Data Processing Agreement
In effect from: August 14, 2026
This Data Processing Addendum ("DPA") governs the Processing of Personal Data by Quochi Tiziano, an Italian sole proprietorship operating under the trade name Jarbris ("Jarbris"), on behalf of the merchant using the Jarbris Services ("Customer" or "Controller").
This DPA forms an integral part of the Jarbris Terms of Service (the "Terms") and governs all Processing of Personal Data carried out by Jarbris as Processor on behalf of the Customer.
Where Jarbris Processes Personal Data on behalf of the Customer, the Customer acts as Data Controller ("Controller") and Jarbris acts as Data Processor ("Processor").
With respect to Personal Data Processing matters, this DPA prevails over the Terms to the extent of any conflict.
1. PARTIES AND ROLES
This DPA applies exclusively to Personal Data of the merchant's customers and end users that Jarbris Processes on behalf of the Customer.
Merchant data relating to the merchant's account, operators, billing, administration and activities for which Jarbris independently determines the purposes and means of Processing are processed by Jarbris as Controller and are governed by the Jarbris Privacy Policy and, where applicable, the Terms.
The Customer remains responsible for determining the purposes of Processing of its customers' data.
2. SUBJECT MATTER, NATURE AND DURATION
Jarbris Processes Personal Data as necessary to provide the features enabled by the Customer.
Processing may include:
- collection and import;
- synchronization;
- organization;
- structuring;
- storage;
- consultation;
- retrieval;
- indexing;
- search;
- classification;
- analysis;
- AI-based Processing;
- transmission;
- communication;
- automation; and
- deletion.
Processing may occur through the Jarbris widget, merchant dashboard, omnichannel inbox, email, Instagram, Messenger, Shopify integrations and other Services.
Processing continues for as long as Jarbris Processes Personal Data on behalf of the Customer, subject to retention required under this DPA or applicable law.
3. PURPOSES OF PROCESSING
Jarbris may Process Personal Data to:
- respond to customer requests;
- provide ecommerce assistance;
- search, select and recommend products;
- manage order and shipping information;
- support returns and refunds;
- manage abandoned-cart recovery;
- send and receive email communications;
- manage Instagram and Messenger conversations;
- execute authorized workflows and actions;
- provide customer memory and context;
- classify messages and interactions;
- generate preferences, profiles and derived information necessary for the Services;
- provide analytics and reporting;
- provide post-purchase functionality;
- maintain the security, reliability and integrity of the Services;
- prevent fraud, abuse and security incidents; and
- comply with applicable law.
4. CUSTOMER INSTRUCTIONS
Jarbris shall Process Personal Data only on documented instructions from the Customer.
Documented instructions include:
- this DPA;
- the Terms;
- Customer configurations;
- Customer authorizations;
- Customer policies, rules and workflows; and
- additional documented instructions compatible with the Services.
Where law requires Jarbris to Process Personal Data other than as instructed, Jarbris shall inform the Customer before such Processing unless legally prohibited.
If Jarbris considers a Customer instruction to violate Data Protection Law, Jarbris shall inform the Customer without undue delay.
5. CATEGORIES OF DATA SUBJECTS
Depending on the Services used, Personal Data may concern:
- customers of the Customer;
- store visitors;
- users interacting with Jarbris;
- persons contacting the Customer by email;
- persons contacting the Customer through Instagram or Messenger;
- purchasers and prospective purchasers;
- recipients of Customer communications;
- persons submitting order, return or refund requests; and
- other persons whose data is made available to Jarbris by the Customer.
6. CATEGORIES OF PERSONAL DATA
Depending on the features used, Jarbris may Process:
- name and surname;
- email address;
- telephone number;
- order history;
- purchased products and variants;
- cart information;
- chat content;
- inbound and outbound email content;
- Instagram and Messenger conversations;
- IP addresses;
- user-agent and device information;
- viewed pages and products;
- session and technical identifiers;
- consent information;
- return and refund requests;
- feedback;
- detected preferences and interests;
- size, price-band and brand preferences;
- customer profile;
- customer memory;
- message classifications;
- objections extracted from conversations; and
- other derived or inferred information generated through the Services.
Jarbris is not intended for the deliberate Processing of special categories of Personal Data under Article 9 GDPR.
The Customer shall not deliberately introduce such data into the Services unless the relevant feature expressly supports such Processing and the Processing is lawful.
Jarbris cannot guarantee that an end user will never incidentally enter such data into a free-text field.
