Jarbris

Data Processing Agreement

In effect from: August 14, 2026

This Data Processing Addendum ("DPA") governs the Processing of Personal Data by Quochi Tiziano, an Italian sole proprietorship operating under the trade name Jarbris ("Jarbris"), on behalf of the merchant using the Jarbris Services ("Customer" or "Controller").

This DPA forms an integral part of the Jarbris Terms of Service (the "Terms") and governs all Processing of Personal Data carried out by Jarbris as Processor on behalf of the Customer.

Where Jarbris Processes Personal Data on behalf of the Customer, the Customer acts as Data Controller ("Controller") and Jarbris acts as Data Processor ("Processor").

With respect to Personal Data Processing matters, this DPA prevails over the Terms to the extent of any conflict.

1. PARTIES AND ROLES

This DPA applies exclusively to Personal Data of the merchant's customers and end users that Jarbris Processes on behalf of the Customer.

Merchant data relating to the merchant's account, operators, billing, administration and activities for which Jarbris independently determines the purposes and means of Processing are processed by Jarbris as Controller and are governed by the Jarbris Privacy Policy and, where applicable, the Terms.

The Customer remains responsible for determining the purposes of Processing of its customers' data.

2. SUBJECT MATTER, NATURE AND DURATION

Jarbris Processes Personal Data as necessary to provide the features enabled by the Customer.

Processing may include:

Processing may occur through the Jarbris widget, merchant dashboard, omnichannel inbox, email, Instagram, Messenger, Shopify integrations and other Services.

Processing continues for as long as Jarbris Processes Personal Data on behalf of the Customer, subject to retention required under this DPA or applicable law.

3. PURPOSES OF PROCESSING

Jarbris may Process Personal Data to:

  1. respond to customer requests;
  2. provide ecommerce assistance;
  3. search, select and recommend products;
  4. manage order and shipping information;
  5. support returns and refunds;
  6. manage abandoned-cart recovery;
  7. send and receive email communications;
  8. manage Instagram and Messenger conversations;
  9. execute authorized workflows and actions;
  10. provide customer memory and context;
  11. classify messages and interactions;
  12. generate preferences, profiles and derived information necessary for the Services;
  13. provide analytics and reporting;
  14. provide post-purchase functionality;
  15. maintain the security, reliability and integrity of the Services;
  16. prevent fraud, abuse and security incidents; and
  17. comply with applicable law.

4. CUSTOMER INSTRUCTIONS

Jarbris shall Process Personal Data only on documented instructions from the Customer.

Documented instructions include:

Where law requires Jarbris to Process Personal Data other than as instructed, Jarbris shall inform the Customer before such Processing unless legally prohibited.

If Jarbris considers a Customer instruction to violate Data Protection Law, Jarbris shall inform the Customer without undue delay.

5. CATEGORIES OF DATA SUBJECTS

Depending on the Services used, Personal Data may concern:

6. CATEGORIES OF PERSONAL DATA

Depending on the features used, Jarbris may Process:

Jarbris is not intended for the deliberate Processing of special categories of Personal Data under Article 9 GDPR.

The Customer shall not deliberately introduce such data into the Services unless the relevant feature expressly supports such Processing and the Processing is lawful.

Jarbris cannot guarantee that an end user will never incidentally enter such data into a free-text field.

7. CUSTOMER RESPONSIBILITIES

The Customer is responsible for:

8. JARBRIS OBLIGATIONS

Jarbris shall:

  1. Process Personal Data only on documented Customer instructions, except where required by law;
  2. ensure authorized persons are bound by confidentiality obligations;
  3. implement appropriate technical and organizational measures;
  4. reasonably assist the Customer under Data Protection Law;
  5. assist with Data Subject requests;
  6. assist with Personal Data Breaches;
  7. make available information reasonably necessary to demonstrate compliance; and
  8. inform the Customer where Jarbris becomes aware of an instruction it considers contrary to applicable law.

9. CONFIDENTIALITY

Jarbris shall ensure that persons authorized to Process Personal Data:

Confidentiality obligations survive termination to the extent required by law.

10. TECHNICAL AND ORGANIZATIONAL MEASURES

Jarbris implements appropriate technical and organizational measures.

Measures may include:

Measures may be updated and improved over time provided the level of protection is not materially reduced.

11. PERSONAL DATA BREACHES

Where Jarbris becomes aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Customer, Jarbris shall notify the Customer:

without undue delay and in any event within 48 hours after becoming aware of the breach.

