Data Processing Agreement for Verba - Post-Purchase Surveys

Effective date: September 14, 2026

This Data Processing Agreement ("DPA") is part of the Verba Terms of Service between the merchant using Verba ("Merchant") and homedoctor LLC ("Processor", "we"). It applies whenever we process personal data about the Merchant's customers on the Merchant's behalf. If this DPA and the Terms of Service conflict, this DPA controls for personal data.

1. Roles

2. Details of the processing

Item Description
Subject matter Running post-purchase surveys on the Merchant's Shopify store and reporting the results
Duration For as long as the Merchant has Verba installed, then until the data is deleted as described in section 8
Nature and purpose Showing surveys, storing answers against orders, analytics, exports, AI features the Merchant uses, and sending data to services the Merchant connects
Data subjects Customers of the Merchant's store who see or answer a survey
Personal data Survey answers (including free text), order identifier and order name, order total and currency, first order flag, the order email address on completed responses, and response timestamps
Sensitive data None intended. The Merchant agrees not to collect it through surveys

3. Our obligations

We will:

  1. Process personal data only on the Merchant's documented instructions. The Merchant's use and configuration of Verba are its instructions. If we believe an instruction breaks data protection law, we'll tell the Merchant.
  2. Make sure anyone who can access the data is bound by confidentiality. Today only the owner of homedoctor LLC has that access.
  3. Protect the data with the security measures in section 4.
  4. Help the Merchant respond to requests from its customers to access, correct, or delete their data. Verba handles Shopify's customer data request and customer deletion request webhooks as described in the Privacy Policy.
  5. Help the Merchant with data protection impact assessments and regulator consultations where the processing requires it, using information we reasonably have.
  6. Not sell the personal data, not share it for cross-context behavioral advertising, and not combine it with data from other merchants or sources, except as the CCPA allows for a service provider.

4. Security measures

5. Subprocessors

The Merchant authorizes these subprocessors:

Subprocessor Purpose Location
Fly.io, Inc. Hosting for the app and database United States (US East, Ashburn, Virginia)
Anthropic, PBC AI features the Merchant uses (chat, Content Studio, Demand Lab, Recovery) United States

We will give the Merchant at least 30 days' notice by email before adding or replacing a subprocessor. The Merchant can object on reasonable data protection grounds, and if we can't resolve the objection, the Merchant can uninstall Verba. We will bind each subprocessor to data protection terms at least as protective as this DPA, and we remain responsible for their work.

Services the Merchant connects itself, such as Klaviyo, webhook endpoints, API clients, and AI assistants like Claude, are not our subprocessors. The Merchant chooses to send data to them.

6. Personal data breaches

If we become aware of a breach affecting the Merchant's personal data, we will notify the Merchant without undue delay, and within 72 hours where feasible. We will share what we know about the breach, the data and customers affected, the likely consequences, and the steps we are taking, and we will keep the Merchant updated.

7. International transfers

Verba stores and processes data in the United States. Where the GDPR or UK GDPR applies to a transfer, the parties agree to the European Commission's Standard Contractual Clauses (Module 2, controller to processor) and, for the UK, the UK International Data Transfer Addendum, which are incorporated by reference. For the Standard Contractual Clauses:

For the UK Addendum, Table 1 is completed with the parties' details above, Tables 2 and 3 refer to the Standard Contractual Clauses as completed here, and in Table 4 neither party may end the Addendum when the approved Addendum changes.

8. Deletion and return of data

9. Audits

On written request, and no more than once a year unless a regulator requires it or a breach has occurred, we will provide information reasonably needed to show we meet this DPA. That can include written answers to security questionnaires. The Merchant pays its own audit costs.

10. Liability

Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the law doesn't allow those limits.

11. Contact

homedoctor LLC 145 E 16th Street, Apt 20D New York, NY 10003 phil@homedoctor.pro