7. CUSTOMER RESPONSIBILITIES
The Customer is responsible for:
- determining the purposes and means of Processing within its sphere of responsibility;
- establishing a valid legal basis;
- providing required notices to Data Subjects;
- ensuring that Personal Data may lawfully be provided to Jarbris;
- providing lawful instructions;
- properly configuring the Services;
- configuring permissions, policies, workflows and automation limits;
- complying with applicable law; and
- responding to Data Subject requests within its sphere of responsibility.
8. JARBRIS OBLIGATIONS
Jarbris shall:
- Process Personal Data only on documented Customer instructions, except where required by law;
- ensure authorized persons are bound by confidentiality obligations;
- implement appropriate technical and organizational measures;
- reasonably assist the Customer under Data Protection Law;
- assist with Data Subject requests;
- assist with Personal Data Breaches;
- make available information reasonably necessary to demonstrate compliance; and
- inform the Customer where Jarbris becomes aware of an instruction it considers contrary to applicable law.
9. CONFIDENTIALITY
Jarbris shall ensure that persons authorized to Process Personal Data:
- are bound by confidentiality obligations;
- access Personal Data only as necessary for their functions; and
- receive appropriate privacy and security instructions.
Confidentiality obligations survive termination to the extent required by law.
10. TECHNICAL AND ORGANIZATIONAL MEASURES
Jarbris implements appropriate technical and organizational measures.
Measures may include:
- TLS for data in transit;
- infrastructure encryption at rest;
- AES-256-GCM encryption of messaging-channel tokens;
- access controls;
- role-based permissions;
- store-level data isolation;
- webhook signature verification;
- rate limiting;
- input validation;
- input sanitization;
- structured logging;
- sensitive-data log redaction;
- error monitoring;
- CI/CD security controls;
- dependency vulnerability controls; and
- secret management.
Measures may be updated and improved over time provided the level of protection is not materially reduced.
11. PERSONAL DATA BREACHES
Where Jarbris becomes aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Customer, Jarbris shall notify the Customer:
without undue delay and in any event within 48 hours after becoming aware of the breach.
The initial notification may be partial where complete information is not yet available.
Missing information shall be provided subsequently without undue delay.
The notification shall contain, to the extent available:
- nature of the breach;
- categories of affected Personal Data;
- categories of affected Data Subjects;
- known or reasonably foreseeable consequences;
- measures taken or proposed; and
- contact information.
Notification to supervisory authorities and Data Subjects, where required, remains the Customer's responsibility.
12. SUBPROCESSORS
The Customer generally authorizes Jarbris to engage Subprocessors.
The current list is published in Jarbris privacy documentation:
https://jarbris.com/en/informativa-prodotto/#sub-responsabili
Jarbris Subprocessors may include:
- Railway;
- MongoDB Atlas;
- Sentry;
- Vercel;
- Google Gemini API;
- Pinecone;
- Resend.
Jarbris shall impose data protection obligations on Subprocessors substantially equivalent to those in this DPA to the extent required by law.
Jarbris remains responsible for its Subprocessors to the extent required by Data Protection Law.
13. NEW SUBPROCESSORS
Where Jarbris intends to add or replace a Subprocessor, it shall, where required by applicable law, provide at least 30 days' prior notice to the email address associated with the Customer's account.
The Customer may object on reasonable and documented grounds relating to the protection of Personal Data.
If the objection cannot reasonably be resolved, the Customer may terminate the affected Services under the Terms without a penalty specifically resulting from the objection, to the extent permitted by law.
14. META
For Instagram and Messenger integrations, Meta is treated for purposes of this DPA as the merchant's platform and an independent party for its own Processing, rather than as a Jarbris Subprocessor.
The merchant connects its own Meta assets using its own credentials and permissions and maintains its own contractual relationship with Meta.
Jarbris uses Meta APIs to provide the communication and omnichannel inbox features requested by the Customer.
Processing carried out by Meta for its own purposes under its own terms and notices remains separate from Processing carried out by Jarbris on behalf of the Customer.
At go-live, Meta integrations include:
- Instagram Messaging;
- Facebook Messenger.
WhatsApp is outside the scope of the Services at go-live.
The Facebook Login for Business configuration may change over time for technical or product reasons without requiring an amendment to this DPA, provided such changes do not create Processing incompatible with this DPA.
15. SHOPIFY
Shopify is the Customer's ecommerce platform and the relationship between the Customer and Shopify is separate from the Jarbris–Customer relationship governed by this DPA.
Jarbris may receive data from Shopify and synchronize data with Shopify as necessary to provide the Services, including:
- product catalogues;
- customer data;
- orders;
- refunds;
- carts;
- store policies and content;
- customer events; and
- other data made available through authorized integrations.
