Legal
Data Processing Agreement
Last updated: April 2026. This DPA supplements our Terms of Service and Privacy Policy for merchants subject to GDPR and similar data protection regulations.
1. Definitions
- "Data Controller" means you, the merchant, who determines the purposes and means of processing personal data.
- "Data Processor" means FilterIQ, which processes personal data on behalf of the Data Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined by Article 4(1) of the GDPR.
- "Sub-processor" means a third-party service provider engaged by FilterIQ to process personal data on behalf of the Data Controller.
- "Processing" means any operation performed on personal data, including collection, storage, use, modification, retrieval, disclosure, and erasure.
2. Scope of Processing
FilterIQ processes personal data solely for the purpose of providing search, filter, merchandising, and analytics services as described in our Terms of Service.
Types of personal data processed
Product data (which may include personal data if products are personalized), anonymized shopper search queries and click events, and merchant account information (store URL, name, email).
Categories of data subjects
Shoppers who use search and filter features on your store, and merchant account holders who configure the service.
Duration of processing
For the duration of the service agreement, plus up to 48 hours for data deletion after termination.
3. Data Processor Obligations
As Data Processor, FilterIQ undertakes to:
- Process personal data only on documented instructions from the Data Controller, except where required by applicable law.
- Ensure that all personnel authorized to process personal data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures as described in Section 5.
- Assist the Data Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, and objection).
- Notify the Data Controller without undue delay (and within 72 hours) upon becoming aware of a personal data breach.
- Delete or return all personal data upon termination of the service agreement, at the Data Controller's choice.
- Make available to the Data Controller all information necessary to demonstrate compliance with GDPR obligations.
4. Sub-processors
The Data Controller authorizes FilterIQ to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Primary database (PostgreSQL) for merchant accounts, configurations, and analytics | United States |
| Meilisearch SAS | Search engine hosting for product index and query processing | Europe (France) |
| Upstash Inc. | Redis caching and rate limiting | United States |
| Render Services Inc. | Backend API hosting and worker processes | United States |
| Vercel Inc. | Frontend hosting and edge functions | United States |
| OpenAI, L.L.C. | AI-powered filter generation and synonym suggestions — processes merchant catalog metadata (product titles, tags, vendors, product types) under OpenAI's Business Terms. Submitted prompts are not used to train OpenAI's models. OpenAI may retain prompts for up to 30 days for abuse-monitoring purposes, after which they are deleted. We are working to enable OpenAI's Zero Data Retention option before general availability of paid plans. | United States |
| Anthropic, PBC | AI-powered filter generation and synonym suggestions (alternate model provider) — processes merchant catalog metadata under Anthropic's Commercial Terms. Submitted inputs and outputs are not used to train Anthropic's models. Operational logs may be retained for safety review for up to 30 days under Anthropic's standard terms; we are working with Anthropic to enable Zero Retention before general availability of paid plans. | United States |
| Functional Software, Inc. (Sentry) | Application error monitoring and performance telemetry. Configured
with PII redaction (sendDefaultPii: false) so that
request bodies, headers, cookies, and IP addresses are not
transmitted. | European Union (Frankfurt) |
Future sub-processors: If and when FilterIQ activates Stripe-based billing for paid plans, Stripe Payments Europe Ltd. (Ireland) and Stripe, Inc. (United States) will be added to this table prior to charging any merchant.
We will notify you of any changes to sub-processors at least 30 days in advance via email, giving you the opportunity to object. If you reasonably object to a new sub-processor and we cannot accommodate your objection, you may terminate the service agreement without penalty.
All sub-processors are bound by data processing agreements that provide protections at least equivalent to those in this DPA.
5. Security Measures
FilterIQ implements the following technical and organizational measures to protect personal data:
- Encryption in transit: All data transmitted between clients, APIs, and infrastructure providers uses TLS 1.3.
- Encryption at rest: Database and search index data is encrypted at rest using AES-256.
- Access controls: Role-based access controls with multi-factor authentication for all internal systems.
- Tenant isolation: Each merchant's data is isolated by their myshopify domain. All database queries and search operations are scoped to the authenticated tenant.
- Incident response: Documented incident response procedures with breach notification within 72 hours.
- Regular assessments: Periodic security reviews of infrastructure, dependencies, and access patterns.
6. Data Transfer Mechanisms
Where personal data is transferred outside the European Economic Area (EEA), we ensure adequate protections through:
- Standard Contractual Clauses (SCCs): We use the European Commission's approved SCCs with all sub-processors located outside the EEA.
- Supplementary measures: Encryption, pseudonymization, and access controls serve as supplementary safeguards in accordance with the Schrems II ruling.
- Transfer impact assessments: We conduct transfer impact assessments for each sub-processor to evaluate the level of data protection in the recipient country.
7. Data Breach Notification
In the event of a personal data breach, FilterIQ will:
- Notify the Data Controller without undue delay and in any event within 72 hours of becoming aware of the breach.
- Provide the nature of the breach, including the categories and approximate number of data subjects and records affected.
- Describe the likely consequences of the breach and measures taken or proposed to address it.
- Cooperate with the Data Controller and supervisory authorities in investigating and resolving the breach.
8. Audits and Inspections
FilterIQ will make available to the Data Controller, upon reasonable request and subject to confidentiality obligations, all information necessary to demonstrate compliance with this DPA. FilterIQ will allow for and contribute to audits, including inspections, conducted by the Data Controller or an auditor mandated by the Data Controller, provided that such audits are conducted with reasonable notice (at least 30 days) and do not unreasonably disrupt operations.
9. Term and Termination
This DPA is effective for as long as FilterIQ processes personal data on behalf of the Data Controller. Upon termination of the service agreement, FilterIQ will delete all personal data within 48 hours, unless applicable law requires longer retention. FilterIQ will certify the deletion of personal data upon request.
10. Contact
For questions about this DPA, to request a signed copy, or to report a data protection concern, contact us at privacy@filteriq.app.
For general legal inquiries, contact legal@filteriq.app.