Effective date: August 26, 2026
Processor: K1 Apps LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA
Controller: the Shopify merchant installing the App ("you")
Contact: privacy@k1apps.com
This Addendum ("DPA") forms part of the Terms and Conditions for K1 ChatGPT and Claude MCP (the "App") and applies where K1 processes personal data on your behalf. On any conflict about personal data, this DPA prevails over the Terms.
1.1 For Store Data, including your customers' personal data, you are the controller and K1 is the processor. For merchant account, organization, billing and audit data, K1 is an independent controller and this DPA does not apply to it; the Privacy Policy does.
1.2 K1 processes personal data only on your documented instructions. The following constitute your instructions: the Terms; this DPA; your configuration of the App, including which Stores you link, which operations each Access Key permits, and whether an Access Key returns personal data masked or in full; and each request your AI Assistant makes through the endpoint using an Access Key you created.
1.3 K1 will inform you if, in its opinion, an instruction infringes applicable data protection law, and may suspend the affected processing until the instruction is amended.
1.4 Transmission to an AI Provider is a documented instruction, and the AI Provider is not K1's sub-processor. By creating an Access Key you instruct K1 to transmit Store Data, within that key's permissions, to the AI Assistant that presents it. That assistant is operated by an AI Provider under your account and your agreement with them. K1 has no contract with that provider covering your data, exercises no control over their retention, human review or model training, and cannot recall data once transmitted. You are responsible for having a lawful basis and, where required, a data processing agreement with that provider. This clause is the central allocation of responsibility in this DPA and you should not sign it without reading it.
K1 processes personal data to authenticate requests, evaluate the permissions of an Access Key, read from and write to your Shopify store as instructed, relay the result to your AI Assistant, and record the operation in the audit journal. Processing lasts for the term of the Terms, subject to §10.
Data subjects: your customers and prospective customers; visitors whose data appears in your store records; your staff who administer the App.
Categories of personal data: identifiers (customer ID, order ID); name; email address; telephone number; postal and shipping address; order and fulfilment history; amounts and currencies; notes, tags and metafields you have created, whose contents you control; and, for your staff, the Shopify identity used to administer the App.
Special categories: none are required by the App. If you place special-category data in fields the App can read — a customer note, a metafield — it will be read and transmitted like any other field. Do not do this unless you have a lawful basis and have set the relevant Access Keys accordingly.
Frequency: continuous, on request.
K1 ensures that persons authorised to process personal data are bound by confidentiality obligations that survive the end of their engagement, are informed of the confidential nature of the data, and receive access only to the extent their role requires.
K1 implements the technical and organisational measures in Annex II, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing as well as the risk to data subjects. K1 may update those measures provided the level of protection is not reduced.
6.1 You give general authorisation for K1 to engage the sub-processors listed in the Privacy Policy Appendix.
6.2 K1 will give at least 30 days' notice, by email or in the App, before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, you may terminate the affected part of the App and receive a pro-rata refund of prepaid fees for the unused period.
6.3 K1 imposes on each sub-processor data protection obligations no less protective than this DPA and remains liable for their performance.
6.4 As stated in §1.4, an AI Provider you connect is not a sub-processor of K1, and this section does not apply to it.
7.1 K1 hosts the App in the European Union and is established in the United States.
7.2 Where K1 transfers personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) — Module 2 for controller-to-processor transfers and Module 3 for processor-to-sub-processor transfers — as incorporated in Annex III, and by the UK International Data Transfer Addendum (IDTA) or the UK Addendum to the EU SCCs for UK-subject data.
7.3 Transfers to an AI Provider you connect are made on your instruction and are governed by your own arrangements with that provider (§1.4).
8.1 K1 assists you, at your cost where the assistance is substantial, in meeting your obligations to respond to data subject requests, taking into account the nature of the processing.
8.2 If K1 receives a request directly from a data subject relating to your Store Data, it will not respond substantively but will refer the data subject to you and inform you without undue delay.