Jarbris Processes such data according to the Customer's instructions.
Processing carried out by Shopify under its own terms and purposes remains separate from Processing carried out by Jarbris.
16. EMAIL AND RESEND
Resend is a Jarbris Subprocessor for email functionality.
Resend may be used for:
- sending email;
- receiving forwarded inbound email;
- managing email conversations;
- cart recovery;
- post-purchase communications; and
- merchant notifications.
Processed data may include:
- email addresses;
- message content;
- delivery-related metadata; and
- attachments.
Jarbris retains email conversations for 365 days under its retention rules.
Resend may apply its own technical retention periods under its applicable agreements and documentation.
17. ARTIFICIAL INTELLIGENCE
Jarbris uses the direct Google Gemini API for certain AI features.
Google may receive message content necessary to provide the relevant functionality.
Jarbris does not use Customer Data to train its own AI models.
Jarbris does not authorize the use of Customer Data for provider-model training to the extent prohibited by the applicable service agreements.
AI functionality may:
- interpret messages;
- classify requests;
- select and recommend products;
- generate responses;
- determine certain automated communications; and
- generate customer memory, classifications and derived information.
AI functionality available at go-live may operate without human review for supported categories and use cases.
Pinecone is used for semantic search. It does not receive customer conversation text in clear form; it may receive catalogue data and vector representations necessary for semantic search.
AI functionality is not designed to make decisions producing legal or similarly significant effects on Data Subjects under Article 22 GDPR.
18. DATA FOR SERVICE IMPROVEMENT
Jarbris does not use Customer Personal Data to train its own AI models.
Jarbris may use anonymous and aggregated data, not reasonably linkable to a merchant or Data Subject, for:
- statistics;
- aggregate analytics;
- benchmarking;
- aggregate performance measurement; and
- general Service improvement.
Jarbris may Process the minimum amount of information necessary for security, debugging and issue resolution.
19. RETENTION
The principal retention periods applied to Personal Data are:
| Category | Retention |
|---|---|
| Navigation events | 90 days |
| Website chats | 365 days after session closure |
| Email conversations | 365 days |
| Instagram / Messenger | 365 days from the last message |
| Feedback | 365 days |
| Consent Log | 3 years |
| Customer memory and profiling | for as long as necessary for the relevant feature and until deletion |
| Orders | as necessary for the Services and until deletion |
| Carts | as necessary for the Services and until deletion |
| Merchant account without linked stores | 30 days |
Technical logs may be retained according to their operational, security and legal requirements.
20. DELETION AND RETURN
Upon termination of the Services, Jarbris shall delete or return Personal Data in accordance with the Customer's instructions, unless retention is required by law.
For Shopify-related data, deletion may be initiated through Shopify GDPR mechanisms, including requests concerning individual customers and stores.
Jarbris may also handle Data Subject deletion requests through available privacy mechanisms.
A merchant account with no linked stores may be retained for 30 days before permanent deletion.
The Customer may request export of its data before deletion, where the functionality is available.
21. BACKUPS
Jarbris may maintain backup copies to support service continuity and recovery.
Personal Data contained in backups may remain available until the natural expiry of the technical retention period configured in the production infrastructure.
During that period:
- backup data is not used for purposes other than restoration;
- backup data is not ordinarily subject to routine Processing; and
- backup data remains protected by applicable security measures.
22. LEGAL RETENTION
Jarbris may retain certain information beyond normal retention periods where required or permitted by law, including for:
- tax and accounting obligations;
- fraud and abuse prevention;
- security;
- dispute management; and
- establishment, exercise or defense of legal claims.
Such retained data shall not be Processed for incompatible purposes.
23. DATA SUBJECT RIGHTS
Jarbris shall reasonably assist the Customer in responding to requests under Articles 15-22 GDPR.
Where Jarbris receives a request directly relating to Personal Data Processed on behalf of the Customer, Jarbris shall:
- notify the Customer without undue delay where legally permitted;
- not respond on the merits except where authorized or legally required; and
- provide reasonable assistance.
GDPR requests transmitted by Shopify are handled under the applicable verification and deletion mechanisms.
24. CUSTOMER ASSISTANCE
Taking into account the nature of the Processing and information available, Jarbris shall reasonably assist the Customer with:
- security of Processing;
- Personal Data Breaches;
- Data Subject requests;
- Data Protection Impact Assessments; and
- prior consultations with supervisory authorities, where applicable.
25. AUDITS AND COMPLIANCE INFORMATION
Jarbris shall make available the information reasonably necessary to demonstrate compliance with this DPA.