The initial notification may be partial where complete information is not yet available.

Missing information shall be provided subsequently without undue delay.

The notification shall contain, to the extent available:

Notification to supervisory authorities and Data Subjects, where required, remains the Customer's responsibility.

12. SUBPROCESSORS

The Customer generally authorizes Jarbris to engage Subprocessors.

The current list is published in Jarbris privacy documentation:

https://jarbris.com/en/informativa-prodotto/#sub-responsabili

Jarbris Subprocessors may include:

Jarbris shall impose data protection obligations on Subprocessors substantially equivalent to those in this DPA to the extent required by law.

Jarbris remains responsible for its Subprocessors to the extent required by Data Protection Law.

13. NEW SUBPROCESSORS

Where Jarbris intends to add or replace a Subprocessor, it shall, where required by applicable law, provide at least 30 days' prior notice to the email address associated with the Customer's account.

The Customer may object on reasonable and documented grounds relating to the protection of Personal Data.

If the objection cannot reasonably be resolved, the Customer may terminate the affected Services under the Terms without a penalty specifically resulting from the objection, to the extent permitted by law.

14. META

For Instagram and Messenger integrations, Meta is treated for purposes of this DPA as the merchant's platform and an independent party for its own Processing, rather than as a Jarbris Subprocessor.

The merchant connects its own Meta assets using its own credentials and permissions and maintains its own contractual relationship with Meta.

Jarbris uses Meta APIs to provide the communication and omnichannel inbox features requested by the Customer.

Processing carried out by Meta for its own purposes under its own terms and notices remains separate from Processing carried out by Jarbris on behalf of the Customer.

At go-live, Meta integrations include:

WhatsApp is outside the scope of the Services at go-live.

The Facebook Login for Business configuration may change over time for technical or product reasons without requiring an amendment to this DPA, provided such changes do not create Processing incompatible with this DPA.

15. SHOPIFY

Shopify is the Customer's ecommerce platform and the relationship between the Customer and Shopify is separate from the Jarbris–Customer relationship governed by this DPA.

Jarbris may receive data from Shopify and synchronize data with Shopify as necessary to provide the Services, including:

Jarbris Processes such data according to the Customer's instructions.

Processing carried out by Shopify under its own terms and purposes remains separate from Processing carried out by Jarbris.

16. EMAIL AND RESEND

Resend is a Jarbris Subprocessor for email functionality.

Resend may be used for:

Processed data may include:

Jarbris retains email conversations for 365 days under its retention rules.

Resend may apply its own technical retention periods under its applicable agreements and documentation.

17. ARTIFICIAL INTELLIGENCE

Jarbris uses the direct Google Gemini API for certain AI features.

Google may receive message content necessary to provide the relevant functionality.

Jarbris does not use Customer Data to train its own AI models.

Jarbris does not authorize the use of Customer Data for provider-model training to the extent prohibited by the applicable service agreements.

AI functionality may:

AI functionality available at go-live may operate without human review for supported categories and use cases.

Pinecone is used for semantic search. It does not receive customer conversation text in clear form; it may receive catalogue data and vector representations necessary for semantic search.

AI functionality is not designed to make decisions producing legal or similarly significant effects on Data Subjects under Article 22 GDPR.

18. DATA FOR SERVICE IMPROVEMENT

Jarbris does not use Customer Personal Data to train its own AI models.

Jarbris may use anonymous and aggregated data, not reasonably linkable to a merchant or Data Subject, for:

Jarbris may Process the minimum amount of information necessary for security, debugging and issue resolution.

19. RETENTION

The principal retention periods applied to Personal Data are:

CategoryRetention
Navigation events 90 days
Website chats 365 days after session closure
Email conversations 365 days
Instagram / Messenger 365 days from the last message
Feedback 365 days
Consent Log 3 years
Customer memory and profiling for as long as necessary for the relevant feature and until deletion
Orders as necessary for the Services and until deletion
Carts as necessary for the Services and until deletion
Merchant account without linked stores 30 days

Technical logs may be retained according to their operational, security and legal requirements.

20. DELETION AND RETURN

Upon termination of the Services, Jarbris shall delete or return Personal Data in accordance with the Customer's instructions, unless retention is required by law.

For Shopify-related data, deletion may be initiated through Shopify GDPR mechanisms, including requests concerning individual customers and stores.

Jarbris may also handle Data Subject deletion requests through available privacy mechanisms.

A merchant account with no linked stores may be retained for 30 days before permanent deletion.

The Customer may request export of its data before deletion, where the functionality is available.

