In short
- This agreement covers the personal information HawkShift processes on your behalf when your store uses Concierge, such as a signed-in shopper’s orders.
- What shoppers share with Concierge, including their conversations and remembered preferences, is held by HawkShift for the shopper. You get insight combined across groups, not individual records.
- You decide how Concierge is used on your store. We process your shoppers’ information only to provide Concierge to you, and never sell it.
- We keep it secure, tell you about a breach without undue delay, help you answer shopper requests, and delete it when you stop using Concierge.
- It applies automatically as part of our Terms of Service. You don’t need to sign anything, though we will countersign a copy if you need one.
1. About this agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between HawkShift and the business that uses Concierge (“you”). It applies whenever HawkShift processes personal information on your behalf while providing Concierge, and it takes priority over the Terms on anything about personal information.
Words such as “controller”, “processor”, “personal data”, “data subject” and “service provider” mean what they mean in the data protection laws that apply to that processing, such as the EU and UK GDPR and the California Consumer Privacy Act (CCPA).
2. Roles
You are the controller (or “business”) for your store’s own customer records, such as customer accounts and orders, and HawkShift is your processor (or “service provider”) when Concierge uses them to serve a shopper. You decide that Concierge is used on your store and how it is set up.
There are two things we handle in our own right, and this DPA explains them so there is no surprise:
- What shoppers share with Concierge. A shopper’s conversations, the preferences they ask Concierge to remember, the prices and stock it watches for them and the alerts it sends, and the record of what Concierge did for them are held by HawkShift for that shopper, under our Privacy Policy. You don’t receive them and can’t instruct us to disclose them, including through a privacy request. You receive insight into what shoppers asked for, in categories and counts, never who asked, and never a shopper’s words, contact details or individual profile. This is what lets shoppers trust Concierge.
- Running a safe service. We may use information about how the service performs, in a form that doesn’t identify shoppers, to secure, maintain and improve Concierge.
3. What we process
4. Your instructions
We process personal information only on your documented instructions. Your instructions are the Terms, this DPA and the way you set up and use Concierge. If we believe an instruction breaks data protection law, we will tell you. If the law requires us to process personal information in another way, we will tell you first unless the law prevents it.
You are responsible for having a lawful basis to use Concierge with your shoppers, and for telling them about it in your own privacy notice.
5. No selling or sharing
We will not sell or share your shoppers’ personal information, as those words are used in the CCPA. We will not keep, use or disclose it for any purpose other than providing Concierge to you, or outside our direct business relationship with you, and we will not combine it with personal information from other sources except as the law permits. We don’t use one business’s data to benefit another business.
6. Our people
Everyone at HawkShift who can access personal information is bound by confidentiality and may access it only when needed to provide, support or secure Concierge.
7. Security
We protect personal information with technical and organisational measures appropriate to the risk, including:
- encryption of data in transit;
- separation between businesses, so one store’s data can’t be reached from another’s;
- access limited to what each store granted Concierge, and to the staff who need it;
- a record of every action Concierge takes for a shopper;
- built-in limits on what Concierge may remember, and automatic deletion of browser-only shopper memory after 180 days without use;
- signed, time-limited credentials between your store and Concierge.
8. Subprocessors
You authorise us to use other companies (“subprocessors”) to help provide Concierge, such as AI, hosting, storage and email providers, including backup or fallback providers. We will:
- give you the current list of subprocessors on request;
- bind each one by written terms that protect personal information at least as well as this DPA;
- tell you at least 30 days before we add or replace a subprocessor, so you can object on reasonable data protection grounds. If we can’t resolve your objection, you may stop using Concierge and we will refund any fees you paid in advance for the unused period;
- remain responsible for our subprocessors’ work;
- allow our subprocessors to use personal information only to provide their service to us, and never to train their own AI models.
9. Shopper requests
Your customer records stay in your store, and we don’t keep copies of them, so a shopper’s request to see or correct those records is yours to answer. If a shopper asks us about them, we will send them to you.
When you pass us a shopper’s request to see their data, for example through Shopify, we confirm that we hold no store records about that shopper for you, and give you a message telling them how to get what Concierge holds for them from us directly. When you tell us a shopper has been deleted from your store, we delete everything we hold for them on your store, including what we hold for the shopper. We will also help you respond to requests, taking into account what we can reasonably do, and help with data protection impact assessments and consultations with regulators where they concern Concierge.
10. Security incidents
If we become aware of a breach of security that leads to accidental or unlawful loss, change, disclosure of or access to your shoppers’ personal information, we will tell you without undue delay, and within 72 hours where possible. We will tell you what happened, what information is involved, what we are doing about it, and help you meet any duty you have to notify regulators or shoppers.
11. When you stop using Concierge
When you stop using Concierge, we delete the personal information we process for you, and everything we hold for shoppers on your store, within 30 days, unless the law requires us to keep it. Deleted information may remain in encrypted backups for a limited time until they expire.
12. Audits
We will give you the information you reasonably need to show that we meet this DPA. If that isn’t enough, you may audit our compliance once a year, with at least 30 days’ notice, during business hours, at your cost and under confidentiality, or more often if a regulator requires it.
13. International transfers
HawkShift processes personal information in the United States. Where the law of your country requires a transfer mechanism, such as the European Commission’s Standard Contractual Clauses or the UK Addendum, those clauses apply to the transfer and are incorporated into this DPA, with you as data exporter and HawkShift as data importer.
14. General
This DPA lasts as long as we process personal information for you. Each side’s liability under this DPA is subject to the limits in the Terms, as far as the law allows. We may update this DPA to reflect changes in the law or in Concierge, and we will not reduce the protection it gives your shoppers’ information without telling you in advance.
Need a signed copy for your records, or the list of subprocessors? Email hello@hawkshift.com.











