Data Processing Agreement
Last updated: 2026-06-24
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between TicketON (“Processor”, “we”, “us”) and the customer that uses the Service (“Merchant”, “Controller”, “you”). It applies where, and to the extent that, we process Personal Data on your behalf as a processor in connection with the Service and you are subject to the EU General Data Protection Regulation (“GDPR”), the UK GDPR, or comparable data-protection law. If there is a conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA prevails.
1. Definitions
“Controller”, “Processor”, “Personal Data”, “Processing”, “Data Subject”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data that we process on your behalf to provide the Service. “Sub-processor” means a third party engaged by us to process Customer Personal Data. “Standard Contractual Clauses” (“SCCs”) means the clauses approved by the European Commission for transfers of Personal Data to third countries.
2. Roles and scope
For Customer Personal Data, you are the Controller (or a processor acting on behalf of your own controller) and we are the Processor. We process Customer Personal Data only to provide and support the Service and only on your documented instructions, including as set out in the Terms, this DPA, and your use and configuration of the Service. We will inform you if, in our opinion, an instruction infringes applicable data-protection law (without obligation to monitor your instructions for legality).
3. Our obligations as Processor (GDPR Art. 28)
- Instructions. Process Customer Personal Data only on your documented instructions, including for international transfers, unless required by law (in which case we will inform you, unless legally prohibited).
- Confidentiality. Ensure that persons authorized to process Customer Personal Data are bound by confidentiality.
- Security. Implement appropriate technical and organizational measures under Art. 32 (see Annex 2).
- Sub-processors. Engage Sub-processors only under Section 4.
- Data-subject requests. Taking into account the nature of the processing, assist you with appropriate measures to respond to Data Subject requests under Chapter III of the GDPR. The Service also provides self-service tools (e.g., contact deletion/anonymization and, for Shopify, mandatory compliance webhooks) to help you fulfil such requests.
- Assistance. Assist you in ensuring compliance with Art. 32–36 (security, breach notification, data-protection impact assessments, prior consultation), taking into account the information available to us.
- Breach notification. Notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with information reasonably available to us.
- Deletion or return. At your choice, delete or return Customer Personal Data at the end of the provision of the Service, and delete existing copies unless storage is required by law.
- Audits. Make available information reasonably necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and security conditions.
4. Sub-processors
You give us general authorization to engage Sub-processors to process Customer Personal Data, provided that we impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Our current Sub-processors are listed in Annex 3. We will give you reasonable prior notice of any intended addition or replacement of a Sub-processor so that you can object on reasonable data-protection grounds.
5. International transfers and Standard Contractual Clauses
Where we or our Sub-processors process Customer Personal Data outside the EEA, the UK, or another jurisdiction recognized as providing adequate protection, the parties incorporate the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914, the “SCCs”) by reference, completed as follows:
- Module Two (controller-to-processor) applies where you act as a controller, and Module Three (processor-to-processor) where you act as a processor on behalf of your own controller;
- the optional docking clause (Clause 7) applies; the option under Clause 9(a) is general authorization with the notice period in Section 4; the option under Clause 11(a) (independent dispute resolution) does not apply;
- Annex I (parties and description of the transfer) and the competent supervisory authority are completed by Annex 1 of this DPA; Annex II (technical and organizational measures) by Annex 2; and the list of sub-processors by Annex 3.
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum applies to the SCCs. The official text of the SCCs is published by the European Commission. If there is any conflict between this DPA and the SCCs in respect of restricted transfers, the SCCs prevail.
6. Liability
Each party’s liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability set out in the Terms.
7. Governing law
This DPA is governed by the same law as the Terms, except where mandatory data-protection law requires otherwise.
Annex 1 — Details of the processing
- Subject matter: our provision of the TicketON Service to you.
- Duration: the term of the Terms, plus any period until Customer Personal Data is deleted or returned.
- Nature and purpose: operating an omnichannel customer-support platform — receiving, routing, storing, and responding to customer communications across channels; AI-assisted reply drafting, search, and content moderation; calls; notifications; and visitor analytics, all to provide the Service to you.
- Types of Personal Data: identity and contact details (name, email, phone); conversation content (messages and attachments, including photos, videos, and audio); online identifiers (user/account and device identifiers, IP address); approximate location (country/city from IP); and, where you connect a store, order and customer information.
- Categories of Data Subjects: your end-customers and website visitors, and your support agents (Operators).
- Competent supervisory authority (for the SCCs): the supervisory authority of the Controller’s main establishment in the EEA, or as otherwise determined under Clause 13 of the SCCs.
Annex 2 — Technical and organizational measures (Art. 32)
- Encryption of data in transit (HTTPS / TLS).
- Passwords stored hashed; support for two-factor authentication.
- Access controls and least-privilege access to production systems.
- Use of reputable cloud infrastructure with physical and network security.
- Logging and monitoring of relevant system activity.
- Data minimization and, where feasible, pseudonymization or anonymization.
- Regular backups and a documented incident-response process.
Annex 3 — Current Sub-processors
| Sub-processor | Purpose |
|---|---|
| OpenAI | AI processing of conversation / knowledge-base content (replies, embeddings, search, moderation) |
| Managed database hosting (Neon, on AWS — EU / Frankfurt) | Hosting our primary application database (operator and end-customer records) |
| Email delivery provider (Mailgun) | Sending transactional emails |
| IP-geolocation provider (IPInfo) | Deriving approximate location from IP address |
| Cloud hosting & object-storage providers | Hosting our systems and storing attachments and files |
| Real-time communications provider (LiveKit) | Audio / video call infrastructure |
| Apple (APNs) & Google (FCM) | Push-notification delivery |
| Shopify | Exchanging order / customer data where you connect a Shopify store |
Contact
For any question about this DPA or to exercise rights under it, contact [email protected].