Roles
You (the merchant or agency) are the controller of personal data in your workspace that concerns your staff and of any personal data that happens to sit inside catalogue content you supply (for example a person in a product photograph).
FeedGraph is the processor of that workspace data. We process it only to provide the platform, on your documented instructions: the product configuration, the consents you record, and the actions your members take.
FeedGraph is the controller of its own account, billing, security, and website data, as described in the Privacy Policy. This DPA does not cover that.
What is processed
Subject matter: operating a commerce catalogue, feed, creative, and advertising-intelligence workspace.
Duration: for as long as the workspace is active, then according to the retention classes below.
Nature: storage, sync, validation, optional AI enrichment and generation, feed publication, and aggregate performance import.
Personal data typically involved: member identity and contact; authentication artefacts; activity logs; encrypted third-party credentials; optional assistant and feedback content. Catalogue rows themselves are treated as commercial data about products. We do not require customer or order PII to run the product.
Your instructions
Connecting a store or ad account, choosing an import scope, approving an enrichment, publishing a feed, and recording or withdrawing consent in Settings → Privacy are instructions.
We will not use processor data for our own purposes, sell it, or train shared models on it. If a legal demand would require us to process outside your instructions, we will tell you unless the law prohibits that notice.
Subprocessors
We use the following active subprocessors. You authorise them for the purposes listed. Optional AI and channel vendors only receive data when you use those features.
Security measures
Measures are documented on the Security page and include: OAuth-scoped connections; encrypted storage of third-party tokens; SHA-256 hashed API keys with scopes and optional expiry; HMAC-SHA256 signed webhooks; Ed25519 signatures on high-assurance event streams; workspace roles enforced server-side; human approval before AI writes land; an immutable change history that can be reverted.
A staff erasure anonymises actor columns on the audit trail rather than deleting the event, so SOC-style evidence and GDPR de-identification can both hold.
Assistance with rights and incidents
Export, erasure, and rectification for people in your workspace are available in Settings → Privacy, scoped to that workspace. Platform-wide requests are not offered to workspace admins because they would reach other tenants.
If we become aware of a personal-data breach affecting your workspace, we will notify you without undue delay and include the facts we have: what was involved, likely consequences, and measures taken or proposed.
Return and deletion
You can export catalogue and enrichment data at any time. Disconnecting Shopify revokes that integration immediately.
After a workspace is closed, we delete or anonymise processor data according to the retention classes in the Privacy Policy. Legally retained financial and consent-proof records age out on their own clocks rather than being kept indefinitely.
International transfers
Where a subprocessor is outside the EEA/UK, the transfer mechanism is the vendor SCCs (or adequacy where applicable), as listed against each subprocessor above.
How this document is used
These pages are the public DPA description. Enterprise evaluations can receive additional architecture detail under NDA via the contact form. A signed addendum, if we execute one, prevails over this page to the extent of any conflict.
This page describes how FeedGraph actually operates. It is written in plain language and pending external legal review. If something here conflicts with a signed order form or data processing addendum, the signed document wins.