The Customer may conduct:
- documentary reviews;
- security questionnaires; and
- remote reviews.
Reviews shall be reasonable, proportionate and preceded by reasonable notice.
Unless required by law or following a material incident, ordinary reviews shall not occur more than once per year.
An on-site audit may be requested in exceptional circumstances, including a material Personal Data Breach or a justified request from a competent authority.
26. INTERNATIONAL DATA TRANSFERS
Some Jarbris Subprocessors may operate outside the EEA.
Where a transfer is subject to Chapter V GDPR, Jarbris shall use a legally valid mechanism, which may include:
- adequacy decisions;
- the EU-U.S. Data Privacy Framework, where applicable;
- the European Commission's Standard Contractual Clauses; or
- another lawful safeguard.
For transfers subject to the SCCs:
- Module 2 applies to Controller → Processor transfers, where applicable;
- Module 3 applies to Processor → Subprocessor transfers, where applicable; and
- the UK International Data Transfer Addendum applies where required for the United Kingdom.
The applicable SCCs and their completed annexes form part of the relevant transfer arrangement.
27. TERM AND AMENDMENTS
This DPA becomes effective when the Customer accepts the Terms and remains effective for as long as Jarbris Processes Personal Data on behalf of the Customer.
Jarbris may update this DPA where necessary to:
- comply with law;
- reflect changes to the Services;
- add or replace Subprocessors;
- improve security; or
- reflect technological or organizational changes.
Material changes shall be communicated in accordance with the Terms and applicable law.
Provisions that by their nature should survive termination remain effective, including confidentiality, security, deletion, retention and audit provisions.
28. CONTACTS
Quochi Tiziano — Jarbris Via D. Alighieri n. 1 — 81034 Mondragone (CE), Italy VAT No. 04970050615 REA CE-370173 Certified email (PEC): tizianoquochi@pec.it Privacy email: [privacy@jarbris.com](mailto:privacy@jarbris.com)
SCHEDULE 1 — PROCESSING DETAILS
Subject Matter: provision of the Jarbris Services.
Duration: for the duration of Processing on behalf of the Customer, plus applicable retention periods under this DPA or applicable law.
Nature: collection, synchronization, organization, storage, consultation, retrieval, indexing, search, classification, analysis, Processing, transmission, communication, automation and deletion.
Purposes: provision of the Services and performance of actions authorized by the Customer.
Data Subjects: customers, visitors, end users, purchasers, communication recipients and other individuals whose data is made available through the Services.
Data: identity and contact data, orders, purchases, carts, communications, technical data, interactions, consents, returns, refunds, preferences, memory, classifications, objections and derived information.
Special Categories: not intended for ordinary use and not to be deliberately introduced.
SCHEDULE 2 — SUBPROCESSORS
The current list is published in Jarbris privacy documentation:
https://jarbris.com/en/informativa-prodotto/#sub-responsabili
| Subprocessor | Function | Region |
|---|---|---|
| Railway | application infrastructure | EU |
| MongoDB Atlas | database | EU |
| Sentry | error monitoring | EU |
| Vercel | widget, dashboard and website delivery | United States |
| Google Gemini API | AI functionality | United States |
| Pinecone | semantic search | United States |
| Resend | United States |
Meta Platforms and Shopify are not classified as Jarbris Subprocessors under this DPA based on the relationship described in Sections 14 and 15.
SCHEDULE 3 — INTERNATIONAL DATA TRANSFERS
Where applicable:
- SCC Module 2 — Controller → Processor;
- SCC Module 3 — Processor → Subprocessor;
- UK International Data Transfer Addendum — where required.
The European Commission's official SCCs and their completed annexes form part of the relevant transfer arrangement.
SCHEDULE 4 — SECURITY MEASURES
Measures may include:
- TLS;
- encryption at rest;
- AES-256-GCM;
- RBAC;
- store-level isolation;
- webhook signature verification;
- rate limiting;
- input validation and sanitization;
- structured logging;
- sensitive-data redaction;
- monitoring;
- vulnerability scanning;
- CI/CD security gates;
- secret management; and
- deletion and privacy-request procedures.
SCHEDULE 5 — ORDER OF PRECEDENCE
In the event of a conflict between documents forming the Agreement, the following order applies:
- Standard Contractual Clauses, solely with respect to matters governed by those clauses and to the extent applicable;
- Data Processing Addendum, for matters relating to Personal Data Processing;
- Jarbris Terms of Service;
- Acceptable Use Policy; and
- other documentation expressly incorporated into the Agreement.
This order is intended to align with the order of precedence in the Terms, subject only to the special precedence of applicable SCCs in matters governed by them.