Effective Date: 11th July, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Meta Mine, a limited liability company established in Bulgaria (European Union) ("Seokai", "we", "us"), and the merchant that installs or uses the Seokai application ("Merchant", "you"). It applies where Seokai processes personal data on your behalf in the course of providing the Seokai app, and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR. In the event of a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails.
1. Roles of the Parties
For personal data contained in your Shopify store content that you submit to the app for processing (for example, product, collection, page, and article text you ask us to analyse or optimise), you act as the controller and Seokai acts as your processor. For data we determine the purposes of ourselves — such as merchant account administration, billing, security, and product analytics — Seokai acts as a controller, and that processing is governed by our Privacy Policy rather than this DPA. Seokai does not access Shopify Protected Customer Data (we do not request access to your customers' or orders' personal data).
2. Subject Matter, Duration, Nature and Purpose
- Subject matter: processing of personal data as necessary to provide the Seokai SEO application and its features.
- Duration: for as long as the app is installed, plus any period required to complete deletion or return of data.
- Nature and purpose: generating, analysing, storing, and writing back SEO metadata and related content, including AI-assisted generation, embeddings for internal-link suggestions, and reporting.
3. Categories of Data Subjects and Personal Data
The personal data processed under this DPA is limited and incidental. It may include the identity and contact details of the merchant's staff members who use the app (name, email, Shopify user ID, locale) and any personal data that the merchant chooses to include in store content or in support messages submitted to us. No special categories of personal data, and no data relating to the merchant's own customers or orders, are processed under this DPA.
4. Seokai's Obligations
Seokai will:
- process personal data only on your documented instructions, including as set out in the Terms of Service and this DPA, unless required to do otherwise by EU or Member State law (in which case we will inform you unless legally prohibited);
- ensure that persons authorised to process the personal data are bound by confidentiality;
- implement appropriate technical and organisational measures as described in Section 7 (Article 32 GDPR);
- respect the conditions in Section 5 for engaging sub-processors;
- taking into account the nature of the processing, assist you by appropriate measures in responding to data subject rights requests;
- assist you in ensuring compliance with your obligations regarding security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36 GDPR);
- at your choice, delete or return the personal data at the end of the provision of services, as set out in Section 8; and
- make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits as set out in Section 9.
Where assistance requested under this Section requires effort beyond the self-service tools and standard functionality of the app, we may charge a reasonable fee for that assistance, and will tell you the expected cost before proceeding.
5. Sub-processors
You provide general authorisation for Seokai to engage sub-processors to provide the service. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Our sub-processors fall into the following categories:
- the Shopify platform (authentication, billing, and store data access);
- our AI provider, OpenAI (content generation via its API);
- cloud infrastructure providers (hosting, database, storage, email delivery, and error monitoring).
A current list naming our specific sub-processors is available on request. We will inform you of any intended addition or replacement of a sub-processor, giving you the opportunity to object on reasonable data protection grounds.
6. International Transfers
Personal data is primarily processed within the European Union. Where a sub-processor processes personal data outside the EEA or the UK (for example, in the United States), such transfers are made under an appropriate safeguard within the meaning of Chapter V GDPR — the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), and/or the sub-processor's certification under the EU–U.S. Data Privacy Framework where applicable.
7. Security Measures
Seokai maintains appropriate technical and organisational measures, including: encryption of data in transit (TLS) and encryption of sensitive fields at rest; access controls and authentication via Shopify OAuth; segregation of environments; short-lived, rate-limited handling of IP addresses; logging and monitoring; and least-privilege access to production systems. Measures are reviewed and updated as appropriate to the evolving risk.
8. Return and Deletion of Data
On uninstallation of the app, and in response to Shopify's shop/redact request, Seokai deletes your Shopify session and access tokens, staff and merchant identity and contact details, store content copies, image backups and exported files, support tickets, and content embeddings. Certain records with an accounting, legal, or non-personal analytics basis (such as billing, subscription, and usage history) are retained for the periods described in our Privacy Policy. Upon written request, we will confirm deletion.
9. Audit
Seokai will make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. Such information will ordinarily be provided in the form of existing documentation, policies, and, where available, third-party certifications or reports. An on-site inspection will be permitted only where strictly required by applicable data protection law or by a competent supervisory authority, and in that case is subject to at least thirty (30) days' prior written notice, confidentiality obligations, no more than once in any twelve (12) month period, being conducted during business hours without disrupting our operations, and being carried out at your cost.
10. Personal Data Breach
Seokai will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and will provide information reasonably available to assist you in meeting your notification obligations under Articles 33–34 GDPR.
11. Liability and Governing Law
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA is governed by the laws of the Republic of Bulgaria and applicable European Union law.
12. Contact
Data protection queries and requests under this DPA can be sent to support@seokai.ai, or to Meta Mine, Burgas 8018, Bulgaria.