Data Processing Agreement

VCenter Live  ·  Version 1.0  ·  Effective 1 September 2026

This Agreement is incorporated into the Terms of Service and is accepted by the merchant when the VCenter Live application is installed on their Shopify store. It applies whenever we process personal data on the merchant's behalf. No signature is required for it to take effect; a countersigned copy is available on request to [email protected].

1. Parties and roles

The Merchant is the controller. VCenter Live is the processor. This Agreement governs our processing of personal data relating to the Merchant's customers and site visitors, carried out in the course of providing the application.

Where we process data about the Merchant's own staff accounts, or about shoppers who register directly with VCenter Live, we act as a controller and our Privacy Policy applies instead.

2. Subject matter, duration, nature and purpose

3. Categories of data subject and personal data

Data subjects: the Merchant's customers and store visitors.

Personal data: first and last name; email address; Shopify customer identifier; order details (order number, totals, currency, line items, financial and fulfilment status).

We do not process telephone numbers, postal addresses, payment or card data, or any special category data within the meaning of Article 9 GDPR.

4. Processing on documented instructions

We process personal data only on the Merchant's documented instructions, which are constituted by this Agreement, the Terms of Service, and the Merchant's use of the application's features. We will not process personal data for any other purpose. In particular we do not sell personal data, do not use it for advertising, and do not use it to train machine-learning models.

If we consider an instruction to infringe applicable data protection law, we will inform the Merchant before carrying it out.

5. Confidentiality

Personnel authorised to process personal data are bound by a duty of confidentiality, are granted access on a need-to-know basis, and receive periodic data protection and security training.

6. Security measures

We implement the technical and organisational measures required by Article 32 GDPR, including:

7. Subprocessors

The Merchant gives general authorisation for the engagement of the subprocessors listed in the Annex below. Each is bound by data protection obligations no less protective than those in this Agreement. We will give the Merchant at least 30 days' notice before adding or replacing a subprocessor, during which the Merchant may object on reasonable data protection grounds; if the objection cannot be resolved, the Merchant may terminate by uninstalling the application.

8. Assistance to the Merchant

Taking into account the nature of the processing, we will assist the Merchant with:

9. Erasure and return of data

10. Personal data breach

We will notify the Merchant without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting their data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We maintain a written incident response policy governing this process.

11. Audit

We will make available to the Merchant the information necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor they mandate, on reasonable notice and no more than once per year unless required by a supervisory authority.

12. International transfers

Personal data is hosted in the European Economic Area (AWS eu-west-3, Paris). Any transfer outside the EEA relies on the European Commission's Standard Contractual Clauses, which are incorporated into this Agreement by reference, together with supplementary technical measures.


Annex — Authorised subprocessors

SubprocessorPurposeLocationPersonal data received
Amazon Web Services EMEA SARLHosting, database, encrypted backupsEU (eu-west-3, Paris)All categories in clause 3
Cloudflare, Inc.DNS, TLS termination, CDNGlobal edgeTraffic metadata in transit
Microsoft Ireland Operations Ltd (Graph / 365)Transactional email deliveryEUName, email address
OpenRouter, Inc.Language model inferenceUSNone — catalogue text only
Groq, Inc.Language model inferenceUSNone — catalogue text only
Jina AI GmbHText embeddings for product searchEU / USNone — catalogue text only
FASHN AI, Inc.Virtual try-on renderingUSNone — product and model imagery only
Features and Labels, Inc. (fal.ai)Image background replacement and upscalingUSNone — product and model imagery only