Legal

Data Processing Addendum

Last updated: 14 July 2026

This Data Processing Addendum (DPA) forms part of the Terms of Service between EMARKSS LTD and the merchant, and governs our processing of personal data on the merchant's behalf. It is written to satisfy Article 28 of the UK and EU GDPR. Installing or using Lumnya constitutes acceptance of this DPA; a countersigned copy is available on request at contact@lumnya.ai.

01Parties & roles

The merchant (“Controller”) determines the purposes and means of processing the personal data of its customers and staff. EMARKSS LTD, Company No. 16181893, 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE (“Processor”) processes that data solely to provide the Lumnya service.

Where EMARKSS processes merchant account data for its own purposes (billing, service communications), it does so as an independent controller under the Privacy Policy — that processing is outside this DPA.

02Subject matter, nature & purpose

Subject matter: personal data contained in the Controller's store and storefront conversations. Nature and purpose: hosting and storage; retrieval and analysis by AI models to answer shoppers and generate business recommendations; execution of actions approved by the Controller; audit logging; support. Duration: the term of the Controller's use of Lumnya, plus the deletion window below.

03Categories of data & data subjects

Data subjects: the Controller's customers and prospective customers (storefront visitors), and the Controller's staff who use the dashboard.

Categories of personal data: identification and contact data (name, email, address, phone) contained in orders and customer records; order and transaction data; chat messages and any content a shopper submits (including images); technical identifiers (session IDs). The service is not designed for, and the Controller agrees not to direct into it, special-category data (health, beliefs, biometrics, etc.) or data of children.

04Documented instructions

The Processor processes personal data only on the Controller's documented instructions — namely: the Terms of Service, this DPA, the Controller's configuration of the service, and the actions the Controller approves in the product — unless required to do otherwise by law, in which case the Processor will inform the Controller unless the law prohibits it. The Processor will inform the Controller if, in its opinion, an instruction infringes data-protection law.

05Confidentiality

Persons authorized to process the personal data (EMARKSS personnel) are bound by confidentiality obligations and receive access on a least-privilege basis. Operator access to production data is authenticated with multi-factor authentication and is logged.

06Security measures (Annex II summary)

Technical and organizational measures include: strict per-store (per-tenant) data isolation enforced in the data-access layer; encryption in transit (TLS 1.2+) and at rest; secrets management in a dedicated secret store with rotation; least-privilege service accounts; confirm-gating of consequential actions with a complete audit trail (actor, change, reasoning, timestamp); rate limiting and abuse controls on public endpoints; daily automated backups with a 30-day lifecycle and a tested restore procedure; point-in-time recovery on the primary database; error and uptime monitoring with alerting; and multi-factor authentication on operator accounts.

07Sub-processors

The Controller grants general authorization for the sub-processors listed in the Privacy Policy's sub-processor register (hosting, AI model providers, email delivery, monitoring, analytics). The Processor will update the register and give notice — via the changelog and, for material additions, by email — at least 14 days before a new sub-processor processes Controller data, during which the Controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service.

The Processor imposes data-protection obligations on each sub-processor materially equivalent to this DPA and remains liable for their performance. AI model providers are engaged under terms that prohibit training their models on Controller data.

08Data subject requests

Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organizational measures to fulfil data-subject requests (access, erasure, rectification, portability, objection). Requests arriving via Shopify's privacy webhooks (customers/data_request, customers/redact, shop/redact) are processed automatically. If a data subject contacts the Processor directly, the Processor will forward the request to the Controller without undue delay.

09Personal data breach

The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Controller data, providing the information reasonably required for the Controller's own notification obligations, and will cooperate in the investigation and remediation.

10Assistance & DPIAs

The Processor provides reasonable assistance to the Controller with data-protection impact assessments and prior consultations with supervisory authorities, insofar as they relate to processing under this DPA and the information is available to the Processor.

11Audits

The Processor makes available the information necessary to demonstrate compliance with this DPA, including this document, the sub-processor register, and summaries of security measures. Where that is insufficient, the Controller (or an independent auditor bound to confidentiality, not a competitor) may audit — limited to once per 12 months, on 30 days' notice, during business hours, at the Controller's cost, and without access to other merchants' data.

12International transfers

Processing takes place primarily on Google Cloud infrastructure in the United States. For transfers of UK/EEA personal data to third countries, the parties rely on: the EU–US Data Privacy Framework and its UK Extension where the recipient is certified; otherwise the EU Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK International Data Transfer Addendum, which are deemed incorporated into this DPA with EMARKSS's details as importer.

13Return & deletion

During the term, the Controller can export its data through the product (analytics and conversation exports). Upon uninstall or termination, the Processor deletes the Controller's workspace data within the timelines mandated by Shopify's shop/redact process, and in any event within 90 days, unless retention is required by law. Backup copies expire on the backup lifecycle (30 days) after deletion from the live system.

14Liability & precedence

Liability under this DPA is subject to the limitations of liability in the Terms of Service, except where data-protection law does not permit such limitation. If this DPA conflicts with the Terms of Service on data-protection matters, this DPA prevails; if the incorporated SCCs conflict with this DPA, the SCCs prevail.

Questions about this document? Write to contact@lumnya.ai. EMARKSS LTD · Company No. 16181893 · 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE.