefold is established in Mexico and uses Sub-processors in the United States and the European Union, as set out in the Sub-processor Register and the Truefold Data Residency & International Transfers statement, which forms part of this DPA.
12.2 Where the Merchant is established in the EEA (or the Processing is otherwise subject to the GDPR), the transfer of Customer Data from the Merchant to Truefold is made under the SCCs, Module Two (controller to processor), which are incorporated into this DPA by reference and completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorisation, 30 days' notice); Clause 11(a) optional wording not included; Clause 17 Option 1, governed by the law of Ireland; Clause 18(b) courts of Ireland; Annexes I, II and III to the SCCs are completed by Annexes I, II and III to this DPA; the competent supervisory authority is that of the Merchant's establishment. In case of conflict between the SCCs and any other term of this DPA or the Agreement, the SCCs prevail.
12.3 For Merchants subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum (version B1.0), with Table 1–3 information taken from this DPA and its Annexes. For Merchants subject to the Swiss FADP, the SCCs apply with the adaptations customarily required by the FDPIC (references to the GDPR read as references to the FADP; the competent authority is the FDPIC; Swiss law governs where the FADP so requires).
12.4 Onward transfers from Truefold to Sub-processors are protected by each Sub-processor's data processing agreement incorporating the SCCs (Module Three) and/or, where the Sub-processor is certified, the EU-U.S. Data Privacy Framework, as recorded in the Sub-processor Register.
13. Liability, term, miscellaneous
13.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Applicable Data Protection Law does not permit such limitation (including a Data Subject's rights under Clause 12 of the SCCs).
13.2 This DPA takes effect on the date the Merchant accepts the Agreement or connects a data source, whichever is earlier, and remains in force as long as Truefold processes Customer Data on the Merchant's behalf.
13.3 This DPA is governed by the law governing the Agreement (the law of Mexico), except that the SCCs are governed as stated in Section 12. If any provision of this DPA is held invalid, the remainder remains in effect.
Annex I — Description of the Processing
Data exporter (Controller): the Merchant — an online commerce business using Shopify and connected marketing platforms. Contact: the Merchant's administrative user as registered in the Truefold application.
Data importer (Processor): Auke Vos, doing business as Truefold, Mexico. Contact: privacy@truefold.ai.
Subject matter and nature of Processing: ingestion, storage, transformation, aggregation and analysis of the Merchant's commerce and marketing data in order to provide automated analytics: a reviewed semantic data model, dashboards, a blended profit-and-loss view, natural-language (AI-assisted) querying, and data-quality alerts. Processing operations: collection via the platform APIs the Merchant connects; pseudonymisation and minimisation at ingestion; storage in an isolated per-merchant dataset; querying and aggregation; display to the Merchant's authorised users; deletion.
Purpose: providing the Truefold service to the Merchant. Truefold does not use Customer Data for its own purposes, does not sell it, does not use it for advertising, does not combine it across merchants, and does not use it to train machine-learning or AI models.
Duration: for as long as the Merchant subscribes to the service and the relevant data source remains connected, plus the deletion period in Section 10. Raw ingested records are retained on a rolling 90-day basis; derived aggregates are retained for the duration of the subscription.
Categories of Data Subjects: the Merchant's end customers (purchasers and marketing recipients); recipients of the Merchant's email marketing (Klaviyo); users interacting with the Merchant's advertising (in aggregate form only).
Categories of Personal Data — persistently stored (minimised): pseudonymised customer email (keyed one-way hash, used solely as a within-merchant join key); platform customer/order identifiers; order, line-item, refund and transaction financial data; product/catalog data; coarse location (city, region, country, postal code); marketing-consent status. Transiently processed only (received from the connected APIs and discarded before storage): customer name, street address, phone number, IP address, browser/user-agent and session identifiers, payment-card metadata (last four digits, BIN, AVS), order note attributes, and the embedded customer profile on orders.
Special categories of data: none, and the Merchant instructs that none be submitted.
Frequency: continuous (scheduled synchronisation), with an initial historical backfill of approximately 13 months.
Annex II — Technical and Organisational Measures
-
Minimisation and pseudonymisation at ingestion. Every record passes through a field-level minimisation policy before it is written: fields not needed for the service (Annex I list) are dropped, and customer email addresses are replaced with a per-merchant keyed HMAC-SHA256 hash. For Shopify data the policy is default-deny: a field not expressly allow-listed is dropped, and an unrecognised table fails closed rather than storing unminimised data. No plaintext customer email, name, street address, phone number or IP address is stored at rest.
-
Tenant isolation. Each merchant's warehouse data is stored in a dedicated, logically isolated dataset in a dedicated Google Cloud project used only for customer data; dataset identity is derived server-side from the merchant's organisation ID and is never client-supplied. The application database enforces row-level security keyed to the merchant's organisation on every table.
-
Encryption. TLS on all connections in transit. Encryption at rest, including backups, on all storage systems (provider-managed AES-256). Connected-platform credentials (OAuth tokens, API keys) are additionally encrypted at the application layer with AES-256-GCM before storage, decrypted only in memory at execution time, never logged and never exposed via any API.
-
Egress controls on AI features. The AI querying features operate behind server-side guardrails that are enforced independently of the AI model: only approved tables can be queried, every query is validated to be read-only, and columns flagged as personal data are blocked from appearing in query output. Raw stored records are not used as AI training data, and AI providers process queries and their PII-filtered results only to generate the requested response.
-
Access control. Role-based access within each merchant organisation (admin/editor/viewer) enforced at the database layer; platform-level administrative access is separately gated. Service-to-service calls are authenticated with dedicated keys compared in constant time. AI-agent access tokens are stored only as keyed hashes and are revocable immediately.
-
Retention and deletion. Raw ingested tables carry a 90-day automatic partition expiry. Disconnection or uninstallation triggers deletion under Section 10 of this DPA; Shopify redaction webhooks trigger targeted or store-wide deletion.
-
Logging hygiene. Query logs are redacted of literal values (e.g. filter values such as email addresses) before persistence; credentials and personal data are excluded from application logs and error tracking.
-
Secure development. Version-controlled infrastructure and code; automated CI gates including tests, static security analysis, dependency-vulnerability scanning and verified-secret scanning on every change; documented security reference and periodic internal security audits with adversarial review of high-severity findings.
-
Organisational measures. Single-operator organisation: access to production systems is limited to the operator, protected by strong unique credentials with multi-factor authentication on the administrative consoles of all providers; a documented Incident Response Policy (detection, triage, containment, notification) is maintained; sub-processors are bound by data processing agreements as per Annex III.
Annex III — Sub-processors
The authorised Sub-processors are those listed in the Truefold Sub-processor Register (published at truefold.ai/legal/subprocessors and provided with this DPA), which specifies for each Sub-processor its role, the categories of data it processes, its processing location, and the applicable transfer mechanism. At the date of this DPA the Sub-processors are: Google Cloud (Google LLC) — data warehouse and AI model hosting; Supabase, Inc. — application database, authentication and file storage; Railway Corp. — backend application hosting; Vercel Inc. — web application hosting and delivery; Anthropic, PBC and OpenAI, LLC — contingent (fallback) AI model providers.