21. BACKUPS

Jarbris may maintain backup copies to support service continuity and recovery.

Personal Data contained in backups may remain available until the natural expiry of the technical retention period configured in the production infrastructure.

During that period:

22. LEGAL RETENTION

Jarbris may retain certain information beyond normal retention periods where required or permitted by law, including for:

Such retained data shall not be Processed for incompatible purposes.

23. DATA SUBJECT RIGHTS

Jarbris shall reasonably assist the Customer in responding to requests under Articles 15-22 GDPR.

Where Jarbris receives a request directly relating to Personal Data Processed on behalf of the Customer, Jarbris shall:

GDPR requests transmitted by Shopify are handled under the applicable verification and deletion mechanisms.

24. CUSTOMER ASSISTANCE

Taking into account the nature of the Processing and information available, Jarbris shall reasonably assist the Customer with:

25. AUDITS AND COMPLIANCE INFORMATION

Jarbris shall make available the information reasonably necessary to demonstrate compliance with this DPA.

The Customer may conduct:

Reviews shall be reasonable, proportionate and preceded by reasonable notice.

Unless required by law or following a material incident, ordinary reviews shall not occur more than once per year.

An on-site audit may be requested in exceptional circumstances, including a material Personal Data Breach or a justified request from a competent authority.

26. INTERNATIONAL DATA TRANSFERS

Some Jarbris Subprocessors may operate outside the EEA.

Where a transfer is subject to Chapter V GDPR, Jarbris shall use a legally valid mechanism, which may include:

For transfers subject to the SCCs:

The applicable SCCs and their completed annexes form part of the relevant transfer arrangement.

27. TERM AND AMENDMENTS

This DPA becomes effective when the Customer accepts the Terms and remains effective for as long as Jarbris Processes Personal Data on behalf of the Customer.

Jarbris may update this DPA where necessary to:

Material changes shall be communicated in accordance with the Terms and applicable law.

Provisions that by their nature should survive termination remain effective, including confidentiality, security, deletion, retention and audit provisions.

28. CONTACTS

Quochi Tiziano — Jarbris Via D. Alighieri n. 1 — 81034 Mondragone (CE), Italy VAT No. 04970050615 REA CE-370173 Certified email (PEC): tizianoquochi@pec.it Privacy email: [privacy@jarbris.com](mailto:privacy@jarbris.com)

SCHEDULE 1 — PROCESSING DETAILS

Subject Matter: provision of the Jarbris Services.

Duration: for the duration of Processing on behalf of the Customer, plus applicable retention periods under this DPA or applicable law.

Nature: collection, synchronization, organization, storage, consultation, retrieval, indexing, search, classification, analysis, Processing, transmission, communication, automation and deletion.

Purposes: provision of the Services and performance of actions authorized by the Customer.

Data Subjects: customers, visitors, end users, purchasers, communication recipients and other individuals whose data is made available through the Services.

Data: identity and contact data, orders, purchases, carts, communications, technical data, interactions, consents, returns, refunds, preferences, memory, classifications, objections and derived information.

Special Categories: not intended for ordinary use and not to be deliberately introduced.

SCHEDULE 2 — SUBPROCESSORS

The current list is published in Jarbris privacy documentation:

https://jarbris.com/en/informativa-prodotto/#sub-responsabili

SubprocessorFunctionRegion
Railway application infrastructure EU
MongoDB Atlas database EU
Sentry error monitoring EU
Vercel widget, dashboard and website delivery United States
Google Gemini API AI functionality United States
Pinecone semantic search United States
Resend email United States

Meta Platforms and Shopify are not classified as Jarbris Subprocessors under this DPA based on the relationship described in Sections 14 and 15.

SCHEDULE 3 — INTERNATIONAL DATA TRANSFERS

Where applicable:

The European Commission's official SCCs and their completed annexes form part of the relevant transfer arrangement.

SCHEDULE 4 — SECURITY MEASURES

Measures may include:

SCHEDULE 5 — ORDER OF PRECEDENCE

In the event of a conflict between documents forming the Agreement, the following order applies:

  1. Standard Contractual Clauses, solely with respect to matters governed by those clauses and to the extent applicable;
  2. Data Processing Addendum, for matters relating to Personal Data Processing;
  3. Jarbris Terms of Service;
  4. Acceptable Use Policy; and
  5. other documentation expressly incorporated into the Agreement.

This order is intended to align with the order of precedence in the Terms, subject only to the special precedence of applicable SCCs in matters governed by them.