Last updated: July 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Cartio (“Processor”) and the merchant (“Controller”) and governs the processing of personal data carried out by Cartio on the Controller’s behalf.
The Controller determines the purposes and means of processing personal data. Cartio acts as a Processor and processes personal data only on documented instructions from the Controller, including as set out in the main agreement.
Cartio processes customer contact details, order and checkout information, and message/call metadata solely to provide cart recovery, customer support and related services. Processing lasts for the duration of the agreement.
Cartio may engage sub-processors (such as messaging, voice and cloud infrastructure providers) to deliver the services. Cartio remains responsible for their compliance and will impose data-protection obligations no less protective than those in this DPA.
Cartio maintains appropriate technical and organizational measures, including encryption in transit and at rest, access controls, and audit logging, designed to protect personal data against unauthorized access, loss or disclosure.
Cartio will assist the Controller, insofar as reasonably possible, in responding to requests from data subjects to exercise their rights, including access, correction, deletion and portability. Shopify GDPR webhooks for customer data requests and redaction are supported.
Cartio will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and will provide information reasonably required to meet the Controller’s notification obligations.
Upon termination of the services, Cartio will delete or return the Controller’s personal data, except where retention is required by applicable law.