Data Processing Agreement for Verba - Post-Purchase Surveys
Effective date: September 14, 2026
This Data Processing Agreement ("DPA") is part of the Verba Terms of Service between the merchant using Verba ("Merchant") and homedoctor LLC ("Processor", "we"). It applies whenever we process personal data about the Merchant's customers on the Merchant's behalf. If this DPA and the Terms of Service conflict, this DPA controls for personal data.
1. Roles
- The Merchant is the controller (under the GDPR and UK GDPR) and the business (under the CCPA) for its customers' personal data.
- homedoctor LLC is the processor and service provider. We process that data only to provide Verba to the Merchant.
2. Details of the processing
| Item | Description |
|---|---|
| Subject matter | Running post-purchase surveys on the Merchant's Shopify store and reporting the results |
| Duration | For as long as the Merchant has Verba installed, then until the data is deleted as described in section 8 |
| Nature and purpose | Showing surveys, storing answers against orders, analytics, exports, AI features the Merchant uses, and sending data to services the Merchant connects |
| Data subjects | Customers of the Merchant's store who see or answer a survey |
| Personal data | Survey answers (including free text), order identifier and order name, order total and currency, first order flag, the order email address on completed responses, and response timestamps |
| Sensitive data | None intended. The Merchant agrees not to collect it through surveys |
3. Our obligations
We will:
- Process personal data only on the Merchant's documented instructions. The Merchant's use and configuration of Verba are its instructions. If we believe an instruction breaks data protection law, we'll tell the Merchant.
- Make sure anyone who can access the data is bound by confidentiality. Today only the owner of homedoctor LLC has that access.
- Protect the data with the security measures in section 4.
- Help the Merchant respond to requests from its customers to access, correct, or delete their data. Verba handles Shopify's customer data request and customer deletion request webhooks as described in the Privacy Policy.
- Help the Merchant with data protection impact assessments and regulator consultations where the processing requires it, using information we reasonably have.
- Not sell the personal data, not share it for cross-context behavioral advertising, and not combine it with data from other merchants or sources, except as the CCPA allows for a service provider.
4. Security measures
- Data encrypted in transit (HTTPS only) and at rest (encrypted storage volume).
- Klaviyo API keys and webhook signing secrets encrypted with AES-256-GCM. API keys and connected app tokens stored only as one-way hashes.
- Every request is limited to one store. The survey block is checked with a token signed by Shopify, and admin pages use Shopify's authenticated sessions.
- Two-factor authentication on the hosting, source code, Shopify Partner, and AI provider accounts, with access limited to the owner.
- Daily encrypted snapshots of the database volume, kept for 5 days.
- Unanswered survey responses deleted after 90 days.
5. Subprocessors
The Merchant authorizes these subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Fly.io, Inc. | Hosting for the app and database | United States (US East, Ashburn, Virginia) |
| Anthropic, PBC | AI features the Merchant uses (chat, Content Studio, Demand Lab, Recovery) | United States |
We will give the Merchant at least 30 days' notice by email before adding or replacing a subprocessor. The Merchant can object on reasonable data protection grounds, and if we can't resolve the objection, the Merchant can uninstall Verba. We will bind each subprocessor to data protection terms at least as protective as this DPA, and we remain responsible for their work.
Services the Merchant connects itself, such as Klaviyo, webhook endpoints, API clients, and AI assistants like Claude, are not our subprocessors. The Merchant chooses to send data to them.
6. Personal data breaches
If we become aware of a breach affecting the Merchant's personal data, we will notify the Merchant without undue delay, and within 72 hours where feasible. We will share what we know about the breach, the data and customers affected, the likely consequences, and the steps we are taking, and we will keep the Merchant updated.
7. International transfers
Verba stores and processes data in the United States. Where the GDPR or UK GDPR applies to a transfer, the parties agree to the European Commission's Standard Contractual Clauses (Module 2, controller to processor) and, for the UK, the UK International Data Transfer Addendum, which are incorporated by reference. For the Standard Contractual Clauses:
- Clause 7 (docking clause) applies.
- Clause 9: option 2 (general written authorization) applies, and we will give the Merchant at least 30 days' notice of any new subprocessor.
- Clause 11: the optional language does not apply.
- Clause 17: option 1 applies, and the clauses are governed by the law of Ireland.
- Clause 18: disputes are resolved by the courts of Ireland.
- Annex I is completed by Sections 1 and 2 of this agreement, Annex II by Section 4, and Annex III by Section 5.
For the UK Addendum, Table 1 is completed with the parties' details above, Tables 2 and 3 refer to the Standard Contractual Clauses as completed here, and in Table 4 neither party may end the Addendum when the approved Addendum changes.
8. Deletion and return of data
- The Merchant can export survey responses as CSV at any time and delete surveys in the app.
- When the Merchant uninstalls Verba, Shopify sends a shop deletion request 48 hours later, and we then delete all of the store's data. Copies in volume snapshots are overwritten within 5 days.
- We keep data longer only if the law requires it.
9. Audits
On written request, and no more than once a year unless a regulator requires it or a breach has occurred, we will provide information reasonably needed to show we meet this DPA. That can include written answers to security questionnaires. The Merchant pays its own audit costs.
10. Liability
Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the law doesn't allow those limits.
11. Contact
homedoctor LLC 145 E 16th Street, Apt 20D New York, NY 10003 phil@homedoctor.pro