8.3 K1 honours the Shopify privacy webhooks customers/data_request, customers/redact and shop/redact. Because Store Data is not retained, the practical scope of a redaction request against K1 is the audit journal.
8.4 K1 does not sell personal data and does not share it for cross-context behavioural advertising. Global Privacy Control and equivalent opt-out signals are therefore not applicable to K1's processing under this DPA; where they apply to your storefront, they remain your responsibility.
9.1 K1 notifies you without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and in any event in time to allow you to meet your own notification deadlines.
9.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where the information is not all available at once, K1 provides it in phases without further undue delay.
9.3 K1 maintains an incident response procedure covering detection, containment, eradication, recovery and post-incident review, and cooperates with you in investigating and remediating a breach.
9.4 A breach at an AI Provider you connect is outside K1's control and outside this section.
10.1 On termination, and at your written request at any time, K1 deletes or returns personal data processed on your behalf, and deletes existing copies, except where retention is required by law.
10.2 Without a request, deletion follows the retention schedule in the Privacy Policy: tokens and sessions are deleted when the Store is unlinked or the App uninstalled; audit journal entries are deleted 12 months after the operation; an Organization is deleted 30 days after its last Store leaves; billing records are retained for 7 years as a legal obligation.
10.3 K1 certifies deletion in writing on request.
K1 provides you, on request, with the information reasonably necessary for a data protection impact assessment or a prior consultation with a supervisory authority, and makes available the information necessary to demonstrate compliance with Article 28 GDPR. Audits are satisfied in the first instance by K1's documentation and written responses; an on-site audit may be requested no more than once in twelve months, on 30 days' notice, at your cost, subject to confidentiality and to not compromising other customers' data — unless a supervisory authority requires otherwise.
12.1 K1's access to your Store Data derives from the Shopify permissions you grant at install. Reducing those permissions, or uninstalling the App, terminates that access.
12.2 K1 supports your Shopify obligations by: honouring the mandatory privacy webhooks (§8.3); recording operations performed through the endpoint in the audit journal so you can evidence what was done and by which Access Key; defaulting personal data in Access Keys to masked; and deleting tokens on uninstall.
12.3 Where Shopify's Protected Customer Data requirements impose obligations on K1 as an app partner, K1 complies with them; where they impose obligations on you as a merchant, they remain yours.
13.1 Each party's liability under this DPA is subject to the limitations in the Terms, except where applicable data protection law does not permit such limitation.
13.2 Nothing in this DPA limits a data subject's rights or a supervisory authority's powers. Where the SCCs apply and conflict with this DPA, the SCCs prevail.
13.3 This DPA is governed by the law stated in the Terms, save that where the SCCs apply their governing law is the law of Ireland, and disputes are resolved in the courts of Ireland, in accordance with Clause 17 and 18 of the SCCs. For UK-subject transfers, the UK Addendum's governing law and forum apply.
13.4 If a provision is unenforceable, the remainder stands and the parties will replace it with a valid provision of equivalent effect.
A. List of parties
B. Description of transfer
C. Competent supervisory authority
Determined under Clause 13 of the SCCs by the exporter's place of establishment. Where the exporter is not established in the EEA but has an Article 27 representative, that member state's authority; otherwise the authority of the member state where the data subjects are located.
K1 holds no third-party security certification and does not represent otherwise.
The EU Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 are incorporated by reference and apply to transfers described in §7, as follows:
For transfers of UK-subject personal data, the UK Addendum issued under section 119A of the Data Protection Act 2018 is incorporated, with the SCCs as the Approved EU SCCs, Tables 1 to 3 completed by the corresponding parts of this DPA, and Table 4 selecting neither party as entitled to end the Addendum under Section 19.
For transfers of Swiss-subject personal data, references to the GDPR are read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner is the competent authority, and "member state" includes Switzerland.